Principal Security Engineer
Security Engineer Job 39 miles from Decatur
At Oracle Cloud Infrastructure (OCI) we build the future of the cloud for Enterprises. We act with the speed and attitude of a start-up along with the scale and customer focus of the leading enterprise software company in the world. **About the team:**
The Enterprise Engineering SRE team is tasked with ensuring the security and compliance of internal systems by conducting regular audits, identifying potential gaps in existing standards and proactively improving the organization's overall security posture. The team plays a critical role in safeguarding the integrity, confidentiality and availability of all systems while driving risk management initiatives across departments including disaster recovery planning and execution. We are also responsible for liaising with various internal teams during audits, ensuring data sharing is concise, accurate and aligned for successful audit outcomes.
**Ideally, the candidate will possess several of the following skills:**
Supports the strengthening of Oracle's security posture, focusing on one or more of the following: regulatory compliance; risk management; incident management and response; security policy development and enforcement; Threat and Vulnerability Management; Incident Management and response and similar focus areas.
+ **Regulatory Compliance:** Brings advanced level skills to manage programs to establish, document and track compliance to industry and government standards and regulations, e.g. ISO-27001, PCI-DSS, HIPAA, FedRAMP, CMMC, GDPR, etc. Researches and interprets current and pending governmental laws and regulations, industry standards and customer and vendor contracts to communicate compliance requirements to the business. Participates in industry forums monitoring developments in regulatory compliance
+ **Risk Management:** Brings advanced level skills to assess the information security risk associated with existing and proposed business operational programs, systems, applications, practices and procedures in very complex, business-critical environments. Conduct and document very complex information security risk assessments and assist in the creation and implementation of security solutions and programs
+ **Cloud Security:** In-dept knowledge of cloud security principles and best practices, including securing cloud infrastructure, services, and applications in platforms, OCI experience is a plus
+ **Threat and Vulnerability Management:** Brings advanced level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required
+ **Incident Management and response:** Brings advanced level skills to respond to security events and responding in line with Oracle incident response playbooks to mitigate vulnerabilities
+ Mentors and trains other team members
+ Compiles information and reports for management
**Qualifications:**
+ Bachelor's degree in computer science, Information Security, or a related field. Master's degree preferred
+ 10+ years of experience in cybersecurity, security architecture, or a related technical security role securing cloud environments and developing automation workflows, incident detection, response, and vulnerability remediation
+ Industry certifications such as CISSP, OSCP, CISM, GIAC, or OCI/AWS/Azure Security Specialty highly preferred.
+ Proven experience in security architecture, threat modeling, and risk management at an enterprise level.
+ Expertise in network security, cloud security (OCI, AWS, Azure, GCP), endpoint security, Operating systems (Linux, Windows), MiddleTier, Database and identity management.
+ Develop and enforce security policies, governance frameworks, and compliance controls (NIST, ISO 27001, SOC 2, GDPR, HIPAA, etc.).
+ Hands-on experience with firewalls, SIEM tools, IDS/IPS, EDR solutions, and security automation.
+ Oversee security incident response, forensic analysis, red/blue teaming experience, containment, and remediation of cyber threats
+ Strong knowledge of cryptography, secure coding practices, zero-trust architecture, and IAM.
+ Scripting experience with one or more scripting languages: bash, python, perl, YAML or infrastructure as code tools such as Terraform or Cloudformation.
+ Familiarly with container orchestration technologies such as Kubernetes, Openshift, EKS, AKS, container image scanning and vulnerability management
+ Excellent communication skills with the ability to effectively communicate technical concepts to both technical and non-technical stakeholders. Exhibits excellent written and verbal communication skills
Career Level - IC4
**Responsibilities**
+ Develop and manage information security governance, including creating policies, procedures, standards, baselines, and guidelines to ensure the secure operation of information systems.
+ Collaborate with cross-functional teams to establish and maintain robust security policies and procedures, ensuring alignment with industry best practices
+ Build application security frameworks review process (e.g., OWASP Top 10) to identify vulnerabilities such as SQL injection, XSS, and insecure APIs.
+ Designing secure system architectures, both on-premise and in the cloud, with knowledge of zero-trust security models, segmentation, and access control models
+ Evaluate and implement encryption at rest and in transit to secure sensitive data using encryption algorithms (e.g., AES, RSA), public key infrastructure (PKI), SSL/TLS, secrets in vault and key management practices.
+ Build security patterns for hosting platforms (compute, OKE, containers, cloud native services), SaaS, and PaaS services, conduct security architecture and design review
+ Perform code reviews, security testing (e.g., SAST, DAST), and the implementation of secure coding practices within SDLC pipeline, and utilizing CI/CD tools (Jenkins, Git, GitHub Actions, Artifactory, sonarqube), as well as managing secrets, SCA, and open-source tools
+ Build, develop and monitor systems configuration management automation and infrastructure as code (IaC) strategies to achieve secure by design framework
+ Monitors information systems for security incidents and vulnerabilities; develops monitoring and visibility capabilities; reports on incidents, vulnerabilities, and trends to IT or executive management.
+ Proven leadership abilities with experience leading security projects and initiatives independently with Agile or Waterfall methodologies
+ Architects, designs, implements, maintains and operates information system security controls and countermeasures; supervises and trains operators in the administration of these systems; documents the operation, use, and expected outputs of these systems
+ Develop and maintain cybersecurity documentation such as the System Security Plan (SSP), Privacy Impact Assessment (PIA), Configuration Management Plan (CMP), Plan of Action and Milestones (POA&M), and Standard Operating Procedures (SOP) as necessary
+ Write stakeholder reports to explain the assessment, audit results, and recommendations. Create and provide metrics for cybersecurity leadership. Brief executive leadership on compliance matters
+ Participate in internal and external audit and provide executive leadership with briefings on compliance issues, assessment findings, audit results, and recommended actions.
Disclaimer:
**Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.**
**Range and benefit information provided in this posting are specific to the stated locations only**
US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
**About Us**
As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_************* or by calling *************** in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Cyber SDC- M365 Security Operations Lead Engineer - Senior - Consulting - Location OPEN
Security Engineer Job 39 miles from Decatur
At EY, you'll have the chance to build a career as unique as you are, with the global scale, support, inclusive culture and technology to become the best version of you. And we're counting on your unique voice and perspective to help EY become even better. Join us and build an exceptional experience for yourself, and a better working world for all.
The exceptional EY experience. It's yours to build.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
We are seeking a skilled and motivated Microsoft Purview and Defender for Office Operations Engineer to join our cybersecurity team. The ideal candidate will be responsible for the administration, management, and optimization of Microsoft Purview and Microsoft Defender for Office platforms. This role requires a strong understanding of data governance, compliance, and security best practices, along with the ability to work collaboratively with cross-functional teams to enhance our information protection posture.
**Key Responsibilities:**
1. **Platform Administration:**
1. Administer and support Microsoft Purview and Microsoft Defender for Office, ensuring optimal performance and availability of the platforms.
2. Configure and manage security settings, policies, and compliance features within Microsoft Purview and Defender for Office.
2. **Data Governance and Compliance:**
1. Implement and maintain data governance policies and procedures to ensure compliance with regulatory requirements and organizational standards.
2. Monitor and report on compliance metrics, data classification, and data loss prevention (DLP) policies.
3. **User Support:**
1. Provide technical support to end-users regarding Microsoft Purview and Defender for Office tools and best practices.
4. **Collaboration and Communication:**
1. Work closely with IT, security, and compliance teams to integrate Microsoft Purview and Defender for Office with existing systems and workflows.
2. Communicate effectively with stakeholders to report on security incidents, compliance metrics, and recommendations for improvement.
5. **Continuous Improvement:**
1. Stay updated on the latest features, updates, and best practices related to Microsoft Purview and Defender for Office.
2. Identify opportunities for process improvements and automation within the operations of Microsoft Purview and Defender for Office.
3. Automate activities through scripting (PowerShell, Python) and automation (Tines, PowerAutomate, etc.)
6. **Documentation and Reporting:**
1. Maintain accurate documentation of configurations, processes, and procedures related to Microsoft Purview and Defender for Office operations.
2. Generate reports on platform performance, security incidents, and compliance metrics for management review.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
+ Proven experience in managing and supporting Microsoft Purview and Microsoft Defender for Office.
+ Strong understanding of data governance, compliance frameworks, and information security best practices.
+ Excellent problem-solving skills and attention to detail.
+ Strong communication and interpersonal skills.
+ Scripting experience, including PowerShell, Python, etc.
+ Ticket and change management experience in ServiceNow
+ Relevant certifications (e.g., Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft Certified: Azure Security Engineer Associate) are a plus.
**Preferred Skills:**
+ Experience with data loss prevention (DLP) technologies and strategies.
+ Familiarity with compliance regulations (e.g., GDPR, HIPAA) and data protection laws.
+ Knowledge of cloud security concepts and technologies.
**Work Environment:**
This position may require occasional after-hours support and on-call availability. The Microsoft Purview and Defender for Office Operations Engineer will work in a collaborative team environment, contributing to the overall security and compliance posture of the organization.
**What we offer**
We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $73,100 to $132,900. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $87,600 to $151,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
+ **Continuous learning:** You'll develop the mindset and skills to navigate whatever comes next.
+ **Success as defined by you:** We'll provide the tools and flexibility, so you can make a meaningful impact, your way.
+ **Transformative leadership:** We'll give you the insights, coaching and confidence to be the leader the world needs.
+ **Diverse and inclusive culture:** You'll be embraced for who you are and empowered to use your voice to help others find theirs.
EY accepts applications for this position on an on-going basis. **If you can demonstrate that you meet the criteria above, please contact us as soon as possible.**
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.
Enabled by data and technology, diverse EY teams in over 150 countries provide trust through assurance and help clients grow, transform and operate.
Working across assurance, consulting, law, strategy, tax and transactions, EY teams ask better questions to find new answers for the complex issues facing our world today.
For those living in California, please click here (********************************************************************************************************************************************************************** for additional information.
EY is an equal opportunity, affirmative action employer providing equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law.
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at **************************
Cloud Security Engineer
Security Engineer Job 39 miles from Decatur
At CVS Health, we're building a world of health around every consumer and surrounding ourselves with dedicated colleagues who are passionate about transforming health care. As the nation's leading health solutions company, we reach millions of Americans through our local presence, digital channels and more than 300,000 purpose-driven colleagues - caring for people where, when and how they choose in a way that is uniquely more connected, more convenient and more compassionate. And we do it all with heart, each and every day.
**Position Summary**
As a Cloud Security Engineer of GCP and AWS at CVS Health, you will be responsible for designing, implementing, and maintaining secure cloud environments across AWS and Google Cloud Platform. Your expertise will ensure our cloud operations remain robust against threats while aligning with industry standards. Experience with Microsoft Azure is considered an advantage. You will work collaboratively with cross-functional teams to integrate security throughout the cloud lifecycle. The Cloud Security Engineer will develop security blueprints and implement security automation tools for continuous monitoring and threat detection. The right candidate will also conduct regular risk assessments, vulnerability analyses, and threat modeling for cloud assets.
