Connected Asset Security Engineer
Security Engineer Job In Nashville, TN
Your Work Shapes the World at Caterpillar Inc. When you join Caterpillar, you're joining a global team who cares not just about the work we do - but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here - we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.
Connected Asset Security Engineer
Role Definition:
The Connected Asset Security Engineer is responsible for providing embedded and connected Caterpillar product security assessments including back-office components. You will facilitate the continued adoption and implementation of Connected Asset Security Program processes into Caterpillar NPI processes and software development lifecycles. Additionally, the engineer will be working with product teams on security by design concepts and remediation activities resulting from security assessments and testing.
The Connected Asset Security Engineer will be responsible for collaborating with global teams and maintaining a thorough awareness and understanding of the Connected Asset Security processes.
What You Will Do:
* Perform security assessments on connected asset solutions while influencing business decisions that affect cybersecurity for the next generation of on-board products and solutions.
* Work with Development teams to provide Security Guidance and influence the cybersecurity posture of the solution during the development phase.
* Actively participate in solution attack and penetration test scoping and vulnerability assessments
* Provide periodic internal stakeholder updates and function as the communication focal point for internal engineering team inquiries and presentations.
* Provide input and support to solution teams throughout the product development lifecycle on connected product security requirements, including secure coding and configuration, software testing, third-party component management and security defect management.
* Document product vulnerabilities and communicate recommended remediations to product owners.
* Maintain current industry expert knowledge on modern ICS (Industrial Control Systems) and Cloud security procedures, directives, tools, attack methodologies, directives, secure configuration baselines, and technology controls.
* Leverage expertise in application testing, threat modeling, attack and penetration testing, data classification and data handling.
* Function as the SME (Subject Matter Expert) for Product Communication, ICS, and Cloud technologies for embedded device development teams.
* Provide connected asset security expertise and leadership in defining and prioritizing Connected Asset Security Programs initiatives.
What You Have:
* Bachelor's degree in information technology, Computer Science, or a related field
* Working knowledge of control systems, IIoT, embedded controllers, autonomy solutions and/or telematics
* Working knowledge of cybersecurity threat modeling and mitigation/remediation techniques of control systems, embedded controllers, autonomy solutions and/or telematics
* Excellent written and verbal communications skills
* Ability to coordinate multiple teams in accomplishing process review and improvement.
* Committed to technical learning and continuous education in cybersecurity.
* Intermediate understanding of ISA/IEC 62443, ISO 27001, and NIST CSF
Top Candidates Will Have:
* Expert experience in cybersecurity technical concepts, secure by design techniques, and industry best practices.
* Demonstrated ability in project management and change management.
* Demonstrated ability to perform critical analysis and develop executive decision support content.
* Experience with a wide variety of information security processes and principles, for example:
* Vulnerability assessment
* Risk analysis
* Defense in depth
* SDLC and product development processes
* Identity and access management
* Networking concepts (routing, design, TCP/IP)
* Network and endpoint security software.
* Business process design
* Web services security
* Professional information security certification (e.g., CISSP, CCSP, SANS Certifications, etc.)
* Expert experience in control systems, IIoT, embedded controllers, autonomy solutions and telematics.
* Expert experience with ISA/IEC 62443, ISO 27001, and NIST CSF
* Ability to adjust to multiple demands, changing priorities, uncertainty, ambiguity, and rapid change, while multitasking effectively
* Experience with RTOS control systems, Embedded Component Programming including Cybersecurity testing and assessment.
Skill Descriptors:
Communicating Complex Concepts:
* Knowledge of effective presentation tools and techniques to ensure clear understanding; ability to use summarization and simplification techniques to explain complex technical concepts in simple, understandable language appropriate to the audience.
Consulting:
* Knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply consulting knowledge appropriately.
Information Security Management:
* Knowledge of the processes, tools and techniques of information security management; ability to deploy and monitor information security systems, while detecting, controlling and preventing violations of IT security.
Cybersecurity Standards and Policies:
* Knowledge of developing cybersecurity policies, standards and procedures; ability to develop and communicate policies, standards and procedures that guide interactions with customers.
Cybersecurity Risk Management:
* Knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.
Information Technology (IT) Security Policies:
* Knowledge of IT security policies, standards, and procedures; ability to utilize a variety of administrative skill sets and technical knowledge to ensure cyber security compliance.
Additional Info:
* The primary locations for this position are: East Peoria, IL, Nashville TN, or Dallas, TX
* Must be willing to work a minimum of 3 days a week onsite.
* Sponsorship is NOT available.
* Relocation is available for qualified candidates.
About Caterpillar -
Caterpillar Inc. is the world's leading manufacturer of construction and mining equipment, off-highway diesel and natural gas engines, industrial gas turbines and diesel-electric locomotives. For nearly 100 years, we've been helping customers build a better, more sustainable world and are committed and contributing to a reduced-carbon future. Our innovative products and services, backed by our global dealer network, provide exceptional value that helps customers succeed.
Summary Pay Range:
$126,000.00 - $189,000.00
Compensation and benefits offered may vary depending on multiple individualized factors, job level, market location, job-related knowledge, skills, individual performance and experience. Please note that salary is only one component of total compensation at Caterpillar.
Benefits:
Subject to plan eligibility, terms, and guidelines. This is a summary list of benefits.
* Medical, dental, and vision benefits*
* Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
* 401(k) savings plans*
* Health Savings Account (HSA)*
* Flexible Spending Accounts (FSAs)*
* Health Lifestyle Programs*
* Employee Assistance Program*
* Voluntary Benefits and Employee Discounts*
* Career Development*
* Incentive bonus*
* Disability benefits
* Life Insurance
* Parental leave
* Adoption benefits
* Tuition Reimbursement
* These benefits also apply to part-time employees
Relocation is available for this position.
Visa Sponsorship is not available for this position. This employer is not currently hiring foreign national applicants that require or will require sponsorship tied to a specific employer, such as, H, L, TN, F, J, E, O. As a global company, Caterpillar offers many job opportunities outside of the U.S which can be found through our employment website at ****************************
Posting Dates:
March 17, 2025 - March 30, 2025
Any offer of employment is conditioned upon the successful completion of a drug screen.
EEO/AA Employer. All qualified individuals - Including minorities, females, veterans and individuals with disabilities - are encouraged to apply.
Not ready to apply? Join our Talent Community.
Microsoft Security Engineer - Information Protection
Security Engineer Job In Nashville, TN
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
The Global Technology Microsoft Center of Excellent (MCoE) drives strategic direction and enablement. We accelerate innovation and learning, advance sales and delivery excellence by amplifying Slalom's proven local model with high-caliber Microsoft technology expertise. Our focus is Microsoft's six go-to-market solution areas: Modern Work, Security, Azure Infrastructure, Digital & Application Innovation, Data & AI, and Business Applications.
Slalom is targeting Sr. Consultant or Consultant hires for this role.
What You'll Do
* Implement and manage security solutions for Microsoft environments.
* Focus on enhancing the end user experience across secure solution architectures.
* Deploy tailored M365 Compliance configurations with Purview Information Protection, Data Loss Prevention (DLP), data lifecycle management, and records management.
* Implement and manage Azure data governance solutions.
* Collaborate with IT and security teams to ensure compliance with security policies.
* Conduct security audits and assessments.
* Provide technical support and guidance on security matters.
* Develop and maintain security policies, standards, and guidelines.
* Stay current with emerging security threats and technologies.
Who You Are
* Experience as a Microsoft Security Engineer or similar role.
* Proficiency in Microsoft security technologies and tools, including Purview Information Protection, DLP, data lifecycle management, records management, and Azure data governance.
* Strong troubleshooting and problem-solving skills.
* Excellent communication and teamwork skills.
* Ability to work independently and as part of a team.
* Strong understanding of security best practices and regulatory requirements.
* Experience with security frameworks such as NIST, ISO 27001, and CIS Controls.
About Us
Slalom is a purpose-led, global business and technology consulting company. From strategy to implementation, our approach is fiercely human. In six countries and 43 markets, we deeply understand our customers-and their customers-to deliver practical, end-to-end solutions that drive meaningful impact. Backed by close partnerships with over 400 leading technology providers, our 13,000+ strong team helps people and organizations dream bigger, move faster, and build better tomorrows for all. We're honored to be consistently recognized as a great place to work, including being one of Fortune's 100 Best Companies to Work For seven years running. Learn more at slalom.com.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position at the Consultant level the base salary pay range is $96,000 to $177,000. For this position at the Senior Consultant level the base salary pay range is $110,000 to $203,000. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applicants until 4/4/2025..
Security Engineer
Security Engineer Job In Tennessee
(Systems) Security Engineer Description: For the position of (Systems) Security Engineer, ideal candidates are those who have experience in protecting system boundaries, keeping computer systems and network devices secure against attacks, and securing sensitive data. Ideal candidates should be comfortable working independently or with a team. Ideal candidates should be able to communicate security measures to coworkers and supervisors who in non-specialized terms.
(Systems) Security Engineer Responsibilities:
Engineering, implementing and monitoring security measures for the protection of computer systems, networks and information.
Identifying and defining system security requirements.
Designing computer security architecture and developing detailed cybersecurity designs.
Preparing and documenting standard operating procedures and protocols.
Configuring and troubleshooting security infrastructure devices.
Developing technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
Ensuring that the company knows as much as possible, as quickly as possible about security incidents.
Writing comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement.
