person looking for a Security Operations Remote Jobs

Get Remote Security Operations Jobs in your mailbox.

104 exciting remote jobs on file from 2500+ top remote companies.

  • Hot new jobs of this week
  • 104 active jobs from past weeks to consult
  • Segmented for USA, Europe or Worldwide.
  • Personally selected for you by our experienced remote hiring managers.


A selection of jobs from the previous newsleterrs.

Western Digital is hiring a Remote Principal Firmware Security Engineer

Job Description

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Development of various cryptography-based security features such as data encryption, Secure Boot, and Device Attestation.
  • Integrate these security protocols and features into the SSD data and control flows to ensure a robust and secure system. Additionally, investigate and resolve any security protocol compatibility issues that may arise.
  • Investigating failures, documenting bug reports, and providing valuable assistance to product teams in identifying and resolving issues.
  • Debugging, optimizing, and validating the Firmware on SoC platforms, as well as bringing up of FPGA and ASIC.
  • Contribute to the Security Development Lifecycle of the Firmware by supporting its development at different stages, including design, threat analysis, implementation, validation, vulnerability testing, certification, and audit.

Qualifications

REQUIRED:

To qualify for this position, an ideal candidate would have/be

  • A degree in Computer Science, Electrical/Computer Engineering, Software Engineering, or a related field.
  • 8+ years of experience in embedded programming, with proficiency in C/C++ and one or more of the following: Python, Rust, Go.
  • Experience in firmware code review, CI/CD test and validation methodology, as well as static and dynamic code analysis. Familiarity with the Agile software development process life cycle is also desired.
  • Proficiency in failure analysis in debugging an embedded firmware application, using debuggers such as Lauterbach.
  • An engineer who can take ownership of given features and manage them from start to finish. Being self-motivated and driven is essential for this role.
  • Good communication skills and be able to work effectively with cross-functional teams.

What Sets You Apart

  • Detailed knowledge of RISC-V Instruction Set Architectures (ISA)
  • Technical expertise in applied cryptography and firmware/hardware security, including knowledge of data encryption, trusted execution environment, secure boot, and device attestation.
  • Knowledge of storage controller architectures and security protocols, such as TCG Opal/Ruby/Pyrite, IEEE 1667, SPDM, and IDE.
  • Familiarity with writing code in Github repository and it’s CI/CD testing framework.

See more jobs at Western Digital

Apply for this job

Daxko is hiring a Remote Director of Information Security

Job Description

As the Director of Information Security at Daxko, you will oversee and ensure the integrity, confidentiality, and availability of all data and information systems. This role requires strategic leadership, exceptional analytical skills, and a deep understanding of cybersecurity threats and countermeasures. You will lead the information security team in protecting our company’s digital assets, ensuring compliance with security regulations and standards, and ensuring the team has the aptitude to not only address today’s needs but also the needs of tomorrow.  

As a leader, you will: 

  • Recruit, interview, hire, and train new staff. 
  • Oversee the daily workflow of the department. 
  • Provide constructive and timely performance evaluations.  
  • Handle discipline and termination of team members in accordance with company policy. 
  • Oversee departmental budgets and manage expenses related to information security for Daxko. 

You will also: 

  • Develop and implement comprehensive information security strategies and policies that align with business objectives. 
  • Lead the information security team to protect our production environments, software products, internal IT infrastructure, and field operations against potential threats. 
  • Coordinate with technical operations and software development departments to ensure security is integrated throughout our software development life cycle. 
  • Oversee the management of security incidents and events to protect corporate IT assets, including intellectual property, regulated data, and the company's reputation. 
  • Conduct risk assessments, security audits, and coordinate remediation plans with a focus on both current and potential future threats. 
  • Collaborate with other departments to establish and maintain a consistent security posture across all platforms and systems. 
  • Manage the development and implementation of IT security education and awareness programs. 
  • Stay current with the latest security threats, technologies, and trends that may impact information security. 
  • Serve as the primary point of contact for external auditors and agencies on all information security matters. 
  • Advise senior management on security direction and resource investments. 

Qualifications

  • BS in Computer Science, Information Security or a related field.  
  • Minimum of 8 years of experience in a combination of risk management, information security and technical operations jobs. 
  • Minimum of 10 years of experience in a combination of software engineering and architectural jobs. 
  • At least 5 years in a senior leadership role 
  • Experience with incident response management and information security frameworks (ISO 27001, NIST, etc.), with additional knowledge of quantum-safe protocols. 
  • Strong understanding of the cybersecurity landscape, including emerging threats and effective countermeasures. 
  • Proven work experience as a System Security Engineer or Information Security Engineer 
  • Experience in building and maintaining security systems 
  • Hands on experience in firewalls, intrusion detection systems, anti-virus software, authentication systems, log management, content filtering, etc. 
  • Experience with network security and networking technologies  
  • Strong background with system, security, and network monitoring tools 
  • Familiarity with various compliance such as PCI-DSS, SOC 1, SOC 2, GDPR among others. 
  • Exposure to the payment card or financial industries. 
  • Strong background in software architecture and software engineering.  
  • Technical knowledge of database and operating system security 


Preferred Education and Experience:  

  • Master’s degree preferred. 
  • Hands-on experience addressing application security issues with industry best practices. 
  • CISSP: Certified Information Systems Security Professional 
  • CISM: Certified Information Security Manager 
  • CEH: Certified Ethical Hacker 
  • CompTIA Security+ 
  • DSOE: DevSecOps Engineering 