**As a Cloud Security Engineer, you will**
+ Design and deploy secure cloud infrastructures on AWS and GCP, applying industry-leading practices
+ Integrate security controls and best practices inspired by the robust environments at Google and Facebook
+ Ensure adherence to regulatory requirements (e.g., HIPAA, PCI-DSS) and CVS Health security policies.
+ Lead incident response efforts, including forensic investigations and remediation processes
+ Collaborate with cybersecurity teams to enforce robust security policies, manage access controls, and ensure compliance with healthcare regulations (e.g., HIPAA)
+ Stay abreast of emerging trends in cloud security, leveraging insights from industry leaders like Google and Facebook to drive innovation
+ Evaluate and implement new cloud security tools and frameworks to enhance our security posture
+ Continuously improve processes and strategies to reduce risks and optimize performance
**Required Qualifications**
+ 7+ years of experience in cloud security or a related field with hands-on experience in securing AWS and GCP environments
+ 3+ years of experience with automation and Infrastructure as Code (IaC) tools (e.g., Terraform, AWS CloudFormation, Azure ARM, Pulumi, CDK)
+ Scripting and programming skills (e.g., Python, Bash, Javascript, Go, Typescript) for automating security tasks
+ Experience mentoring team members and fostering a culture of security awareness and proactive risk management
+ Experience partnering with Developers, DevOps, Engineering, and IT teams to embed security into CI/CD pipelines and Infrastructure as Code (IaC) practices
**Preferred Qualifications**
+ Familiarity with container security, CI/CD integration, and DevSecOps methodologies
+ Proficiency in cloud security tools, network security, identity and access management, encryption, and compliance monitoring
+ Experience with Azure is a bonus
**Education**
+ Bachelor's degree in computer science engineering, or a related field; Master's degree preferred
**Pay Range**
The typical pay range for this role is:
$118,450.00 - $260,590.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.
Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong.
**Great benefits for great people**
We take pride in our comprehensive and competitive mix of pay and benefits - investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include:
+ **Affordable medical plan options,** a **401(k) plan** (including matching company contributions), and an **employee stock purchase plan** .
+ **No-cost programs for all colleagues** including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching.
+ **Benefit solutions that address the different needs and preferences of our colleagues** including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility.
For more information, visit *****************************************
We anticipate the application window for this opening will close on: 05/30/2025
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
We are an equal opportunity and affirmative action employer. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law.
Security Architect
Security Engineer Job In Decatur, IL
Are you someone who never rests on their laurels, always strives to go above and beyond, and is committed to keeping your PROMISES? Do you appreciate a company culture that is open, fosters work-life balance, and a dynamic team environment? Then Old Dominion is the home for you. We take pride in being the best in the industry, and from our humble beginnings we know that our People and our Family Spirit are the main ingredient in our secret sauce to success. At Old Dominion we are looking for individuals to join the OD Family that will provide innovative solutions and exceed expectations to keep OD the premier transportation solutions provider.
As the Cybersecurity Architect at Old Dominion Freight Line, you will play a critical role in designing, implementing, and maintaining a comprehensive cybersecurity architecture to safeguard the integrity, confidentiality, and availability of the organization's information systems and data. You will lead the development of cybersecurity strategies, provide expert guidance on technical security solutions, and ensure the effective implementation of security controls to mitigate risks across the enterprise. This position requires a high level of technical expertise, strategic thinking, and the ability to collaborate across teams to support business continuity and protect the organization from cyber threats.
Primary Responsibilities
* Lead the development and implementation of a comprehensive cybersecurity architecture strategy aligned with Old Dominion's business objectives and security goals.
* Design secure IT environments and systems, including network security, cloud architecture, endpoint security, identity and access management, and data protection, while ensuring compliance with regulatory requirements and industry best practices (NIST, ISO 27001, SOC 2, etc.).
* Architect and implement security controls for on-premises and cloud-based infrastructure, focusing on scalability, resilience, and defense-in-depth principles.
* Conduct thorough risk assessments of current and emerging technologies, systems, and software applications to ensure they meet security standards and policies.
* Develop, implement, and maintain a cybersecurity governance framework, including policies, procedures, and standards to guide security practices across the organization.
* Collaborate with senior leadership to define the organization's cybersecurity strategy, risk appetite, and incident response framework.
* Oversee the integration of security tools and platforms (SIEM, IDS/IPS, vulnerability management, etc.) into the enterprise's existing IT architecture.
* Ensure compliance with relevant security frameworks, including NIST Cybersecurity Framework, CCPA, PCI-DSS, HIPAA, and others applicable to logistics and transportation industries.
* Monitor and assess emerging cybersecurity threats, vulnerabilities, and attack vectors, recommending proactive measures to mitigate risk to business-critical systems.
* Lead vulnerability assessments and penetration testing efforts, working closely with internal teams and third-party security consultants to identify weaknesses and implement corrective actions.
* Establish a robust vulnerability management process, ensuring timely remediation of critical security issues.
* Develop and maintain incident response plans and processes to ensure quick identification, containment, and resolution of cybersecurity incidents, with a focus on minimizing business disruption.
* Lead incident response efforts, providing expert guidance on detection, analysis, forensics, and post-mortem evaluations.
* Work closely with legal, compliance, and communication teams to ensure incidents are managed effectively, with proper escalation, documentation, and reporting procedures in place.
* Collaborate with IT infrastructure, network, and development teams to design secure solutions that align with business requirements and security best practices.
* Provide cybersecurity leadership and training to staff across departments, increasing awareness of cyber risks and promoting security best practices.
* Serve as a technical leader and mentor for cybersecurity engineers and analysts, fostering a collaborative environment focused on continuous improvement.
* Lead the assessment and management of third-party risks, ensuring that external vendors and partners adhere to Old Dominion's cybersecurity requirements.
* Conduct due diligence for third-party software and services, identifying and mitigating potential security risks associated with outsourcing and vendor relationships.
Job Qualifications
Education:
* Bachelor's Degree in Cybersecurity, Information Technology, Computer Science, or a related field. Master's degree preferred.
Experience:
* Minimum of 10+ years of experience in cybersecurity, with at least 5 years in a leadership role or as a cybersecurity architect.
* Extensive experience in security architecture design, particularly in enterprise environments, covering network, cloud, data, and endpoint security.
* Deep understanding of cybersecurity frameworks (e.g., NIST CSF, ISO 27001, CIS) and experience applying them within a large, complex organization.
* Strong knowledge of security technologies such as firewalls, intrusion detection/prevention systems (IDS/IPS), VPNs, SIEM, DLP, endpoint protection, and encryption solutions.
* Proficiency in cloud security (AWS, Azure, Google Cloud), including secure cloud architecture, identity and access management, and cloud-native security services.
* Experience in vulnerability management tools (e.g., Rapid7, Qualys, Nessus), penetration testing methodologies, and risk management platforms.
* Familiarity with regulatory compliance requirements, such as CCPA, HIPAA, PCI-DSS, and others relevant to transportation/logistics.
* Advanced knowledge of threat intelligence and incident response frameworks, including hands-on experience in threat hunting and managing real-time security incidents.
* Strong understanding of the SDLC and secure development practices, with experience in DevSecOps integration.
* Preferred Experience:
* Professional certifications, such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), CISA (Certified Information Systems Auditor), or AWS Certified Security - Specialty.
* Experience with automation and orchestration tools in a security context (e.g., SOAR, Ansible, Terraform).
* Advanced knowledge of networking protocols and technologies (e.g., TCP/IP, VPNs, DNS, HTTP/HTTPS).
* Experience with the logistics and transportation industry and understanding the specific security challenges and regulatory requirements in this sector.
Compensation Range:
The referenced salary range is based on the Company's good faith belief at the time of posting. Actual compensation may vary based on factors such as geographic location, work experience, market conditions, education/training and skill level.
($139,078-$173,826)
Working Days:
Shift and hours to be determined.
Working Shift:
Shift and hours to be determined.
Work Days and Shift are estimates and are subject to change, at any given time, based on job scheduling and/or business levels. Any information listed regarding Days and Shifts shall be considered a guideline of expectations for the specific position at the time of posting.
Application Window:
Ongoing
Candidates are encouraged to apply as soon as possible. Old Dominion plans to screen candidates, conduct interviews, and proceed with hiring candidates to meet its business needs, which may result in filling the role before the current anticipated application window closes.
Join the OD Family Today!
As a Full Time member of our Family, you and your family are eligible to receive:
* Great Health Benefits including a Zero premium medical plan for employee only coverage
* Vision & Dental
* Short Term & Long Term Disability
* Flex Spending Accounts
* 401k Retirement plan with company match and additional company annual discretionary match opportunity
* Life Insurance
* Wellness Program
* 12 Days Paid Time Off
* 9 Paid Holidays including a birthday holiday
* Training and growth opportunities to build a career
* We prioritize our OD family of employees
* Ability to advance through our promote from within philosophy
* National Career Opportunities Available at our 260+ service centers
Old Dominion Freight Line, Inc. is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, gender identity, and/or gender expression, sexual orientation, age, disability, pregnancy, genetic information, military status, Vietnam Era and/or veteran status, or any other characteristic protected by applicable law(s).
If you have questions regarding this posting or require assistance with the application process, please click here for contact information.
Sr. Security Engineer - COE Services
Security Engineer Job 39 miles from Decatur
Splunk, a Cisco company, is building a safer and more resilient digital world with an end-to-end full stack platform made for a hybrid, multi-cloud world. Leading enterprises use our unified security and observability platform to keep their digital systems secure and reliable. Our customers love our technology, but it's our caring employees that make Splunk stand out as an amazing career destination. No matter where in the world or what level of the organization, we approach our work with kindness. So bring your work experience, problem-solving skills and talent, of course, but also bring your joy, your passion and all the things that make you, you. Come help organizations be their best, while you reach new heights with a team that has your back.
**Role Summary**
The Splunk Senior Security Engineer will be responsible for driving processes and metrics that help other security teams better deliver their service offerings as part of our Center of Excellence Services team. You are someone who has expert level understanding of Information Security principles and disciplines coupled with excellent communication skills and a continuous desire to learn and grow. We are a passionate team that has fun, and enjoys a good laugh but above all else think security first.
**Meet the Global Security Team**
Our team of problem solvers and security engineers collaborate with teams across Splunk to address urgent escalations, investigate open-source vulnerabilities, elevate the internal customer experience, and more. Learn more about the team, meet our leaders, and hear more from our Splunk security experts at splunk.com/careers/splunk-global-security .
**What you'll get to do**
+ Make key decisions in selecting methods, techniques, and evaluation criteria for necessary resolution
+ Improve analytical content used to tell actionable stories, and anomalous behavior within our environment multiple Information Security teams.
+ You will analyze existing data, logs, and other information about various security service offerings and develop meaningful metrics to support those offerings
+ You will maintain, and support existing dashboards and analytical content across our internal customers
+ You will author and help define procedures to consistently follow, managing large-scale deployments of new content and other service offerings with the Center of Excellence Services team.
+ You use your wealth of experience to provide recommendations and requirements for new technologies.
