Information Security Risk Specialist, Senior
Security Architect Job In Pittsburgh, PA
Information Security Risk Specialist, Senior
The Opportunity:
As an information security risk specialist on our team, you'll use your experience to work witha government clientto discover their cyber risks, understand applicable policies, and develop a mitigation plan. You'll review technical, environmental, and personnel details to assess the entire threat landscape. Then, you'll guide the Veterans Administration (VA) client through a plan of action with presentations, white papers, and milestones.
You'll work with your client to translate security concepts, so theycan make the best decisions to secure their mission critical systems and critical infrastructure. This is your opportunity to act as an information security subject matter expert while broadening your skills in Risk Management Framework and NIST Security and Privacy controls.Join us as we protect VA systems and data and provide a safer cyber environment for Veteran's healthcare.
Join us. The world can't wait.
You Have:
Experience with NIST special publications and FIPS
Experience with information security and assurance principles, including the NIST Cybersecurity Framework and RMF process
Experience with leading and coaching efforts involving presentations, SOPs, whitepapers, and change management processes
Experience with assessing NIST security and privacy controls and maintaining Plans of Action and Milestones (POA&Ms)
Experience with analyzing data from Governance Risk Compliance (GRC) tools, including eMASSorRiskVision to determine trends, root cause, and possible solutions
Experience with providing guidance for the NIST security and privacy controls and for providing sufficient documentation and artifacts for each control in the GRC tool
Experience in reviewing security requirements, recommending a mitigation strategy for deficiencies, and working directly with clients to provide solutionsand education
Experience with performingannual security reviews in accordance with FISMA reporting
Ability to obtain and maintain a Public Trust or Suitability/Fitness determination based on client requirements
Master's degree in CS, Engineering, or IT and 5+ years of experience with IT or 15+ years of experience with IT in lieu of a degree
Nice If You Have:
Experience with Privacy and Security control implementation, testing and assessment, and POAM management
Experience with using data analytical tools
Experience with the VA
Experience with scanning tools
Experience with creating formulas and data analysis in Excel
Possession of excellent customer service and organization skills
Possession of excellent verbal and written communication skills
Public Trust
CAP, CISSP, CISM, PMP, or CCSK Certification
Vetting:
Applicants selected will be subject to a government investigation and may need to meet eligibility requirements of the U.S. government client; Public Trust determination is required.
Create Your Career:
Grow With Us
Your growth matters to us-that's why we offer a variety of ways for you to develop your career. With professional and leadership development opportunities like , tuition reimbursement, mentoring, and firm-sponsored networking, you can chart a unique and fulfilling career path on your own terms.
A Place Where You Belong
Diverse perspectives cultivate collective ingenuity. means that, here, you are free to bring your whole self to work. With an array of business resource groups and other opportunities for connection, you'll build your community in no time.
Support Your Well-Being
Our includes wellness programs with HSA contributions, paid holidays, paid parental leave, a generous 401(k) match, and more. With these benefits, plus the option for flexible schedules and remote and hybrid locations, we'll support you as you pursue a balanced, fulfilling life-at work and at home.
Your Candidate Journey
At Booz Allen, we know our people are what propel us forward, and we value relationships most of all. so you'll know what to expect as we forge a connection with you during your journey as a candidate with us.
Compensation
At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page.
Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $73,000.00 to $166,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees.
Work Model
Our people-first culture prioritizes the benefits of flexibility and collaboration, whether that happens in person or remotely.
If this position is listed as remote or hybrid, you'll periodically work from a Booz Allen or client site facility.
If this position is listed as onsite, you'll work with colleagues and clients in person, as needed for the specific role.
EEO Commitment
We're an equal employment opportunity/affirmative action employer that empowers our people to fearlessly drive change - no matter their race, color, ethnicity, religion, sex (including pregnancy, childbirth, lactation, or related medical conditions), national origin, ancestry, age, marital status, sexual orientation, gender identity and expression, disability, veteran status, military or uniformed service member status, genetic information, or any other status protected by applicable federal, state, local, or international law.
RequiredPreferredJob Industries
Other
Deloitte Microsoft Technology Services Practice (DMTSP) - Security Pre-Sales Architect
Security Architect Job In Pittsburgh, PA
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Advisory Cloud Cyber Risk Services team and become a member of the largest group of Cyber Risk individuals worldwide.
Microsoft is an audit client for Deloitte - as a result, Deloitte does not and cannot have any form of alliance or partnership with Microsoft. Deloitte, however, can advise on and implement Microsoft products, and interact with Microsoft in certain ways in connection with these activities. When doing so, Deloitte and Microsoft must be sensitive to and mindful of the need for independence.
Recruiting for this role ends on 4.1.25
Work you'll do
As a DMTSP - Security Pre-Sales Architect, you will be at the front lines with our clients who have chosen the Microsoft technology platform and supporting them with their Cloud Cyber Risk needs specifically helping them navigate the journey on securing their Microsoft platform infrastructure such as Azure and Office 365 and the design and deployment of Microsoft Security solutions. This is a Deloitte services pre-sales role and not a project implementation role. This will include:
+ Lead or support proposals and/or also function as proposal lead architect with services potentially including the following Microsoft technologies: Microsoft Defender for Cloud, Azure Policies, Purview, Intune, Sentinel, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM
+ Assist in business development activities such as defining scope of services, building resource estimates and related pricing, packaging proposals and supporting the delivery of the proposal to the client for security services at clients who may have selected Microsoft infrastructures.
+ Lead the delivery of cloud security analysis, recommendations and configurations of prospective clients' Microsoft Entra ID, Office 365 (O365), Exchange Online, Teams, OneDrive for Business, M365 Copilot and SharePoint Online environments based on Deloitte's Microsoft 365 Cyber Risk Framework. This can include leveraging security solutions services which may include Microsoft's technology products such as Entra, Purview, Defender, Intune, and Sentinel.
+ Support or lead the delivery of Cyber Security workshops with clients(remote/in-person) including building demo labs, PowerPoint decks and Deloitte best practice perspectives
+ Function as a Cyber security architect (experienced in applicable Microsoft technologies) supporting Deloitte project teams for practice development and eminence
+ Function as deep subject matter expert on Microsoft security and securing Microsoft solutions staying abreast of Gartner research and Microsoft product roadmaps and advising Deloitte teams and clients on new developments.
+ Function as the primary client day-to-day interface building rapport and trust with the client.
+ Perform technical health checks of client's Microsoft platforms/environments as part of client development activities prior to broader deployments.
+ When clients have expressed a desire to discuss Microsoft technologies, assist clients in a pre-sales role, with transitions to the Microsoft 365 security services such as solution setup and service configuration, focused on risk mitigation. Additional technologies include MFA, Conditional Access, Purview Compliance Manager, M365 Defender, Defender for O365, Defender for Cloud Apps (MDCA), Purview Information Protection (MPIP), Purview Data Loss Prevention (DLP).
+ Implement industry leading practices around M365 E5 cyber risks and cloud security for clients.
+ As part of the Deloitte Microsoft Technology Services security practice development and eminence activities; Design and develop cloud-specific security policies, standards and procedures e.g., O365 tenant management and configuration, identify management and access control, auditing and monitoring, security incident and event management, data protection (classification/labeling, DLP, encryption), user and administrator account management, SSO, conditional access controls and password/key management.
+ Provide internal technical training to Advisory personnel as needed.
+ Act as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune, Entra ID, Azure security, Microsoft Defender, and Microsoft Sentinel capabilities.
+ Lead the development of Point-of-Views (PoVs) on providing leading practices to our clients on Cyber, including the Microsoft security challenges they face.
+ Support talent process in the architect role such as for recruiting and coaching.
+ Function as an expert in CNAPP, CWPP and CSPM technologies and security risk frameworks relevant to cloud as well as the Microsoft Cloud Security Benchmark
The successful candidate will possess:
+ Strong critical thinking, analysis, and problem-solving skills
+ Strong written and oral communication skills
+ Experience working independently as well as collaboratively across large teams
The team
Deloitte Advisory's Cloud Cyber Risk team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive cyber risk programs. Join the team developing the future state of cyber risk solutions. Learn more about Deloitte Advisory's Cyber Risk Services practice.
Qualifications
Required:
+ 5+ years of experience in technical consulting, client problem solving, architecting and designing solutions in a consulting role with project leadership and/or architect experience with Microsoft technologies
+ 5+ years of hands-on technical experience with securing Microsoft 365 enterprise-level messaging and collaboration and/or Azure Infrastructure in implementation and operations.
+ 5+ years of hands-on technical experience with enterprise-level systems management systems such as SCCM, End point security and Intune and endpoint engineering (MEM) and mobile device management (MAM & MDM)) implementation or operations.
+ 5+ years of hands-on technical and project / professional experience enterprise-with at least two of the following technologies: Microsoft Endpoint Security Platforms (e.g. Defender for Endpoints and Defender for Servers), Microsoft Sentinel, Microsoft's email security platform (Defender for Office), Microsoft Purview, Azure security & Entra ID
+ Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
+ Limited sponsorship may be available
Preferred:
+ BA/BS Degree preferred. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
+ Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400, AZ 500),
+ Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA.
Ideally the following technical experience is a plus in any of the technologies below:
+ Microsoft Security Copilot
+ Defender for Vulnerabilities
+ Defender for Cloud Apps
+ Defender XDR
+ Experience with Azure data, analytics, or AI/ML services (Azure SQL, HDInsight, Databricks, Data Factory, Data Lake Storage, Azure Analysis Services, Synapse Analytics, Azure Machine Learning, etc.)