Security Detection Engineer, Insider Trust
Security Engineer Job In Nashville, TN
As part of Meta Security, our Insider Trust team is focused on identifying and responding to insider threats to data. The team's mission is to identify malicious use of otherwise legitimate access to data from people inside the company and respond to it before damage is done. We investigate across a broad spectrum of abuse including abuse of user data, intellectual property, and leaks of sensitive information. We collaborate with software engineering teams to build advanced detection capabilities and understand how abuse happens so that we can stay ahead of those who are interested in misusing their access. The Insider Trust team is looking for a highly motivated Security Engineer to build and improve internal tools and systems to detect malicious activities related to insider threats. Candidates are expected to analyze and monitor internal tools, hunt for insider threats against company data and infrastructure, and have the ability to carry out complex internal investigations from collection to reporting. As part of the role, this person will work side by side with our engineering teams to build advanced detection solutions to help keep systems and information safe, and partner closely with our Human Resources and Legal teams to carry out complex investigations.
**Required Skills:**
Security Detection Engineer, Insider Trust Responsibilities:
1. Lead cross-functional projects to improve our GenAI capabilities to effectively detect and respond to internal threats and security incidents
2. Leverage threat modeling and analysis to build event and/or behavioral based detections to protect our critical GenAI assets and infrastructure
3. Perform analysis of logs from a variety of sources (e.g., individual host logs, network traffic logs) to identify potential insider threats
4. Build operational workflows and actions that auto-resolve false positives and provide context scaling our ability to investigate
5. Identify gaps in our infrastructure, and work with software engineers, product managers, and business partners to gain visibility through logging and detection
**Minimum Qualifications:**
Minimum Qualifications:
6. Bachelor's degree in Computer Science, Engineering, or equivalent experience
7. 5+ years of experience in Detection & Response Engineering or similar Security Engineering role
8. Experience developing detections using event or anomaly based methods
9. Experience interpreting information from multiple sources and working with data sets
10. Experience with database tools/systems such as SQL, HQL
11. Coding proficiency in Python
**Preferred Qualifications:**
Preferred Qualifications:
12. M.S. or PhD in Computer Science or related field, or equivalent experience
13. Experience conducting technical security investigations (response, forensics, log analysis)
14. Experience with anomaly detection applicable to the insider threat detection space
15. Experience in system, network, and/or application security
16. Coding proficiency in OOP languages, e.g. PHP, C++, etc.
17. Coding proficiency in Pandas, NumPy, Scikit-learn, TensorFlow
**Public Compensation:**
$147,000/year to $208,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Security Architect
Security Engineer Job In Tennessee
Designs enterprise and systems security throughout the development lifecycle; translates technology and environmental conditions (e.g., law and regulation) into security designs and processes.
Key Skills & Experience
5 years of experience in network security, security architecture and its development with
a focus on federal government network environments.
Experience in a variety of networking technologies and protocols, including LAN, WAN,
wireless, data center networking, and network security.
Experience in security measures such as firewalls, intrusion detection, and prevention
systems (IDS/IPS), network access controls, and network segmentation.
Strong understanding of federal government security requirements, including FISMA and
NIST guidelines.
Experienced with operating systems like Windows, Linux, and UNIX.
Understanding of DNS security principles such as routing, authentication, VPN, proxy
services, and DDOS mitigation technology.
Solid understanding of the ISO 27001/27002, COBIT, and ITIL frameworks.
Third-party auditing skills and cloud risk assessment methodologies.
Education, Certifications, & Credentials
Bachelor of Science (BS) Degree in Computer Science, Information Technology (IT),
Cybersecurity, or Engineering related field.
DoD 8570 IAT Level III Certification, including CASP+ CE, CCNP Security, CISA, CISSP,
GCED, or GCIH Certification.
Active Q clearance required.
Candidates with TS/SCI clearance can be switched over to Q clearance easily
*All duties and responsibilities are not captured in this job description. To find out more, please
reach out to the recruiter for this role*
Senior/Lead Cloud Security Engineer
Security Engineer Job In Tennessee
iHeartMedia Current employees and contingent workers click here to apply and search by the Job Posting Title. The audio revolution is here - and iHeart is leading it! iHeartMedia, the number one audio company in America, reaches 90% of Americans every month -- a monthly audience that's twice the size of any other audio company - almost three times the size of the largest TV network - and almost 4 times the size of the largest ad-supported music streaming service. In fact, we have:
* More #1 rated markets than the next two largest radio companies combined;
* We're the largest podcast publisher, with more monthly downloads than the second- and third-largest podcast publishers combined. Podcasting, the fastest-growing new media, today has more monthly users than streaming music services or Netflix;
* iHeart is the home of many of the country's most popular and trusted on-air personalities and podcast influencers, who build important connections with hundreds of communities across America;
* We create and produce some of the most popular and well-known branded live music events in America, including the iHeartRadio Music Festival, the iHeartRadio Music Awards, the iHeartCountry Festival, iHeartRadio Fiesta Latina and the iHeartRadio Jingle Ball Tour;
* iHeartRadio is the #1 streaming radio digital service in America;
* Our social media footprint is 7 times larger than the next largest audio service; and
* We have the only complete audio ad technology stack in the industry for all forms of audio, from on demand to broadcast radio, digital streaming radio and podcasting, which bring data, targeting and attribution to all forms of audio at an unparalleled scale. As a result, we're able to combine our strong leadership position in audience reach, usage and ad tech with powerful tools and insights for our sales organizations to help them build success for their clients at a more efficient cost than any other option.
Because we reach almost every community in America, we're committed to providing a range of programming that reflects the diversity of the many communities we serve - and our company reflects that same kind of diversity. Our company values stress collaboration, curiosity, welcoming dissent, accepting mistakes in the pursuit of new ideas, and respect for everyone.
Only one company in America has the #1 position in everything audio: iHeartMedia!
If you're excited about this role but don't feel your experience aligns perfectly with the job description, we encourage you to apply anyway. At iHeartMedia we are dedicated to building a diverse, inclusive, and authentic workplace and are looking for teammates passionate about what we do!
What We Need:
iHeartMedia seeks candidates for the position of Senior Cloud Security Engineer. This role is responsible for reviewing cloud architectures and leading the efforts to secure and ensure compliance enforcement through automation, environment assessments, and policy shaping.
What You'll Do:
* Provide guidance to product and IT teams for all public cloud related matters in AWS, GCP, and Azure
* Act as highly technical cloud security Subject Matter Expert (SME) for the InfoSec team.
* Research, innovate, and design cloud and hybrid security solutions.
* Create design artifacts to enable members of the operations or infrastructure teams to implement solutions.
* Identify opportunities to reduce cloud security risk for iHeartMedia.
* Collaborate with senior management and department leaders to assess near and long-term cloud security needs.
* Review cloud architectures and advise development teams on strong security design principles.
* Provide advanced level IAM policy guidance to enable product teams to shape least privilege access.
* Create and maintain documentation as it relates to cloud security designs/configurations, processes, standards, and recommendations.
* Stay current with the latest cloud threat mitigation tools and techniques.
* Provide guidance for security remediation to business and IT partners by demonstrating real, practical risk and valuer.
* Provides vulnerability assessment of cloud assets, deliver remediation recommendations, and provides knowledgeable assistance in resolving identified vulnerabilities.
* Provides input to the overall architecture and governance model.
What You'll Need:
* Minimum of 6+ years of experience in a Cyber Security Administrator, Analyst or Engineer role with a focus on cloud-based security.
* Broad understanding of information security and compliance risks, and how those apply to public cloud.
* Keen interest in learning about modern cloud security and information security threats, mitigation strategies, and control frameworks.
* Strong understanding of cloud-based and hybrid infrastructure components with specific understanding of the security risks presented in a centralized or decentralized and hybrid environment.
* Strong understanding of security operations and compliance environment with experience in managing multiple tasks, reporting to management, and driving security initiatives within the InfoSec group.
* Experience with SIEMs, including Azure Sentinel, and custom log sources.
* Proficiency in EDR/MDR incident investigation and threat management.
* Strong understanding of cloud native and third-party security related tools.
* Strong understanding of Multiple Public Cloud security and compliance features and configuration.
* Knowledge of network infrastructure security (physical and virtual) technologies and solutions.
* Knowledge of identify providers and identity management security.
* Demonstrated critical thinking and analytical ability.
* Demonstrated willingness and ability to learn new and emerging technologies.
What You'll Bring:
* Respect for others and a strong belief that others should do this in return
* Demonstrated initiative and achievement-oriented leadership
* Ability to manage several projects at a time
* Growth mindset and desire for continued knowledge sharing and learning
* Understanding of impact of your own decisions and decisions of your team
* Strong business insights that contribute to resolving complex problems
* Catalyst for new and innovative ideas
* Ability to identify and support new opportunities for continued improvement across business
* Ability to interact with individuals of all levels and maintain professional relationships
* Strong relationships with other leaders with the ability to manage external business partners where appropriate
Compensation:
Salary to be determined by multiple factors including but not limited to relevant experience, knowledge, skills, other job-related qualifications, and alignment with market data.
$136,000 - $170,000
Location:
Orlando, FL: 3024 East Amelia Street, 32803
Position Type:
Regular
Time Type:
Full time
Pay Type:
Salaried
Benefits:
iHeartMedia's benefits offering is flexible and offers a variety of choices to meet the diverse needs of our changing workforce, including the following:
* Employer sponsored medical, dental and vision with a variety of coverage options
* Company provided and supplemental life insurance
* Paid vacation and sick time
* Paid company holidays, including a floating holiday that enable our employees to celebrate the holiday of their choosing
* A Spirit day to encourage and allow our employees to more easily volunteer in their community
* A 401K plan
* Employee Assistance Program (EAP) at no cost - services include telephonic counseling sessions, consultation on legal and financial matters, emotional well-being, family and caregiving
* A range of additional voluntary programs, such as spending accounts, student loan refinancing, accident insurance and more!