See more jobs at Daxko

Apply for this job

Urbint is hiring a Remote Director of Information Security

Job Application for Director of Information Security at Urbint{"@context":"schema.org","@type":"JobPosting","hiringOrganization":{"@type":"Organization","name":"Urbint","logo":"https://s3-recruiting.cdn.greenhouse.io/external_greenhouse_job_boards/logos/400/025/900/resized/two-color-960_(1).png?1578429270"},"title":"Director of Information Security","datePosted":"2024-11-14","jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Toronto, Ontario, Canada","addressRegion":"ON","addressCountry":null,"postalCode":null}},"description":"\u003cp\u003e\u003cstrong\u003eDirector of Information Security\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eLocation: Canada - East Coast Hours\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eUrbint uses AI and the latest industry science to identify threats to workers and infrastructure to stop safety incidents before they happen. We are a tight-knit team working together to build powerful technology that prevents serious injuries and infrastructure damages. Many of the largest energy and infrastructure companies in North America trust Urbint to protect workers, assets, communities, and the environment.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eJob Summary\u003c/strong\u003e\u003c/p\u003e\n\u003cp\u003eThe Director of Information Security, reporting to our Chief Product and Technology Officer (CPTO), will be responsible for developing, implementing, and managing a comprehensive information security program that safeguards Urbint’s and our customers’ data, systems, and assets. This role requires a strategic thinker with strong technical expertise and leadership skills who can collaborate across departments to ensure security is embedded in all aspects of our operations and products.\u003c/p\u003e\n\u003cp\u003e\u003cstrong\u003eKey Responsibilities\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003e\u003cstrong\u003eStrategy \u0026amp; Compliance\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eDevelop and implement a company-wide information security strategy for both Urbint’s products and internal systems.\u003c/li\u003e\n\u003cli\u003eEstablish and maintain security policies, standards, and procedures.\u003c/li\u003e\n\u003cli\u003eEnsure compliance with relevant regulatory requirements (e.g., SOC 2, ISO 27001).\u003c/li\u003e\n\u003cli\u003eBe the designated privacy officer for Urbint.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eRisk Management\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eConduct regular risk assessments and vulnerability analyses.\u003c/li\u003e\n\u003cli\u003eIdentify and prioritize security risks; develop and implement mitigation strategies.\u003c/li\u003e\n\u003cli\u003eDevelop and maintain an incident response plan to guide the organization’s response to security breaches.\u003c/li\u003e\n\u003cli\u003eOversee incident response planning and execution, including post-incident analysis and remediation.\u003c/li\u003e\n\u003cli\u003eDevelop and test the business continuity/disaster recovery plans for Urbint.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eCustomer Cybersecurity Questionnaires\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eLead the creation and management of responses to customer cybersecurity questionnaires, ensuring accuracy and alignment with our security policies and practices.\u003c/li\u003e\n\u003cli\u003eWork closely with sales and customer success teams to address customer security concerns and communicate our security posture effectively.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eTeam Leadership \u0026amp; Development\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eFoster a culture of security awareness, conduct security training.\u003c/li\u003e\n\u003cli\u003eBuild, mentor, and lead a small team of security professionals as Urbint’s needs grow.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003ePlatform Operations\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eLead the SRE team operating and securing Urbint’s US production SaaS environment, creating a secure platform for all products.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eSecurity Operations Governance\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eManage security monitoring, threat detection, and response activities for Urbint’s corporate infrastructure and products.\u003c/li\u003e\n\u003cli\u003eEnsure regular security testing, including penetration testing, vulnerability scanning, and code reviews.\u003c/li\u003e\n\u003cli\u003eSpec and manage common security tools (e.g., SIEM), enabling the operations and development teams to use the tools for their product areas.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eProduct Security\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eCollaborate with IT, DevOps, product development, and other teams to ensure security best practices are integrated into the development lifecycle (SDLC).\u003c/li\u003e\n\u003cli\u003eEnsure the SDLC covers testing, developing, architecting, and managing secure systems including e.g. penetration and fuzz testing, DAST, SAST, threat modeling, S-BOM generation and management, and data encryption policies.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eThird-Party Management\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eAssess and manage security risks associated with third-party vendors and partners.\u003c/li\u003e\n\u003cli\u003eImplement and enforce security requirements in vendor contracts.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cli\u003e\u003cstrong\u003eReporting \u0026amp; Communication\u003c/strong\u003e\u003c/li\u003e\n\u003cul\u003e\n\u003cli\u003eRegularly report on the status of the information security program to executive leadership.\u003c/li\u003e\n\u003cli\u003eCommunicate security risks and issues effectively to non-technical stakeholders.\u003c/li\u003e\n\u003cli\u003eLead security awareness training for all employees.\u003c/li\u003e\n\u003c/ul\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eWho you are\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eBachelor's degree in Information Security, Computer Science, or a related field.\u003c/li\u003e\n\u003cli\u003e8+ years of experience in information security, with at least 3 years in a leadership role at a software company.\u003c/li\u003e\n\u003cli\u003eIn-depth knowledge of information security principles, technologies, and best practices.\u003c/li\u003e\n\u003cli\u003eHands-on experience with security tools such as SIEM, IDS/IPS, firewalls, and encryption technologies.\u003c/li\u003e\n\u003cli\u003eFamiliarity with SaaS cloud security, particularly in GCP, Azure, or AWS environments.\u003c/li\u003e\n\u003cli\u003eStrong understanding of web application security concepts, including OWASP vulnerabilities and common attack vectors.\u003c/li\u003e\n\u003cli\u003eRelevant certifications such as CISSP, CISM, CISA, or equivalent are strongly preferred.\u003c/li\u003e\n\u003cli\u003eProven ability to lead and develop a security team.\u003c/li\u003e\n\u003cli\u003eStrong communication and interpersonal skills, with the ability to influence and drive change across the organization.\u003c/li\u003e\n\u003cli\u003eAbility to balance strategic thinking with hands-on execution.\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003eCompensation:\u003c/strong\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eSalary Range: C$170,000 to C$200,000\u003c/li\u003e\n\u003c/ul\u003e\n\u003cp\u003e\u003cstrong\u003e\u003cspan data-contrast=\"auto\"\u003eBenefits\u003c/span\u003e\u003c/strong\u003e\u003cspan data-ccp-props=\"{\u0026quot;335559738\u0026quot;:240,\u0026quot;335559739\u0026quot;:240}\"\u003e\u0026nbsp;\u003c/span\u003e\u003c/p\u003e\n\u003cul\u003e\n\u003cli data-leveltext=\"●\" data-font=\"Arial\" data-listid=\"2\" data-list-defn-props=\"{\u0026quot;335552541\u0026quot;:1,\u0026quot;335559685\u0026quot;:720,\u0026quot;335559991\u0026quot;:360,\u0026quot;469769242\u0026quot;:[8226],\u0026quot;469777803\u0026quot;:\u0026quot;left\u0026quot;,\u0026quot;469777804\u0026quot;:\u0026quot;●\u0026quot;,\u0026quot;469777815\u0026quot;:\u0026quot;multilevel\u0026quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"\u003e\u003cspan data-contrast=\"none\"\u003eMission Driven - Some companies use AI to serve better digital ads and trade stocks, we seek to make our communities safer and more resilient \u003c/span\u003e\u003c/li\u003e\n\u003cli data-leveltext=\"●\" data-font=\"Arial\" data-listid=\"2\" data-list-defn-props=\"{\u0026quot;335552541\u0026quot;:1,\u0026quot;335559685\u0026quot;:720,\u0026quot;335559991\u0026quot;:360,\u0026quot;469769242\u0026quot;:[8226],\u0026quot;469777803\u0026quot;:\u0026quot;left\u0026quot;,\u0026quot;469777804\u0026quot;:\u0026quot;●\u0026quot;,\u0026quot;469777815\u0026quot;:\u0026quot;multilevel\u0026quot;}\" data-aria-posinset=\"4\" data-aria-level=\"1\"\u003e\u003cspan data-contrast=\"none\"\u003eCompetitive compensation package\u003c/span\u003e\u003c/li\u003e\n\u003cli data-leveltext=\"●\" data-font=\"Arial\" data-listid=\"2\" data-list-defn-props=\"{\u0026quot;335552541\u0026quot;:1,\u0026quot;335559685

See more jobs at Urbint

Apply for this job

6d

IT Security Analyst

NorgineHarefield,England,United Kingdom, Remote Hybrid

Norgine is hiring a Remote IT Security Analyst

Want a 3D Career? Join Norgine.

At Norgine, our colleagues Dare themselves to be different and try new things, Drive to achieve their goals and beyond, and Develop themselves and their community.

We call it the 3D career at Norgine and it offers you a fully-rounded experience with no limits.

Bring everything about yourself that you’re proud of, whether that’s your passion for making a difference, focus on others’ well-being, or intellectual curiosity to unleash in a fast-paced environment and supportive community.

In return, get a sense of belonging, a long-term career with ongoing development and upskilling, and a company that cares about people’s wellness as much as you do.

Because at Norgine, we transform lives with innovative healthcare solutions.

We have an exciting opportunity for a IT Security Analyst to join Norgine.

The person holding this position will report to Director of IT Governance.

If you want a multi-dimensional 3D career in a leading healthcare organisation, join us.

• Collate and share security Key Performance Indicator (KPI)/metrics data with the business to ensure transparent communication and alignment with agreed security goals.

• Conduct thorough technical security reviews of both new and existing services, documenting findings, and implementing necessary measures to ensure they meet the requirements as set out by the security team at Norgine.

• Assist as part of the wider team, the response and recovery of data and assets in the event of a cyber breach. Leading the thought process behind incident management solutions with internal stakeholders and external partners.

• Assist in the management of the security requirements of the supply chain through the technical analysis of systems and applications within Norgine

• Oversee the effectiveness and deployment of cyber security tools and technologies on a regular basis to ensure optimal performance and responsiveness.

• Understand and advise on the current and emerging Cyber Security legal/compliance measures which Norgine need to adhere to, relevant to where the business operates. Identify opportunities for improvement to be aligned with emerging legislation.

• Collaborate with the Security team to engage and lead projects with external partners and internal stakeholders to conduct penetration tests, interpret results, and develop response plans to address identified vulnerabilities.

• Oversight of the analysis of legacy operating systems and services, identifying potential security risks, and work with relevant stakeholders to implement security hardening or network isolation solutions where necessary.

• Participation in the internal and external security audits to ensure that there is the compliance to the required security and associated data protection standards.

• Monitor and assess the patch status of IT assets to ensure compliance and minimize vulnerabilities.

• Review and test the applicability of the security policies, processes, and controls to ensure their effectiveness within the business and alignment with best practices.

• Act as a subject matter expert, providing guidance and support to internal project delivery pipeline, BAU initiatives, and changes to ensure compliance with security policies and architectural principles.

• Maintain the Cyber Technology roadmap, working with the Technology team to research and propose innovative solutions to security challenges that may reduce Norgine’s risk and threat profile.

• Provides direction and input into the security incident response process, including supporting the development of new incident monitoring use cases, reviewing alerts generated by monitoring tools, and leading the coordination of security incidents.

• Provide assurance monitoring on standard, serviced and privileged access management, to ensure that the partners involved are efficient and effective in the delivery of this function.

• Engage in any other necessary activities that contribute to the organization's cyber security and risk mitigation efforts.

• Ensure compliance to Norgine policies and procedures at all times.

Our benefits may vary per location. Please liaise with the Norgine TA representative to obtain more information.