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $102,500.00 to $210,600.00.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Information for applicants with a need for accommodation:Hyperlink: ************************************************************************************************************
#DeloitteNDO, #SalesOpsGreenDot
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Enterprise Security Architect
Security Architect Job In Pittsburgh, PA
Enterprise Security Architect Duration: Full Time Interview mode: Inperson Brand new role Serve as a member of the enterprise architecture team, providing technical security insight that aligns with business objectives and security requirements. Establish and evangelize the security architecture (principles, policies, standards and patterns) to development groups, business groups and other stakeholders; Govern adherence to the architecture golden rules. Analyze gaps between current and target security architecture and develops plans to close the gaps.
Responsibilities:
Works with IT departments, information security architects, technical architects, data custodians, and governance groups to develop and update Client security policies, standards, procedures, and solutions for secure application architecture. Ensures that security practices are aligned with Client's overall business strategies.
Advises and drives the security maturity of the development lifecycle including secure coding and system security for operations. Recommends and implements changes in security procedures and practices using best-in-class information to ensure that Client is maintaining best-in-class security practices.
Maintains security by monitoring and ensuring compliance to standards, policies, and procedures; conducting incident response analyses; developing and conducting training programs. Conducts Penetration Test, Vulnerability, and Risk assessments to improve the security architecture and security product toolset.
Prepares system security reports by collecting, analyzing, and summarizing data and trends. Executes validation by external vendors.
Verifies security systems and network configurations by developing and implementing test scripts while monitoring adherence to standards in architecture, application design, development, and testing frameworks.
Qualifications
Qualifications:
Bachelor degree with Master preferred. Security certification required.
7 to 10 years of experience operating in a cloud environment (e.g. Azure, AWS, Rackspace) along with at least 5 years working in a dedicated information security role with a focus on Security Architecture for at least 3 years.
7 to 10 years of experience with PaaS, IaaS, SaaS, and/or mobile architecture
Solid experience with security hacking tools and techniques.
Solid understanding in application architectures and technology including web applications, mobile technology, identity and access management, security event and incident management as well as web security controls (e.g. Web Application Firewall, Database Activity Monitor, Distributed Denial of Service controls, etc.)
Extensive working knowledge of web application security best practices to include, but not limited to, Cloud Security Alliance controls matrix, OWASP Top 10.
Experience with compliance standards such as HIPAA, CMS, SOX, GLBA; as well as security frameworks such as SANS 20 CSC, CoBIT, or NIST.
Previous involvement with developing and/or maintaining an Enterprise Security Architecture. Familiarity with TOGAF is a plus
Strong understanding and experience of software development methodologies and life cycles
Excellent written and verbal communications skills required, with the ability to explain advanced concepts to audiences of varying levels
Can be counted on to exceed goals successfully, very bottom-line orientated while steadfastly pushes self and others for results.
Has working knowledge of web application security best practices to include, but not limited to, Cloud Security Alliance controls matrix, OWASP Top 10.
Demonstrated ability to make sound decisions using a mixture of analysis, wisdom, experience, and judgement coupled with a strong ability to learn on the fly (quickly learns new tasks, open to change).
Certifications, licenses or registrations: Security+, CISSP, CISA, CEH
Proven ability to organize/manage multiple priorities coupled with the flexibility to quickly adapt to ever-changing business needs.
Additional Information
All your information will be kept confidential according to EEO guidelines.
Sr. Information Security Manager
Security Architect Job In Murrysville, PA
Job TitleSr. Information Security ManagerJob Description
Sr. Information Security Manager - Murrysville, PA
The Integrated Supply Chain (ISC) Information Security Manager will be responsible for developing, implementing and monitoring a strategic and comprehensive IT security plans across multiple geographies and driving security in manufacturing sites, Distribution Centers, and warehouses across the US.
Your role:
Develop and implement robust OT (Operational Technology), Cloud, Network, IoT (Internet of Things) security strategies on ISC (Integrated Supply Chain) manufacturing process aligned with industry standards, such as establishing security architecture compliance with regulations (e.g., HIPAA, FDA) and deploy technologies like firewalls and OT IDS (Operational Tech. Intrusion Detection System) solutions for system segmentation and protection.
Leverage experience with OT technologies (e.g., Nozomi Guardian, Armis, Claroty) and perform vulnerability assessments by applying frameworks like MITRE ATT&CK and STRIDE for threat modeling and attack simulations, driving solutions to address security threats.
Identify, assess, and mitigate: Operational Tachnology (OT) Cloud, Network, IoT (Internet of Things) risk and/or threats on Integraged Supply Chain (ISC) manufacturing security through cross-functional collaboration, develop incident response plans, lead investigations, and implement corrective actions to address root causes of security breaches.
Secure supply chain systems by collaborating with vendors, conducting assessments, and enforcing compliance with security standards.
Build a culture of security through targeted training programs and stakeholder education.
You're the right fit if:
You have +10 years experience on developing and implementing cybersecurity strategies on manufacturing/ supply chain/ logistics environment.
Bachelor's in Computer Science, Information Technology and/or an equivalent academic field. Master's degree in a similar academic field is preferred.
You have a Cybers Security Certification such as CISSP, CISM, CISA, CIPP etc. preferred. Knowledge on MITRE Framework, IEC 62443/NIST 800:23 is preferred.
Your skills a thorough understanding of Security Management and Governance principles, along being able to deliver cross-cultural etiquette, customer-centric and collaborative mindset.
You must be able to successfully perform the following minimum Physical, Cognitive and Environmental job requirements with or without accommodation for this position.
How we work together
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week. Onsite roles require full-time presence in the company's facilities. Field roles are most effectively done outside of the company's main facilities, generally at the customers' or suppliers' locations.
This is an in office role.
About Philips
We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help improve the lives of others.
Learn more about our business.
Discover our rich and exciting history.
Learn more about our purpose.
Learn more about our commitment to diversity and inclusion.
Philips Transparency Details
The pay range for this position in Murrysville, PA is from $ 107,000. 00 to $154,000.00
The actual base pay offered may vary within the posted ranges depending on multiple factors including job-related knowledge/skills, experience, business needs, geographical location, and internal equity.
In addition, other compensation, such as an annual incentive bonus, sales commission or long-term incentives may be offered. Employees are eligible to participate in our comprehensive Philips Total Rewards benefits program, which includes a generous PTO, 401k (up to 7% match), HSA (with company contribution), stock purchase plan, education reimbursement and much more. Details about our benefits can be found here.
At Philips, it is not typical for an individual to be hired at or near the top end of the range for their role and compensation decisions are dependent upon the facts and circumstances of each case.
Additional Information
US work authorization is a precondition of employment. The company will not consider candidates who require sponsorship for a work-authorized visa, now or in the future.
Company relocation benefits
will not
be provided for this position. For this position, you must reside in
or
within commuting distance to Murrysville, PA.
#LI-PH1
#LI-OFFICE
This requisition is expected to stay active for 45 days but may close earlier if a successful candidate is selected or business necessity dictates. Interested candidates are encouraged to apply as soon as possible to ensure consideration.
Philips is an Equal Employment and Opportunity Employer/Disabled/Veteran and maintains a drug-free workplace.
Sr. Information Security Manager
Security Architect Job In Murrysville, PA
**Sr. Information Security Manager** **- Murrysville, PA** The Integrated Supply Chain (ISC) Information Security Manager will be responsible for developing, implementing and monitoring a strategic and comprehensive IT security plans across multiple geographies and driving security in manufacturing sites, Distribution Centers, and warehouses across the US.
**Your role:**
+ Develop and implement robust OT (Operational Technology), Cloud, Network, IoT (Internet of Things) security strategies on ISC (Integrated Supply Chain) manufacturing process aligned with industry standards, such as establishing security architecture compliance with regulations (e.g., HIPAA, FDA) and deploy technologies like firewalls and OT IDS (Operational Tech. Intrusion Detection System) solutions for system segmentation and protection.
+ Leverage experience with OT technologies (e.g., Nozomi Guardian, Armis, Claroty) and perform vulnerability assessments by applying frameworks like MITRE ATT&CK and STRIDE for threat modeling and attack simulations, driving solutions to address security threats.
+ Identify, assess, and mitigate: Operational Tachnology (OT) Cloud, Network, IoT (Internet of Things) risk and/or threats on Integraged Supply Chain (ISC) manufacturing security through cross-functional collaboration, develop incident response plans, lead investigations, and implement corrective actions to address root causes of security breaches.
+ Secure supply chain systems by collaborating with vendors, conducting assessments, and enforcing compliance with security standards.
+ Build a culture of security through targeted training programs and stakeholder education.
**You're** **the right fit if:**
+ You have +10 years experience on developing and implementing cybersecurity strategies on manufacturing/ supply chain/ logistics environment.
+ Bachelor's in Computer Science, Information Technology and/or an equivalent academic field. Master's degree in a similar academic field is preferred.
+ You have a Cybers Security Certification such as CISSP, CISM, CISA, CIPP etc. preferred. Knowledge on MITRE Framework, IEC 62443/NIST 800:23 is preferred.
+ Your skills a thorough understanding of Security Management and Governance principles, along being able to deliver cross-cultural etiquette, customer-centric and collaborative mindset.
+ You must be able to successfully perform the following minimum Physical, Cognitive and Environmental job requirements with or without accommodation for this position.
**How we work together**
We believe that we are better together than apart. For our office-based teams, this means working in-person at least 3 days per week. Onsite roles require full-time presence in the company's facilities. Field roles are most effectively done outside of the company's main facilities, generally at the customers' or suppliers' locations.
**This is an in office role.**
**About Philips**
We are a health technology company. We built our entire company around the belief that every human matters, and we won't stop until everybody everywhere has access to the quality healthcare that we all deserve. Do the work of your life to help improve the lives of others.
+ Learn more about our business.
+ Discover our rich and exciting history.
+ Learn more about our purpose.
+ Learn more about our commitment to diversity and inclusion.