We are accepting applications for this role on an ongoing basis.
The Company is an equal opportunity employer and will not tolerate discrimination in employment on the basis of race, color, age, sex, sexual orientation, gender identity or expression, religion, disability, ethnicity, national origin, marital status, protected veteran status, genetic information, or any other legally protected classification or status.
Non-Compete will be required for certain positions and as allowed by law.
Our organization participates in E-Verify. Click here to learn about E-Verify.
Network Security Engineer Director
Security Engineer Job In Tennessee
Zayo provides mission-critical bandwidth to the world's most impactful companies, fueling the innovations that are transforming our society. Zayo's 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo's communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.
Zayo is seeking a Network Security Engineer Director to be responsible for promoting and ensuring customers successfully understand, migrate to, and fully utilize Zayo's growing portfolio of security services. The Network Security Engineer Director is responsible for the complete end-to-end configuration of customer security services. The Network Security Engineer Director will work closely with customers before purchase, during trials and pilots, and after purchase to demonstrate Zayo's security products and ensure customers are receiving the full benefit of the Zayo portfolio of services. The Network Engineer Director will develop regular cadence for ongoing customer interaction to help ensure customers are satisfied with the services they receive, promote broader customer adoption, and work with internal teams to as an advocate for customer-requested improvements.
Responsibilities:
Leads or assists on all implementations of UTM or security related services.
Supports existing security implementations including advanced features available in UTM and filtering policies.
Develop expert understanding of Zayo's portfolio of security services and features.
Participates in design discussions with the architecture and network engineering teams and leads implementation of new security products and services at customer sites.
Works with customers, post-sale, to ensure customers have successfully met their project objectives.
Provide customer feedback to internal teams for user experience improvements and the development of new features.
Provide customers with industry standard best practice recommendations for firewall rules and policies during new implementations.
Perform periodic firewall rule/policy audits for existing Zayo hosted firewall customers.
Ensure accurate customer-facing and internal support documentation.
Other duties as assigned.
Qualifications :
Bachelor's Degree in Computer Science or Engineering preferred.
Required certifications for this position are CEH (Certified Ethical Hacker) and NSE 4 (Network Security Expert 4). NSE 5, NSE 7, CCNP or CCIE is a plus. Applicable experience may be considered as a substitute.
Minimum of ten (10) years of technical experience supporting and troubleshooting large-scale multi-protocol environments.
Experience supporting Fortinet firewall is required (including chassis models), including ACL/rules, UTM and Fortinet web filtering policies.
Must have strong analytical and problem-solving abilities; must have a positive attitude, ability to work in a team environment and perform efficiently with minimal supervision
Strong dedication to providing quality customer service, prompt support and complete resolutions.
Willingness to work in a dynamic team atmosphere to resolve issues and learn.
Ability to multi-task between customers, vendors, peers, and management while showing the ability to independently resolve complex issues.
Must be flexible in order to support a 24/7 operation and willing to travel throughout our service area.
Estimated base pay range for this role is $114,900 - $164,200 USD/annually
The base pay range shown is a guideline and reasonable estimate for this role. It takes into account the wide variety of factors that are considered in making compensation decisions. Actual compensation offered may vary from the posted range based upon geographic location, work experience, skill level, certifications, and other business and organizational needs. Non- sales roles may be eligible to participate in a discretionary annual incentive plan. Sales roles may be eligible to participate in a sales incentive plan.
Additionally, this position may be eligible for certain benefits, such as health insurance, life insurance, disability retirement plans, paid time off.
The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.
#LI-CC1
The base pay range shown is a guideline and reasonable estimate for this role. It takes into account the wide variety of factors that are considered in making compensation decisions. Actual compensation offered may vary from the posted range based upon geographic location, work experience, skill level, certifications, and other business and organizational needs. Non- sales roles may be eligible to participate in a discretionary annual incentive plan. Sales roles may be eligible to participate in a sales incentive plan.
Additionally, this position may be eligible for certain benefits, such as health insurance, life insurance, disability retirement plans, paid time off.
The posting will be active for a minimum of 3 days. The active posting will continue to extend by 3 days until the position is filled.
Benefits, Rewards & Wellness
Excellent Health, Dental & Vision Insurance
Retirement 401(k) Savings Plan
Generous paid time off policy including paid parental leave
Zayo provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state, provincial or local laws.
This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.
Infrastructure Security Engineer - FedRAMP (US Citizen)
Security Engineer Job In Nashville, TN
**Title:** Infrastructure Security Engineer (US citizen) **Salary:** $120K/annually **About PSI** We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.
We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.
At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.
Learn more about what we do at: *************************
**About the Role**
The Infrastructure Security Engineer (ISE) is responsible for ensuring that PSI systems are secure, well maintained, and appropriately monitored. They work with senior management across all business units to design security solutions and ensure that PSI environments are designed and maintained in accordance with industry standards.
Infrastructure Security Engineers ensure adherence to ISO27001, SOC2, CIS, NIST and other standards. They possess a broad understanding of log aggregation solutions, server hardware, Linux and Windows operating systems, storage, networking, and load balancing. The Infrastructure Security Engineer leads projects and organizes teams to achieve technical and security objectives.
Infrastructure Security Engineers work as part of a global team to design, implement, and monitor security across the organization. They engage with vendors, business and technology partners to lead projects and constantly improve security posture.
**Role Responsibilities**
+ Lead projects to evaluate, select, and implement security technologies
+ Design, configure, implement, and maintain all security platforms and their associated software: firewalls, intrusion detection/intrusion prevention, antivirus/EDR, URL Filtering, email security gateway, SIEM, vulnerability assessment solutions, DLP
+ Respond to security events and incidents performing containment, root cause analysis, and remediation.
+ Maintain enterprise vulnerability scanning infrastructure, ensuring daily operation of scans and reporting are occurring as required
+ Coordinate and sequence external scans and penetration testing
+ Monitor application and system activity logs for potential threats
+ Keep up to date with evolving trends and changes in security models and methodologies
+ Threat model common attacker methods to develop appropriate mitigation techniques
+ Define and develop technical security standards and guidelines with business stakeholders
+ Participate in product security architecture planning for both on-premises and cloud-based solutions
+ Ensure server infrastructure is secure, patched and updated
+ Take proactive steps to resolve issues before they impact the business
+ Maintain accurate and up to date security documentation
+ Serve as team lead and subject matter expert for security
**Knowledge, Skills and Experience Requirements**
+ Bachelor's degree in computer science or equivalent training/certification.
+ 10+ years of working experience as a Security Engineer or Systems Engineer
+ 5+ years of working experience with email security tools such as Proofpoint
+ 5+ years of working experience with CrowdStrike EDR and SIEM solutions
+ Ability to achieve federal security clearance, must be a US Citizen
+ Experience with FedRamp security controls,
+ In-depth knowledge and understanding of the integration of AWS with fundamental Information Security methodologies for both architectural review and implementation
+ Strong knowledge of Windows and Linux environments
+ Experience drafting and promoting security policy with all levels of business stakeholders
+ Experience and detailed technical knowledge of security engineering, system and network security, authentication and security protocols, cryptography, and application security
+ Detailed knowledge of core server technologies and domain configuration and management, including DNS, DHCP, AD and group policy
+ Experience in Domain Trusts, Active Directory Federation, and Entra ID
+ Experience managing remote infrastructure across multiple time zones
+ Detailed understanding of Azure, AWS, Hyper-V, VMWare and SAN technologies
+ Understanding of network topologies such as VLANs, IPs, subnets, and routing
+ Understanding of PowerShell / VB Scripting
+ Good written and verbal communication skills with the ability to follow a project from beginning to end while providing updates along the way, while prioritizing time and dealing with multiple projects
+ Experience with CIS Hardening Standards and/or DISA STIGs
+ Experience with load balancers (F5, Barracuda, Azure)
**Benefits & Culture**
At PSI, our culture is to be transparent and fair. That's why all of our roles have been benchmarked at a competitive rate against the local market they are based in. To be transparent all of our adverts now include the salary so you can see if we align with your expectations when looking for your next role.
In addition to a competitive salary, we offer a comprehensive benefits package and supportive culture when you join us. This includes:
+ 401k/Pension/Retirement Plan - with country specific employer %
+ Enhanced PTO/Annual Leave
+ Medical insurance - country specific
+ Dental, Vision, Life and Short-Term Disability for US
+ Flexible Spending Accounts - for the US
+ Medical Cashback plan covering vision, dental and income protection for UK
+ Employee Assistance Programme
+ Commitment and understanding of work/life balance
+ Dedicated DE&I group that drive core people initiatives
+ A culture of embracing wellness, including regular global initiatives
+ Access to supportive and professional mechanisms to help you plan for your future
+ Volunteer Day and a culture of giving back to our community and industry through volunteering opportunities
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
SETS - TEMP Information Security Specialist - Senior
Security Engineer Job In Tennessee
February-July 2025
The Senior Information Security Specialist will provide critical support in protecting and securing the Air National Guard's (ANG) information systems. This role requires a comprehensive understanding of cybersecurity policies, practices, and procedures, including risk management, security architecture, and incident response. The specialist will ensure that security measures for information systems meet stringent compliance standards and will be instrumental in maintaining operational security posture.
Key Responsibilities:
Develop, implement, and oversee comprehensive information security programs, including policies, procedures, and control systems, to ensure the integrity and confidentiality of sensitive information.
Provide expert guidance on cybersecurity matters, including the interpretation and application of Air Force Instructions (AFIs), Defense Federal Acquisition Regulation Supplement (DFARS), and other relevant cybersecurity directives.