+ Make key contacts and network/partner with senior internal and external personnel in areas of Security and areas of outside expertise
+ Partner with internal Products and Technologies teams to advise on our product content being deployed to external Splunk customers, providing concepts and ideas for new innovations.
+ Mentor and advise junior engineers as needed to facilitate growth
**Must-have Qualifications**
+ A bachelor's degree in computer science, information security or field is required or equivalent work experience.
+ You have 8 years of experience in Security Operations Engineering or knowledge
+ You have expert-level knowledge of security-related technologies including cloud service providers, firewalls, intrusion detection systems, and endpoint security tools
+ Proven experience using regular expressions (RegEx)
+ Extensive knowledge of designing efficient Splunk searches and knowing what to do to make our Splunk searches more efficient and accurate
+ Expert level of experience in data sciences, proven with examples of dashboarding and metrics-driven change
+ You have expert knowledge in various types and formats of system logs
+ You have a working knowledge of endpoint and server systems administration
+ Proven mentorship and leadership skills
+ You have the willingness and desire to think outside of the box for creative solutions to problems with the moxie to follow through.
+ Excellent interpersonal skills and ability to see things through the customer's eyes
**Splunk is an Equal Opportunity Employer**
Splunk, a Cisco company, is an Equal Opportunity Employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation, national origin, genetic information, age, disability, veteran status, or any other legally protected basis.
Note:
**Base Pay Range**
SF Bay Area, Seattle Metro, and New York City Metro Area
Base Pay Range: $159,200.00 - 218,900.00 per year
California (excludes SF Bay Area), Washington (excludes Seattle Metro), Washington DC Metro, and Massachusetts
Base Pay Range: $143,280.00 - 197,010.00 per year
All other cities and states excluding California, Washington, Massachusetts, New York City Metro Area and Washington DC Metro Area.
Base Pay Range: $127,360.00 - 175,120.00 per year
Splunk provides flexibility and choice in the working arrangement for most roles, including remote and/or in-office roles. We have a market-based pay structure which varies by location. Please note that the base pay range is a guideline and for candidates who receive an offer, the base pay will vary based on factors such as work location as set out above, as well as the knowledge, skills and experience of the candidate. **In addition to base pay, this role is eligible for incentive compensation and may be eligible for equity or long-term cash awards.**
Benefits are an important part of Splunk's Total Rewards package. This role is eligible for a competitive benefits package which includes medical, dental, vision, a 401(k) plan and match, paid time off and much more! Learn more about our next-level benefits at ************************** .
Security Engineer, Incident Response
Security Engineer Job 39 miles from Decatur
Meta Security is looking for an Incident Response Engineer with experience coordinating, investigating and responding to internal and external threats. You will help the team establish, lead and execute multi-year roadmaps to mature investigative and response services, drawing upon automation and cross functional partnerships to create scalable and resilient operational capabilities.
**Required Skills:**
Security Engineer, Incident Response Responsibilities:
1. Conduct security investigations and lead security incident response in a cross-functional environment and drive incident resolution.
2. Develop Incident Response initiatives that improve our capabilities to effectively respond and remediate security incidents.
3. Refine operational metrics, key performance indicators, and service level objectives to measure Security Operations and Incident Response services.
4. Influence and align the team's vision and strategy. Collaboratively prioritize and deliver specific multi-year roadmaps and projects.
5. Build, cultivate, and maintain positive relationships with internal customers to identify and facilitate solutions to increase the impact of the team's work.
6. Partner with cross-functional teams to solve challenges related to a broad spectrum of detection and response initiatives.
7. Collaborate with software and production engineering teams to develop scalable and flexible Incident Response and Investigative solutions.
8. Focus on ruthlessly prioritizing, automating and scaling every aspect of our detection and response capabilities.
9. Coach, mentor, support and care for the team in a way that enables long-term career development, happiness and success at scale.
**Minimum Qualifications:**
Minimum Qualifications:
10. B.S. or M.S. in Computer Science or related field, or equivalent experience
11. 10+ years of work experience in Security Incident Response and Detection & Response Engineering in a large, regulated organization.
12. Be a technical and process subject matter expert regarding Security Operations and Incident Response services.
13. Experience developing and delivering information on incident and program status for leadership.
14. Experience leading and managing complex cross-functional programs.
15. Experience responding to both external and insider threats.
16. Experience analyzing network and host-based security events.
17. Knowledge of networking technologies, specifically TCP/IP and the related protocols.
18. Knowledge of operating systems, file systems, and memory structures on Windows, MacOS and Linux.
19. Coding/scripting experience in one or more general purpose languages.
20. Experience with attacker tactics, techniques, and procedures.
**Preferred Qualifications:**
Preferred Qualifications:
21. Background in malware analysis, digital forensics, intrusion detection, and/or threat intelligence.
22. Experience in threat hunting including leveraging intelligence data to proactively identify and iteratively investigate suspicious behavior across networks and systems.
23. Broad knowledge across the Security domain, as well as demonstrated experience in one (or more) areas such as Logs and events processing, Incident Management, Digital Forensics, Detection and/or response tool development.
24. Experience recruiting, building, and leading technical teams, including performance management.
**Public Compensation:**
$177,000/year to $251,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
In-Vehicle Cyber Security Engineer
Security Engineer Job 39 miles from Decatur
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we're all a part of something bigger than ourselves. Are you ready to change the way the world moves?
The In-Vehicle Cybersecurity Engineer will act as a technical lead designing security into our vehicles. Engineers will evaluate, critique, and drive secure designs from concept to implementation. In-Vehicle Cybersecurity Engineers identify new methods of securing our technologies from drafting specifications to executing testing.
Engineers need to be able to understand and evaluate risk for in-vehicle systems. Recognizing and accommodating the limitations of embedded in-vehicle systems is essential. Engineers are expected to take ownership of assignments including developing in-depth understanding of the technologies under review, working to close security gaps and mitigate identified vulnerabilities, and report out to security management. Over time, Engineers will grow to become subject matter experts acting to develop and mature security controls and features in the vehicle.
**What you'll do...**
+ Own ECU and Vehicle level cyber security design and process integration
+ Interface with cross-functional teams on technical issues related to cyber security
+ Perform risk analysis (i.e. TARA) so that appropriate countermeasures can be developed
+ Develop and maintain security requirements and design validation methodologies (DVM)
+ Develop and maintain technical documentation as required
+ Provide training and consulting to internal Ford function teams
+ Support major product programs/new features with security needs
+ Collaborate on Advanced Engineering projects with internal and external partners
+ Research technologies and security benchmarking data gathering
+ Some traveling may be required (conferences, regional team meetings, government/academia visits, etc.)
**You'll have...**
+ Bachelor's Degree in Electrical Engineering, Computer Engineering, Software Engineering or Computer Science OR a combination of education and experience
+ 5+ years of experience with embedded, IoT and/or automotive systems cyber security
+ Experience with security system engineering, development, and testing
+ Experience with networking and communication protocols (e.g. firewall config, TLS, MACsec, etc.)
+ Experience designing cyber security controls such as secure communication/networking, secure gateway, IDS, IPS, secure boot, etc.
+ Experience developing and maintaining engineering documentation including requirements, specifications, test plans, etc.
+ Self-starter with ability to work independently and collaboratively
+ Strong communication and analytical skills
**Even better, you may have...**
+ Master's Degree in Cyber Security, Electrical Engineering, Computer Engineering, Software Engineering or Computer Science is a plus
+ 7+ years of experience with embedded, IoT and/or automotive systems cyber security
+ Experience with in-vehicle network architecture, modules, and protocols (Automotive Ethernet, CAN/CAN-FD, J1939, USB, SPI, UART, JTAG, etc.)
+ Experience with symmetric and asymmetric cryptography, digital signature, hash, message authentication, encryption, key exchange
+ Experience with HSM, SHE, TEE, SELinux, hypervisor, etc.
+ Experience with SecOC, AUTOSAR
+ Understanding of embedded RTOS and Linux based operating systems
+ Understanding of system level architecture, development, design principals
+ Experience with at least one modern software programming language (C, C++, C#, Python, Java, etc.)
+ CISSP, GSEC, etc. are a plus
This description outlines the general nature and scope of work typically performed in this job. It is not intended to be an exhaustive list of all duties, responsibilities, knowledge, skills, work requirements, etc. It may vary slightly based on business or geographic needs and is subject to being reviewed and updated periodically.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year's Day
- Paid time off and the option to purchase additional vacation time.
For a detailed look at our benefits, click here:
******************************* (****************************************************************************************************************************************************************************
This position is a range of salary grades **7-8.**
Visa sponsorship is not available for this position.
SOUTHEAST MI RESIDENTS: Please note, this job is posted as remote unless the selected candidate lives within 50 miles of Dearborn, MI. In this case we request the candidate to be on-site 1-2 days a week.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call **************.
\#LI-Remote
**Requisition ID** : 41638
Sr. SQL Engineer Secure Release II
Security Engineer Job 39 miles from Decatur
Employment Type: Full Time, Senior-level Department: Information Technology CGS is seeking a Sr. SQL Engineer Secure Release to join our team supporting a wide-ranging technical support initiative for a large Federal agency. CGS brings motivated, highly skilled, and creative people together to solve the government's most dynamic problems with cutting-edge technology. To carry out our mission, we are seeking candidates who are excited to contribute to government innovation, appreciate collaboration, and can anticipate the needs of others. Here at CGS, we offer an environment in which our employees feel supported, and we encourage professional growth through various learning opportunities.
Skills and attributes for success:
* Web Development on the Microsoft.NET technology with experience in at least one JavaScript UI framework.
* Very Strong Relational Database technologies such as Microsoft SQL server.
* Data Warehousing using SQL Server Integration Services (SSIS), including significant experience with Extract, Transform, and Load (ETL) operations.
Qualifications:
* Microsoft SQL Server Integration Services (SSIS), MySQL, Oracle, Nuix, Relativity.
* At least 7 years of professional software development experience.
* At least 7 years of web development experience, preferably on a Microsoft development stack.
* At least 7 years of experience with development against enterprise-grade RDBMS platforms such as MS SQL Server, Oracle, MySQL, etc. and the ability to write complex database queries.
* Must be eligible to obtain US government security clearance.
* A bachelor's degree.
Ideally, you will also have:
* Experience with eDiscovery tools such as Relativity, IPRO, NUIX, LAW, etc.
* Domain experience with eDiscovery, FOIA Processing, Litigation Support, or Federal Government.
Our Commitment:
Contact Government Services (CGS) strives to simplify and enhance government bureaucracy through the optimization of human, technical, and financial resources. We combine cutting-edge technology with world-class personnel to deliver customized solutions that fit our client's specific needs. We are committed to solving the most challenging and dynamic problems.
For the past seven years, we've been growing our government contracting portfolio, and along the way, we've created valuable partnerships by demonstrating a commitment to honesty, professionalism, and quality work.
Here at CGS we value honesty through hard work and self-awareness, professionalism in all we do, and to deliver the best quality to our consumers mending those relations for years to come.
We care about our employees. Therefore, we offer a comprehensive benefits package.