**Philips Transparency Details**
The pay range for this position in Murrysville, PA is from $ 107,000. 00 to $154,000.00
The actual base pay offered may vary within the posted ranges depending on multiple factors including job-related knowledge/skills, experience, business needs, geographical location, and internal equity.
In addition, other compensation, such as an annual incentive bonus, sales commission or long-term incentives may be offered. Employees are eligible to participate in our comprehensive Philips Total Rewards benefits program, which includes a generous PTO, 401k (up to 7% match), HSA (with company contribution), stock purchase plan, education reimbursement and much more. Details about our benefits can be found here.
At Philips, it is not typical for an individual to be hired at or near the top end of the range for their role and compensation decisions are dependent upon the facts and circumstances of each case.
**Additional Information**
**US work authorization is a precondition of employment** . The company **will not** consider candidates who require sponsorship for a work-authorized visa, now or in the future.
Company relocation benefits **_will not_** be provided for this position. For this position, you must reside in **_or_** within commuting distance to **Murrysville, PA.**
**\#LI-PH1**
**\#LI-OFFICE**
It is the policy of Philips to provide equal employment and advancement opportunities to all colleagues and applicants for employment without regard to race, color, ethnicity, religion, gender, pregnancy/childbirth, age, national origin, sexual orientation, gender identity or expression, disability or perceived disability, genetic information, citizenship, veteran or military status or a person's relationship or association with a protected veteran, including spouses and other family members, marital or domestic partner status, or any other category protected by federal, state and/or local laws.
As an equal opportunity employer, Philips is committed to a diverse workforce. In order to ensure reasonable accommodation for individuals protected by Section 503 of the Rehabilitation Act of 1973, the Vietnam Veterans' Readjustment Act of 1974, and Title I of the Americans with Disabilities Act of 1990, applicants that require accommodation in the job application process may contact ************, option 5, for assistance.
Equal Employment and Opportunity Employer/Disabled/Veteran
Assistant AI Security Researcher
Security Architect Job In Pittsburgh, PA
Are you a cybersecurity and/or AI researcher who enjoys a challenge? Are you excited about pioneering new research areas that will impact academia, industry, and national security? If so, we want you for our team, where you'll collaborate to deliver high-quality results in the emerging area of AI security.
The CERT Division of the Software Engineering Institute (SEI) is seeking applicants for the AI Security Researcher role. Originally created in response to one of the first computer viruses -- the Morris worm - in 1988, CERT has remained a leader in cybersecurity research, improving the robustness of software systems, and in responding to sophisticated cybersecurity threats. Ensuring the robustness and security of AI systems is the next big challenge on the horizon, and we are seeking life-long learners in the fields of cybersecurity, AI/ML, or related areas, who are willing to cross-train to address AI Security.
The Threat Analysis Directorate, is a group of security experts focused on advancing the state of the art in AI security at a national and global scale. Our tasks include vulnerability discovery and assessments, evaluation of the effectiveness and robustness of AI systems, exploit discovery and reverse engineering, and identifying new areas where security research is needed. We participate in communities of network defenders, software developers and vendors, security researchers, AI practitioners, and policymakers.
You'll get a chance to work with elite AI and cybersecurity professionals, university faculty, and government representatives to build new methodologies and technologies that will influence national AI security strategy for decades to come. You will co-author research proposals, execute studies, and present findings and recommendations to our DoD sponsors, decision makers within government and industry, and at academic conferences. The SEI is a non-profit, federally funded research and development center (FFRDC) at Carnegie Mellon University.
What you'll do:
Develop state of the art approaches for analyzing robustness of AI systems.
Apply these approaches to understanding vulnerabilities in AI systems and how attackers adapt their tradecraft to exploit those vulnerabilities.
Reverse engineer malicious code in support of high-impact customers, design and develop new analysis methods and tools, work to identify and address emerging and complex threats to AI systems, and effectively participate in the broader security community.
Study and influence the AI security and vulnerability disclosure ecosystems.
Evaluate the effectiveness of tools, techniques and processes developed by industry and the AI security research community.
Uncover and shape some of the fundamental assumptions underlying current best practice in AI security.
Develop models, tools and data sets that can be used to characterize the threats to, and vulnerabilities in, AI systems, and publish those results. You will also use these results to aid in the testing, evaluation and transition of technologies developed by government-funded research programs.
Identify opportunities to apply AI to improve existing cybersecurity research.
Who you are:
You have BS in machine learning, cybersecurity, statistics, or related discipline.
You have an interest in AI/ML and cybersecurity with a penchant for intellectual curiosity and a desire to make an impact beyond your organization.
You have practical experience with applying cybersecurity knowledge toward vulnerability research, analysis, disclosure, or mitigation.
You have experience with advising on a range of security topics based on research and expert opinion.
You have familiarity with implementing and applying AI/ML techniques to solving practical problems.
You have familiarity with common AI/ML software packages and tools (e.g., Numpy, Pytorch, Tensorflow, ART).
You have knowledge or familiarity with reverse engineering tools (e.g. NSA Ghidra, IDA Pro)
You have experience with Python, C/C++, or low-level programming.
You have experience developing frameworks, methodologies, or assessments to evaluate effectiveness and robustness of technologies.
You have superb communication skills (oral and written), particularly regarding technical communications with non-experts.
You enjoy mentoring and cross-training others and sharing knowledge within the broader community.
Applicants with a solid technical background in AI/ML or cybersecurity, but not both, are encouraged to apply provided a strong desire to rapidly learn on the job.
You are able to:
Travel to various locations to support the SEI's overall mission. This includes within the SEI and CMU community, sponsor sites, conferences, and offsite meetings on occasion (5%).
You will be subject to a background check and will need to obtain and maintain a Department of Defense security clearance.
Why work here?
Join a world-class organization that continues to have a significant impact on software.
Work with cutting-edge technologies and dedicated experts to solve tough problems for the government and the nation.
Be surrounded by friendly and knowledgeable staff with broad expertise across AI/ML, cybersecurity, software engineering, risk management, and policy creation.
Get 8% monthly contribution for your retirement, without having to contribute yourself.
Get tuition benefits to CMU and other institutions for you and your dependent children.
Enjoy a healthy work/life balance with flexible work arrangements and paid parental and military leave.
Enjoy annual professional development opportunities; attend conferences and training or obtain a certification and get reimbursed for membership in professional societies.
Qualify for relocation assistance and so much more.
Joining the CMU team opens the door to an array of exceptional benefits.
Benefits eligible employees enjoy a wide array of benefits including comprehensive medical, prescription, dental, and vision insurance as well as a generous retirement savings program with employer contributions. Unlock your potential with tuition benefits, take well-deserved breaks with ample paid time off and observed holidays, and rest easy with life and accidental death and disability insurance.
Additional perks include a free Pittsburgh Regional Transit bus pass, access to our Family Concierge Team to help navigate childcare needs, fitness center access, and much more!
For a comprehensive overview of the benefits available, explore our Benefits page.
At Carnegie Mellon, we value the whole package when extending offers of employment. Beyond credentials, we evaluate the role and responsibilities, your valuable work experience, and the knowledge gained through education and training. We appreciate your unique skills and the perspective you bring. Your journey with us is about more than just a job; it's about finding the perfect fit for your professional growth and personal aspirations.
Are you interested in an exciting opportunity with an exceptional organization?! Apply today!
Location
Pittsburgh, PA
Job Function
Software/Applications Development/Engineering
Position Type
Staff - Regular
Full Time/Part time
Full time
Pay Basis
Salary
More Information:
Please visit “Why Carnegie Mellon” to learn more about becoming part of an institution inspiring innovations that change the world.
Click here to view a listing of employee benefits
Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
Statement of Assurance
Security Researcher
Security Architect Job In Pittsburgh, PA
Join a dynamic team of motivated individuals with deep collective experience throughout digital forensics, incident response, investigation, operations, and academic research. We seek individuals with strong interest in understanding and resolving technical challenges in the national security space.
Our group focuses on applied research into the functionality of emerging and already ubiquitous technologies at all constituent logical layers, from component-level aspects through system and software implementation to communication protocols. Concurrent with achieving this understanding, we examine the variation between expected and actual functionality that results from real-world implementation. Finally, in support of stakeholders throughout the US Government, we reason about and advise on the implications of our findings.
Qualified individuals will have a strong aptitude to reformulate open questions; devise creative solutions; deliver concise, rigorous prototype implementations; and clearly articulate this process in discussions, presentations, and formal reports. Recent examples of our work have included novel approaches to analyzing network traffic, reasoning about automated imaging analysis, and software implementation of novel file and format extraction techniques.
Requirements:
* BS in Computer Science or related quantitative discipline plus eight (8) years of related work experience; OR MS in the same fields with five (5) years of experience, OR PhD in the same fields with two (2) years of experien.
* Willingness to occasionally travel to customer sites, conferences, and offsite meetings. (10%)
* You will be subject to a background investigation and must be eligible to obtain and maintain a Department of Defense security clearance
Knowledge, Skills, and Abilities:
* Deep technical knowledge of and experience with fundamental Internet protocols and functionality
* Systems-level programming experience
* Strong experience with UNIX/Linux
* Familiarity with current hardware and software vulnerabilities and mitigations
Why work here?
* Join a world-class organization that continues to have a significant impact on software.
* Work with cutting-edge technologies and dedicated experts to solve tough problems for the government and the nation.
* Be surrounded by friendly and knowledgeable staff with broad expertise across AI/ML, cybersecurity, software engineering, risk management, and policy creation.
* Get 8% monthly contribution for your retirement, without having to contribute yourself.
* Get tuition benefits to CMU and other institutions for you and your dependent children.
* Enjoy a healthy work/life balance with flexible work arrangements and paid parental and military leave.
* Get access to university resources including mindfulness programs, childcare and back-up care benefits, a monthly transit benefit on WMATA, free transportation on the Pittsburgh Regional Transit System.