Conduct security assessments and audits, identify vulnerabilities, and implement mitigation strategies to enhance the security posture of the ANG enterprise network.
Ensure compliance with the Risk Management Framework (RMF) and support the attainment of Authorization to Operate (ATO) for systems.
Collaborate with IT and cybersecurity teams to manage security incidents and breaches, including providing timely response and remediation actions.
Assist in the development and maintenance of the Disaster Recovery Plan (DRP) and Continuity of Operations Plan (COOP).
Support the implementation of security measures in accordance with the DoD Cybersecurity Workforce Qualification and Management Program.
Provide training and guidance to staff on information security protocols and best practices.
Maintain knowledge of current and emerging cybersecurity threats and trends to advise on security enhancements.
Participate in the planning and execution of information security projects and initiatives, ensuring alignment with the ANG's strategic objectives.
Network Security Engineer II
Security Engineer Job In Tennessee
Segra is searching for a dynamic and experienced Network Security Engineer II. The primary responsibilities of the Network Security Engineer II include providing Tier III support, standards development and maintenance, project support, and capacity planning and management of firewalls and other security technologies, products, and solutions supported by the Security Operations Center. The successful candidate will be an integral member of the security operations team and will need to be fully cognizant of state-of-the-art network, firewall, and other security technologies, products and solutions, as well as industry best practice with regard to the design, implementation and deployment of firewall solutions. The successful candidate should also have deep hands-on experience with firewalls, networking, and security technologies. Candidate will also maintain Segra's DDoS mitigation processes and procedures.
Required Qualifications:
* Must have a minimum of 5 years of experience in network security, such as firewall management, IDS, and IPS technologies.
* Must have prior Fortinet (FortiGate) experience.
Preferred Qualifications:
* Cisco Meraki is highly preferred
* Bachelor degree or equivalent combination of education and experience
* 5+ years supporting configuration and testing Firewall, IDS, and IPS technologies
* 5+ years of experience implementing/deploying Information Security Best Practices, Network Routing, Switching, and Security Design infrastructures
* 5+ years of experience in Networking and Network Operations
* 5+ years of experience in Troubleshooting & Analysis tools
* 5+ years of experience supporting Virtual Private Networking (VPNs)/MPLS VPN
* 5+ years of experience with system administration
Key Competencies:
* Evaluates and recommends solutions for highly complex security systems according to industry best practices to safeguard internal information systems and database
* Exceptional ability to work in a cooperative team environment to formulate complex technical solutions
* Ability to be available for on-call duties
* Excellent verbal and written communication skills
* Must possess and demonstrate excellent customer service skills
* Must be detail oriented with good organizational and time management skills
* Must be analytical and have proven problem solving abilities
About Segra:
Segra is one of the largest independent fiber network companies in the nation, able to offer state-of-the-art communication solutions backed by always-on customer service. We are known for our future-forward infrastructure and state-of-the-art voice and data technology solutions for businesses and the public sector, as well as wholesale transport services to some of the world's largest carriers. Our network features the latest advances in IP, ethernet, and dark fiber architectures, as well as high performance data centers. Furthermore, our network powers technology solutions such as hosted voice, security, and cloud.
Segra has engineered our entire company operations to put our customers at the very center of everything we do. We invest in the communities we serve by hiring locally and continually upgrading our network infrastructure. Segra has over 1200 employees, 500k+ on-net and near-net buildings, and 44k+ fiber-route miles. We exist purely to help businesses within our footprint be successful.
Benefits Overview:
Segra offers a very robust benefits package to our full-time employees, some of which include:
* Medical, dental, vision insurance
* Life insurance
* 401(k) match
* Flexible Spending/Health Savings Accounts
* Tuition and gym reimbursements
* Vacation/PTO, paid holidays, floating holidays
* Volunteer days, parental leave
* Legal, accidental, hospital indemnity, identify theft, pet insurance
Our Commitment to Equality:
Segra is an equal opportunity employer and prohibits discrimination of any kind. Segra does not discriminate on the basis of race, color, religion, sex (including pregnancy and gender identity), national origin, political affiliation, sexual orientation, marital status, disability, genetic information, age, membership in an employee organization, retaliation, parental status, military service, or other non-merit factor.
Other details
* Job Family 50
* Pay Type Salary
Apply Now
* Alabama, USA
* Charlotte, NC, USA
* Georgia, USA
* Missouri, USA
* North Carolina, USA
* Ohio, USA
* Pennsylvania, USA
* South Carolina, USA
* Tennessee, USA
* Texas, USA
* Virginia, USA
* West Virginia, USA
Information Systems Security
Security Engineer Job In Tennessee
Specialization Description
Information Systems Security work focuses on preventing IT-based crime, hacking, intentional or inadvertent modification, disclosure, or destruction to an organization's information systems and IT assets and intellectual property including:
Designing, testing, and implementing secure operating systems, networks, and databases
Password auditing, network based and Web application based vulnerability scanning, virus management, and intrusion detection
Conducting risk audits and assessments, providing recommendations for application design
Monitoring and analyzing system access logs
Planning for security backup and system disaster recovery
Level Description
An experienced support level position that requires a basic knowledge of a given job area and tools, typically seen through work experience as well as vocational or technical training. Works under moderate supervision. Problems are typically of a routine nature, but may at times require interpretation or deviation from standard procedures. Communicates information that requires some explanation or interpretation to achieve business results for a given area of a department or function.
Artificial Intelligence (AI) Security Engineer
Security Engineer Job In Knoxville, TN
Artificial Intelligence (AI) Security Engineer Founded in 1999 in the beautiful Smoky Mountains of East Tennessee, Cadre5 provides innovative technical solutions to our customers locally and nationally. Our Cadre5 Lab Partners division has partnered with the Information Technology Services Directorate (ITSD) at Oak Ridge National Laboratory (ORNL) to recruit a qualified Artificial Intelligence Security Engineer. You will assist in drafting and publishing guidance and policies governing secure and responsible AI. ORNL delivers scientific discoveries and technical breakthroughs needed to realize solutions in energy and national security and provides economic benefit to the nation. This premier research institution located near Knoxville in Oak Ridge, TN, addresses national needs through impactful research and world-leading research centers. #CJ This is a full-time, permanent position that requires onsite work. Telecommuting with occasional travel to the Oak Ridge facility may be negotiable. Why Cadre5?
Working with highly talented team members
3 weeks' vacation
Excellent medical insurance, up to 100% paid by employer
Job Responsibilities:
Develop, implement, and maintain AI governance frameworks, policies, and procedures to ensure secure and responsible use of AI technologies.
Ensure compliance with relevant regulatory requirements, standards, and best practices for AI security and ethics.
Establish guidelines for the ethical creation, management, and use of AI datasets and models.
Conduct risk assessments of AI systems and datasets to identify potential security vulnerabilities and ethical concerns.
Implement controls and mitigation strategies to address identified risks and ensure the integrity of AI models.
Monitor AI systems for compliance with established governance policies and procedures.
Prepare and present reports on AI governance and security metrics to senior management and stakeholders.
Collaborate with cross-functional teams, including data scientists, researchers, and IT security, to promote a culture of responsible AI use.
Develop and deliver training programs to educate staff on AI governance, security policies, and best practices.
Stay updated with the latest developments in AI governance, ethics, and security.
Continuously review and improve AI governance frameworks and processes to adapt to evolving technologies and regulatory landscapes.
Basic Qualifications:
Bachelor's or Master's degree in Computer Science, Information Security, Data Science, or a related field.
Proven experience in developing and implementing governance frameworks and policies, preferably in an AI or data-intensive environment.
Strong understanding of AI technologies, ethical AI principles, and data privacy regulations.
Excellent analytical, problem-solving, and communication skills.
Ability to work collaboratively in a multidisciplinary team environment.
Certifications in information security (e.g., CISSP, CISM) or AI ethics (e.g., AI Ethics Certification) are a plus.
The ability to obtain and maintain a Department of Energy "Q" clearance is required. This requires US Citizenship.
Preferred Qualifications:
Q or Top Secret Clearance is preferred
Benefits Cadre5 offers excellent pay and benefits, to include full medical, dental, and vision coverage coupled with 401K match, 15 days PTO, and 10 holidays.
Cadre5 is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. Cadre5 is an E-Verify Employer.
Information Systems Security Officer
Security Engineer Job In Tennessee
Top Secret Clearance Jobs is dedicated to helping those with the most exclusive security clearance find their next career opportunity and get interviews within 48 hours. Requisition Id 13888 As a U.S. Department of Energy (DOE) Office of Science national laboratory, ORNL has an extraordinary 80-year history of solving the nation's biggest problems. We have a dedicated and creative staff of over 6,000 people! Our vision for diversity, equity, inclusion, and accessibility (DEIA) is to cultivate an environment and practices that foster diversity in ideas and in the people across the organization, as well as to ensure ORNL is recognized as a workplace of choice. These elements are critical for enabling the execution of ORNL's broader mission to accelerate scientific discoveries and their translation into energy, environment, and security solutions for the nation.
We are currently seeking qualified applicants with Information Systems Security Officer (ISSO) experience to support Secure Operations for classified operations in the areas of Classified Intelligence Information Technology (IT)/Information Assurance (IA), Classified R&D Computing, and physical and personnel security in the Field Intelligence Operations Division (FIOD). Under the DOE Office of Intelligence and Counterintelligence (IN) authorities, the FIE serves as the ORNL focal point for all intelligence community matters and supports national security science by providing secure IT, communications, facilities, and analysis.