* Health, Dental, and Vision
* Life Insurance
* 401k
* Flexible Spending Account (Health, Dependent Care, and Commuter)
* Paid Time Off and Observance of State/Federal Holidays
Contact Government Services, LLC is an Equal Opportunity Employer. Applicants will be considered without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Join our team and become part of government innovation!
Explore additional job opportunities with CGS on our Job Board:
*************************************
For more information about CGS please visit: ************************** or contact:
Email: *******************
$149,760 - $216,320 a year
Information Security Firewall Engineer
Security Engineer Job 39 miles from Decatur
Lumen connects the world. We are igniting business growth by connecting people, data and applications - quickly, securely, and effortlessly. Together, we are building a culture and company from the people up - committed to teamwork, trust and transparency. People power progress.
We're looking for top-tier talent and offer the flexibility you need to thrive and deliver lasting impact. Join us as we digitally connect the world and shape the future.
**The Role**
The Senior Information Security Engineer is a member of the Fusion Center Corporate Firewall Operations (CNFW) team that is responsible for managing and securing the Lumen Enterprise including but not limited to maintaining Firewall and VPN Operations. In addition, CNFW Engineers are responsible to evaluate current capabilities and predict future needs, then work with internal stakeholders, vendors, and peers to anticipate, define, and pursue these capabilities.
**The Main Responsibilities**
+ Perform as Subject Matter Expert (SME) for existing environments, mentor lower-level engineers, and assume ownership and accountability in areas of recognized technical expertise
+ Perform high-level trouble identification, interpretation of standards, and implement resolution for internal network security problems or issues
+ Develop and maintain written procedures to maintain technical accuracy
+ Maintain a multitude of firewall vendor hardware across various environments
+ Support security projects dedicated to improving Cyber Defense Team or Lumen's security posture
+ Verify and validate security notifications from both internal and external sources
+ Identify and resolve incidents that are not defined by (or deviate from) an existing incident response guide
+ Respond to, remediate, and document network security related alerts and issues not limited to dashboard alerts, tickets, emails, or phone calls
+ Participate in on-call rotation
+ Able to work other shifts as needed based on business requirements
+ Maintain security of the network by ensuring firewall rules meet company policy and configuring best practice security measures on devices
**What We Look For in a Candidate**
+ Bachelor's degree in computer science, engineering, or related field, or equivalent experience
+ 5+ years of experience in Network Operations, Security Operations, Network Security, or Application Security
+ Knowledge of information security industry and regulatory obligations; PCI, CIS, NIST Frameworks (800-53, CSF, CMMC, etc.), HIPAA, FedRAMP, etc.
+ Excellent understanding of common computing platforms including Windows Client/Server, Macintosh, Linux, networking, and security appliances
+ Extensive hands-on experience with Next-Generation Firewalls, web-content filtering systems, IPS/IDS, and/or VPN devices
+ Candidate must possess, or be willing to pursue, applicable professional/technical certifications, such as CISSP, GSEC, Palo Alto, Checkpoint, Juniper, and Cisco
+ Strong work ethic, ability to work in a fast-paced team-oriented environment, and solid oral and written communication skills
+ Able to obtain a GSA Public Trust suitability
**Preferred Qualifications:**
+ 5+ years of experience in network and/or firewall engineering, administration, design, and implementation including experience in applying methodologies and principles for all levels of security
+ Solid understanding of information security fundamentals, host and network security hardening and requirements; networking protocols; common risk management concepts
+ Knowledge of Project Management processes and practices
+ Solid analytical and problem-solving skills related to networking and operating systems
+ Development experience in scripting languages such as Python or Perl is a plus
+ Experience with large enterprise data centers and/or networks and applications
+ Advanced knowledge of cloud-based firewalls from Amazon, Google, Microsoft, or firewall vendors
**Compensation**
This information reflects the anticipated base salary range for this position based on current national data. Minimums and maximums may vary based on location. Individual pay is based on skills, experience and other relevant factors.
Location Based Pay Ranges:
$82,969 - $110,625 in these states: AL, AR, AZ, FL, GA, IA, ID, IN, KS, KY, LA, ME, MO, MS, MT, ND, NE, NM, OH, OK, PA, SC, SD, TN, UT, VT, WI, WV, and WY.
$87,117 - $116,156 in these states: CO, HI, MI, MN, NC, NH, NV, OR, and RI.
$91,266 - $121,688 in these states: AK, CA, CT, DC, DE, IL, MA, MD, NJ, NY, TX, VA, and WA.
\#LI-MG1
Lumen offers a comprehensive package featuring a broad range of Health, Life, Voluntary Lifestyle benefits and other perks that enhance your physical, mental, emotional and financial wellbeing. We're able to answer any additional questions you may have about our bonus structure (short-term incentives, long-term incentives and/or sales compensation) as you move through the selection process.
Learn more about Lumen's:
+ Benefits (****************************************************
+ Bonus Structure
**What to Expect Next**
Requisition #: 337230
**Background Screening**
If you are selected for a position, there will be a background screen, which may include checks for criminal records and/or motor vehicle reports and/or drug screening, depending on the position requirements. For more information on these checks, please refer to the Post Offer section of our FAQ page (************************************* . Job-related concerns identified during the background screening may disqualify you from the new position or your current role. Background results will be evaluated on a case-by-case basis.
Pursuant to the San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
**Equal Employment Opportunities**
We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, gender expression, marital status, family status, pregnancy, or other legally protected status (collectively, "protected statuses"). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.
**Disclaimer**
The job responsibilities described above indicate the general nature and level of work performed by employees within this classification. It is not intended to include a comprehensive inventory of all duties and responsibilities for this job. Job duties and responsibilities are subject to change based on evolving business needs and conditions.
In any materials you submit, you may redact or remove age-identifying information such as age, date of birth, or dates of school attendance or graduation. You will not be penalized for redacting or removing this information.
Please be advised that Lumen does not require any form of payment from job applicants during the recruitment process. All legitimate job openings will be posted on our official website or communicated through official company email addresses. If you encounter any job offers that request payment in exchange for employment at Lumen, they are not for employment with us, but may relate to another company with a similar name.
**Application Deadline**
04/05/2025
Infrastructure Security Engineer - FedRAMP (US Citizen)
Security Engineer Job 39 miles from Decatur
**Title:** Infrastructure Security Engineer (US citizen) **Salary:** $120K/annually **About PSI** We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.
We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.
At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.
Learn more about what we do at: *************************
**About the Role**
The Infrastructure Security Engineer (ISE) is responsible for ensuring that PSI systems are secure, well maintained, and appropriately monitored. They work with senior management across all business units to design security solutions and ensure that PSI environments are designed and maintained in accordance with industry standards.
Infrastructure Security Engineers ensure adherence to ISO27001, SOC2, CIS, NIST and other standards. They possess a broad understanding of log aggregation solutions, server hardware, Linux and Windows operating systems, storage, networking, and load balancing. The Infrastructure Security Engineer leads projects and organizes teams to achieve technical and security objectives.
Infrastructure Security Engineers work as part of a global team to design, implement, and monitor security across the organization. They engage with vendors, business and technology partners to lead projects and constantly improve security posture.
**Role Responsibilities**
+ Lead projects to evaluate, select, and implement security technologies
+ Design, configure, implement, and maintain all security platforms and their associated software: firewalls, intrusion detection/intrusion prevention, antivirus/EDR, URL Filtering, email security gateway, SIEM, vulnerability assessment solutions, DLP
+ Respond to security events and incidents performing containment, root cause analysis, and remediation.
+ Maintain enterprise vulnerability scanning infrastructure, ensuring daily operation of scans and reporting are occurring as required
+ Coordinate and sequence external scans and penetration testing
+ Monitor application and system activity logs for potential threats
+ Keep up to date with evolving trends and changes in security models and methodologies
+ Threat model common attacker methods to develop appropriate mitigation techniques
+ Define and develop technical security standards and guidelines with business stakeholders
+ Participate in product security architecture planning for both on-premises and cloud-based solutions
+ Ensure server infrastructure is secure, patched and updated
+ Take proactive steps to resolve issues before they impact the business
+ Maintain accurate and up to date security documentation
+ Serve as team lead and subject matter expert for security
**Knowledge, Skills and Experience Requirements**
+ Bachelor's degree in computer science or equivalent training/certification.
+ 10+ years of working experience as a Security Engineer or Systems Engineer
+ 5+ years of working experience with email security tools such as Proofpoint
+ 5+ years of working experience with CrowdStrike EDR and SIEM solutions
+ Ability to achieve federal security clearance, must be a US Citizen
+ Experience with FedRamp security controls,
+ In-depth knowledge and understanding of the integration of AWS with fundamental Information Security methodologies for both architectural review and implementation
+ Strong knowledge of Windows and Linux environments
+ Experience drafting and promoting security policy with all levels of business stakeholders
+ Experience and detailed technical knowledge of security engineering, system and network security, authentication and security protocols, cryptography, and application security
+ Detailed knowledge of core server technologies and domain configuration and management, including DNS, DHCP, AD and group policy
+ Experience in Domain Trusts, Active Directory Federation, and Entra ID
+ Experience managing remote infrastructure across multiple time zones
+ Detailed understanding of Azure, AWS, Hyper-V, VMWare and SAN technologies
+ Understanding of network topologies such as VLANs, IPs, subnets, and routing
+ Understanding of PowerShell / VB Scripting
+ Good written and verbal communication skills with the ability to follow a project from beginning to end while providing updates along the way, while prioritizing time and dealing with multiple projects
+ Experience with CIS Hardening Standards and/or DISA STIGs
+ Experience with load balancers (F5, Barracuda, Azure)
**Benefits & Culture**
At PSI, our culture is to be transparent and fair. That's why all of our roles have been benchmarked at a competitive rate against the local market they are based in. To be transparent all of our adverts now include the salary so you can see if we align with your expectations when looking for your next role.
In addition to a competitive salary, we offer a comprehensive benefits package and supportive culture when you join us. This includes:
+ 401k/Pension/Retirement Plan - with country specific employer %
+ Enhanced PTO/Annual Leave
+ Medical insurance - country specific
+ Dental, Vision, Life and Short-Term Disability for US
+ Flexible Spending Accounts - for the US
+ Medical Cashback plan covering vision, dental and income protection for UK
+ Employee Assistance Programme
+ Commitment and understanding of work/life balance
+ Dedicated DE&I group that drive core people initiatives
+ A culture of embracing wellness, including regular global initiatives
+ Access to supportive and professional mechanisms to help you plan for your future
+ Volunteer Day and a culture of giving back to our community and industry through volunteering opportunities
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
Senior Security Engineer II - Detection and Response
Security Engineer Job 39 miles from Decatur
With Confluent, organizations can harness the full power of continuously flowing data to innovate and win in the modern digital world. We have a purpose that drives us to do better every day - we're creating an entirely new category within data infrastructure - data streaming. This technology will allow every organization to create experiences and use the power of data in ways that profoundly impact the way we all live. This impact is our purpose and drives us to do better every day.
One Confluent. One team. One Data Streaming Platform.