* Enjoy annual professional development opportunities; attend conferences and training or obtain a certification and get reimbursed for membership in professional societies.
* Qualify for relocation assistance and so much more.
Location
Pittsburgh, PA
Job Function
Software/Applications Development/Engineering
Position Type
Staff - Regular
Full time/Part time
Full time
Pay Basis
Salary
More Information:
* Please visit "Why Carnegie Mellon" to learn more about becoming part of an institution inspiring innovations that change the world.
* Click here to view a listing of employee benefits
* Carnegie Mellon University is an Equal Opportunity Employer/Disability/Veteran.
* Statement of Assurance
Manager - Information Security
Security Architect Job In Pittsburgh, PA
Buchanan Ingersoll & Rooney is a national law firm with a proven reputation for providing progressive, industry-leading legal, business, regulatory and government relations advice to our regional, national and international clients.
We are searching for a Manager of Information Security for our corporate Pittsburgh, PA office. This is a pivotal leadership role responsible for the development and oversight of a comprehensive information security management system (ISMS) and privacy information management system (PIMS) across the firm. The Manager of Information security will manage a skilled team dedicated to security engineering, operations, incident response, and the development of security policies and procedures.
Essential Duties and Responsibilities:
Reporting to the Firm's Director of Enterprise Operations & Security, the Manager will collaborate closely with various Technology teams and Firm leadership to inspire, mentor, and cultivate the skills of the security team members, fostering a high-performance environment.
Develops and maintains information security policies, procedures and training and advise the various departments and practice groups in adhering to them.
Leads the ongoing ISO 27001/27701 lifecycle and manage the relationship with our consulting team to ensure security operations compliance within the Firm.
Provides expert opinions and leadership over existing technical threats and advice on how to mitigate or identify as acceptable risks.
Oversees vulnerability scanning and remediation programs.
Establish and Oversee Security Metric investments and risk trending dashboard.
Oversees and/or assists in performing on-going security monitoring threat avoidance analyses.
Manage relationships with security managed service providers and continuously develop their capabilities.
Analyzes new systems (hardware and software) and provides recommendations concerning their security.
Coordinates the development of an ongoing information security awareness program to ensure that employees are aware of threats and how to help ensure privacy of Firm data.
Works with general counsel to provide responses to client security audits/questionnaires/RFP's.
Maintains appropriate security measures and mechanisms to guard against unauthorized access to electronically stored and /or transmitted client data and reasonably protect against anticipated threats and hazards.
Ensures compliance through adequate training programs and oversight of periodic internal and 3rd party security audits. Assesses audit results and partners with staff to create pragmatic action plans. Monitors execution and completion of action plans.
Provides technical guidance and training to information owners and designs and implements programs for user awareness, compliance monitoring and security compliance.
Develops and maintain an ongoing risk assessment program targeting information security and privacy matters.
Active participant in Information Security and serves as Technology leader for incident response. Serves as primary contact for Technology incident responses.
Performs other work related duties as assigned.
Required Qualifications:
Bachelor's Degree or equivalent experience.
10+ years of experience working in an information security related field.
5+ years of experience managing a team of technical security engineers.
One or more of the following certifications strongly preferred: CISSP, CISM; matriculating candidates considered.
Strong understanding of various security frameworks; ISO27001/ISO27701 and SOC.
Working knowledge of EDR, Vulnerability Scanning, Firewall, Proxy, PAM/PIM, SIEM and other security-related technologies.
Excellent listening skills and written and oral communication skills, including effective presentation skills.
Ability to relate to non-technical users in user-friendly language.
Ability to understand technical implications of security threats and prioritize risk.
Ability to manage multiple concurrent objectives or activities and effectively make judgments in prioritizing and time allocation in a high-pressure environment.
Ability to gauge one's strengths and limitations.
Ability to deal with changes and adapt to a changing environment.
Must demonstrate the ability to maintain strict confidentiality of the Firm's internal and personnel affairs.
Ability to work well with others, harness different skills and experience and build a strong sense of team spirit.
Highly self-motivated and directed.
Ability to work in a multi-office environment and willingness to travel to other offices as required.
Experience working in a law Firm or professional services Firm environment preferred.
Why should you work at Buchanan?
Our Firm offers outstanding benefits that include:
Competitive salary and generous Paid Time Off
Hybrid work schedules
Paid Holidays, including a floating holiday
WorkWell wellness program, including free use of the Calm App
Free use of building gym
Caregiving assistance with Bright Horizons (child, elder, and pet care!)
Access to our Firm-wide emergency assistance fund
Free full access to LinkedIn Learning
Insurance - Medical, Dental, Vision
401K Program
Retirement Savings Program
We are an Equal Opportunity Employer.
Lead Security Analyst - Information System Security Officer (ISSO)
Security Architect Job In Pittsburgh, PA
Description & Requirements Reporting to the Sr. Manager for the Program Security Services team (US Services), the Lead Security Analyst-ISSO is responsible for managing the overall security posture of their assigned projects. Acting as an independent contributor, the Lead Analyst-ISSO will document and validate security compliance requirements, as defined in client contracts and established regulatory frameworks (NIST 800-53, HIPAA, IRS 1075, CMS MARS-E/ARC-AMPE, PCI-DSS). This position requires broad knowledge of Information Technology, including cloud providers such as Azure and AWS. This role will also manage stakeholder relationships with both internal and external customers. US citizenship is required per contract/client, at least one of the following certifications is required: CISSP (preferred), CISA or CISM. Experience with NIST 800-53 and the ability to travel up to 10% is required.
Essential Duties and Responsibilities:
- Responsible for ensuring information security for an assigned area of Business/Project focusing on key areas of risk, as outlined in the Information Security policy, under the direction of the Information Security management team.
- Conduct Information Security risk assessments and compliance evaluations for infrastructure and application assets within required timeframes and to industry standards and regulatory specifications.
- Ensure controls are properly and fully implemented to address identified Information Security risks for assigned area of responsibility.
- Define, create and maintain the documentation for certification and accreditation of each information system in accordance with regulatory requirements.
- Lead and support audits and client reviews of security posture; coordinate the collection, review and submission of Information Security deliverables and track the remediation of audit findings and exceptions.
- Manage expectations with multiple stakeholders on projects and programs in conjunction with the Information Security team.
- Promotion of Information Security awareness through various communication channels within the organization.
- Collaborate with the Information Security team members on process improvements, secure design and recertification of MAXIMUS assets.
Identify potential security control gaps by reviewing evidence provided by stakeholders, system generated reports and/or control implementation statements.
Perform risk assessments using vulnerability management and application security testing reports.
Initiate formal security exception process, when required.
Develop Plan of Action and Milestones (POA&M) as necessary.
Minimum Requirements
- Please refer to the additional information section of the job requisition for this opening to determine clearance eligibility required.
- Bachelor's degree and 7+ years of relevant professional experience required, or equivalent combination of education and experience.
US Citizenship is REQUIRED per contract/client.
At least one of the following certifications is REQUIRED: CISSP (preferred), CISA or CISM
Experience with NIST 800-53 is REQUIRED
Ability to travel nationally up to 10% is REQUIRED
HIPAA experience is preferred
Experience with Cloud providers, such as Azure and AWS
Knowledge of any of the following security frameworks is preferred: IRS 1075, CMS MARS-E/ARC-AMPE, PCI-DS
Demonstrates excellent interpersonal, presentation and verbal/written communication skills
Demonstrates strong customer service skills
Ability to communicate technical information to non-technical staff
Ability to work collaboratively with a broad range of staff (including analysts, engineers and leadership)
Proficiency with Microsoft Office
SmartSheet experience is a plus
Ability to perform comfortably in a fast-paced, deadline-oriented work environment
Ability to organize and execute complex tasks
Ability to work as a team member as well as independently
#LI-JH1 #maxcorp #LeadSecurityAnalyst
EEO Statement
Active military service members, their spouses, and veteran candidates often embody the core competencies Maximus deems essential, and bring a resiliency and dependability that greatly enhances our workforce. We recognize your unique skills and experiences, and want to provide you with a career path that allows you to continue making a difference for our country. We're proud of our connections to organizations dedicated to serving veterans and their families. If you are transitioning from military to civilian life, have prior service, are a retired veteran or a member of the National Guard or Reserves, or a spouse of an active military service member, we have challenging and rewarding career opportunities available for you. A committed and diverse workforce is our most important resource. Maximus is an Affirmative Action/Equal Opportunity Employer. Maximus provides equal employment opportunities to all qualified applicants without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status or disabled status.
Pay Transparency
Maximus compensation is based on various factors including but not limited to job location, a candidate's education, training, experience, expected quality and quantity of work, required travel (if any), external market and internal value analysis including seniority and merit systems, as well as internal pay alignment. Annual salary is just one component of Maximus's total compensation package. Other rewards may include short- and long-term incentives as well as program-specific awards. Additionally, Maximus provides a variety of benefits to employees, including health insurance coverage, life and disability insurance, a retirement savings plan, paid holidays and paid time off. Compensation ranges may differ based on contract value but will be commensurate with job duties and relevant work experience. An applicant's salary history will not be used in determining compensation. Maximus will comply with regulatory minimum wage rates and exempt salary thresholds in all instances.
Minimum Salary
$
111,605.00
Maximum Salary
$
145,000.00
GRC Security Engineer (Governance, Risk and Compliance)
Security Architect Job In Pittsburgh, PA
The GRC Engineer will be responsible for implementing, maintaining, and enhancing policies, standards, procedures, and internal controls to ensure compliance with regulatory and legal requirements, as well as information security best practices. The ideal candidate will possess a security engineer mindset, focusing on building out GRC frameworks, automation, and integrating technical controls. The GRC Engineer will proactively collaborate with key business stakeholders to assess and design controls aimed at reducing information security risk. They should be able to understand and articulate the impact of information security controls on the business and effectively communicate this to stakeholders.