Purpose:
Assist the Information Systems Security Manager (ISSM) in the certification and accreditation (C&A) of systems/networks and implementation of cyber security requirements and procedures across the National Security Sciences Directorate (NSSD) at ORNL. The NSSD conducts research and development to solve some of the nation's most difficult security challenges and adversaries. We house S&T leadership in cybersecurity and cyber-physical resiliency, data analytics, geospatial science and technology, nuclear nonproliferation, and high-performance computing for sensitive national security missions. NSSD draws on the Laboratory's exceptional facilities and work closely with leading researchers in other areas at the lab such as nuclear and chemical sciences and engineering, applied materials, advanced manufacturing, biosecurity, transportation, and computing. Our multi-disciplinary research teams are passionate about discovery and innovation as we create science-based solutions to complex security threats that put public safety, national defense, energy infrastructure, and our economy at risk.
Major Duties/Responsibilities:
Provide day-to-day support for Sensitive Compartmented Information (SCI) and Special Access Program (SAP) activities.
Coordinate and ensure adherence to DOE security policies and procedures, as outlined in relevant System Security Plans (SSPs), for the operation, maintenance, and disposal of systems.
Perform routine self-inspection reviews of the information systems.
Perform comprehensive investigations of computer security incidents and ensuring proper measures are taken post discovery of the incident / event.
Manage and implement the information security continuous monitoring requirements relevant to the system.
Oversee the compliance of security settings within operating systems and applications integrated in the classified information systems under the candidate's purview.
Establish and implement procedures for granting access to classified information systems, conduct annual evaluations of user accounts, and provide guidance and support to the ISSM in implementing and enforcing cyber security policies at multiple facilities.
Create, review, and maintain SSPs for system certification and accreditation in the Xacta application, managing plans and timelines for the accreditation of information systems, and conducting regular reviews to ensure compliance with SSPs.
Implement and monitor system recovery processes to ensure that system data, security features, and procedures are properly restored and for creating and testing contingency plans to meet recovery time objectives.
Provide leadership and support for annual self-inspections, system certification testing, periodic security testing, and functional testing on systems/networks.
Regularly review and analyze information system audit records, perform approved Authorized Data Transfers between systems of different classifications, and follow established procedures for media management.
Continuously update and enhance document best practices and local security procedures, train users on these procedures, and consistently apply appropriate ES&H standards.
Maintain a strong commitment to the implementation and perpetuation of values and ethics.
All team members deliver ORNL's mission by aligning behaviors, priorities, and interactions with our core values of Impact, Integrity, Teamwork, Safety, and Service. Promote diversity, equity, inclusion, and accessibility by fostering a respectful workplace - in how we treat one another, work together, and measure success.
Basic Qualifications:
BS in information technology or technical equivalent and eight (8) years of relevant experience.
Experience in cyber security and the C&A process.
Experience supporting SAP / SCI environments.
Security + or equivalent DoD Directive 8570 / 8140 Information Assurance Management Level I - III certification.
Experience developing, testing, and collecting artifacts for RMF packages and BoEs of multiple systems.
Experience in authorized data transfers across multiple systems and different classifications.
Preferred Qualifications:
Working knowledge of:"
Risk Management Framework (RMF) process & requirements.
NIST and CNSSI requirements
Intelligence Community Directive 503 (ICD-503)
Joint Special Access Program (SAP) Implementation Guide (JSIG)
Demonstrated organizational skills.
Must be organized, self-motivated, and be able to work with minimal guidance.
Excellent written and verbal communication skills with an ability to work with numerous cognizant security agencies, customers, and senior managers.
Current TS clearance with SCI eligibility
Eligibility for access to SAP Information
Relevant ISSO / ISSE experience within the DoD or Intelligence Community.
Working knowledge of:"
DCSA Assessment and Authorization Process Manual (DAAPM)
National Industrial Security Program Operating Manual (NISPOM Chapter 8)
Knowledge of the Defense Information Systems Agency (DISA) Security Technical Implementation Guides (STIGs) and configuration standards.
Working knowledge of Industry Standard tools for purposes of audit reduction, vulnerability scanning, and malware analysis is preferred. Relevant tools include but are not limited to: Splunk, Tenable Nessus, Host Based Security System (HBSS) components, Security Content Automation Protocol (SCAP) Checker, and STIG viewer.
Experience with Security Directives, Policies, Publications, and Regulations.
Special Requirements:
Visa sponsorship is not available for this position.
This position requires the ability to obtain and maintain a Secret Compartmented Information (SCI) clearance from the Department of Energy. As such, this position is a Workplace Substance Abuse (WSAP) testing designated position. WSAP positions require passing a pre-placement drug test and participation in an ongoing random drug testing program. In addition, due the SCI, you may also be subject to random polygraph testing.
Benefits at ORNL:
ORNL offers competitive pay and benefits programs to attract and retain dedicated people! The laboratory offers many employee benefits, including medical and retirement plans and flexible work hours, to help you and your family live happy and healthy. Employee amenities such as on-site fitness, banking, and cafeteria facilities are also provided for convenience.
Other benefits include the following: Prescription Drug Plan, Dental Plan, Vision Plan, 401(k) Retirement Plan, Contributory Pension Plan, Life Insurance, Disability Benefits, Generous Vacation and Holidays, Parental Leave, Legal Insurance with Identity Theft Protection, Employee Assistance Plan, Flexible Spending Accounts, Health Savings Accounts, Wellness Programs, Educational Assistance, Relocation Assistance, and Employee Discounts.
If you have difficulty using the online application system or need an accommodation to apply due to a disability, please email: ***********************
This position will remain open for a minimum of 5 days after which it will close when a qualified candidate is identified and/or hired.
We accept Word (.doc, .docx), Adobe (unsecured .pdf), Rich Text Format (.rtf), and HTML (.htm, .html) up to 5MB in size. Resumes from third party vendors will not be accepted; these resumes will be deleted and the candidates submitted will not be considered for employment.
If you have trouble applying for a position, please email ***********************.
ORNL is an equal opportunity employer. All qualified applicants, including individuals with disabilities and protected veterans, are encouraged to apply. UT-Battelle is an E-Verify employer.
Information Security Engineer
Security Engineer Job In Nashville, TN
What IT Network & Telecommunications contributes to Cardinal Health Information Technology oversees the effective development, delivery, and operation of computing and information services. This function anticipates, plans, and delivers Information Technology solutions and strategies that enable operations and drive business value.
Job Purpose:
Directly accountable for safeguarding the organization's information assets. The role involves designing, implementing, and enforcing security protocols and procedures that mitigate risks and ensure compliance. With heavy focus in information security operations, including vulnerability management, incident/event management, compliance management, policy/procedure development and information security awareness.
This responsibility will be carried out through the development of information security requirements, planning, design, implementation, and periodic audit/validation of effectiveness of all security controls.
Essential Functions:
* Determine information security requirements by evaluating and researching information security standards; conducting system security and vulnerability analyses and risk assessments; studying architecture/platform; and identifying integration issues.
* Design, and implement security controls for our infrastructure and critical systems.
* Verify information security systems effectiveness by developing and implementing testing and validation processes to periodically audit systems.
* Collaborate with managed security service provider (MSSP) to ensure their services are effectively delivered to our organization and validate that alerts are properly acted upon to mitigate identified threats.
* Support security incident response activities utilizing security tools (SIEM/SOAR)
* Collaborate in the development of a Business Continuity and Disaster Recovery plan.
* Prepare system security reports by collecting, analyzing, and summarizing data and trends.
* Track and understand emerging security practices and threats. Leverage this knowledge to improve security configurations across the enterprise and hunt for potential or active threats.
* This role will be responsible for monitoring Healthcare industry and regulatory trends to ensure prompt and complete action plans are developed and implemented to address such requirements.
* Serve as the liaison for audit activities related to the areas of information security.
* This will also include maintaining ongoing cybersecurity risk profile using the recommended industry tools, and being certain that activities which keep us aligned with our target levels are implemented.
* Demonstrable expertise in implementing, managing, and fine-tuning security controls using a variety of security tools and frameworks. Specific experience with Palo Alto firewalls and Palo Alto suite of security tools, Fortinet Fortigate Firewalls, Meraki, Active Directory and other infrastructure tools as identified.
* In-depth experience with Identity and Access Management (IAM), specifically in designing and implementing IAM solutions for provisioning, de-provisioning, and role-based access controls within the organization. Familiarity with industry standard IAM solutions and best practices is a must.
* Familiarity with monitoring and managing security incidents, including the use of Security Information and Event Management (SIEM) tools.
* Proven track record in working with cross-functional teams to address security and compliance challenges, specifically in a Healthcare environment.
* Experience in developing and implementing security policies and procedures that align with industry regulations such as PCI and HIPPA.
* Previous involvement in handling external and internal audits related to information security, along with remediation of identified issues.
* A high level of problem-solving skills and the ability to communicate in a clear, concise manner.
* Must be able to communicate effectively in both oral and written form and explain technical concepts in non-technical terms to staff and prepare clear and concise written communications.
* Must be able to manage multiple projects/tasks concurrently; and prioritize requests and complete assignments within an estimated timeframe; and organize, schedule, and coordinate a variety of activities and projects.
* Must have the ability to learn new software and hardware packages and adapt to changes in technology.
Qualifications and Education Requirements:
* Bachelor's Degree in computer science or Equivalent work experience
* At least 5 years of experience in information security
* Excellent written communication skills.
* Strong organizational and planning skills.
* Demonstrates a high degree of personal integrity and practices ethical standards. Must remain objective and independent when completing assignments, and consistently demonstrate the ability to hold information in confidence.
* Demonstrated proactiveness and an ability to work independently and self-directed in managing multiple concurrent projects.
* Excellent analytical and problem-solving skills
Candidates who are back-to-work, people with disabilities, without a college degree, and Veterans are encouraged to apply.