Data Connects Us.
**About the Role:**
We are looking for an experienced security engineer to join our infrastructure security engineering team with a strong focus on detection and response. You will have a unique opportunity to leverage your threat detection and response experience and build some of the foundational systems and services to keep our infrastructure free from malicious actors and threats. You will partner closely with all engineering teams, IT administrators, and compliance analysts to ensure that we maintain sufficient visibility into our environments and develop effective programs and practices to ensure that our environments are always secure. Tooling and automation will be key to success as we scale our environments to meet customer demand.
We intend to be the world's best, fastest, and most complete stream processing service built by an excellent team, all while having fun - come join us on the journey!
**What You Will Do:**
+ Collaborate with engineering teams for building and setting up pipelines needed to gather relevant security telemetry.
+ Build and maintain an effective and scalable security monitoring infrastructure solution.
+ Develop detection strategies to identify anomalous activity and ensure that our critical infrastructure and services operate in a safe environment.
+ Triage alerts and drive security incidents to closure while reducing its potential impact to Confluent.
+ Build processes and workflows to triage security alerts and respond to real incidents.
+ Research new threat attack vectors and ensure that our detection and response capability is in line with the current threat landscape.
+ Proactively improve the quality of our detection rules and strive to eliminate classes of issues by working directly with engineering teams.
+ Contribute to strategy, risk management and prioritization for all efforts around detection and response.
**What You Will Bring:**
+ 5+ years of relevant industry experience.
+ Strong domain knowledge in security incident detection and response.
+ Hands-on experience in instrumenting and deploying telemetry solutions to ensure visibility in large-scale, heterogenous deployments.
+ Demonstrated experience with effective incident response and containment practices, preferably in a cloud-first environment.
+ Experience with operating open-source and/or commercial solutions for logging and security event management.
+ Decision-maker with the ability to operate with freedom and autonomy.Experience working with distributed teams and other cross-functional stakeholders.
+ Ability to manage competing priorities and workload.
+ Ability to script or code fluently in an interpreted language.
+ Experience with serverless deployments in AWS, GCP, or Azure is a plus.
**Come As You Are**
At Confluent, equality is a core tenet of our culture. We are committed to building an inclusive global team that represents a variety of backgrounds, perspectives, beliefs, and experiences. The more diverse we are, the richer our community and the broader our impact. Employment decisions are made on the basis of job-related criteria without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, veteran status, or any other classification protected by applicable law.
At Confluent, we are committed to providing competitive pay and benefits that are in line with industry standards. We analyze and carefully consider several factors when determining compensation, including work history, education, professional experience, and location. This position has an annual estimated salary of 192,200 - 225,810 USD and a competitive equity package. The actual pay may vary depending on your skills, qualifications, experience, and work location. In addition, Confluent offers a wide range of employee benefits. To learn more about our benefits click HERE (******************************* .
Click HERE (******************************************************************* to review our Candidate Privacy Notice which describes how and when Confluent, Inc., and its group companies, collects, uses, and shares certain personal information of California job applicants and prospective employees.
\#LI-Remote
Security Engineer II
Security Engineer Job 39 miles from Decatur
Trustmark's mission is to improve wellbeing - for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture of diversity and inclusion where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. At Trustmark, we have a commitment to welcoming people, no matter their background, identity or experience, to a workplace where they feel safe being their whole, authentic selves. A workplace made up of diverse, empowered individuals that allows ideas to thrive and enables us to bring the best to our colleagues, clients and communities.
We are seeking a highly skilled Cyber Security Engineer to join our team and play a pivotal role in safeguarding our organization's digital assets. The ideal candidate will possess a deep understanding of cybersecurity principles, a strong technical background, and a passion for protecting sensitive information.
You will be responsible for engineering, implementing and monitoring security measures for the protection of Trustmark's computer systems, networks and information. The role helps identify and define system security requirements as well as develop detailed cyber security designs.
**Responsibilities:**
+ Design, implement, and maintain security architectures, systems, and solutions to protect critical infrastructure and data.
+ Conduct vulnerability assessments and penetration testing to identify and mitigate risks.
+ Develop and implement security policies, standards, and procedures.
+ Monitor security systems and respond to incidents promptly and effectively.
+ Stay up-to-date with the latest cybersecurity threats and trends.
+ Collaborate with cross-functional teams to ensure security is integrated into all aspects of the business.
+ Provide technical guidance and support to internal stakeholders.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, or a related field or
+ 3-5 Years of network engineering or cyber engineering experience
+ Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001).
+ Proficiency in network security, systems security, application security, and data security.
+ Hands-on experience with security tools and technologies (e.g., firewalls, intrusion detection systems, encryption, SIEM).
+ Excellent problem-solving and analytical skills.
+ Strong communication and interpersonal skills.
+ Ability to work independently and as part of a team.
**Preferred Qualifications:**
+ Certifications such as CISSP, CISA, or CEH.
+ Experience with cloud security (e.g., AWS, Azure, GCP).
+ Knowledge of scripting and programming languages (e.g., Python, PowerShell).
Brand: Trustmark
Come join a team at Trustmark that will not only utilize your current skills but will enhance them as well. Trustmark benefits include health/dental/vision, life insurance, FSA and HSA, 401(k) plan, Employee Assistant Program, Back-up Care for Children, Adults and Elders and many health and wellness initiatives. We also offer a Wellness program that enables employees to participate in health initiatives to reduce their insurance premiums.
**For the fourth consecutive year we were selected as a Top Workplace by the Chicago Tribune.** The award is based exclusively on Trustmark associate responses to an anonymous survey. The survey measured 15 key drivers of engaged cultures that are critical to the success of an organization.
All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, sexual identity, age, veteran or disability.
Join a passionate and purpose-driven team of colleagues who contribute to Trustmark's mission of helping people increase wellbeing through better health and greater financial security. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves.
Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.
When you join Trustmark, you become part of an organization that makes a positive difference in people's lives. You will play a vital role in delivering on our mission of helping people increase wellbeing through better health and greater financial security. Our customers tell us they simply appreciate the personal attention and knowledgeable service. Others tell us we've changed their lives.
At Trustmark, you'll be part of a close-knit team. You'll enjoy abundant opportunities to grow your career. That's why so many of our associates stay at Trustmark and thrive. Trustmark benefits from more than 100 years of experience but pairs that rich history with a palpable sense of optimism, growth and excitement for what's ahead - and beyond. This is a place where associates bring their whole selves to work each day. A place where you can be yourself. Whatever your beyond is, you can achieve it at Trustmark.
Infrastructure Security Analyst
Security Engineer Job 45 miles from Decatur
TekWissen provides a unique portfolio of innovative capabilities that seamlessly combines clients insights, strategy, design, software engineering, and systems integration.
*****************
Job Description
Required:
· Must Have: Citrix Netscaler support and configuration
· Significant experience in supporting network security devices such as firewalls and proxies with emphasis on remote access technologies such as VPN and Citrix Netscaler
· Significant experience in TCP/IP networking, including network design and troubleshooting.
· 1 to 2 years experience in network sniffers and packet analysis.
· 1 to 2 years experience in general security.
Desired Skills:
· Some experience in scripting languages such as Shell and Perl.
· Strong customer service and results focus.
· Strong organizational, communication, and interpersonal skills.
· Strong problem resolution and decision making skills.
· Working both independently and in a team environment.
· Ability to handle competing priorities.
· Able to consult other Business areas.
· Sound decision-making ability regarding matters of moderate to high complexity and importance.
· Strong analytical and problem-solving skills to solve complex problems logically and systematically
· Self-motivated; Ability to work independently on matters of moderate to high complexity and importance with only broad direction.
· High technical aptitude.
· Security and/or Network Certification is a plus, especially CISSP
Additional Information
All your information will be kept confidential according to EEO guidelines.
Senior Security Systems Engineer
Security Engineer Job 39 miles from Decatur
**170+ Years Strong. Industry Leader. Global Impact.** At Pinkerton, the mission is to protect our clients. To do this, we provide enterprise risk management services and programs specifically designed for each client. Pinkerton employees are one of our most important assets and critical to the delivery of world-class solutions. Bonded together, we share a commitment to integrity, vigilance, and excellence.
Pinkerton is an inclusive employer who seeks candidates with diverse backgrounds, experiences, and perspectives to join our family of industry subject matter experts.
The Senior Security Systems Engineer, assigned to one of Pinkerton's largest global clients, will be responsible for the design, implementation, and optimization of advanced physical security systems, with a primary focus on Genetec platforms. The Engineer ensures the seamless integration of security technologies to protect corporate offices, personnel, and assets while aligning with organizational goals and industry best practices. This role brings technical expertise, programmatic leadership, and a proactive approach to maintaining and enhancing security systems. **This position can be based anywhere (remote) within the United States.**
**Responsibilities**
+ Represent Pinkerton's core values of integrity, vigilance, and excellence.
+ Design, configure, deploy and maintain Genetec security systems, including access control, video surveillance, and analytics while tailoring to corporate office environments.
+ Lead the integration of Genetec platforms with existing IT and physical security infrastructure while ensuring scalability and interoperability.
+ Develop and maintain system documentation, including configurations, diagrams, and operational procedures to ensure operational reliability.
+ Collaborate with cross-functional teams including IT, security operations, and external vendors to implement and optimize security solutions.
+ Monitor system performance, conduct regular audits, and recommend enhancements to improve efficiency, security, and compliance.
+ Provide technical support and training to security and operational teams while ensuring effective use of Genetec systems.
+ Support project management efforts, including timelines, resource allocation, and stakeholder communication for new security system deployments.
+ Design and implement access control and CCTV systems while recommending appropriate hardware and software solutions.
+ Provide technical support and training to clients and internal teams for effective system use.
+ Develop and maintain comprehensive documentation including programming standards and hardware configurations.
+ Participate in end-to-end testing efforts and knowledge transfer.
+ Install, program, and configure Genetec enterprise security systems such as door access control, CCTV, intrusion detection, and related components.
+ Design, configure, and manage virtual machines (VMs) on server infrastructures across platforms like VMware, Hyper-V, and cloud-based solutions.
+ Apply expertise in networking fundamentals including TCP/IP, routing protocols, VLANs, VPNs, and firewalls to design and troubleshoot complex network infrastructures.
+ Troubleshoot and ensure proper functioning of new security installations in compliance with relevant requirements.
+ Analyze and implement software and hardware enhancements to optimize existing systems while maintaining design standards and operating procedures.
+ Stay current with industry trends and emerging technologies to propose innovative solutions and maintain the organization's competitive edge.
+ All other duties, as assigned.
**Qualifications**
Bachelor's degree in engineering, information technology, or a related field with at least ten to twelve years of experience in physical security system design, implementation, and support and a focus on Genetec platforms.
+ Genetec Certified Professional or PSP, preferred.
+ Knowledge of network architecture and protocols related to security systems.
+ Proficiency in configuring and managing Genetec Security Center including access control and video management modules.
+ Able to analyze complex situations and recommend solutions.
+ Able to collaborate with cross-functional teams and manage vendor relationships.
+ Client orientated and results driven.