Sound good? Find out more about the career you’ll have with Norgine, then apply here.

 

#LI-PP1

See more jobs at Norgine

Apply for this job

6d

Senior Security Engineer

LatticeRemote - US

Lattice is hiring a Remote Senior Security Engineer

This is Engineering at Lattice

Lattice’s Engineering team is continuously working to better both our product and our craft. We use a modern, cutting-edge tech stack and love experimenting with new technologies. We strive for maintainable, robust, and performant code. We’re highly collaborative and continuously iterative and work closely with designers and product managers. We prioritize not only great technical architecture but also an amazing product experience.

As a critical member of Lattice's security team, you will play a pivotal role in auditing and strengthening our identity and access management (IAM) controls. Your responsibilities will include reviewing IAM configurations, pulling audit evidence and writing documentation, capturing configuration screenshots, and ensuring alignment with Lattice's security standards and compliance requirements. This role is ideal for someone with a deep technical understanding of IAM systems and a proactive approach to continuous improvement.

What You Will Do

  • Conduct in-depth audits of systems for IAM configurations, ensuring compliance with security standards by gathering audit evidence and capturing configuration screenshots.
  • Review and enhance IAM security controls across key corporate systems like Okta (identity and access management), Zscaler (network access controls), and CrowdStrike (endpoint access controls), recommending best practices for improved security.
  • Collaborate with IT and engineering teams to assess and optimize IAM configurations, ensuring they support secure, role-based access and effective incident detection.
  • Lead compliance initiatives and walkthroughs from a system perspective, including SOC2 audits, by preparing audit documentation specific to IAM controls and ensuring all evidence is properly documented and accessible.
  • Proactively manage IAM-related security alerts, triaging incidents to mitigate potential access threats and continually optimizing alert rules and thresholds.
  • Develop and maintain detailed documentation for IAM processes, controls, and evidence, ensuring they reflect current industry standards and Lattice security policies.

What You Will Bring to the Table

  • 5+ years of experience in security operations, auditing, or IT with a focus on identity and access management systems and security compliance.
  • Strong expertise in managing IAM tools and controls within platforms like Okta, Zscaler, and CrowdStrike, with a comprehensive understanding of secure configuration and role-based access control options.
  • Demonstrated ability to assess IAM configurations, recommend security improvements, and implement best practices for system hardening.
  • Knowledge of compliance frameworks (SOC2 preferred), authentication protocols, access management best practices, and role-based access control methods.

----

The estimated annual cash salary for this role is $166,000 - $207,500. This position is also eligible for incentive stock options, subject to the terms of Lattice’s applicable plans

Benefits: The Company offers the following benefits for this position, subject to applicable eligibility requirements: Medical insurance; Dental insurance; Vision insurance; Life, AD&D, and Disability Insurance; Emergency Weather Support; Wellness Apps; Paid Parental Leave, Paid Time off inclusive of holidays and sick time; Commuter & Parking Accounts; Lunches in the Office; Workplace Amenities Stipend, Internet and Phone Stipend; One time WFH Office Set-Up Stipend; 401(k) retirement plan; Financial Planning; Learning & Development Budget; Sabbatical Program; and Invest in Your People Fund

*Note on Pay Transparency:

Lattice provides an estimate of the compensation for roles that may be hired as required by state regulations. Compensation may vary based on (a) location, as Lattice factors in specific location when benchmarking compensation for most roles; (b) individual candidate skills and qualifications; and (c) individual candidate experience.

Additionally, Lattice leverages current market data to determine compensation, so posted compensation figures are subject to change as new market data becomes available. The salary, other compensation, and benefits information is accurate as of the date of this posting. Lattice reserves the right to modify this information at any time, subject to applicable law.

#LI-remote

About Lattice

Lattice is on a mission to build cultures where employees and their companies thrive. In an age where employees have more choices than ever before, businesses that put employees first are winning ????– and Lattice is building the tools to empower those people-centric companies.

Lattice is a people success platform that offers performance reviews, employee engagement surveys, real-time feedback, weekly check-ins, goal setting, and career planning in a way that allows companies to focus on employee development, growth, and engagement – yielding stronger employee retention, performance, and impact to the bottom line ????. Since launching in 2016, we have grown to over 5,000+ customers globally, including brands like Slack, Robinhood, and Gusto. 


Lattice is committed to equal treatment and opportunity in all aspects of recruitment, selection, and employment without regard to gender, race, religion, national origin, ethnicity, disability, gender identity/expression, sexual orientation, veteran or military status, or any other category protected under the law. Lattice is an equal opportunity employer; committed to a community of inclusion, and an environment free from discrimination, harassment, and retaliation.

By clicking the "Submit Application" button below, you consent to Lattice processing your personal information for the purpose of assessing your candidacy for this position in accordance withLattice's Job Applicant Privacy Policy.

Apply for this job

7d

Security Analyst

Aviso WealthToronto,Ontario,Canada, Remote Hybrid

Aviso Wealth is hiring a Remote Security Analyst

Aviso Wealth:

At Aviso, we are dedicated to improving the financial well-being of Canadians. As a leading wealth management organization, we are committed to leadership, innovation, partnership, responsibility, and community. Working with talented and energetic professionals who exemplify our values every day, you will quickly notice that our people and dynamic ‘oneaviso’ culture sets us apart. If you are looking for interesting and challenging work, at a company committed to its people, find out more about what Aviso has to offer at www.aviso.ca.

The Opportunity:

We’re looking for an experienced Security Analyst to join our growing cybersecurity team.

Reporting to the Director of Cyber Security, the Security Analyst is responsible for identifying, mitigating, and resolving security threats across Aviso's IT and Cloud infrastructure while continuously improving Aviso's security posture.

Who you are:

  • Service – You consider both internal and external stakeholders and demonstrate intent of understanding and putting the clients’ needs first. You advocate service excellence and work to deliver solutions that meet the needs. You proactively develop strategic partnerships that allow Aviso Wealth to become a trusted advisor and partner
  • Execution – You are committed to achieving your goals and to succeed. This includes focusing on “getting things done”, as well as recognizing and taking advantage of opportunities as they arise. You are consistently looking for ways to improve your personal best and see value in continuous improvement. You take accountability for your actions and learn from mistakes
  • Collaboration – You work collaboratively with others with the common goal of driving positive results. Making meaningful contributions to your team to achieve organizational goals is a priority. You proactively encourage collaboration, build trust and inclusion, and work to establish effective relationships both inside and outside of the organization

What your day looks like:

  • Conduct daily security investigations, monitor network activities, and analyze logs to detect potential threats or breaches
  • Proactively identify and respond to security threats across the IT and Cloud environments
  • Implement and enhance security controls to protect Aviso's network against the evolving threat landscape
  • Deploy, maintain, and enhance new security solutions and technologies, including SIEM, SOAR, and XDR solutions
  • Participate in security projects and collaborate with stakeholders to ensure the solutions align with security standards and business objectives
  • Propose changes and improvements to existing policies and procedures to ensure operating efficiency and regulatory compliance

Your experience and skills:

  • Bachelor's degree in Cybersecurity or a related field is required; a Master’s degree is preferred
  • Minimum of 10 years of experience in Security Operations (SOC) teams or equivalent roles
  • Proven experience in Incident Response, Threat Management, Cloud Security, and Attack Surface Management
  • Practical experience in deploying and managing SIEM, XDR/EDR, SOAR, and other advanced security solutions
  • Proven experience in SIEM technologies such as Sumo Logic, Splunk, Microsoft Sentinel, or similar products
  • Practical experience implementing security controls and enhancing capabilities based on leading security frameworks, such as MITRE ATT&CK, NIST CSF, OWASP, or ISO:27001
  • Experience building new SIEM threat use cases and alerts mapped to the MITRE ATT&CK framework
  • Experience developing tactical playbooks covering various attack vectors
  • Experience conducting security investigations within Microsoft 365 (M365), Defender, or similar security platforms, including analyzing alerts, logs, and events to identify and mitigate potential threats
  • Experience in managing endpoint protection (EDR) solutions, developing new policies, and ensuring optimal agent coverage
  • Practical experience in building automation solutions to support Security Operations (SOC) functions
  • Certifications in Cloud Security on platforms such as Microsoft Azure, Amazon AWS, or Google GCP
  • Proven experience in Cloud and Cloud Security technologies such as Microsoft Azure, Amazon AWS, or Google GCP
  • Experience with behavior analytics and AI tools
  • Experience leading attack simulation (purple teaming) engagements to improve threat detection capabilities
  • Ability to work in a fast-paced environment and stay updated on emerging threats and vulnerabilities
  • Natural curiosity, a willingness to learn, adaptability in an evolving environment, and a strong problem-solving mindset
  • Fluent communication skills in English are required and bilingual skills in French are an asset

Why Aviso Wealth?