Cardinal Health supports an inclusive workplace that values diversity of thought, experience and background. We celebrate the power of our differences to create better solutions for our customers by ensuring employees can be their authentic selves each day. Cardinal Health is an Equal Opportunity/Affirmative Action employer. All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, ancestry, age, physical or mental disability, sex, sexual orientation, gender identity/expression, pregnancy, veteran status, marital status, creed, status with regard to public assistance, genetic status or any other status protected by federal, state or local law.
Information Security Analyst
Security Engineer Job In Clarksville, TN
Abacus Technology is seeking an Information Security Analyst to support security and information assurance activities for Fort Campbell. This is a full-time position.
Responsibilities
Ensure all network user account documentation is complete and accurate for the installation unit/organizations when processing account requests and other actions.
Maintain and monitor the cyber security training records; verify, validate, and monitor the records for compliance.
Provide weekly reports for cyber security training and certification status; support for all areas of cyber security compliance reporting for higher headquarters; prepare and/or submit cyber security reports.
Support the Government with the DoD Risk Management Framework (RMF) program and the Cybersecurity Inspection Program.
Monitor compliance with cyber security policies and procedures across the installation.
Identify and report potential cyber security issues to the Government.
Qualifications
3+ years experience in information security. Must be Security+ CE certified. Experience with ACAS, operating and administering HBSS, implementing RMF, and Continuous Monitoring Risk Score (CMRS). Knowledge and experience communicating cyber security concepts to technical and non-technical personnel. Able to develop technical documents and produce system design documentation. Knowledge of DoD and Army A&A requirements and processes, including RMF and eMASS. Knowledge in application and evaluation of DISA STIGs for supported IT. Possess excellent technical writing, critical thinking/analytical, oral and written communication skills. Knowledge and experience communicating IA concepts to technical and non-technical personnel. Must have excellent customer service skills. Must be a US citizen and hold a current Secret clearance.
Applicants selected will be subject to a U.S. government security investigation and must meet eligibility requirements for access to classified information.
EOE/M/F/Vet/Disabled
Security Engineer 4 - FedRAMP Compliance Architect
Security Engineer Job In Nashville, TN
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Security Engineer 4 - FedRAMP Compliance Architect** to join our diverse, customer-focused team! This **Security Engineer 4 - FedRAMP Compliance Architect** will design, implement, and maintain secure architectures that meet FedRAMP requirements in a multi-tenant cloud environment. This role combines deep technical expertise with FedRAMP compliance knowledge to create scalable, secure solutions. You'll be the glue between security compliance requirements and technical implementation, ensuring our cloud infrastructure meets federal security standards while enabling business objectives.
**Key Responsibilities:**
+ Design, implement, and maintain system architectures to align with FedRAMP requirements.
+ Serve as the subject matter expert (SME) on FedRAMP, advising internal teams on security best practices, control implementations, and risk mitigation strategies.
+ Collaborate with engineering, operations, product, and corporate IT teams to develop secure cloud-based architectures that meet federal compliance mandates.
+ Implement governance strategy on technical security controls, including access management, configuration, encryption, logging, monitoring, and vulnerability management.
+ Support annual assessments, security control reviews, and audits, coordinating with third-party assessors (3PAO) and government sponsors.
+ Technical support for external stakeholders on customer responsibilities.
+ Key contributor to the development and maintenance of the System Security Plan (SSP), Policies and Procedures, Configuration Management Plan, Secure System Development Life Cycle, and other FedRAMP documentation
+ Partner with the GRC (Governance, Risk, and Compliance) team to efficiently track and resolve security findings.
**Basic Qualifications:**
+ 5+ years of experience in cloud security architecture, compliance, or cybersecurity engineering, with at least 3 years of experience supporting FedRAMP Moderate or High authorization.
+ Deep expertise in FedRAMP, NIST 800-53, FISMA, and cloud security best practices.
+ Strong ability to assess security risks and recommend technical and procedural mitigations.
+ Experience working with AWS GovCloud, Azure Government, or other federal cloud environments.
+ Experience with audit preparation, risk assessments, and working with third-party assessors (3PAOs).
+ Exceptional written and verbal communication skills for creating and managing FedRAMP documentation.
**Preferred Qualifications:**
+ Experience supporting DoD IL 4 or 5 environments.
+ Experience with data governance frameworks, secure data storage, and data lifecycle management in multi-tenant cloud environments.
+ Understanding of NIST AI Risk Management Framework (AI RMF) and its implications for secure AI adoption in government environments.
+ Familiar with SaaS security tools (such as Sumo Logic, Datadog, Crowdstrike, Wiz, Lucidchart, Snyk, and Qualys).
+ Familiarity with Cloud Native and SaaS constructs, including architectures, DevOps, CI/CD, and SecOps disciplines.
+ Relevant certifications, such as:
+ Certified Information Systems Security Professional (CISSP)
+ AWS Security Specialty, or equivalent
+ CompTIA Advanced Security Practitioner (CASP+)
+ Certificate of Cloud Security Knowledge (CCSK)]]
The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). **This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.**
The base salary range for this position is 176,000 - 281,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.
Information Security Analyst II
Security Engineer Job In Knoxville, TN
Our Mission is to help Members grow financially.
Our Vision is to be Members' First Choice for all Financial Services.
We can achieve these goals through our commitment to providing excellent service to our membership and our communities. And it all starts with YOU! We are looking for a service-minded individual to join our team in order to continue to provide the high-quality service our members expect from us.
Our full-time team members enjoy a wealth of benefits including employer-paid medical and dental insurance premiums, competitive pay, and a 401(k) plan with an employer match. The great service we provide to our Members is reflected in our team environment and the professional development opportunities our positions offer. People Helping People is what we do every day.
Submit your application to us today and let us be the First Choice for your new career journey!
About Us:
Knoxville TVA Employees Credit Union is a not-for-profit, Member-owned, and locally operated financial institution serving the financial needs of its communities of Membership. We have 25 locations throughout East Tennessee and we serve more than 264,000 Members. The Credit Union helps Members grow financially by offering a variety of accounts including: checking, savings and investments. Also offered are competitive loan rates on new and used autos and recreational vehicles, mortgages, personal loans and credit cards.
Benefits:
Employer-paid health and dental insurance monthly premiums
Accrual of PTO Leave
Employer-matched 401k, 50% match up to 6% of employee contributions
Employer-paid Group Life Insurance and Long-Term Disability benefits
Potential bonus up to 11% of average salary over the past year based on Credit Union-wide goals
Paid Holidays and Paid Training
Potential pay increases through additional training opportunities
The ability to help serve your local community through our mindset of People Helping People!
This position is on-site in Knoxville, TN.
PRIMARY RESPONSIBILITIES
Administrative:
Report known and potential information security risks and vulnerabilities to Credit Union management. Track the status of known information security vulnerabilities and work with IT and business departments to promote remediation or acceptance of known exposures.
Maintain an inventory of VPN, mobile devices, and file sharing site users and ensure only active, authorized individuals have external access to Credit Union data.
Develop and conduct user awareness training for new employees during new employee orientation. Develop and conduct periodic user security awareness campaigns and training.
Prepare, document, and maintain standard operating procedures and technical references for security solutions/tools.
Make information security a cultural focus of the organization by utilizing various methods such as awareness campaigns and branch visits.
Technical:
Manage and maintain all IT security related applications, hardware, and tools. Ensure all aspects of these products are working as intended and are updated against the latest threats.
Perform routine monitoring and analysis of system logs, user activity reports, and other security related alerts and reports in order to identify suspicious, unauthorized, or malicious activity.
Participate in the evaluation of new products and services and ensure the Credit Union understands and properly weighs the potential security risks inherent within these products.
Review the configuration of workstations, servers, and network devices, including firewalls and other external facing devices, on a periodic basis. Provide guidance and recommendations around any potential security risks or violations of Credit Union security best practices.
Ensure patch management is completed in an accurate and timely manner.
Responsible for malware analysis, threat modeling and deployment/usage of a malware detonation device/sandbox to test for potential malicious software or websites.
Information Security:
Maintain knowledge of relevant laws and standards including Gramm-Leach-Bliley Act, National Credit Union Administration (NCUA), Federal Financial Institutions Examination Council (FFIEC) and National Institute of Standards and Technology (NIST) requirements and standards.
Determine security violations and inefficiencies by conducting periodic audits and vulnerability assessments. Determine the potential impacts and mitigations and relay to appropriate staff for remediation.
Assist in collecting documentation from IT and business departments in preparation for NCUA and external audit annual exams and participate in audit interviews and responses.
Responsible for incident response, mitigation, and reporting.
Maintain up-to-date knowledge and skills in the Information Security field through yearly training and skills maintenance.
Standards:
Follow all Credit Union policies, procedures and regulations.
Represent the Credit Union in a professional manner (including but not limited to appearance, behavior and performance).
Maintain regular and predictable attendance.
Work cooperatively with others.
All other duties as assigned.
QUALIFICATIONS
Education/Experience - Bachelor's degree from four-year college or university or related experience or equivalent combination of education and experience. Five or more years of experience in Information Technology preferred. IT security certifications are preferred.
Qualifications and Requirements - Individual must possess the knowledge skills and ability required to execute the essential functions in a satisfactory manner.
Language - Ability to read, analyze and interpret general business periodicals, professional journals, or governmental regulations. Ability to write reports and procedure manuals and use proper grammar, punctuation and spelling. Ability to effectively present information and respond to questions from groups.
Mathematical - Ability to add, subtract, multiply, and divide in all units of measure, using whole numbers, common fractions and decimals. Ability to compute rate, ratio and percent.