+ Able to understand business requirements and deliver tailored solutions.
+ Sound analytical and problem-solving skills.
+ Project management skills.
+ Effective communication skills including the ability to convey technical concepts to non-technical stakeholders.
+ Attentive to detail and accuracy.
+ Consistently delivers on commitments and achieves expected business results.
+ Computer skills; Microsoft Office.
**Working Conditions:**
With or without reasonable accommodation, requires the physical and mental capacity to effectively perform all essential functions;
+ Regular computer usage.
+ Occasional reaching and lifting of small objects and operating office equipment.
+ Frequent sitting.
+ Travel, as required.
**Benefits**
Benefit options include employer-paid life and AD&D, voluntary life and AD&D, medical, (HSA) Health Savings Account, (FSA) Flexible Savings Account, dental, vision, short-term disability, long-term disability, 401(K), paid time off (vacation, personal, sick, and holidays) and several employee assistance-related programs. This information provides a brief benefit overview. Upon the acceptance of an employment offer, the new employee will receive comprehensive plan details based on specific eligibility rules.
**Posted Salary Range**
USD $120,000.00 - USD $180,000.00 /Yr.
Submit a Referral (******************************************************************************************************************************************
**Location** _US-_
**ID** _2025-1543_
**Category** _Security Risk Management_
**Position Type** _Full-Time_
**Min Pay Rate** _USD $120,000.00/Yr._
**Max Pay Rate** _USD $180,000.00/Yr._
**Job Type** _Remote_
Pinkerton is an equal opportunity employer to all applicants and positions without regard to race/ethnicity, color, national origin, ancestry, sex/gender, gender identity/expression, sexual orientation, marital/prenatal status, pregnancy/childbirth or related conditions, religion, creed, age, disability, genetic information, veteran status, or any protected status by local, state, federal or country-specific law.
Senior Information Security & Risk Engineer
Security Engineer Job 39 miles from Decatur
Headquartered in Dublin, Ohio, Cardinal Health, Inc. (NYSE: CAH) is a global, integrated healthcare services and products company, providing customized solutions for hospitals, health systems, pharmacies, ambulatory surgery centers, clinical laboratories and physician offices worldwide.
The company provides clinically-proven medical products and pharmaceuticals and cost-effective solutions that enhance supply chain efficiency from hospital to home. Cardinal Health connects patients, providers, payers, pharmacists and manufacturers for integrated care coordination and better patient management. Backed by nearly 100 years of experience, with approximately 50,000 employees in 46 countries, Cardinal Health ranks among the top 20 on the Fortune 500.
We currently have a full-time career opening within Information Security to support the growth of our Navista Application Suite and the Integrated Oncology Network (IoN).
**Department overview**
The Information Security department at Cardinal Health enables Cardinal Health to securely deliver healthcare products and solutions that improve the lives of people every day by ensuring security practices and controls are embedded into Cardinal Health's people, process and technology. We are a remote-first team and are excited to offer full-time remote opportunities.
**Functional Overview**
The Senior Information Security & Risk Engineer is a new capability for Cardinal Health and will be executed by the Product Security team. The primary goal of this position is to ensure delivery of best-in-class cybersecurity, risk management, and compliance for Navista, an oncology Managed Service Offering hosted by Cardinal Health.
**Job Overview**
The Information Security & Risk Engineer will be responsible for day-to-day activities in implementing the corporate information security and compliance program. The individual will be a front-line partner to technical teams and work across the organization to deliver security and compliance initiatives aligning to corporate policies, standards, procedures and audit activities. Success in the role will be measured by the effectiveness of the implementation of information security, risk management and compliance directives.
This role will work with various IT and business teams to drive both information security and compliance initiatives. The individual will assist with internal and external security compliance monitoring activities, review client audits, IT control audits, architecture reviews, threat modeling and security risk assessments. Good interpersonal and relationship building skills are essential for success.
**Job Responsibilities Include:**
+ Maintain governance program that ensures that the security policies, standards and process are in place
+ Serve as liaison to other Cardinal Health teams to ensure knowledge share and best practices
+ Partner with the engineering, architecture and operations teams to ensure delivery of infrastructure design and threat models which prove security requirements
+ Monitor security trends and drive security best practices throughout the organization via threat models and risk analysis
+ Evaluate, design, test, and recommend new or improved controls
+ Work with third party firms and consultants to conduct independent security audits, vulnerability scans, and penetration tests
+ Partner with developers to mentor and advise on secure coding and SDLC practices, define test cases and ensure appropriate testing, remediations, and mitigations
+ Investigate, drive resolution and document security incidents
+ Travel to various Integrated Oncology Network (IoN) sites may be required
**Qualifications**
+ Bachelors Degree in related field, or equivalent work experience leading cybersecurity or information security initiatives
+ Have 5+ years information security related work experience, preferably within the healthcare industry
+ Extensive experience with network and infrastructure design and security, ideally within the Azure cloud
+ Experience in vulnerability management programs, vulnerability assessments and advanced understanding of risk management
+ Familiarity with at least one common programming language, software development pipelines, and system lifecycles
+ Familiarity with standards such as HIPAA/HITECH, ISO, ITIL, NIST, PCI DSS, & SOX, CCPA, OWASP
+ Professional security certification (CISSP or CISM preferred)
+ Experience advising and mentoring diverse teams where you do not have direct authority
+ Strong written and verbal communication skills
**Anticipated salary range:** $121,600 - $182,385
**Bonus eligible:** Yes
**Benefits:** Cardinal Health offers a wide variety of benefits and programs to support health and well-being.
+ Medical, dental and vision coverage
+ Paid time off plan
+ Health savings account (HSA)
+ 401k savings plan
+ Access to wages before pay day with my FlexPay
+ Flexible spending accounts (FSAs)
+ Short- and long-term disability coverage
+ Work-Life resources
+ Paid parental leave
+ Healthy lifestyle programs
**Application window anticipated to close:** 4/7/2025 *if interested in opportunity, please submit application as soon as possible.
The salary range listed is an estimate. Pay at Cardinal Health is determined by multiple factors including, but not limited to, a candidate's geographical location, relevant education, experience and skills and an evaluation of internal pay equity.
_Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply._
_Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal_ _Opportunity/Affirmative_ _Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law._
_To read and review this privacy notice click_ here (***************************************************************************************************************************
Physical Security Systems Engineer (Manufacturing)
Security Engineer Job 48 miles from Decatur
About Rivian Rivian is on a mission to keep the world adventurous forever. This goes for the emissions-free Electric Adventure Vehicles we build, and the curious, courageous souls we seek to attract. As a company, we constantly challenge what's possible, never simply accepting what has always been done. We reframe old problems, seek new solutions and operate comfortably in areas that are unknown. Our backgrounds are diverse, but our team shares a love of the outdoors and a desire to protect it for future generations. Role Summary The Technical Security Engineer will be responsible for engineering support of Rivian's physical security technology deployments, specifically focused on our manufacturing facilities in Normal, IL. You'll be responsible for the entire engineering lifecycle of these tech deployments - owning the programming, commissioning, and reliability of the devices we install, in addition to ensuring that their use meets the operational needs of our security operations team and close business partners. Our manufacturing facilities are large, fast paced, and demanding - you'll be expected to dive deep, get your hands dirty in the field, and execute with precision. While no two days will end up looking the same, generally speaking you'll be responsible for the following things: Responsibilities Program, configure, commission, and test all of our physical security devices. The project managers will physically install it for you - your job is to bring it to life, give it purpose, and make it useful. Ensure the operational availability and reliability of all of the physical security devices that we've deployed. We invest heavily in our technology and platforms; everything must be functional, online, and ready to use by our operational teams. Provide hands-on support for our security team, literally and figuratively. Some days you'll be a keyboard warrior buried in slacks, zooms, and configs and other days you'll be in the field physically installing, fixing, or troubleshooting devices. Provide design engineering support for our new construction projects, moves/adds/changes (MACs), and any other special projects that pop up. You're the engineering SME and the team will look to you to help build it the right way. Design, deploy, support, and maintain our Manufacturing Engineering (ME) camera systems. The production teams leverage our expertise, platforms, and technologies to build cars. How cool is that?! Build strong relationships and collaborate closely with our security operations teams to understand their needs and translate operational requirements into technical solutions. We get to help make their dreams a reality. Harden, patch, and update our technical security devices. Cyber threats are real, new functionality becomes available, and every device has a lifecycle. You'll own it. Provide technical security support for our facilities maintenance teams, security operations center (SOC), and security operations teams. When they call, you answer! Utilize Rivian tech platforms for issue tracking, alerting, documentation, and communication. These aren't the fun parts of the job, but they're important. Maintain databases, datasets, and logical access to our technical security systems. Our data is gold. You'll ensure that the correct controls are in place to protect it. Support cross functional business teams with requests for workflows, features, and integrations. You'll get several new asks, everyday. Your job is to filter them, prioritize impact, and execute with a bias towards action. Foster close collaboration with partners in Enterprise Technology, including our Cybersecurity, Networking, Platform Engineering, Digital Tech, and Support teams. They're our friends and we're largely dependent on them to help make the magic happen. Provide engineering support, in varying forms, to the larger technical security team. Priorities change, workload fluctuates, and we have some wicked ideas. Teamwork makes the dream work. HEADS UP: You'll be on call 24/7. Yep, really. Things break; usually when you're already super busy or fast asleep. Either way, you're the person everyone will call when it's critical. You'll need to be flexible with your hours. Our manufacturing facility is large, complex, and critical to the production of our vehicles. We're often given small maintenance windows and super tight project deadlines. This means that you'll occasionally work nights, weekends, or holidays to support our business needs. Qualifications Some teams have strict requirements about certifications, degrees, and things like that. Not us! We're more interested in the unique perspectives and expertise you'll bring to the team, rather than acronyms on your resume. However, you'll be much more likely to be successful in this role if these bullet points seem like a good description of you: You've been a technical security engineer for a little while now, probably in the realm of 2+ years Your technical skills are wide and deep. You're a master of physical security technology, including all core IT dependencies, and you're a wizard at things like querying and scripting You enjoy building things. If we handed you a pile of parts and a soldering iron you would build us something great! You're really good at deploying resilient, scalable, solutions that are frictionless for end users You frequently get praise from your peers and coworkers about your communication skills, both written and verbal You have effective methods to handle stress and pressure, even in high intensity or emotionally charged situations and environments You're meticulous and demand perfection Pay Disclosure Salary Range for Normal, IL based applicants: $71,000 - $88,000 annually (Actual compensation will be determined based on experience, location and other factors permitted by law). Benefits Summary: Rivian provides robust medical/Rx, dental and vision insurance packages for full-time and part-time employees, their spouse or domestic partner, and children up to age 26. Full Time Employee coverage is effective on the first day of employment. Part-Time employee coverage is effective the first of the month following 90 days of employment. Equal Opportunity Rivian is an equal opportunity employer and complies with all applicable federal, state, and local fair employment practices laws. All qualified applicants will receive consideration for employment without regard to race, color, religion, national origin, ancestry, sex, sexual orientation, gender, gender expression, gender identity, genetic information or characteristics, physical or mental disability, marital/domestic partner status, age, military/veteran status, medical condition, or any other characteristic protected by law. Rivian is committed to ensuring that our hiring process is accessible for persons with disabilities. If you have a disability or limitation, such as those covered by the Americans with Disabilities Act, that requires accommodations to assist you in the search and application process, please email us at candidateaccommodations@rivian.com. Candidate Data Privacy Rivian may collect, use and disclose your personal information or personal data (within the meaning of the applicable data protection laws) when you apply for employment and/or participate in our recruitment processes ("Candidate Personal Data"). This data includes contact, demographic, communications, educational, professional, employment, social media/website, network/device, recruiting system usage/interaction, security and preference information. Rivian may use your Candidate Personal Data for the purposes of (i) tracking interactions with our recruiting system; (ii) carrying out, analyzing and improving our application and recruitment process, including assessing you and your application and conducting employment, background and reference checks; (iii) establishing an employment relationship or entering into an employment contract with you; (iv) complying with our legal, regulatory and corporate governance obligations; (v) recordkeeping; (vi) ensuring network and information security and preventing fraud; and (vii) as otherwise required or permitted by applicable law. Rivian may share your Candidate Personal Data with (i) internal personnel who have a need to know such information in order to perform their duties, including individuals on our People Team, Finance, Legal, and the team(s) with the position(s) for which you are applying; (ii) Rivian affiliates; and (iii) Rivian's service providers, including providers of background checks, staffing services, and cloud services. Rivian may transfer or store internationally your Candidate Personal Data, including to or in the United States, Canada, the United Kingdom, and the European Union and in the cloud, and this data may be subject to the laws and accessible to the courts, law enforcement and national security authorities of such jurisdictions. Please note that we are currently not accepting applications from third party application services.