Primary Responsibilities:
Risk Assessment: Identify, assess, and prioritize risks that could impact the clients compliance, financial health, or reputation.
Compliance Management: Develop, implement, and maintain compliance programs and policies that align with regulatory requirements and industry best practices.
Auditing: Conduct internal and external audits to assess compliance with regulations and identify areas for improvement.
Reporting: Prepare and analyze compliance reports, metrics, and dashboards to track progress and identify trends.
Training and Awareness: Develop and deliver training programs to educate employees about compliance requirements and information security best practices.
Incident Management: Respond to compliance incidents, conduct investigations, and implement corrective actions.
Technology Implementation: Evaluate and implement GRC software and tools to streamline compliance processes and improve efficiency.
Continuous Improvement: Explore opportunities to enhance GRC processes through automation and continuous monitoring of information security controls, risks, and exceptions, and develop reporting metrics, dashboards, and evidence artifacts.
Vulnerability Management: Assist in the development and ongoing oversight of a vulnerability management program.
Risk Remediation: Manage the remediation of risks identified through the risk register process and contribute to the improvement of risk treatment plans and the overall risk management program.
Security Exceptions: Manage the security exception process, including the completion of security exceptions, tracking, and following up on alternative mitigating action items detailed within approved security exceptions.
Audit Coordination: Coordinate and track security-related audits, including scope of audits, stakeholder engagement, and deliverable timelines; work with teams as appropriate to achieve audit readiness; provide guidance, evaluation, and advocacy on audit responses.
Vendor Risk Management: Maintain the vendor risk management program, including vendor reviews and risk assessments; improve the program with the build-out of repositories, tools, and documentation for third-party vendor risk assurance.
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment regardless of their race, color, ethnicity, religion, sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military or uniformed service member status, or any other status or characteristic protected by applicable laws, regulations, and ordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or recruiting process, please send a request to ******************** .
To learn more about how we collect, keep, and process your private information, please review Insight Global's Workforce Privacy Policy: *************************************************** .
Skills and Requirements
Over 7 years of experience in Information Technology, Security Engineering, Governance, Risk and Compliance, and Internal Audit management.
Proficient in designing, implementing, and managing GRC software tools and platforms (e.g., Vanta) to streamline risk assessment, compliance monitoring, and incident management processes, including the development and automation of auditing tasks.
Skilled in conducting risk assessments on operational processes, procedures, and policies; interpreting audit results to evaluate the adequacy and reliability of controls; and preparing and presenting comprehensive reports.
Experienced in reviewing risk analyses, drafting corrective action plans, and driving the risk treatment process.
Adept at conducting security compliance reviews and audits of both on-premises and hosted environments, including AWS and Azure.
Background in working within a SaaS company environment.
Proven track record in implementing and maintaining HITRUST CSF and ISO 27001 compliance frameworks.
Experience in working within highly regulated industry verticals, such as healthcare.
Bachelors degree in a technical discipline related to Information Technology. Professional certifications such as CGRC, CISSP, CISA, CRISC, or similar are highly desirable. null
We are a company committed to creating diverse and inclusive environments where people can bring their full, authentic selves to work every day. We are an equal employment opportunity/affirmative action employer that believes everyone matters. Qualified candidates will receive consideration for employment without regard to race, color, ethnicity, religion,sex (including pregnancy), sexual orientation, gender identity and expression, marital status, national origin, ancestry, genetic factors, age, disability, protected veteran status, military oruniformed service member status, or any other status or characteristic protected by applicable laws, regulations, andordinances. If you need assistance and/or a reasonable accommodation due to a disability during the application or the recruiting process, please send a request to ********************.
Electronic Security Engineer
Security Architect Job In Pittsburgh, PA
Embark on a trailblazing career in Security Technology with Allied Universal Technology Services, a global leader in security technology that's transforming the security industry. We integrate state-of-the-art technology with physical security to protect our clients and communities, harnessing tools like electronic access control, video surveillance, and alarm monitoring, alongside emergent innovations such as robotics, drones, and augmented technology. As a valued team member, you'll be part of a diverse and dynamic workforce that thrives on innovation and inclusivity. We offer a wide spectrum of job opportunities for both stability and growth across various roles, including service and installation technicians, engineers, and project managers. At Allied Universal , we don't just embrace change; we drive it, creating a culture where diversity fosters innovation and forges caring connections. Join us and help set new benchmarks in the security industry while advancing your career. Enjoy comprehensive benefits for most full-time positions, including medical, dental, and vision coverage, life insurance, retirement plans, employee assistance programs, and exclusive perks.
Job Description
Allied Universal Technology Services is looking to hire an Applications Engineer. The Applications Engineer is responsible for software-specific support of our installation team to include the integration / interface of multiple disparate software applications into fully functioning solutions. This position will be responsible for all levels of system head-end commissioning, upgrades, and advanced diagnostics to achieve the defined functionality of systems operation. The Applications Engineer should be capable of utilizing existing SDK's and/or API's to ensure the desired level of integration and should be capable to perform customized integration between software applications. The Applications Engineer's schedule will be coordinated by Operations and Project Managers to be effectively and efficiently utilized.
RESPONSIBILITIES:
Capable of advanced integration between disparate electronic security systems
LAN & Network configurations experience include wireless communications system.
Perform system diagnostic and troubleshooting duties to ensure a fully functioning system
Work with Project Managers, End Users and Technician team to provide assistance in regards to the software systems
Troubleshoot project issues and engage appropriate resources as needed.
Escalate significant issues to management team as needed.
Work with the Project Management team to coordinate project and work schedules to ensure project efficiencies
Work with Operations Manager to schedule and maintain appropriate licensing and software trainings for professional development
Take the lead in End User Software training
QUALIFICATIONS:
A high school diploma or equivalent required; a BA/BS Degree preferred
In-depth knowledge of industry-leading security system and equipment providers
Certification with major enterprise level security/access control systems preferred
Decision-making and problem-solving ability
Ability to read and understand advanced technical information and documentation
Proficient with MS Office Suite (Excel, Outlook, PowerPoint, Project, SharePoint and Word)
Excellent verbal and written communication skills
Ability to establish and maintain effective working relationships with both internal and external customers
Must be detail-oriented and organized
Strong analytical and problem-solving capabilities
Strong time management skills
Self-motivated with the ability to motivate and influence others
Must be able to manage multiple tasks while meeting strict deadlines
Possess excellent follow-up skills
Certifications in the following Software platforms are preferred
AMAG
Idemia (Biometrics)
BENEFITS:
Medical, dental, vision, basic life, AD&D, and disability insurance
Enrollment in our company's 401 (k) or Supplemental Income Plan, subject to eligibility requirements
Eight paid holidays annually, five sick days, and four personal days
Vacation time offered at an accrual rate of 3.08 hours biweekly. Unused vacation is only paid out where required by law.
Closing
Allied Universal is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race/ethnicity, age, color, religion, sex, sexual orientation, gender identity, national origin, genetic information, disability, protected veteran status or relationship/association with a protected veteran, or any other basis or characteristic protected by law. For more information: ***********
If you have any questions regarding Equal Employment Opportunity, Affirmative Action, Diversity and Inclusion, have difficulty using the online system and require an alternate method to apply, or require an accommodation at any time during the recruitment and/or employment process, please contact our local Human Resources department. To find an office near you, please visit: ***********/offices.
Requisition ID 2025-1344294
Product Security Engineer II
Security Architect Job In Pittsburgh, PA
Latitude AI (lat.ai) develops automated driving technologies, including L3, for Ford vehicles at scale. We're driven by the opportunity to reimagine what it's like to drive and make travel safer, less stressful, and more enjoyable for everyone. When you join the Latitude team, you'll work alongside leading experts across machine learning and robotics, cloud platforms, mapping, sensors and compute systems, test operations, systems and safety engineering - all dedicated to making a real, positive impact on the driving experience for millions of people.
As a Ford Motor Company subsidiary, we operate independently to develop automated driving technology at the speed of a technology startup. Latitude is headquartered in Pittsburgh with engineering centers in Dearborn, Mich., and Palo Alto, Calif.
Meet the team:
The Product Security team researches, architects and tests best-in-class security solutions for Latitude's autonomy products. The team is responsible for reviewing the system's features and functions, assessing risks, identifying pragmatic security controls, guiding the product development team to implementing security, and finally testing the system to verify all the required controls are in place. We work closely with the onboard, cloud, and vehicle operations teams to provide them with security solutions that fit within their projects.
What you'll do:
* Work with internal Product Security, Systems Engineering, Development and external stakeholder teams to generate and track security deliverables across all programs to ensure we have complete coverage needed for traceability
* Support security education programs to empower technical and non-technical teams
* Interact with development teams to identify, triage, and test vulnerabilities found within the system
* Develop product security testing plans, implement tests and other scripts to measure secure feature implementation
* Contribute to building a strong security culture within Latitude
What you'll need to succeed:
* Bachelor's degree in Computer Engineering, Computer Science, Electrical Engineering, Robotics or a related field and 2+ years of relevant experience, Master's degree, or PhD
* Must have at least 2 years of experience in cybersecurity or related field
* Familiarity with how to assess cybersecurity risk in systems or software
* Experience in industry standards compliance reviews and/or process auditing
* Experience coding in scripting languages (python, bash, javascript, etc.)