Reasoning - Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists. Ability to interpret a variety of instructions furnished in written or oral form.
Computer - Knowledge of IT networks. Ability to operate related computer applications including Word, Excel and email. Proficient typing skills. Ability to operate other business equipment including adding machine, coin, and money counting machines and telephone.
Certificates and Licenses - At least two professional certifications in IT Security preferred. Valid driver's license.
Physical Security Systems Engineer
Security Engineer Job In Memphis, TN
xAI's mission is to create AI systems that can accurately understand the universe and aid humanity in its pursuit of knowledge.
Our team is small, highly motivated, and focused on engineering excellence. This organization is for individuals who appreciate challenging themselves and thrive on curiosity.
We operate with a flat organizational structure. All employees are expected to be hands-on and to contribute directly to the company's mission. Leadership is given to those who show initiative and consistently deliver excellence. Work ethic and strong prioritization skills are important.
All engineers and researchers are expected to have strong communication skills. They should be able to concisely and accurately share knowledge with their teammates.
About the Role
We are seeking a skilled and proactive Physical Security Systems Engineer to join our security team. This role involves designing, implementing, and maintaining physical security systems to protect our facilities, assets, and personnel. The ideal candidate will have a deep understanding of security technologies and be able to apply this knowledge to enhance our security infrastructure at a rapidly scaling company.
This is an in-person role based in Memphis, Tennessee or the San Francisco, California area and requires regular travel to all xAI sites.
Responsibilities
Develop detailed plans for the installation of physical security systems including access control, surveillance cameras, intrusion detection, and alarm systems.
Collaborate with InfoSec, IT and facility management teams to integrate security hardware with existing systems across locations.
Manage health and configuration of security network infrastructure
Regularly assess the performance of installed security systems and make necessary adjustments or upgrades.
Conduct preventive maintenance to ensure all security equipment is in optimal working condition.
Diagnose and resolve hardware issues promptly to minimize downtime and security risks.
Keep detailed records of all service and maintenance activities.
Participate in or lead security audits to identify vulnerabilities in physical security measures.
Recommend and implement solutions to address identified security gaps.
Liaise with vendors for procurement of security hardware, ensuring compliance with organizational standards and budget constraints.
Manage relationships with external contractors for installation and maintenance services.
Train security and facility staff on the use of new security systems.
Ensure all security hardware installations meet local, state, and federal regulations.
Maintain up-to-date documentation on system configurations, maintenance schedules, and security incident responses.
Basic Qualifications
Minimum of 5 years in a role focused on physical security systems design.
Proven experience with CCTV, access control, and intrusion detection systems.
Preferred Qualifications
Bachelor's degree in Electrical Engineering, Computer Science, or related field; or equivalent experience in security systems.
Experience using CAD software and reading architectural drawings is highly desirable.
Familiarity with Genetec software is a plus.
Proficiency in hardware troubleshooting and system diagnostics.
Experience configuring security and network architecture in integrated security systems.
Familiarity with current security technology trends and innovations.
Certifications such as CPP (Certified Protection Professional) or PSP (Physical Security Professional) are highly desirable.
Excellent problem-solving abilities and attention to detail.
Strong communication skills for effective collaboration with team members and stakeholders.
Ability to work under pressure in a dynamic environment on highly condensed timelines.
Physical Requirements: Light
Regular sitting at a desk or computer for extended periods, typing and writing. Occasionally walking, around the facility and standing.
xAI is an equal opportunity employer and does not unlawfully discriminate based on race, color, religion, ethnicity, ancestry, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, age, disability, medical conditions, genetic information, marital status, military or veteran status, or any other applicable legally protected characteristics.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all applicable federal, state, and local laws, including the San Francisco Fair Chance Ordinance, Los Angeles County Fair Chance Ordinance for Employers, and the California Fair Chance Act.
For Los Angeles County (unincorporated) Candidates:
xAI reasonably believes that criminal history may have a direct, adverse and negative relationship on the following job duties, potentially resulting in the withdrawal of a conditional offer of employment:
Access to information technology systems and confidential information, including proprietary and trade secret information, and/or user data;
Interacting with internal and/or external clients and colleagues; and
Exercising sound judgment.
California Consumer Privacy Act (CCPA) Notice
Connected Asset Security Engineer
Security Engineer Job In Nashville, TN
**Your Work Shapes the World at Caterpillar Inc.** When you join Caterpillar, you're joining a global team who cares not just about the work we do - but also about each other. We are the makers, problem solvers, and future world builders who are creating stronger, more sustainable communities. We don't just talk about progress and innovation here - we make it happen, with our customers, where we work and live. Together, we are building a better world, so we can all enjoy living in it.
**Connected Asset Security Engineer**
**Role Definition:**
The Connected Asset Security Engineer is responsible for providing embedded and connected Caterpillar product security assessments including back-office components. You will facilitate the continued adoption and implementation of Connected Asset Security Program processes into Caterpillar NPI processes and software development lifecycles. Additionally, the engineer will be working with product teams on security by design concepts and remediation activities resulting from security assessments and testing.
The Connected Asset Security Engineer will be responsible for collaborating with global teams and maintaining a thorough awareness and understanding of the Connected Asset Security processes.
**What You Will Do:**
+ Perform security assessments on connected asset solutions while influencing business decisions that affect cybersecurity for the next generation of on-board products and solutions.
+ Work with Development teams to provide Security Guidance and influence the cybersecurity posture of the solution during the development phase.
+ Actively participate in solution attack and penetration test scoping and vulnerability assessments
+ Provide periodic internal stakeholder updates and function as the communication focal point for internal engineering team inquiries and presentations.
+ Provide input and support to solution teams throughout the product development lifecycle on connected product security requirements, including secure coding and configuration, software testing, third-party component management and security defect management.
+ Document product vulnerabilities and communicate recommended remediations to product owners.
+ Maintain current industry expert knowledge on modern ICS (Industrial Control Systems) and Cloud security procedures, directives, tools, attack methodologies, directives, secure configuration baselines, and technology controls.
+ Leverage expertise in application testing, threat modeling, attack and penetration testing, data classification and data handling.
+ Function as the SME (Subject Matter Expert) for Product Communication, ICS, and Cloud technologies for embedded device development teams.
+ Provide connected asset security expertise and leadership in defining and prioritizing Connected Asset Security Programs initiatives.
**What You Have:**
+ Bachelor's degree in information technology, Computer Science, or a related field
+ Working knowledge of control systems, IIoT, embedded controllers, autonomy solutions and/or telematics
+ Working knowledge of cybersecurity threat modeling and mitigation/remediation techniques of control systems, embedded controllers, autonomy solutions and/or telematics
+ Excellent written and verbal communications skills
+ Ability to coordinate multiple teams in accomplishing process review and improvement.
+ Committed to technical learning and continuous education in cybersecurity.
+ Intermediate understanding of ISA/IEC 62443, ISO 27001, and NIST CSF
**Top Candidates Will Have:**
+ Expert experience in cybersecurity technical concepts, secure by design techniques, and industry best practices.
+ Demonstrated ability in project management and change management.
+ Demonstrated ability to perform critical analysis and develop executive decision support content.
+ Experience with a wide variety of information security processes and principles, for example:
+ Vulnerability assessment
+ Risk analysis
+ Defense in depth
+ SDLC and product development processes
+ Identity and access management
+ Networking concepts (routing, design, TCP/IP)
+ Network and endpoint security software.
+ Business process design
+ Web services security
+ Professional information security certification (e.g., CISSP, CCSP, SANS Certifications, etc.)
+ Expert experience in control systems, IIoT, embedded controllers, autonomy solutions and telematics.
+ Expert experience with ISA/IEC 62443, ISO 27001, and NIST CSF
+ Ability to adjust to multiple demands, changing priorities, uncertainty, ambiguity, and rapid change, while multitasking effectively
+ Experience with RTOS control systems, Embedded Component Programming including Cybersecurity testing and assessment.
**Skill Descriptors:**
**Communicating Complex Concepts:**
+ Knowledge of effective presentation tools and techniques to ensure clear understanding; ability to use summarization and simplification techniques to explain complex technical concepts in simple, understandable language appropriate to the audience.
**Consulting:**
+ Knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply consulting knowledge appropriately.
**Information Security Management:**
+ Knowledge of the processes, tools and techniques of information security management; ability to deploy and monitor information security systems, while detecting, controlling and preventing violations of IT security.
**Cybersecurity Standards and Policies:**
+ Knowledge of developing cybersecurity policies, standards and procedures; ability to develop and communicate policies, standards and procedures that guide interactions with customers.
**Cybersecurity Risk Management:**
+ Knowledge of tools, techniques, approaches and processes of cybersecurity risk management; ability to ensure organizational network operation and minimize negative effect by cybersecurity risks.
**Information Technology (IT) Security Policies:**
+ Knowledge of IT security policies, standards, and procedures; ability to utilize a variety of administrative skill sets and technical knowledge to ensure cyber security compliance.
**Additional Info** :
+ The primary locations for this position are: East Peoria, IL, Nashville TN, or Dallas, TX
+ Must be willing to work a minimum of 3 days a week onsite.
+ Sponsorship is **NOT** available.
+ Relocation is available for qualified candidates.
**About Caterpillar -**
Caterpillar Inc. is the world's leading manufacturer of construction and mining equipment, off-highway diesel and natural gas engines, industrial gas turbines and diesel-electric locomotives. For nearly 100 years, we've been helping customers build a better, more sustainable world and are committed and contributing to a reduced-carbon future. Our innovative products and services, backed by our global dealer network, provide exceptional value that helps customers succeed.