Some teams have strict requirements about certifications, degrees, and things like that. Not us! We're more interested in the unique perspectives and expertise you'll bring to the team, rather than acronyms on your resume. However, you'll be much more likely to be successful in this role if these bullet points seem like a good description of you: You've been a technical security engineer for a little while now, probably in the realm of 2+ years Your technical skills are wide and deep. You're a master of physical security technology, including all core IT dependencies, and you're a wizard at things like querying and scripting You enjoy building things. If we handed you a pile of parts and a soldering iron you would build us something great! You're really good at deploying resilient, scalable, solutions that are frictionless for end users You frequently get praise from your peers and coworkers about your communication skills, both written and verbal You have effective methods to handle stress and pressure, even in high intensity or emotionally charged situations and environments You're meticulous and demand perfection
Program, configure, commission, and test all of our physical security devices. The project managers will physically install it for you - your job is to bring it to life, give it purpose, and make it useful. Ensure the operational availability and reliability of all of the physical security devices that we've deployed. We invest heavily in our technology and platforms; everything must be functional, online, and ready to use by our operational teams. Provide hands-on support for our security team, literally and figuratively. Some days you'll be a keyboard warrior buried in slacks, zooms, and configs and other days you'll be in the field physically installing, fixing, or troubleshooting devices. Provide design engineering support for our new construction projects, moves/adds/changes (MACs), and any other special projects that pop up. You're the engineering SME and the team will look to you to help build it the right way. Design, deploy, support, and maintain our Manufacturing Engineering (ME) camera systems. The production teams leverage our expertise, platforms, and technologies to build cars. How cool is that?! Build strong relationships and collaborate closely with our security operations teams to understand their needs and translate operational requirements into technical solutions. We get to help make their dreams a reality. Harden, patch, and update our technical security devices. Cyber threats are real, new functionality becomes available, and every device has a lifecycle. You'll own it. Provide technical security support for our facilities maintenance teams, security operations center (SOC), and security operations teams. When they call, you answer! Utilize Rivian tech platforms for issue tracking, alerting, documentation, and communication. These aren't the fun parts of the job, but they're important. Maintain databases, datasets, and logical access to our technical security systems. Our data is gold. You'll ensure that the correct controls are in place to protect it. Support cross functional business teams with requests for workflows, features, and integrations. You'll get several new asks, everyday. Your job is to filter them, prioritize impact, and execute with a bias towards action. Foster close collaboration with partners in Enterprise Technology, including our Cybersecurity, Networking, Platform Engineering, Digital Tech, and Support teams. They're our friends and we're largely dependent on them to help make the magic happen. Provide engineering support, in varying forms, to the larger technical security team. Priorities change, workload fluctuates, and we have some wicked ideas. Teamwork makes the dream work. HEADS UP: You'll be on call 24/7. Yep, really. Things break; usually when you're already super busy or fast asleep. Either way, you're the person everyone will call when it's critical. You'll need to be flexible with your hours. Our manufacturing facility is large, complex, and critical to the production of our vehicles. We're often given small maintenance windows and super tight project deadlines. This means that you'll occasionally work nights, weekends, or holidays to support our business needs.
Security Analyst- Tivoli (2016-166495)
Security Engineer Job 45 miles from Decatur
Mindlance is a national recruiting company which partners with many of the leading employers in the Life Sciences, IT, and Financial Services sectors, feel free to check us out at *************************
Job Description
Client: NTT DATA / State Farm
Job Title: Security Analyst- Tivoli
Job ID: 2016-166495
Start Date: 4/21/2016
End Date: 12/31/2016
Location:Bloomington, IL, US
Qualifications:
Client is seeking a Tivoli Federated Identity Manager Analyst to be responsible for the planning, designing, customizing, testing, troubleshooting, and documenting of solutions for Tivoli Federated Identity Manager V6.1. This individual is expected to perform these tasks with limited assistance from peers, product documentation, and support resources. Support will require availability 24/7.
Required Skills/Experience:
- Working knowledge/experience: Basic editors such as vi, WebSphere Application Server (administration console, clustering), IBM Tivoli Directory Integrator and JavaScript, IBM Tivoli Access Manager for e-business, F-SSO protocols (SAML, WS Federation, Liberty)
- Working knowledge/experience: Operating systems, Server hardware and networking technologies, System administration of UNIX , Windows, or Linux operating systems, XML terms and concepts including XSLT, XML DSig, and XML encryption, SOAP terms and concepts including WS Security, WS Trust, WSDL, Web service deployment, LDAP (IBM Tivoli Directory Server)
- Have programming and scripting experience including JSPâ„¢, ActiveX , Java
- Have experience and knowledge with TCP/IP networking principles including SSL
- Have general knowledge of security concepts including key management and PKI (Public Key Infrastructure) fundamentals.
- Understand basic Web page development fundamentals (including security issues)
Job Responsibilities:
- Review customer's architecture and solution design documentation
- Analyze the deployment environments
- Assist in project plan development
- Apply federation management concepts (federated identity management, Web services security management, federated provisioning)
- Perform basic installations of the prerequisite applications (IBM Tivoli Directory Integrator, LDAP/DB2 , WebSphere Application Server, Tivoli Access Manager for e-business)
- Understand concepts regarding the Tivoli Federated Identity Manager features and components
- Configure product and component integration points such as WebSphere Application Server and Tivoli Access Manager for e-business
- Install and configure federated single sign-on (F-SSO), Web services security management, and federated provisioning services
- Troubleshoot Tivoli Federated Identity Manager services
Required Qualifications/Experience
Qualification Experience with IBM Tivoli Directory Integrator, IBM Tivoli Access Manager for e-business, IBM Tivoli Directory Server
Minimum Years Required 3
Qualification Experience with WebSphere Application Server (administration console, clustering), F-SSO protocols (SAML, WS Federation, Liberty)
Minimum Years Required 3
Qualification Experience in System administration of UNIX , Windows, or Linux operating systems
Minimum Years Required 2
Qualification Experience with XML terms and concepts including XSLT, XML DSig, and XML encryption, SOAP terms and concepts including WS Security
Minimum Years Required 2
Qualification 2 years / Experience in programming and scripting in JSPâ„¢, ActiveX , Java
Minimum Years Required 2
Additional Information
Note: This is an urgent requirement with one of our client, the hiring manager is actively interviewing candidates and would like to make decision asap. if you are interested please respond to this job posting with your updated copy of resume or you can directly reach me on ************.
Cloud Security Architect - FedRAMP
Security Engineer Job 39 miles from Decatur
**About the team:** The Information Security organization advances the overall state of security at Rubrik through purposeful initiatives and coordination of large security projects. Information Security builds technologies, tools, and processes to better enable teams at Rubrik to develop secure software and protect data and systems with appropriate security controls. Information Security also develops systems to monitor and respond to attacks against our systems, provides awareness education to teams on security best practices for data protection, and ensures data sharing relationships with third parties in order to securely protect Rubrik information.
**What you'll do:**
+ Partner with engineering teams across Rubrik to create secure cloud infrastructure design and deployment architectures utilizing threat models and risk analysis documentation specific to a FedRAMP and IL4+ environment
+ Work with development teams, operations, governance, and other stakeholders to draft security standards and controls and implement monitoring, alerting and governance to adhere to those specifications
+ Support incident responders in analyzing applicable threats, vulnerabilities, controls and residual risks inside and out of the FedRAMP boundary
+ Analyze and harden existing applications, infrastructure, automation, and deployment processes partnering with multiple teams to design & implement solutions within the space
+ Execute Security impact Analysis reviews for all FedRAMP changes coming in to the change management process
**Experience you'll need:**
+ Bachelor's degree required; BS or MS in Computer Science, Information Technology, or a related field
+ 15 years of experience including cloud technologies, technical architecture and application development
+ 8+ years experience in cloud security, with experience across AWS, GCP and/or Azure infrastructure design
+ 2+ years experience in VMWare and/or Network security modeling
+ Broad knowledge of private and public cloud attack vectors and exploits
+ Subject matter expertise in CI/CD, Cloud APIs and Identity management
+ Deep understanding of compute, network and storage technologies in AWS, GCP and/or Azure
+ Programming experience in Python, Go or Java
+ Deep security policy subject matter expertise in at least one major public cloud provider (AWS, GCP, Azure)
+ Experience with deploying and securing SaaS applications and cloud environments at scale
+ Working experience with CI/CD pipeline, containerization (Kubernetes, Docker, etc) and MicroServices
+ Knowledge of of IaC (Infrastructure as Code) concepts and implementing standards within them
+ Understanding of cloud security maturity model frameworks and how to apply them
+ Strong written and verbal communication skills
**Additional Requirements:**
Due to the criteria and security levels for Rubrik's FedRAMP program, this position will require the following:
+ U.S. citizenship at the time of hire
+ Residence within the contiguous United States (i.e., the lower 48 states and the District of Columbia); and
+ Willingness to undergo a Single Source Background Investigation if required.
\#LI-Remote
**Security and Privacy Responsibilities** :
This position carries special Security and Privacy Responsibilities for protecting the U.S. Federal Government's interests:
+ Know, acknowledge, and follow system-specific security policies and procedures;
+ Protect data and individual privacy per requirements and regulations;
+ Perform ongoing activities in compliance with service and contractual obligations;
+ Participate in role-based training, completing assignments on a timely basis;
+ Report security issues promptly, and aid investigation when needed;
+ Support controlled changes and vulnerability remediation activities; and
+ Work collaboratively with Information Security in designing, implementing, assessing or enhancing system-specific security and privacy controls.