At Aviso Wealth, you will find a dynamic and inclusive culture that rewards innovation and celebrates success.
Here are a few things that set us apart:

  • Competitive compensation package that rewards and recognizes individual contributions
  • Excellent health, dental and insurance benefits to meet the diverse needs of our employees
  • Generous vacation time, fitness benefit, parental leave top-up options
  • Matching contributions to our retirement program
  • Commitment to the continuous improvement of our staff through learning & development and an education assistance program
  • Regular social events to foster teamwork

Equal Employment Opportunity

Aviso Wealth welcomes and encourages applications from all qualified individuals including persons with disabilities. If you require an accommodation, we will work with you to meet your needs in all stages of the hiring process.

We thank all applicants for their interest, however, only those selected for further consideration will be contacted.

No recruiters or agencies, please.

Company Overview:

Aviso is a leading wealth management and investment services provider for the Canadian financial industry, with over $130 billion in total assets under administration and management, and over 1,000 employees. We’re building a comprehensive, technology-enabled, client-centric wealth services ecosystem. Our clients include our partners, advisors, and investors. We’re a trusted partner for nearly all credit unions across Canada, in addition to a wide range of portfolio managers, investment dealers, insurance and trust companies, and introducing brokers. Our partners depend on Aviso for specific solutions that give them a competitive edge in a rapidly evolving, highly competitive industry. Our investment dealer and mutual fund dealer and our insurance services support thousands of investment advisors. Our asset manager, NEI Investments, specializes in investing responsibly. Our online brokerage, Qtrade Direct Investing®, empowers self-directed investors, and our fully automated investing service, Qtrade Guided Portfolios®, serves investors who prefer a hands-off approach. Aviso Correspondent Partners provides custodial and carrying broker services to a wide range of firms. We have offices in Toronto, Vancouver, Montreal, and Winnipeg. Aviso is backed by the collective strength of our owners: the credit union Centrals, Co-operators/CUMIS, and Desjardins. We’re proud to power businesses that empower investors.

A career with Aviso means being part of a group of talented, energetic professionals who live their values every day, and belonging to an organization dedicated to your success and career development. If you’re looking for interesting and challenging work, at a company committed to its people, apply to join our team.

Salary

This position is posted with an expected salary range of $109,000 - $123,000 CAD annually. Individual compensation packages are based on various factors unique to each candidate and the requirements of the position.

See more jobs at Aviso Wealth

Apply for this job

8d

Chief Information Security Officer

DataVisorMountain View,California,United States, Remote Hybrid

DataVisor is hiring a Remote Chief Information Security Officer

DataVisor is the world’s leading AI-powered Fraud and Risk Platform that delivers the best overall detection coverage in industry. With an open SaaS platform that supports easy consolidation and enrichment of any data, DataVisor's solution scales infinitely and enables organizations to act on fast-evolving fraud and money laundering activities in real time. Its patented unsupervised machine learning technology, advanced device intelligence, powerful decision engine and investigation tools work together to provide guaranteed performance lift from day one. DataVisor's platform is architected to support multiple use cases across different business units flexibly, dramatically lowering total cost of ownership, compared to legacy point solutions. DataVisor is recognized as an industry leader and has been adopted by many Fortune 500 companies across the globe.

Our award-winning software platform is powered by a team of world-class experts in big data, machine learning, security, and scalable infrastructure. Our culture is open, positive, collaborative, and results driven. Come join us!

Job Summary

As the Chief Information Security Officer (CISO), you will be responsible for developing and implementing a robust security strategy to protect customer data, DataVisor Services and systems. You’ll work closely with executive leadership to ensure security initiatives align with our business objectives. This critical leadership role requires a forward-thinking leader, with strong communication skills, and well-versed in the latest cybersecurity threats, trends, and technologies. 

Key Responsibilities

  • Strategic Security Leadership: Develop and implement a comprehensive information security strategy to protect sensitive data and systems.
  • Risk Management: Identify, assess, and mitigate cybersecurity risks across all areas of the business and services. 
  • Compliance and Governance: Ensure compliance with applicable laws, regulations, and industry standards (e.g., SOC 2, PCIDSS, ISO 27001, etc.. ).
  • Incident Response: Establish and lead the incident response team, coordinating efforts during security incidents or breaches.
  • Security Policies and Procedures: Develop, implement, and regularly update security policies and best practices across the organization.
  • Budgeting and Resource Allocation: Oversee the cybersecurity budget and resource allocation to ensure effective risk mitigation within budget constraints.
  • Vendor Management: Assess and manage security aspects of third-party vendors and partners.
  • Collaboration: Work closely with eng, Legal, Risk Management, and other departments to align security initiatives with business objectives.
  • Customer communications: Communicate with customers regarding our security policies and strategies, and facilitate business teams in completing customer’s security questionnaires and relevant due diligence requirements.  Collaborate with customers on pentest and audit requirements wherever applicable. 
  • Awareness and Training: Lead initiatives to educate and train employees on security best practices and awareness.
  • Continuous Improvement: Stay up-to-date with the latest security technologies, threats, and trends, incorporating them into the security strategy as needed.
  • Experience: 10+ years of experience in information security, with at least 5 years in a senior leadership role. Engineering background and site reliability experience are a plus. 
  • Education: Bachelor’s degree in Computer Science, Information Security, or related field (Master’s degree preferred).
  • Certifications: CISSP, CISM, CISA, or other relevant certifications strongly preferred.
  • Technical Expertise: Strong knowledge of cybersecurity frameworks (e.g., NIST, ISO/IEC 27001) and security operations (SIEM, firewalls, IDS/IPS).
  • Leadership Skills: Proven ability to hire, lead, influence, and inspire cross-functional teams and manage change effectively.
  • Communication and Collaboration Skills: Strong communication skills to translate complex security concepts into business-friendly language.  Ability to collaborate with different internal and external teams effectively and smoothly. 
  • Analytical Skills: Strong analytical and problem-solving skills to assess and address cybersecurity challenges.
  • Strategic Vision: Ability to align security initiatives with business goals and adapt strategies to changing threat landscapes.

Preferred Qualifications

  • Prior experience as a CISO or similar executive role in a high-growth or technology-driven organization.
  • Knowledge of cloud security, especially with AWS, Azure, or Google Cloud environments
  • Experience in implementing zero-trust architectures and leading security transformation programs.
  • Experience in all aspects of security: compliance, application level security, vulnerability testing, and detection and response. 
  • Experience working with banking sectors, regulatory bodies or in highly regulated environments.
    • Top executive level position with competitive salary, stock options,  and benefits package.
    • Opportunity to build a secure and robust next-gen fraud and risk services for the largest transaction players in the world. 
    • A collaborative work environment with an emphasis on innovation and security.

See more jobs at DataVisor

Apply for this job

Talent Acquisition Concepts is hiring a Remote Cybersecurity Engineer

Looking for challenging and rewarding work alongside some the best in the business? Energized by finding new solutions and technologies that benefit your clients, improve efficiency, and make buildings and the environment better? Eager to work in a setting where you can make a difference, be involved from strategy through implementation, and can see your ideas come to life? Do you thrive in an environment where initiative is rewarded with opportunity? If your answer to these questions was a “Yes” then our client may be the right fit for you.

And a few more things -- are you flexible in your work schedule and work location? Our work allows for some work from home, but it also requires us to be hands-on for our clients when and where they need us. Are you up for a little adventure? Our client performs work in some interesting places well worth visiting, and you might want in on that.

The Work:

The Cybersecurity Engineer is a Subject Matter Expert in applying the Risk Management Framework (RMF) and will be responsible for managerial direction and development of one or more projects under the supervision of the Cybersecurity Program Manager. The Project Manager will manage and interface with key clients and cultivate effective relationships with existing and potential stakeholders and partners to develop business, prepare proposals, negotiate contracts, and oversee the successful delivery of projects. This position works collaboratively with the Program Manager and other team members to support network discovery, developing hardware/software lists, and developing network diagrams. As part of a multi-disciplinary team the Project Manager will advise, implement, and manage cybersecurity and control system solutions for SCADA, HVAC, Fire Alarm/Life Safety Systems, and Electronic Security Systems and ensure projects are aligned, and closely with leadership in the successful growth and management of the program, ensuring that financial goals and objectives are maximized.