**Summary Pay Range:**
$126,000.00 - $189,000.00
Compensation and benefits offered may vary depending on multiple individualized factors, job level, market location, job-related knowledge, skills, individual performance and experience. Please note that salary is only one component of total compensation at Caterpillar.
**Benefits:**
Subject to plan eligibility, terms, and guidelines. This is a summary list of benefits.
+ Medical, dental, and vision benefits*
+ Paid time off plan (Vacation, Holidays, Volunteer, etc.)*
+ 401(k) savings plans*
+ Health Savings Account (HSA)*
+ Flexible Spending Accounts (FSAs)*
+ Health Lifestyle Programs*
+ Employee Assistance Program*
+ Voluntary Benefits and Employee Discounts*
+ Career Development*
+ Incentive bonus*
+ Disability benefits
+ Life Insurance
+ Parental leave
+ Adoption benefits
+ Tuition Reimbursement
* These benefits also apply to part-time employees
Relocation is available for this position.
Visa Sponsorship is not available for this position. This employer is not currently hiring foreign national applicants that require or will require sponsorship tied to a specific employer, such as, H, L, TN, F, J, E, O. As a global company, Caterpillar offers many job opportunities outside of the U.S which can be found through our employment website at ****************************
**Posting Dates:**
March 17, 2025 - March 30, 2025
Any offer of employment is conditioned upon the successful completion of a drug screen.
EEO/AA Employer. All qualified individuals - Including minorities, females, veterans and individuals with disabilities - are encouraged to apply.
Not ready to apply? Join our Talent Community (*********************************************** .
Senior Security Engineer 3, Product & Application Security
Security Engineer Job In Nashville, TN
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management. Half of the Fortune 500 and nearly 70% of the Fortune 100 trust PagerDuty as essential infrastructure. Join us. (******************************* At PagerDuty, you'll tackle complex problems, collaborate with kind and ambitious people, and help build a more equitable world-all in a flexible, award-winning workplace.
PagerDuty is seeking a **Senior Security Engineer** to join our diverse, customer-focused team! As a **Senior Security Engineer** , you will be a key contributor in leading, driving and delivering security initiatives for PagerDuty's SaaS offerings, focusing on application & product security through architecture reviews, threat modeling sessions, and defining secure-by-design product standards and protections that support PagerDuty's security mission. Since we own and operate what we build, you'll collaborate closely with engineers across many product development teams. You will work closely with our internal development teams to ensure we deliver secure, highly reliable, and scalable solutions to our customers.
This is an exciting opportunity to build security solutions that make developers and customers happy. The ideal candidate will have a blend of experiences across large enterprise environments and small or mid-size environments and will have focused on establishing security standards, coordinating with product development teams, developing strategies for secure-by-default architectures, and corresponding process and tooling selection and implementation. Things that make you smile: secure product architectures, providing an engaging Developer Experience for security adoption, and cute animal memes.
**KEY RESPONSIBILITIES**
+ Embrace the role of hands-on technical lead in defining product security standards and guiding platform protections.
+ Establish criteria and conduct comprehensive security reviews throughout all stages of product development to identify and address security risks.
+ Perform regular threat assessments, coordinate with third-party testers for penetration testing, and conduct internal penetration testing to identify and mitigate security risks.
+ Mentor and guide team members to ensure product and business objectives are prioritized in project implementations, fostering a strong documentation culture with project charters and design documents.
+ Work with loosely defined requirements where you exercise your analytical skills to clarify questions, share your approach, and collaborate with the team to design and implement effective security frameworks. Maintain a strong appetite for challenging problems with a high degree of ownership.
+ Participate in the team's On-Call rotation, triaging and addressing security issues as they arise, and implement measures to prevent future occurrences.
+ Enable service team security implementations by developing security-as-code constructs, including infrastructure-as-code (IaC) modules, libraries and frontend components, while creating and maintaining developer-focused documentation to promote easy adoption.
+ Establish and uphold baseline standards and hardened configurations for platform components.
+ Continuously enhance security frameworks by focusing on product security standards and software supply chain protections, tailored for application security in cloud-native, microservices environments.
**BASIC QUALIFICATIONS**
+ Proficiency with Application & Product Security typically associated with 4 - 5 years of experience in a Security Engineering role working with a cloud-native, microservices environment, preferably AWS.
+ Familiarity with cloud-native product technologies including:
+ Vulnerability detection via multiple approaches including SAST, DAST, SCA, and runtime (e.g., Qualys/Nessus, Wiz, Snyk, GHAS, Semgrep, etc.)
+ CI/CD technologies and integrations (e.g., CircleCI, Buildkite, Helm, Terraform, Chef)
+ Product security event logging standards and analysis tools (e.g., SIEM such as: SumoLogic, LogRythm, or Splunk, etc.)
+ Security Incident Response & Risk Management processes and tools
+ Proficiency in at least one programming language and framework (e.g. Python, Bash, Phoenix/Elixir, Java, Ruby on Rails), typically associated with 3 - 4 years of experience with the language/framework.
+ Have exceptional written, oral communication, and interpersonal skills.
+ Organizational skills with the ability to successfully manage multiple priorities and deadlines.
**PREFERRED QUALIFICATIONS**
+ Ability to analyze complex problems, develop solutions under guidance, and assist in implementing these solutions with a growing set of change management skills.
+ Possesses a strong sense of ownership and a keen discernment for excellence in securing systems within a SaaS environment, demonstrating the ability to distinguish what constitutes truly robust and effective product security.
+ Current or past experience with obtaining and maintaining FedRAMP authorization.
+ Experience working at a SaaS company larger than 1000 employees and $100M in revenue.
+ Familiarity with Cloud Infrastructure security (such as AWS GuardDuty, AWS CloudTrail, AWS Secrets Manager, AWS IAM & Identity Center, AWS Control Tower, Azure Security Center, Microsoft Defender for Cloud, etc.)
+ Familiarity with Container Security (e.g., Kubernetes, EKS, AKS, service mesh, baseline/benchmark hardening, identity and secrets orchestration, etc.)
+ Demonstrated history of mentoring and coaching.
The successful applicant will be performing work in FedRAMP environments, and therefore, must be a U.S. Person (i.e. U.S. citizen, U.S. national, lawful permanent resident, asylee, or refugee). **This position may also perform work that the U.S. government has specified can only be performed by a U.S. citizen on U.S. soil.**
The base salary range for this position is 152,000 - 248,000 USD. This role may also be eligible for bonus, commission, equity, and/or benefits.
Our base salary ranges are determined by role, level, and location. The range, which is subject to change based on primary work location, reflects the minimum and maximum base salary we expect to pay newly hired employees for the position. Within the range, we determine pay for an individual based on a number of factors including market location, job-related knowledge, skills/competencies and experience.
Your recruiter can share more about the specific offerings for this role, as well as the salary range for your primary work location during the hiring process.
**Hesitant to apply?**
We encourage you to submit your resume even if you don't meet every requirement. We value potential and consider each candidate's full professional story. Whether you're exploring a career change or taking your next step, we look forward to reviewing your application. If this just isn't the right role or time - sign up for job alerts (**************************************** !
**Where we work**
PagerDuty currently has offices (**************************************** in Atlanta, Lisbon, London, San Francisco, Santiago, Sydney, Tokyo, and Toronto. We offer a hybrid, flexible environment. We also provide ample opportunities for connection, like team offsites and volunteering events.
**How we work**
Our values (************************************** guide how we support customers, collaborate with colleagues, develop products, and foster a culture of belonging. They define not just our actions, but what it means to be Dutonian.
**What we offer**
As a global organization, our total rewards approach is competitive with industry standards and aligned with local laws and regulations. Learn more, including country-specific offerings, on our benefits site (********************************************** .
**Your package may include:**
- Competitive salary
- Comprehensive benefits package from day one
- Flexible work arrangements
- Company equity*
- ESPP (Employee Stock Purchase Program)*
- Retirement or pension plan*
- Generous paid vacation time
- Paid holidays and sick leave
- Dutonian Wellness Days & HibernationDuty - companywide paid days off in addition to PTO
- Paid parental leave: 22 weeks for pregnant parent, 12 weeks for non-pregnant parent (some countries have longer leave standards and we comply with local laws)*
- Paid volunteer time off: 20 hours per year
- Company-wide hack weeks
- Mental wellness programs
*Eligibility may vary by role, region, and tenure
**About PagerDuty**
PagerDuty, Inc. (NYSE:PD) is a global leader in digital operations management, enabling customers to achieve operational efficiency at scale with the PagerDuty Operations Cloud. The PagerDuty Operations Cloud combines AIOps, Automation, Customer Service Operations and Incident Management with a powerful generative AI assistant to create a flexible, resilient and scalable platform to increase innovation velocity, grow revenue, reduce cost, and mitigate the risk of operational failure. Half of the Fortune 500 and nearly 70% of the Fortune 100 rely on PagerDuty as essential infrastructure for the modern enterprise.
PagerDuty is Great Place to Work-certified, a Fortune Best Workplace for Millennials, a Fortune Best Medium Workplace, a Fortune Best Workplace in Technology, and a top rated product on TrustRadius and G2.
Go behind-the-scenes on our careers site (*********************************** and @pagerduty on Instagram.
**Additional Information**
PagerDuty is committed to creating a diverse environment and is an equal opportunity employer. PagerDuty does not discriminate on the basis of race, religion, color, national origin, gender, sexual orientation, age, marital status, parental status, veteran status, or disability status.
PagerDuty is committed to providing reasonable accommodations for qualified individuals with disabilities in our job application process. Should you require accommodation, please email accommodation@pagerduty.com and we will work with you to meet your accessibility needs.
PagerDuty uses the E-Verify employment verification program.