* Strong attention to detail
* Teamwork and strong cross-functional communication skills are essential
Nice to have:
* Experience in automotive security programs
* Familiarity with software development lifecycle and best practices
What we offer you:
* Competitive compensation packages
* High-quality individual and family medical, dental, and vision insurance
* Health savings account with available employer match
* Employer-matched 401(k) retirement plan with immediate vesting
* Employer-paid group term life insurance and the option to elect voluntary life insurance
* Paid parental leave
* Paid medical leave
* Unlimited vacation
* 15 paid holidays
* Daily lunches, snacks, and beverages available in all office locations
* Pre-tax spending accounts for healthcare and dependent care expenses
* Pre-tax commuter benefits
* Monthly wellness stipend
* Adoption/Surrogacy support program
* Backup child and elder care program
* Professional development reimbursement
* Employee assistance program
* Discounted programs that include legal services, identity theft protection, pet insurance, and more
* Company and team bonding outlets: employee resource groups, quarterly team activity stipend, and wellness initiatives
Learn more about Latitude's team, mission and career opportunities at lat.ai!
Candidates for positions with Latitude AI must be legally authorized to work in the United States on a permanent basis. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is available for this position.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status.
Security Engineer
Security Architect Job In Pittsburgh, PA
Security Engineer About the Role:
The Security Engineer will be responsible for designing, implementing, and maintaining security controls and frameworks to protect the organization's systems, applications, and data. This role will focus on integrating security best practices into business processes while ensuring compliance with regulatory and industry standards. The ideal candidate will have a strong background in security engineering with hands-on experience in Governance, Risk, and Compliance (GRC) frameworks. The Security Engineer will collaborate with key business stakeholders to identify security risks, design technical controls, and drive automation to enhance security posture and compliance initiatives.
What You'll Do:
Security Architecture & Engineering: Develop and implement security controls to protect cloud and on-premises environments, ensuring alignment with security best practices and compliance frameworks.
Risk Assessment: Identify, assess, and prioritize security risks that could impact the organization's infrastructure, applications, and compliance requirements.
Compliance Management: Implement and maintain compliance programs and policies aligned with regulatory requirements, such as ISO 27001, HITRUST CSF, and other industry standards.
Auditing & Assessment: Conduct internal and external security audits to evaluate compliance, identify security gaps, and recommend improvements.
Security Automation: Develop and implement automated solutions for security monitoring, risk assessment, and compliance reporting.
Incident Management: Assist in investigating security incidents, ensuring proper response and remediation while maintaining compliance with legal and regulatory requirements.
Technology Implementation: Evaluate and deploy security tools, such as vulnerability management, SIEM, endpoint protection, and data loss prevention solutions.
Continuous Improvement: Enhance GRC processes through automation, continuous monitoring, and the development of security metrics, dashboards, and reporting mechanisms.
Vulnerability Management: Support the development and ongoing oversight of a vulnerability management program, ensuring timely remediation of identified security risks.
Security Exception Management: Manage the security exception process, tracking alternative mitigating controls and ensuring risk treatment plans align with organizational policies.
Vendor Risk Management: Maintain and improve the vendor risk management program, conduct security assessments and enhance third-party risk assurance processes.
Training and Awareness: Develop and deliver training programs to educate employees about compliance requirements and information security best practices.
What We Look For:
7+ years of experience in Information Technology, Security Engineering, Governance, Risk, and Compliance (GRC), and/or Internal Audit management.
Experience with security and compliance automation tools (e.g., Vanta) and implementing security best practices in cloud environments (AWS preferred).
Experience in conducting risk assessments, security compliance reviews, and audits for cloud-based (AWS, Azure) and on-premises environments.
Experience implementing and maintaining compliance frameworks such as HITRUST CSF and ISO 27001.
Experience working in SaaS environments, particularly in regulated industries such as healthcare.
Skills:
Strong knowledge of security frameworks, risk management, and security technologies (e.g., SIEM, vulnerability management, data loss prevention, and endpoint protection).
Skilled at applying a risk-based approach to planning, executing, and reporting on audit engagements and auditing processes.
In-depth knowledge of security framework controls as they apply to public cloud (AWS preferred), hybrid, self-hosted, and SaaS environments.
Understanding of security vulnerabilities, threats, and risk mitigation strategies.
Ability to translate security and compliance requirements into technical requirements.
Excellent problem-solving, analytical, and decision-making skills.
Strong written and verbal communication skills with the ability to present security and GRC concepts to both technical and non-technical stakeholders.
Education:
Bachelor's degree in a technical discipline related to Information Technology.
Professional certifications such as CGRC, CISSP, CISA, CRISC, or similar are highly desirable.
Benefits:
Medical/dental/vision plans 100% paid for employees and family members without coverage, which start from day one!
Life and AD&D
Flexible Spending Accounts: Medical, Dependent Care, and Transportation
401 (k) Retirement Savings
Tuition Reimbursement
Military Paid Leave (up to 6 months of base salary while on military leave)
Paid Time Off/ 9 Holidays
Paid parental leave
Disclaimer:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodation may be made to enable qualified individuals with disabilities to perform the essential functions. The term "qualified individual with a disability" means an individual with a disability who, with or without reasonable accommodation, can perform the essential functions of the position.
TeleTracking is an Equal Opportunity/Affirmative Action employer. TeleTracking recruits qualified applicants without regard to race, color, religion, gender, age, ethnic or national origin, veteran status, physical or mental disability, genetic information, sexual orientation or preference, gender identity, marital status, or citizenship status.
Recruiting agencies, please do not submit unsolicited referrals for this or any open role. We have a roster of agencies with whom we partner, and we will not pay any fee associated with unsolicited referrals.
Product Security Engineer II
Security Architect Job In Pittsburgh, PA
Latitude AI (lat.ai) develops automated driving technologies, including L3, for Ford vehicles at scale. We're driven by the opportunity to reimagine what it's like to drive and make travel safer, less stressful, and more enjoyable for everyone.
When you join the Latitude team, you'll work alongside leading experts across machine learning and robotics, cloud platforms, mapping, sensors and compute systems, test operations, systems and safety engineering -
all dedicated to making a real, positive impact on the driving experience for millions of people.
As a Ford Motor Company subsidiary, we operate independently to develop automated driving technology at the speed of a technology startup. Latitude is headquartered in Pittsburgh with engineering centers in Dearborn, Mich., and Palo Alto, Calif.
Meet the team:
The Product Security team researches, architects and tests best-in-class security solutions for Latitude's autonomy products. The team is responsible for reviewing the system's features and functions, assessing risks, identifying pragmatic security controls, guiding the product development team to implementing security, and finally testing the system to verify all the required controls are in place. We work closely with the onboard, cloud, and vehicle operations teams to provide them with security solutions that fit within their projects.
What you'll do:
Work with internal Product Security, Systems Engineering, Development and external stakeholder teams to generate and track security deliverables across all programs to ensure we have complete coverage needed for traceability
Support security education programs to empower technical and non-technical teams
Interact with development teams to identify, triage, and test vulnerabilities found within the system
Develop product security testing plans, implement tests and other scripts to measure secure feature implementation
Contribute to building a strong security culture within Latitude
What you'll need to succeed:
Bachelor's degree in Computer Engineering, Computer Science, Electrical Engineering, Robotics or a related field and 2+ years of relevant experience, Master's degree, or PhD
Must have at least 2 years of experience in cybersecurity or related field
Familiarity with how to assess cybersecurity risk in systems or software
Experience in industry standards compliance reviews and/or process auditing
Experience coding in scripting languages (python, bash, javascript, etc.)
Strong attention to detail
Teamwork and strong cross-functional communication skills are essential
Nice to have:
Experience in automotive security programs
Familiarity with software development lifecycle and best practices
What we offer you:
Competitive compensation packages
High-quality individual and family medical, dental, and vision insurance
Health savings account with available employer match
Employer-matched 401(k) retirement plan with immediate vesting
Employer-paid group term life insurance and the option to elect voluntary life insurance
Paid parental leave
Paid medical leave
Unlimited vacation
15 paid holidays
Daily lunches, snacks, and beverages available in all office locations
Pre-tax spending accounts for healthcare and dependent care expenses
Pre-tax commuter benefits
Monthly wellness stipend
Adoption/Surrogacy support program
Backup child and elder care program
Professional development reimbursement
Employee assistance program
Discounted programs that include legal services, identity theft protection, pet insurance, and more
Company and team bonding outlets: employee resource groups, quarterly team activity stipend, and wellness initiatives
Learn more about Latitude's team, mission and career opportunities at lat.ai!
Candidates for positions with Latitude AI must be legally authorized to work in the United States on a permanent basis. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is available for this position.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status.
SCCM Architect
Security Architect Job In Pittsburgh, PA
Stefanini Group is hiring!
Stefanini is looking for a SCCM Architect, Location: Pittsburgh, PA
For quick Apply, please reach out to Somnath Ghosh- call: ************/ email:
***************************
The client is seeking an SCCM / Client & Server Staging Architect to support our Corporate Enterprise Infrastructure business.
This role reports to the Windows Technical Services Manager and is in Pittsburgh, PA.
This position provides professional-level support for the company's Windows server & client staging, automation, systems design, and implementation.
The successful candidate will lead support in the current environment and develop, deploy and maintain new systems.
If you have a history of success in this space and want to join a growing team that promotes from within, we encourage you to apply! Client is an essential business.
The SCCM / Client & Server Staging Architect is responsible for maintaining an up-to-date process for provisioning and configuring operating systems on Windows servers and clients for Client.
The person in this role must develop, document, make recommendations, and implement plans for automation of IT infrastructure processes, including analysis of cost reduction opportunities for deployment of servers & clients in the business domain.
This position includes both creation of strategic vision, and tactical management including execution, examples include but are not limited to:
Develop, document, make recommendations, and communicate plans for deploying and maintaining server and client staging processes, including analysis of cost reduction opportunities.
Validation of operations teams' designs for adherence to company standards.
Participate in proof-of-concept tests to assist in defining technology direction and enabling business strategy.
Communicate and validate program architecture with Infrastructure Team, Project Management Office, and other organizational teams.