  • Oversee the application of the RMF to client systems
  • Provide project capabilities in design, network system documentation, and identification of FRCS and IT components
  • Lead and perform logical scans to locate FRCS components and assess network architecture and connectivity
  • Lead the completion of detailed network diagrams and network dataflow diagrams
  • Implement risk management programs for our federal clients
  • Enhance cyber awareness with clients and project teams
  • Work alongside federal clients to help them mitigate risk with the use of continuous monitoring and incident response
  • Establish security controls to ensure the protection of client systems
  • Implement cutting edge security tools for our federal clients
  • Create, implement, and maintain project plans for on-going and new initiatives
  • Document meetings minutes and action items and disseminate to meeting participants
  • Monitor status of action items through effective tracking tools and communication of progress and assist with closing of action items
  • Create, draft, and review project documentation

Here's What You Need:

  • 7+ years of experience performing network discovery, developing hardware/software lists, and developing network diagrams.
  • Strong leadership skills with experience managing teams
  • In-depth experience implementing the Risk Management framework
  • IT/OT network design experience
  • Experience designing and configuring servers, switches, workstations.
  • Experience designing and programming control system devices.
  • Experience working with RMF and NIST 800-53
  • Experience working with UFGS 25 05 11
  • Experience working with cyber security tools
  • Bachelor’s Degree in computer science, cybersecurity, or related engineering field or equivalent combination of training and experience
  • AT Level II Certification Required (CCNA-Security, GICSP, GSEC, Security+ CE, or SSCP certification), AT Level III Certification Preferred (CISSP)
  • Certifications in Cisco, Juniper, Moxa, and/or other Network Switches Preferred
  • Certifications in MS Windows Server, Active Directory, Enterprise OS Preferred
  • Certifications in Linux Operating Systems Preferred
  • Project Management Professional (PMP) Preferred
  • Registered Communications Distribution Designer (RCDD) Preferred

Equal Employment Opportunity Statement

Talent Acquisition Concepts is an Equal Opportunity Employer. We do not discriminate against anyone because of their differences, such as age, disability, ethnicity, gender, gender identity and expression, religion, or sexual orientation.

Talent Acquisition Concepts is committed to providing veteran employment opportunities to our service men and women.

Other Employment Statements

Applicants for employment must be US citizens and be able to pass security screens, up to Top Secret level, due to the nature of who we work for.

Applicants must be able to work a full day on a project site, combined sitting, standing, walking, and in front of the monitor. We can guarantee you won’t be bored!

Applicants must be able to stand, climb ladders, stairs, and get to wherever the problem is so you can see it for yourself.

See more jobs at Talent Acquisition Concepts

Apply for this job

9d

Cyber Security Engineer - Vulnerability Management

TestProsRemote (with some travel to Norfolk VA Area), VA
Mid LevelFull Timeswiftqarubyc++

TestPros is hiring a Remote Cyber Security Engineer - Vulnerability Management

Cyber Security Engineer - Vulnerability Management - TestPros - Career Page

See more jobs at TestPros

Apply for this job

Snapsheet is hiring a Remote Senior Security Engineer

Senior Security Engineer - Snapsheet - Career PageResponsibilities as the Senior Security Engineer:

See more jobs at Snapsheet

Apply for this job

In All Media Inc is hiring a Remote Cyber Security Engineer

The candidate must be proficient in:

  • Understanding and background with Intrusion Detection Systems and SIEM products.
  • Background in Incident Response.
  • Understanding and background with Firewalls and Networking.
  • Background in multiple Operating Systems and Cloud Environments. Linux, Windows, AWS, Azure.
  • Excellent written and verbal communication skills in English.

Key Responsibilities

  • Conduct or coordinate vulnerability scans, and penetration tests on systems, document findings, and recommend risk mitigation strategies.
  • Operate, administer and monitor network and host-based intrusion detection/prevention systems.
  • Assist other technical support staff in identifying and implementing appropriate security safeguards, including patch application and anti-malware strategies.
  • Analyze network traffic, intrusion attempts, activity logs, and system alerts for trends, anomalies, and potential security breaches.
  • Develop scripts, tools, and procedures to automate scans, assessments, and other monitoring and discovery activities.
  • Perform other duties as assigned.

See more jobs at In All Media Inc

Apply for this job

Databricks is hiring a Remote Senior Security Engineer (Incident Response)

Job Application for Senior Security Engineer (Incident Response) at Databricks

See more jobs at Databricks

Apply for this job

14d

Senior Security Engineer

NuveiTel Aviv-Yafo,Tel Aviv District,Israel, Remote Hybrid
terraformDesignazuredockerkuberneteslinuxpythonAWS

Nuvei is hiring a Remote Senior Security Engineer

The world of payment processing is rapidly evolving, and businesses are looking for loyal and strategic partners, to help them grow.  

WE ARE NUVEI. Nuvei (NASDAQ: NVEI) (TSX: NVEI) is a Canadian fintech company accelerating the business of clients around the world. Nuvei’s modular, flexible, and scalable technology allows leading companies to accept next-gen payments, offer all payout options, and benefit from card issuing, banking, risk, and fraud management services. Connecting businesses to their customers in more than 200 markets, with local acquiring in 47 markets, 150 currencies, and 586 alternative payment methods, Nuvei provides the technology and insights for customers and partners to succeed locally and globally with one integration.  

At Nuvei, we live our core values, and we thrive on solving complex problems. We’re dedicated to continually improving our product and providing relentless customer service. We are always looking for exceptional talent to join us on the journey!  

We are seeking a highly skilled and motivated Senior Security Engineer to join our dynamic Technical Security Operations team. In this role, you will be responsible for designing, implementing, and maintaining robust security systems across a variety of platforms, protecting the company’s digital assets, and continuously evolving our security posture. You will collaborate closely with the CISO and other key stakeholders to ensure that security is deeply integrated into all aspects of the company’s infrastructure and operations. You will be reporting to the Technical Security Operations team leader. 

Key Responsibilities: 

  • Lead the implementation, configuration, and ongoing maintenance of a variety of advanced security technologies, including but not limited to EDR, Proxy, DLP, email protection, and other critical security solutions. 
  • Collaborate with the CISO and security leadership to align security strategies with business objectives, ensuring security requirements are properly designed and executed across the company’s infrastructure. 
  • Continuously monitor and analyze security systems, firewalls, logs, and relevant data sources to detect, analyze, and respond to potential security threats in real time. 
  • Regularly assess and refine the security architecture to ensure it meets current and emerging threats while aligning with best practices. 
  • Conduct thorough market research and spearhead proof of concept (POC) evaluations for new security tools, identifying opportunities to improve the organization’s overall security posture. 
  • Identify and assess emerging security threats through continuous monitoring, vulnerability assessments, and log analysis, proactively addressing risks before they materialize. 
  • Enhance internal security controls, including identity and access management (IAM), key management, security monitoring, and cloud security posture management (CSPM). 
  • Ensure security best practices and policies are adhered to across all systems and services. 

Required Qualifications: 

  • 5+ years of hands-on experience in security engineering, with deep expertise in multiple IT security domains. 

Proven expertise in the following areas: 

  • Data Loss Prevention (DLP) 
  • Endpoint Protection (EDR/XDR) 
  • Proxy Solutions (Forcepoint, Netskope) 
  • Identity Providers (Okta, Entra ID) 
  • Email Protection 
  • SIEM  
  • Threat Intelligence and Vulnerability Management 
  • Network Security (firewalls, VPNs, WAF, NAC) 
  • Directory Services (Active Directory, Azure AD) 
  • Sandbox Solutions 
  • Vulnerability Assessment Solutions (VAS) 
  • Cloud Security Posture Management (CSPM) 
  • Data Security Posture Management (DSPM) 
  • Static Application Security Testing (SAST) 
  • Dynamic Application Security Testing (DAST) 
  • Strong experience securing Windows, Linux, and macOS environments, with a comprehensive understanding of system security controls. 
  • Demonstrated expertise in both on-premises and cloud architecture security, with experience securing public cloud platforms (AWS, GCP, Azure). 
  • Advanced knowledge of network security, protocols, and the ability to secure complex network environments. 
  • Familiarity with host-based forensics, OS artifacts, and exploitation methods, with the ability to respond to security incidents effectively. 
  • Hands-on experience with scripting languages such as Bash, Python, or PowerShell, along with proficiency in infrastructure-as-code tools (Terraform, CloudFormation). 
  • Familiarity with compliance frameworks and certification programs (PCI-DSS, SOC II, ISO27001), with the ability to manage security audits and maintain compliance. 
  • Proven ability to lead cross-functional security initiatives, driving collaboration and widespread adoption of security best practices across teams. 
  • Passionate about staying ahead of the curve in cybersecurity trends, emerging threats, and security technologies. 