**Position Risk Designation** :
This position carries duties and responsibilities involving the U.S. Federal Government's interests. The selected incumbent may be subject to one or both of the additional background checks with periodic re-screening as noted below:
**Position Risk Designation: Non-Sensitive, Low Risk, Tier 1**
_Incumbents without access to U.S. Government data may be required to complete Standard Form 85 and undergo a Tier 1 Investigation (T1) for non-sensitive positions of Low Risk. (Baseline screening; formerly National Agency Check and Inquiries (NACI))._ **Position Risk Designation: Non-Sensitive, Moderate Risk, Tier 2 (Public Trust)**
_Incumbents with access to U.S. Government data may be required to complete Standard Form 85P and undergo Tier 2 (T2) Investigation for non-sensitive positions designated Moderate Risk._
**Position Risk Designation:Moderate Risk Law Enforcement (CJIS)**
_When hired for a position where access to Moderate Risk criminal justice information is required, the employee must complete a fingerprint-based national criminal history background check within 30 days after the employee's start date._
The minimum and maximum base salaries for this role are posted below; additionally, the role is eligible for bonus potential, equity and benefits. The range displayed reflects the minimum and maximum target for new hire salaries for the role based on U.S. location. Within the range, the salary offered will be determined by work location and additional factors, including job-related skills, experience, and relevant education or training.
US (SF Bay Area, DC Metro, NYC) Pay Range
$206,600-$310,000 USD
The minimum and maximum base salaries for this role are posted below; additionally, the role is eligible for bonus potential, equity and benefits. The range displayed reflects the minimum and maximum target for new hire salaries for the role based on U.S. location. Within the range, the salary offered will be determined by work location and additional factors, including job-related skills, experience, and relevant education or training.
US2 (all other US offices/remote) Pay Range
$186,000-$279,000 USD
**Join Us in Securing the World's Data**
Rubrik (NYSE: RBRK) is on a mission to secure the world's data. With Zero Trust Data Security, we help organizations achieve business resilience against cyberattacks, malicious insiders, and operational disruptions. Rubrik Security Cloud, powered by machine learning, secures data across enterprise, cloud, and SaaS applications. We help organizations uphold data integrity, deliver data availability that withstands adverse conditions, continuously monitor data risks and threats, and restore businesses with their data when infrastructure is attacked.
Linkedin (******************************************************************** | X (formerly Twitter) (****************************** | Instagram (************************************* | Rubrik.com
**Inclusion @ Rubrik**
At Rubrik, we are dedicated to fostering a culture where people from all backgrounds are valued, feel they belong, and believe they can succeed. Our commitment to inclusion is at the heart of our mission to secure the world's data.
Our goal is to hire and promote the best talent, regardless of background. We continually review our hiring practices to ensure fairness and strive to create an environment where every employee has equal access to opportunities for growth and excellence. We believe in empowering everyone to bring their authentic selves to work and achieve their fullest potential.
**Our inclusion strategy focuses on three core areas of our business and culture:**
+ Our Company: We are committed to building a merit-based organization that offers equal access to growth and success for all employees globally. Your potential is limitless here.
+ Our Culture: We strive to create an inclusive atmosphere where individuals from all backgrounds feel a strong sense of belonging, can thrive, and do their best work. Your contributions help us innovate and break boundaries.
+ Our Communities: We are dedicated to expanding our engagement with the communities we operate in, creating opportunities for underrepresented talent and driving greater innovation for our clients. Your impact extends beyond Rubrik, contributing to safer and stronger communities.
**Equal Opportunity Employer/Veterans/Disabled**
Rubrik is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability.
Rubrik provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability or genetics. In addition to federal law requirements, Rubrik complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact us at ************* if you require a reasonable accommodation to apply for a job or to perform your job. Examples of reasonable accommodation include making a change to the application process or work procedures, providing documents in an alternate format, using a sign language interpreter, or using specialized equipment.
EEO IS THE LAW (***********************************************************************************************
NOTIFICATION OF EMPLOYEE RIGHTS UNDER FEDERAL LABOR LAWS
Security Engineer 4 - FedRAMP Compliance Architect
Security Engineer Job 39 miles from Decatur
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Security Engineer 4 - FedRAMP Compliance Architect** to join our diverse, customer-focused team! This **Security Engineer 4 - FedRAMP Compliance Architect** will design, implement, and maintain secure architectures that meet FedRAMP requirements in a multi-tenant cloud environment. This role combines deep technical expertise with FedRAMP compliance knowledge to create scalable, secure solutions. You'll be the glue between security compliance requirements and technical implementation, ensuring our cloud infrastructure meets federal security standards while enabling business objectives.
**Key Responsibilities:**
+ Design, implement, and maintain system architectures to align with FedRAMP requirements.
+ Serve as the subject matter expert (SME) on FedRAMP, advising internal teams on security best practices, control implementations, and risk mitigation strategies.
+ Collaborate with engineering, operations, product, and corporate IT teams to develop secure cloud-based architectures that meet federal compliance mandates.
+ Implement governance strategy on technical security controls, including access management, configuration, encryption, logging, monitoring, and vulnerability management.
+ Support annual assessments, security control reviews, and audits, coordinating with third-party assessors (3PAO) and government sponsors.
+ Technical support for external stakeholders on customer responsibilities.
+ Key contributor to the development and maintenance of the System Security Plan (SSP), Policies and Procedures, Configuration Management Plan, Secure System Development Life Cycle, and other FedRAMP documentation
+ Partner with the GRC (Governance, Risk, and Compliance) team to efficiently track and resolve security findings.
**Basic Qualifications:**
+ 5+ years of experience in cloud security architecture, compliance, or cybersecurity engineering, with at least 3 years of experience supporting FedRAMP Moderate or High authorization.
+ Deep expertise in FedRAMP, NIST 800-53, FISMA, and cloud security best practices.
+ Strong ability to assess security risks and recommend technical and procedural mitigations.
+ Experience working with AWS GovCloud, Azure Government, or other federal cloud environments.
+ Experience with audit preparation, risk assessments, and working with third-party assessors (3PAOs).
+ Exceptional written and verbal communication skills for creating and managing FedRAMP documentation.
**Preferred Qualifications:**
+ Experience supporting DoD IL 4 or 5 environments.
+ Experience with data governance frameworks, secure data storage, and data lifecycle management in multi-tenant cloud environments.
+ Understanding of NIST AI Risk Management Framework (AI RMF) and its implications for secure AI adoption in government environments.
+ Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Lucidchart, Snyk, and Qualys).
+ Familiarity with Cloud Native and SaaS constructs, including architectures, DevOps, CI/CD, and SecOps disciplines.
+ Relevant certifications, such as:
+ Certified Information Systems Security Professional (CISSP)
+ AWS Security Specialty, or equivalent
+ CompTIA Advanced Security Practitioner (CASP+)
+ Certificate of Cloud Security Knowledge (CCSK)]]
The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). **This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.**
The base salary range for this position is 176,000 - 281,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Information System Security Engineer (Active Secret Clearance - Naples, Italy)
Security Engineer Job 39 miles from Decatur
Deloitte is seeking an Information System Security Engineer or a Risk Management Framework (RMF) support specialist to provide FRCS system security engineering support in Far East to achieve and maintain Authorizations to Operate (ATOs). The Information System Security Engineer (ISSE) will be responsible for creating and maintaining RMF artifacts and shall implement security controls, patch vulnerabilities on network devices, and resolve system security engineering concerns to ensure cyber compliance and readiness for a Government Facility Engineering Command in Naples Italy. Candidates must currently reside in Naples, Italy or willing to relocate.
Work You'll Do
+ Complete System / Mission decomposition to identify system components critical to priority mission functions.
+ Work with CYBERSAFE team to complete grading of Facility Related Control Systems (FRCS).
+ Report ongoing Risk Management Framework (RMF) package progress regularly to ISSM, HQ teams and various leadership personnel throughout Government Enterprise.
+ Support government personnel in providing technical capabilities to assist with the development of custom mitigations to challenging technical requirements.
+ Use collected system information and interviews with Subject Matter Experts (SMEs) and various system personnel to review artifacts for compliance, completeness, and quality in support of successful ATOs and ongoing maintenance.
+ RMF Artifacts include but aren't limited to:
+ Hardware and Software Lists
+ Network diagrams in accordance with the Government's Diagram Requirements Job Aid
+ Ports, Protocols, and Services Management (PPSM) forms
+ Categorization Forms
+ Cybersafe Grading Checklists
+ Criticality Analysis Checklist (if applicable)
+ Security Plan (SP)
+ Security Assessment Plan (SAP)
+ System specific policies IAW NIST 800-53 control families
+ Implementation and System Level Continuous Monitoring (SLCM) Plans
+ Raw vulnerability scan results
+ Security Center generated reports
+ Manual Security Technical Implementation Guide (STIG) and Security Requirements Guide (SRG) checklists (CKLs)
+ Performs all necessary tasks to support RMF packages, including uploading artifacts into eMASS in the proper format to support initial RMF authorization, maintenance, or reauthorization efforts. Duties include:
+ Implementing security controls in accordance with STIGs and SRGs
+ Patching vulnerabilities on IT/networking devices and all IP-based controllers
+ Conducting vulnerability scanning of all IP devices and generate reports
+ Completing manual STIG checklists (CKLs) according to the approved SAP
+ eMASS tasks such as inputting test results, uploading scan results, mapping vulnerabilities to controls, updating and maintaining POA&Ms, and processing eMASS workflows
+ Providing on-site validation support
+ Facilitating and managing change requests and authorization boundary changes with Operational Technology Design Authority (OTDA)
+ Collaborating with multiple departments to perform scanning and patching to include intermittent nationwide travel according to multiple site requirements and availability
+ In addition to RMF support, experience with the following:
+ Manage IP schemas.
+ Account management.
+ Manage and maintain windows servers and clients.
+ Ensure standardization of network device configuration and compliance with DISA STIG requirements
+ Provide system administration support for the electrical meter collection and analysis software packages and database requirements.
Qualifications
Required:
+ Active Secret Clearance
+ Bachelor's degree in IT/Cybersecurity related field
+ Five (5) years of related experience and/or training including military or civilian experience
+ Problem-solving skills and attention to detail
+ Experience with obtaining ATO's (Authority to Operate) and RMF (Risk Management Framework) process
+ Experience with RMF artifacts
+ Experience implementing security controls, patching vulnerabilities, scans, completing STIG checklist
+ Ability to be onsite 100% of the time in Naples, Italy
Preferred (Desired):
+ Experience with implementing Security Technical Implementation Guides (STIGs) and Security Requirement Guides (SRGs)
+ Experience conducting ACAS scans and generating reports
+ Knowledge of industrial communication protocols
+ Knowledge of utility information systems and energy-management technologies
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $86,000 to $143,000.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
Information for applicants with a need for accommodation: ************************************************************************************************************
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.