Perform end-to-end technical design, develop infrastructure blueprints for the implementation of new solutions, create impact analyses, and design modifications to existing systems to support new solutions.
Maintain a common documentation library of standardized procedures and configurations.
Provide top level of support for incidents and problems in designated areas of expertise.
Maintain an off-shore and on-shore model of human resources for development efforts and operational support.
Essential Knowledge Skills and Abilities:
Systems and Technology - Ability to demonstrate knowledge of the practical application of systems and technology.
This includes knowledge of systems architecture, hardware, operations and life cycle.
Expert Level Windows Administration Skills and / or Knowledge of:
Windows 10, Windows Server 2016, Windows Server 2019.
Microsoft Deployment Toolkit (MDT).
Experience with Language Packs, WIM management, RSAT tool deployments.
Task sequences for software deployment.
PowerShell automation.
Windows software deployments.
System Center Configuration Manager Current Branch
Project Management - Job requires planning and completion of large and small projects.
Communication and Interpersonal Skills - Job requires partnership with all levels of the organization.
Active Learning - Understanding the implications of new information for both current and future problem-solving and decision-making.
Dependability - Job requires being reliable, responsible, dependable, and fulfilling obligations.
Integrity - Job requires being honest and ethical.
Stress Tolerance - Job requires dealing calmly and effectively in high stress situations, including conflict resolution.
Time Management - Managing one's own time. This position requires self-motivation with autonomous work ethic.
Problem Sensitivity - The ability to tell when something is wrong or is likely to go wrong and manage any resulting conflict.
Works as part of a geographically dispersed team (e.g. local, global) using a variety of technologies. Acknowledges & accommodates, where appropriate, any variance in time zones and native language.
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Basic Qualifications:
Minimum 5 years of experience of relevant IT work.
Minimum 5 years of experience implementing enterprise-wide infrastructure in a global environment.
Employees must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire. Visa sponsorship is not available for this position.
Certifications:
MCP
MCSE
Listed salary ranges may vary based on experience, qualifications, and local market. Also, some positions may include bonuses or other incentives.
Stefanini takes pride in hiring top talent and developing relationships with our future employees. Our talent acquisition teams will never make an offer of employment without having a phone conversation with you. Those face-to-face conversations will involve a description of the job for which you have applied. We also speak with you about the process including interviews and job offers.
About Stefanini Group
The Stefanini Group is a global provider of offshore, onshore and near shore outsourcing, IT digital consulting, systems integration, application, and strategic staffing services to Fortune 1000 enterprises around the world. Our presence is in countries like the Americas, Europe, Africa, and Asia, and more than four hundred clients across a broad spectrum of markets, including financial services, manufacturing, telecommunications, chemical services, technology, public sector, and utilities. Stefanini is a CMM level 5, IT consulting company with a global presence. We are CMM Level 5 company.
#LI-ONSITE
#LI-SG2
Pega Architect
Security Architect Job In Pittsburgh, PA
A Global IT consulting firm with several large customer engagements across Europe and US. It provides strategic business consulting, technology, engineering and outsourcing services to help clients leverage technology and create impactful and measurable business value for every IT investment.
About Us:
Northhill Partners is a global talent acquisition and executive search company. We work exclusively with some of the most reputed and admired clients across various sectors and geographies.
Job Description
* Perform the competitive analysis of products and technologies under guidance to provide input on the service offering and input on suitable customers for pursuit.
* Provide Domain/ Technical consultation to Pre-Sales, Participate in proposal activities and discussions with customer and client visits as SME:
* Participate in POC, Architects and validates complex technical solution when required; Performs estimations and collateral consolidation, brings in alliance product offering/IPs to provide technical leadership and technical differentiation.
* Participate in client discussions to understand the problem faced by the customer and articulates the same to internal stakeholders, define and document the problem and get customer agreement, Brings in best practices in the Industry provide different options in order to assist in identify and define the problem.
* Arrive at possible solution alternatives that factor in gap resolution, impact related functional/technical areas, acceptability of the solution to the user community, technical feasibility and efficiency. In order to assist in arriving at the final solution definition.
* Evaluate and review Design Frameworks and Methodologies and approves design in order to achieve functional and non-functional requirements and conformance to the architecture.
* Create, consult and review Architectural decisions, architecture solution, performs re-engineering of architectures in order to create solution Blue print to meet project requirement.
* Perform As-Is analysis provide To be recommendation's, evaluate product technology solution and provide solution to specialized problems in order to provide inputs on technical and domain road map.
* Evangelize the usage of reusable frameworks and artifacts, create knowledge /certification artifacts and evaluation criteria guide or provide technical training in relevant technology areas in order to develop talent in technology /domain.
Required Skills :
* Over all min 10+ Year Exp in IT industry . Minimum 6 years of PRPC overall SDLC work experience, preferable in User Interface, Work Flow and Business Rules Implementation.
* Strong Knowledge in Designing the PRPC Application.
* Expertise in PRPC Integration with external systems in an enterprise environment.
* Strong in Reports and Correspondence Generation.
* Knowledgeable in Estimation, Performance Tuning and Deployment process.
* Experience on PRPC Healthcare Frameworks.
* Good experience on Design Review, Code Review and PRPC Best Practices.
* Strong RDBMS experience.
* Good domain knowledge on Health care (Provider and payer).
* Motivated person with strong Leadership Qualities.
* Strong analytical and communication skills . This role requires flexibility to relocate within the United States
Qualifications
* Over all min 10+ Year Exp in IT industry . Minimum 6 years of PRPC overall SDLC work experience, preferable in User Interface, Work Flow and Business Rules Implementation.
* Strong Knowledge in Designing the PRPC Application.
* Expertise in PRPC Integration with external systems in an enterprise environment.
* Strong in Reports and Correspondence Generation.
* Knowledgeable in Estimation, Performance Tuning and Deployment process.
* Experience on PRPC Healthcare Frameworks.
* Good experience on Design Review, Code Review and PRPC Best Practices.
* Strong RDBMS experience.
* Good domain knowledge on Health care (Provider and payer).
* Motivated person with strong Leadership Qualities.
* Strong analytical and communication skills . This role requires flexibility to relocate within the United States
Additional Information
All your information will be kept confidential according to EEO guidelines.
Information Security Specialist (Hybrid)
Security Architect Job In Pittsburgh, PA
Job Type: Full Time / Contract
Work Authorization: No Sponsorship
The A.C.Coy company has an immediate opening for an Information Security Specialist. Ideal candidates must have 5+ years of experience in information technology and 3+ years of information security experience. The following technical experience is also required: Report generation/data analysis, ITSM tools/SharePoint, using Active Directory for user provisioning/deprovisioning, customer follow up to resolve outstanding issues/escalation.
Responsibilities
Ability to use Excel and other Microsoft Office tools to generate reports, conduct data analysis
Familiarity with different tools for managing work, ITSM Tools (Cherwell, ServiceNow, etc), SharePoint, etc.
Ability to review reports and determine actions required for follow up based on defined processes
Ability to work independently with appropriate guidance
Ability to follow up with customers to resolve outstanding issues and escalate as needed
Prior experience with Active Directory user provisioning/deprovisioning
Experience with Sailpoint, Varonis, and Delinea (FKA Thycotic) preferred but not required
Experience with IT auditing and/or access certifications preferred
Qualifications
Education:
Bachelor's degree or equivalent experience
Experience Required:
Active Directory user provisioning/deprovisioning -3+ years
ITSM tool (ServiceNow, Cherwell), SharePoint - 3+ years
MS Office/Excel to generate reports and conduct data analysis - 3+ years
Sailpoint, Varonis and Deli (FKA Thycotic) - Preferred
Information Security Analyst with Top Secret Clearance
Security Architect Job In West Mifflin, PA
Opportunity
The Information Security Analyst supports cybersecurity responsibilities and projects for the customer's various network systems. Implement appropriate Risk Management Framework, audit and strategize IT development and monitoring principles, control reviews, monitor system vulnerabilities, data encryption, and oversee security breaches. Perform an assortment of other routine IT tasks with varying degrees of complexity. You will be responsible for protecting computer networks, systems, and data integrity.
Salary: 100-130k
Qualifications
Candidates must have the following combination of knowledge and skill to be considered:
Bachelors Degree in Cyber security, IT, or a related field and four (4) years of relevant experience, Associates Degree in Cybersecurity, IT, or a related field and six (6) years experience, High School Degree and ten (10) years experience, or Similar education / work experience via customer approval.
Technical Writing experience: shall have a strong working knowledge of the English language and experience performing technical writing to support Cybersecurity compliance.
Certification-ISC2 CISSP or similar certification via customer approval
Active DoD Top Secret or DOE Q security clearance
About IMG
Founded in 1987, IMG is a leading small business that exemplifies competence, integrity and follow-through. We consistently provide customer focused professional services, which ensures our company is recognized for continually exceeding expectations. We believe that at the core of our success stand our people. Our people have provided professional services in the Information Technology field for our customers with a commitment to customer satisfaction for over 35 years.
IMG Benefits:
Health, dental, vision, and life insurance
Short term and long term disability insurance
401(k) with generous company match
Flexible Spending Accounts (FSA) and Health Savings Accounts (HSA)
Personal leave plus paid federal holidays
Professional development and training assistance
IMG is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status, or any other protected class.
Architect III
Security Architect Job In Pittsburgh, PA
Life at PE:
Perkins Eastman is a global design firm with expertise that covers all aspects of the built environment. With studios in 25 locations globally, we design for people, to enhance the human experience and leave a lasting and positive impact on people s lives and the world we inhabit.
We are an integrated firm which our professional roster consists of architects, interior designers, planners, urban designers, landscape architects, graphic designers, construction specification writers, construction economists, environmental analysts, resiliency experts, traffic and transportation engineers, and several other professional disciplines.