Preferred Qualifications: 

  • Experience with security design, threat modeling, and conducting security audits. 
  • Familiarity with containerization and cloud-native technologies (Kubernetes, Docker). 
  • Strong analytical and problem-solving skills, with attention to detail and a proactive approach to addressing complex security challenges
  • SOAR solutions. 

See more jobs at Nuvei

Apply for this job

Development InfoStructure is hiring a Remote Facility Security Officer

Facility Security Officer - Development InfoStructure - Career PageSee more jobs at Development InfoStructure

Apply for this job

Vectra is hiring a Remote Sr Security Analyst (US Remote)

Vectra® is the leader in AI-driven threat detection and response for hybrid and multi-cloud enterprises.

The Vectra AI Platform delivers integrated signal across public cloud, SaaS, identity, and data center networks in a single platform. Powered by patented Attack Signal Intelligence, it empowers security teams to rapidly prioritize, investigate and respond to the most advanced cyber-attacks. With 35 patents in AI-driven threat detection and the most vendor references in MITRE D3FEND, organizations worldwide rely on the Vectra AI to move at the speed and scale of hybrid attackers. For more information, visit www.vectra.ai. 

*Location: US-Remote (CONUS)

This position works on a 4x10, 2nd or 3rd shift

Position Overview

Vectra is seeking a highly skilled and experienced MDR (Managed Detection and Response) Security Analyst to join our team. As aSr Security Analyst, you will serve in a critical role in protecting and defending Vectra MDR customer infrastructure. You will be responsible for supervising and analyzing security events, responding to incidents, conducting SOC (Security Operations Center) operations, and assisting MDR customers to ensure their needs are met.

A successful candidate will have sound technical experience and skills, blended with good interpersonal, communication, and project management skills.

Responsibilities 

  • Monitor security logs and alerts from various sources, including intrusion detection systems, Endpoint Detection and Response (EDR) systems, and security information and event management (SIEM) tools. 
  • Investigate and analyze security incidents, identify root cause, and develop appropriate mitigation strategies.
  • Complete security response actions, including full remote remediation of endpoints.
  • Perform threat hunting and proactive analysis to identify potential security risks and vulnerabilities.
  • Collaborate with multi-functional teams, including product, engineering, and support, to resolve customer incidents or issues.
  • Mentor and provide guidance to junior security analysts, sharing knowledge and standard processes.
  • Conduct health checks and architecture reviews, providing technical expertise and real-life experience in creating solutions, designs, and recommendations.
  • Be a strong voice for your customers across business to identify new detection models, identify new product features, build content for both internal and external customer knowledge bases, and ensure successful Vectra deployments.
  • Travel expected 0-5%

Requirements

  • Demonstrable experience as an MDR security analyst, SOC analyst, or similar role in a fast-paced environment.
  • Experience providing remote response and remediation activities within networks and on endpoints.
  • Solid understanding of intrusion detection systems, artificial intelligence-based attack detection and prevention, incident response methodologies, and SOC operations.
  • Experience with SIEM tools, log analysis, network analysis, endpoint analysis, and threat intelligence platforms.
  • Solid knowledge of operating systems, networking protocols, and security technologies.
  • Proficient in incident handling, threat hunting, and forensics.
  • Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
  • Good communication skills to effectively collaborate with multi-functional teams and communicate complex security issues to non-technical stakeholders.
  • Continuous learning attitude to stay updated with the evolving threat landscape and emerging security technologies.

Desirable

  • Prior experience with Vectra, SentinelOne, Microsoft Defender, or CrowdStrike
  • Coding experience in Bash, Python, or Powershell
  • Open-source development
Our competitive total rewards package includes cash compensation within the range provided below. Actual pay for this position may vary based on the hired candidate’s location, experience and relevant incumbent pay position.  
Vectra Total Rewards
$140,000$180,000 USD

Vectraprovides a comprehensive total rewards packagethatsupportsthefinancial,physical, mental and overall health ofour employeesand their families.Compensation includes competitive base pay, incentive plan eligibility, and participation in the employee equity plan (stock options).Specific benefitsofferedvariesby location, but commonly includehealth care insurance,income protection/ life insurance,access to retirementsavingsplans, behavioral &emotionalwellnessservices, generous time away from work,anda comprehensive employee recognition program.

Vectra is committed to creating a diverse environment and is proud to be an equal opportunity employer. 

We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status. 

 

See more jobs at Vectra

Apply for this job

27d

Security Analyst II

ProArchBengaluru,Karnataka,India, Remote

ProArch is hiring a Remote Security Analyst II

ProArch is a global IT consulting firm providing Security, Data, Application Dev, and Cloud services. Offices are located in the US, UK and India.

 

As a Security Analyst II (SOC), you will be responsible for monitoring, detecting, and responding to security incidents while utilizing your expertise in M365 security technologies and Microsoft Sentinel to optimize detection and response capabilities. This role is highly technical. You will play a critical role in improving our security operations by creating and refining use cases and detection rules to safeguard our organization and clients from cyber threats. You will also be responsible for all the technical escalations from the junior SOC Analysts. You will have the Shift Lead responsibilities to ensure that the SOC Monitoring and Response is done with quality adhering to the defined SLAs and overlooking at the operations during your shift. Another goal would be to identify improvements and gaps within the SOC operations, creating standard operating procedures, creating workflows for playbooks that can be used by the SOC to respond to security incidents.

 

Communication skills are essential as this position will be the technical escalation point for the SOC Team. Security Analyst II (SOC) should be able to act proactively to ensure smooth security operations and effective collaboration during the shift. This position should lead by setting a good example and engaging the team to achieve the organizational goals set forth by the Leadership Team for the Security Teams. A key outcome of this position is to continuously improve the efficiency and quality of the security operations center.

  • Act as an escalation point for Tier 1 analysts, handling more complex security incidents and alerts.
  • Investigate, triage, and respond to security incidents detected through the SOAR / SIEM and other security monitoring tools.
  • Perform in-depth analysis of incidents and recommend containment and remediation actions.
  • Lead containment and remediation efforts for security incidents.
  • Develop, test, and fine-tune detection rules and use cases based on log sources, threat intelligence, attack patterns, and client requirements.
  • Identify emerging threats and incorporate them into use-cases for alerts and detections.
  • Optimize and refine alert thresholds and logic to minimize false positives and enhance detection accuracy.
  • Leverage expertise in Microsoft 365 Defender/Defender XDR, Microsoft Defender for Endpoint, Defender for Office 365 and Entra ID Protection to improve overall threat detection and response.
  • Conduct proactive threat hunting to identify unknown threats across endpoints, identities, and network traffic using available tools and log sources.
  • Analyze security logs and telemetry data for signs of compromise, anomalous activities, or malicious behavior.
  • Perform root-cause analysis for security incidents and provide actionable insights to improve security posture.
  • Prioritize the work effectively and handle shifting priorities professionally.
  • Work closely with cross-functional teams (IT, Cloud Operations, Application Development) to mitigate security risks and improve incident response capabilities.
  • Create detailed reports and post-incident analysis to communicate findings and recommendations to technical and non-technical stakeholders.
  • Contribute to continuous improvement of SOC processes, including SOPs, playbooks, runbooks, and escalation procedures.
  • Stay updated with the latest threat landscape, vulnerabilities, and attack methods.
  • Share knowledge and insights with other SOC analysts and participate in team knowledge-sharing sessions.
  • Participate in red/blue team exercises to test and improve detection and response capabilities.