The Opportunity:
Perkins Eastman has an exciting opportunity in our Pittsburgh office. We are looking for a highly motivated Architect to work with integrated design teams on various size projects and complexity.
The ideal candidate will excel in collaborative work environments and demonstrate versatility in design priorities, styles, and project delivery methods. This role encompasses a blend of architectural and strategic planning projects, along with business development responsibilities at both regional and state levels.
Primary Responsibilities:
Work collaboratively in a dynamic office setting, contributing to all phases of architectural work.
Lead and support strategic planning projects in Pittsburgh and around the country, in all of the Pittsburgh practice areas.
Represent Perkins Eastman at professional organization events, committees, and other associations.
Support with business development and client relationships in Pittsburgh.
Coordinate with Perkins Eastman s sustainability and research teams and incorporate into Perkins Eastman s Pittsburgh growth plan.
Manage project staffing, accounting, schedule on projects.
Lead communications among internal team, consultants, owner, and contractors on projects.
Manage agreements and authorizations with owners and consultants.
Support excellence in delivering publicly bid work.
Coordinate logistical aspect of design deliverables.
Advance the performance of projects through establishment and guidance of project team.
Support the growth of staff in the Pittsburgh studio.
Required Qualifications:
Bachelor or Master of Architecture Degree.
Minimum 10 to 12 years of experience.
Ability to develop, communicate and present design concepts.
Effective communication skills and excellent graphic presentation skills.
Experience and passion for high performance, sustainable architectural design.
Proficiency with Revit, Sketch-Up and Adobe Creative Suite is required. Rhino or Environmental analysis design software.
LEED Accreditation. WELL and Phius certification a plus.
Registered Architect preferred.
What we offer you:
Robust medical, dental and vision coverage
401k Options
PTO
Company Paid Holidays
Life Insurance
Pre-tax commuter benefits
Professional Development
Competitive salary
Hybrid Model (3 days working in the office and 2 days working remotely)
Compensation may vary based on the job level and your geographical work location.
Salary Range: $85,000 to $95,000
Perkins Eastman is an affirmative action, equal opportunity employer and a participant in the U.S. Federal E-Verify program. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, gender expression, national origin, age, protected veteran or disabled status, or genetic information.
Deloitte Microsoft Technology Services Practice (DMTSP) - Security Pre-Sales Architect
Security Architect Job In Pittsburgh, PA
Are you interested in working in a dynamic environment that offers opportunities for professional growth and new responsibilities? If so, Deloitte & Touche LLP could be the place for you. Traditional security programs have often been unsuccessful in unifying the need to both secure and support technology innovation required by the business. Join Deloitte's Advisory Cloud Cyber Risk Services team and become a member of the largest group of Cyber Risk individuals worldwide.
Microsoft is an audit client for Deloitte - as a result, Deloitte does not and cannot have any form of alliance or partnership with Microsoft. Deloitte, however, can advise on and implement Microsoft products, and interact with Microsoft in certain ways in connection with these activities. When doing so, Deloitte and Microsoft must be sensitive to and mindful of the need for independence.
Recruiting for this role ends on 4.1.25
Work you'll do
As a DMTSP - Security Pre-Sales Architect, you will be at the front lines with our clients who have chosen the Microsoft technology platform and supporting them with their Cloud Cyber Risk needs specifically helping them navigate the journey on securing their Microsoft platform infrastructure such as Azure and Office 365 and the design and deployment of Microsoft Security solutions. This is a Deloitte services pre-sales role and not a project implementation role. This will include:
* Lead or support proposals and/or also function as proposal lead architect with services potentially including the following Microsoft technologies: Microsoft Defender for Cloud, Azure Policies, Purview, Intune, Sentinel, Entra ID, Defender for Office, Defender for Endpoints and Servers, Defender for Vulnerabilities, Defender for Cloud Apps, Defender XDR and SCCM
* Assist in business development activities such as defining scope of services, building resource estimates and related pricing, packaging proposals and supporting the delivery of the proposal to the client for security services at clients who may have selected Microsoft infrastructures.
* Lead the delivery of cloud security analysis, recommendations and configurations of prospective clients' Microsoft Entra ID, Office 365 (O365), Exchange Online, Teams, OneDrive for Business, M365 Copilot and SharePoint Online environments based on Deloitte's Microsoft 365 Cyber Risk Framework. This can include leveraging security solutions services which may include Microsoft's technology products such as Entra, Purview, Defender, Intune, and Sentinel.
* Support or lead the delivery of Cyber Security workshops with clients(remote/in-person) including building demo labs, PowerPoint decks and Deloitte best practice perspectives
* Function as a Cyber security architect (experienced in applicable Microsoft technologies) supporting Deloitte project teams for practice development and eminence
* Function as deep subject matter expert on Microsoft security and securing Microsoft solutions staying abreast of Gartner research and Microsoft product roadmaps and advising Deloitte teams and clients on new developments.
* Function as the primary client day-to-day interface building rapport and trust with the client.
* Perform technical health checks of client's Microsoft platforms/environments as part of client development activities prior to broader deployments.
* When clients have expressed a desire to discuss Microsoft technologies, assist clients in a pre-sales role, with transitions to the Microsoft 365 security services such as solution setup and service configuration, focused on risk mitigation. Additional technologies include MFA, Conditional Access, Purview Compliance Manager, M365 Defender, Defender for O365, Defender for Cloud Apps (MDCA), Purview Information Protection (MPIP), Purview Data Loss Prevention (DLP).
* Implement industry leading practices around M365 E5 cyber risks and cloud security for clients.
* As part of the Deloitte Microsoft Technology Services security practice development and eminence activities; Design and develop cloud-specific security policies, standards and procedures e.g., O365 tenant management and configuration, identify management and access control, auditing and monitoring, security incident and event management, data protection (classification/labeling, DLP, encryption), user and administrator account management, SSO, conditional access controls and password/key management.
* Provide internal technical training to Advisory personnel as needed.
* Act as a subject matter expert on cloud cyber risk for Microsoft Purview, Microsoft Intune, Entra ID, Azure security, Microsoft Defender, and Microsoft Sentinel capabilities.
* Lead the development of Point-of-Views (PoVs) on providing leading practices to our clients on Cyber, including the Microsoft security challenges they face.
* Support talent process in the architect role such as for recruiting and coaching.
* Function as an expert in CNAPP, CWPP and CSPM technologies and security risk frameworks relevant to cloud as well as the Microsoft Cloud Security Benchmark
The successful candidate will possess:
* Strong critical thinking, analysis, and problem-solving skills
* Strong written and oral communication skills
* Experience working independently as well as collaboratively across large teams
The team
Deloitte Advisory's Cloud Cyber Risk team helps complex organizations more confidently pursue their growth, innovation and performance agendas through proactive management of the associated cyber risks. Our professionals provide advisory and implementation services that integrate risk, regulatory, and technology skills to help clients transform their legacy programs into proactive cyber risk programs. Join the team developing the future state of cyber risk solutions. Learn more about Deloitte Advisory's Cyber Risk Services practice.
Qualifications
Required:
* 5+ years of experience in technical consulting, client problem solving, architecting and designing solutions in a consulting role with project leadership and/or architect experience with Microsoft technologies
* 5+ years of hands-on technical experience with securing Microsoft 365 enterprise-level messaging and collaboration and/or Azure Infrastructure in implementation and operations.
* 5+ years of hands-on technical experience with enterprise-level systems management systems such as SCCM, End point security and Intune and endpoint engineering (MEM) and mobile device management (MAM & MDM)) implementation or operations.
* 5+ years of hands-on technical and project / professional experience enterprise-with at least two of the following technologies: Microsoft Endpoint Security Platforms (e.g. Defender for Endpoints and Defender for Servers), Microsoft Sentinel, Microsoft's email security platform (Defender for Office), Microsoft Purview, Azure security & Entra ID
* Ability to travel up to 50%, on average, based on the work you do and the clients and industries/sectors you serve
* Limited sponsorship may be available
Preferred:
* BA/BS Degree preferred. Ideally in Computer Science, Cyber Security, Information Security, Engineering, Information Technology.
* Microsoft Certifications such as: (SC-900, SC-100, SC-200, SC-300, SC-400, AZ 500),
* Cyber Certifications such as: CCSP, CCSK, CISSP, CCNP, and CCNA.
Ideally the following technical experience is a plus in any of the technologies below:
* Microsoft Security Copilot
* Defender for Vulnerabilities
* Defender for Cloud Apps
* Defender XDR
* Experience with Azure data, analytics, or AI/ML services (Azure SQL, HDInsight, Databricks, Data Factory, Data Lake Storage, Azure Analysis Services, Synapse Analytics, Azure Machine Learning, etc.)
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $102,500.00 to $210,600.00.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Information for applicants with a need for accommodation:Hyperlink: ************************************************************************************************************
#DeloitteNDO, #SalesOpsGreenDot
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Benefits
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte's purpose is to make an impact that matters for our clients, our people, and in our communities. We are creating trust and confidence in a more equitable society. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. We are focusing our collective efforts to advance sustainability, equity, and trust that come to life through our core commitments. Learn more about Deloitte's purpose, commitments, and impact.
Professional development
From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
As used in this posting, "Deloitte Advisory" means Deloitte & Touche LLP, which provides audit and enterprise risk services; Deloitte Financial Advisory Services LLP, which provides forensic, dispute, and other consulting services; and its affiliate, Deloitte Transactions and Business Analytics LLP, which provides a wide range of advisory and analytics services. Deloitte Transactions and Business Analytics LLP is not a certified public accounting firm. Please see ************************* for a detailed description of the legal structure of Deloitte LLP and its subsidiaries. These entities are separate subsidiaries of Deloitte LLP.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Deloitte will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance. See notices of various ban-the-box laws where available.
Requisition code: 211073