TECHNICAL SKILLS:

Candidate should have a minimum of 4 years of experience in IT Security with additional background in Security Operations Center. To be successful, this position will require the candidate to have expertise in the following areas:

  • Strong knowledge of Microsoft Sentinel KQL (Kusto Query Language) for custom queries and rule creation.
  • Familiarity with Security Information and Event Management (SIEM) systems, particularly Microsoft Sentinel.
  • Familiarity of how SOAR (Security Orchestration and Automated Response) works and ability to provide workflows which can be used for automating SOC responses.
  • Experience with endpoint security, identity protection, and network security monitoring.
  • Perform forensic analysis to understand the scope and impact of incidents.
  • Incident Handling, take technical investigation ownership of incidents and coordinate response efforts.
  • Advanced Analysis, perform advanced and complex analysis of sophisticated threats.
  • Knowledge of security frameworks such as MITRE ATT&CK and CIS controls.
  • Industry knowledge and experience in Managed Detection and Response (MDR) technologies.
  • Experience working in a Managed Security Operations or Security Team
  • Knowledge of ITIL Foundation Framework.
  • Microsoft Security and Compliance including:
  1. Microsoft Purview, IRM, DLP, Insider Risk
  2. Defender for Endpoint
  3. Defender for Office 365
  4. Defender for Identity
  5. Defender for Cloud Apps
  6. Defender for Cloud
  7. Defender XDR
  8. Defender for IoT
  9. Entra ID Identity Protection
  10. Entra ID & Intune
  11. Microsoft Sentinel
  • Experience of CrowdStrike EDR and/or IDP is highly desirable.
  • Knowledge / Experience handling OT Security alerts is desirable.
  • Vulnerability Management tools including Qualys and Nucleus.
  • Security Awareness Training using tools such as KnowBe4.
  • Incident Response Management and Reporting.
  • Desirable to have knowledge of Compliance Frameworks including:
  1. NIST
  2. CMMC
  3. HIPAA
  4. NERC / CIP
  5. PCI
  6. Privacy such as GDPR and SHIELD

REQUIREMENTS:

This position requires that the applicant be a professional leader. ProArch is looking for a candidate who can fulfill the following:

  • Outstanding Written, Verbal, Technical, Non-Technical, communication & presentation skills.
  • Self-directed with the ability to prioritize and handle SOC Operations and Alert inflow.
  • Experience in mentoring and guiding a highly technical team.
  • Eager learner continually improving skill sets, earning certifications, and gaining industry knowledge.
  • Skilled in leading a conversation with client to drive an incident investigation and response.
  • Exceptional analytical skills
  • Outstanding written communication and verbal skills
  • 95% of our clients are from Northern USA. A good command over English language is a must.

 

EDUCATION AND CERTIFICATION:

  • Bachelor’s degree in computer science/engineering/IT/Computer Applications or significant demonstrable experience in IT Security / IT.
  • Must have any of these Microsoft Certifications: SC-200, SC-900, AZ-500, SC-300, SC-400.
  • Certifications such as CEH, CISSP, CompTIA CySA+, or others.

See more jobs at ProArch

Apply for this job

Convergint Federal Solutions is hiring a Remote Security System Engineer II

Job Description

As a Security Systems Engineer II at Convergint Federal | SigNet Technologies, you will be an integral part of our team, responsible for designing, implementing, and supporting advanced security systems for our government and federal clients. The Security Systems Engineer II will play a pivotal role in delivering innovative security solutions, ensuring they meet the highest industry standards, and addressing the unique security challenges faced by our clients.

Value and Beliefs of this Role:
The person in this role must provide world-class service to customers, colleagues, and
communities. It requires a person of integrity, self-accountability, commitment to communicate openly and consistently, delivering results and having fun with laughter daily. In this role we want you to grow with us and deliver results as an exceptional Security Systems Engineer II. This job requires a person who remains professional, organized, collaborative, detail, and task oriented, timely, and creative at problem solving.

Key Responsibilities:

System Design:

  • Collaborate with clients and project teams to design, develop, and implement security systems, including access control, video surveillance, intrusion detection, and perimeter security.

Technology Integration:

  • Integrate a wide range of security technologies and systems to create comprehensive and effective security solutions.

Project Management:

  •  Manage the entire project lifecycle, from design and implementation to commissioning and handover, ensuring projects are completed on time and within budget.

Technical Expertise:

  • Provide technical support and expertise throughout all project phases, including troubleshooting and resolving technical issues.

Compliance:

  •  Ensure that all security system designs and implementations comply with relevant codes, regulations, and industry standards.

Documentation:

  • Generate detailed technical documentation, including system drawings, installation guides, and equipment lists.

Client Interaction:

  •  Build strong client relationships by providing expert guidance, project updates, and addressing client concerns.

Other Duties: Other duties assigned within reason of current role previously specified.

Qualifications

  • Bachelor of Science degree Engineering, Computer Science or related field
  • 3 to 5 years of experience in Computer Science or related field
  •  Ability to mentor SSE I
  •  3 to 5 years of experience working with,
    •  Access Control Systems; Video Management Systems; Intrusion Detection (Perimeter and Interior)
    •  Strong knowledge of security technologies, including access control, video surveillance, and intrusion detection systems.
    •  Infrastructure (Interior and Exterior Cabling, Fiber, Network, Wireless)
    •  Reviewing RFPs, technical specifications, and the production of cost estimate and proposals.
    • Providing cost estimates and change orders.
    • Interacting with internal and external customers to interpret technical requirements and provide guidance to shape solutions.
    • Producing a variety of written documents such as pre or post-bid engineering survey reports; read, interpret, and review electrical, electronic, and electromechanical schematics
    • Proficiency in project management and system integration.
    • Reviewing and assess CAD drawings produced by in-hours CAD team;
  • Excellent problem-solving and troubleshooting skills.
  • Strong communication and interpersonal skills.
  • Knowledge of government security regulations and clearances is a plus.

Requirements

  • Active Driver’s License
  • United States Citizenship
  • The job may require lifting objects weighing between 25 to 50 pounds. Accommodations can be provided upon request to enable individuals with disabilities to perform the essential functions.
  •  Security Clearances: This position requires a  Secret security clearance. The clearance requirements are determined by the agency(s) in which you are assigned. Convergint Federal will sponsor the level of clearance required. However, it will be your responsibility to obtain and maintain your required level of clearance.

See more jobs at Convergint Federal Solutions

Apply for this job

Arduino is hiring a Remote Sr. Cloud Security Engineer

Arduino’s mission is to enable people to enhance their lives through accessible open-source electronics and digital technologies. Since 2005 millions of people from around the world starting from young kids to university students and on to people involved in every imaginable profession have been using Arduino to innovate in the fields of music, games and toys, smart homes, farming, autonomous vehicles and many more.

We are now looking for a Sr Cloud Security Engineer to join our team of expert professionals eager to share their knowledge and be part of this vibrant company’s journey towards the democratization of technology. You will be responsible for ensuring the security of Arduino Software and Cloud platforms and also for fostering awareness inside the company about security best practices.

Arduino is a technology-driven company, and you will have the opportunity to join a passionate and collaborative team, within a multinational and driven organization.

What We Offer

  • A challenging career path in a rapidly growing company with a modern vision and talented teams.
  • A competitive salary (and benefits) that values people's skills and experience.
  • A young and inspiring work environment that encourages diversity and cultural exchange.
  • Individual growth objectives with a dedicated budget for learning/training.
  • Flexible working hours and working locations, we value work-life balance!
  • A meaningful work opportunity in a mission-driven company committed to empowering people around the world.

And if you live near one of our offices…

  • Ping pong and football tournaments (sport or gym benefit is also included for everyone!).
  • Seasonal celebrations, happy hours, and everyday drinks and snacks at the office.
  • Sunny rooftop lunch breaks and hamacas for relaxation and concentration.

What you'll work on

  • Make sure that the data we are trusted to protect is secured to the highest standards;
  • Guiding the Development and DevOps teams on Security Best Practices;
  • Provide security guidance on a constant stream of new projects and technologies;
  • Provide subject matter expertise on architecture, authentication and system security
    • Design, implement, and manage security solutions for AWS environment through IaC technologies;
    • Implement and manage standard AWS security tools including but not limited to AWS Security Hub, AWS GuardDuty, Inspector, CloudTrail, WAF, KMS, Config, IAM Access Analyzer.
  • Building secure CI/CD pipelines adopting DevSecOps principles for our applications (Harness Drone, Jenkins, GitHub Actions);
  • Developing internal tooling and systems that help daily work of our Development and DevOps teams, on top of Cloud services, Kubernetes, Terraform;
  • Build internal tools for detecting and responding to security problems and incidents
    • Monitor cloud environments for security incidents and anomalies, and respond to suspected incidents in a timely manner;
    • Collaborate with Infrastructure and Application development teams to integrate security controls in the cloud using standardized configuration tools;
  • Make intelligent decisions around prioritization of efforts based on risk;
  • Ensure alignment and compliance with ISO 27001 and provide definition of Security policy for all the organization, including Training of company employees on security policy.

What you bring

  • Bachelor or Master Degree in Computer Science or related field, or equivalent experience;
  • 5+ years of experience in security engineering or comparable experience (DevOps, SRE);
  • Experience in Containerisation / Orchestration with Docker and Kubernetes;
  • Strong, well-rounded background in host, network, and cloud security;
  • Experience in designing and definition of secure cloud native systems;
  • Experience with applied cryptography including PKI, SSL, and key management;
  • Expertise with modern programming languages and software versioning tools (GIT/GitHub);
  • Knowledge of relevant security compliance, standards and regulations (e.g. ISO, NIST, GDPR, CIS);
  • Knowledge of internet security issues and the threat landscape (e.g. MITRE ATT&CK, CVEs, CWE);
  • Experience with security monitoring, incident detection and response to suspected incidents in a timely manner;
  • Experience with Vulnerability Management, Threat modeling, Risk Assessment and Risk Mitigation;
  • Good written and oral communication skills in English;
  • Ability to work with cross-functional teams (including developers, engineers, and IT) and to explain technical concept to non-technical audience (eg training to employees);
  • Skilled in problem-solving;
  • Analytical skills; result oriented and continuous learning approach.

Bonus Points

  • Previous experience working with Infrastructure and DevOps
  • Working experience with cloud providers like AWS or GCP
  • Working knowledge of Cloudflare, Auth0, Datadog
  • Experience with Arduino or other microcontrollers
  • Experience with hardware security
  • Experience with the Go programming language

If you're excited about this role or about our company but your experience doesn't align perfectly with the points outlined above, we strongly encourage you to apply anyways. Show us the boards you designed! If in any case we feel you don’t fit for this job we may have something else for you!

See more jobs at Arduino

Apply for this job

29d

Senior Application Security Engineer

LatticeSF, NYC, Remote
remote-firstDesignslackgraphqlrubyc++dockertypescriptkubernetespythonAWS

Lattice is hiring a Remote Senior Application Security Engineer

This is Engineering at Lattice

Lattice’s Engineering team is continuously working to better both our product and our craft. We use a modern, cutting-edge tech stack and love experimenting with new technologies. We strive for maintainable, robust, and performant code. We’re highly collaborative and continuously iterative and work closely with designers and product managers. We prioritize not only great technical architecture but also an amazing product experience.

Lattice is looking for someone to help our product developers build applications that our customers can use with confidence, knowing that at Lattice we work with strong security principles in mind. This role will work across a breadth of areas including application security, infrastructure security, and software supply chain. This role will involve both developing and managing tools, as well as acting as a consultant and partner for product developers. As such, it requires a balance of technical know-how and strong collaboration skills. Your days will vary, including: reviewing design proposals, writing design proposals, meeting with development teams to discuss their approaches and challenges, developing training materials, heads-down coding, and triaging bugs to understand their risks and remediations. You will also be involved in deciding how work is done and what tools and processes are appropriate.

What You Will Do

  • Mentor and advise product development teams in the area of application security
  • Assist teams in reproducing, triaging, and addressing application security vulnerabilities
  • Assist in the implementation of security processes and automated tooling that prevent classes of security issues
  • Design and implement Typescript code libraries and patterns to improve application security
  • Perform security-focused code reviews
  • Work with infrastructure teams to ensure our systems are secure
  • Support the bug bounty program
  • Evaluate tools, from SAST/DAST to cloud security analysis tooling, among others
  • Lead application security reviews and threat modeling, including code review and dynamic testing
  • Help develop security training and socialize the material with product development teams

What You Will Bring to the Table

Experience it’s important for you to have at some level:

  • Software development experience, ideally with Javascript/Typescript, or another programming language such as Python or Ruby
  • Familiarity with secure coding practices
  • Familiarity with security tools and libraries such as static/dynamic analysis tools and penetration testing tools
  • Familiarity with and ability to explain common security flaws and ways to address them (e.g. OWASP Top 10)
  • Strong understanding and experience with common security libraries, security controls, and common security flaws
  • Strong communication and collaboration skills

Experience that would be helpful:

  • Familiarity with AI/LLMs for enhancing code quality and automating security analysis.
  • Familiarity with containerization (Docker, containerd, etc) and Kubernetes
  • Experience developing and operating cloud systems in AWS
  • Experience with GraphQL


----

The estimated annual cash salary for this role is $166,000 - $207,500. This position is also eligible for incentive stock options, subject to the terms of Lattice’s applicable plans

Benefits: The Company offers the following benefits for this position, subject to applicable eligibility requirements: Medical insurance; Dental insurance; Vision insurance; Life, AD&D, and Disability Insurance; Emergency Weather Support; Wellness Apps; Paid Parental Leave, Paid Time off inclusive of holidays and sick time; Commuter & Parking Accounts; Lunches in the Office; Workplace Amenities Stipend, Internet and Phone Stipend; One time WFH Office Set-Up Stipend; 401(k) retirement plan; Financial Planning; Learning & Development Budget; Sabbatical Program; and Invest in Your People Fund

*Note on Pay Transparency:

Lattice provides an estimate of the compensation for roles that may be hired as required by state regulations. Compensation may vary based on (a) location, as Lattice factors in specific location when benchmarking compensation for most roles; (b) individual candidate skills and qualifications; and (c) individual candidate experience.

Additionally, Lattice leverages current market data to determine compensation, so posted compensation figures are subject to change as new market data becomes available. The salary, other compensation, and benefits information is accurate as of the date of this posting. Lattice reserves the right to modify this information at any time, subject to applicable law.

#LI-remote

About Lattice

Lattice is on a mission to build cultures where employees and their companies thrive. In an age where employees have more choices than ever before, businesses that put employees first are winning ????– and Lattice is building the tools to empower those people-centric companies.

Lattice is a people success platform that offers performance reviews, employee engagement surveys, real-time feedback, weekly check-ins, goal setting, and career planning in a way that allows companies to focus on employee development, growth, and engagement – yielding stronger employee retention, performance, and impact to the bottom line ????. Since launching in 2016, we have grown to over 5,000+ customers globally, including brands like Slack, Robinhood, and Gusto. 


Lattice is committed to equal treatment and opportunity in all aspects of recruitment, selection, and employment without regard to gender, race, religion, national origin, ethnicity, disability, gender identity/expression, sexual orientation, veteran or military status, or any other category protected under the law. Lattice is an equal opportunity employer; committed to a community of inclusion, and an environment free from discrimination, harassment, and retaliation.

By clicking the "Submit Application" button below, you consent to Lattice processing your personal information for the purpose of assessing your candidacy for this position in accordance withLattice's Job Applicant Privacy Policy.

Apply for this job

+30d

Cyber Security Engineer

Zone ITCanberra,Australian Capital Territory,Australia, Remote Hybrid

Zone IT is hiring a Remote Cyber Security Engineer

We are looking for a skilled Cyber Security Engineer. In this role, you will be instrumental in safeguarding our organization's IT infrastructure, ensuring the highest levels of security and compliance.

Responsibilities:

  • Design, implement, and maintain security systems and policies to safeguard data and infrastructure,
  • Conduct security assessments, audits, and vulnerability assessments to identify and mitigate risks,
  • Monitor security incidents and conduct forensic investigations as needed,
  • Develop and update incident response plans and security procedures,
  • Collaborate with IT teams to integrate security into systems and applications,
  • Stay current with the latest security trends, vulnerabilities, and technology solutions.

Requirements:

  • Bachelor's degree in Computer Science, Information Security, or a related field,
  • Proven experience as a Cyber Security Engineer or in a similar role,
  • Strong understanding of network security protocols and firewall systems,
  • Experience with security information and event management (SIEM) tools,
  • Relevant certifications (e.g. CISSP, CEH, CISM) are a plus,
  • Strong analytical and problem-solving skills.

About Us

Zone IT Solutions is Australia based Recruitment Company. We specialize in Digital, ERP and larger IT Services. We offer flexible, efficient and collaborative solutions to any organization that requires IT, experts. Our agile, agnostic and flexible solutions will help you source the IT Expertise you need. Our delivery Offices are in Melbourne, Sydney and India. If you are looking for new opportunities your profile at Careers@zoneitsolutions.com or contact us at 0434189909

Also follow our LinkedIn page for new job opportunities and more.

Zone IT Solutions is an equal opportunity employer and our recruitment process focuses on essential skills and abilities. We welcome applicants from a diverse range of backgrounds, including Aboriginal and Torres Strait Islander peoples, people from culturally and linguistically diverse (CALD) backgrounds and people with disabilities.

See more jobs at Zone IT

Apply for this job


Other Job subscriptions you might be insterested in