8,945 Database Security jobs in the United States
Database Security Specialist
Posted 3 days ago
Job Viewed
Job Description
Evolver Federal is looking for a Database Security Specialist to join our team supporting our government client.
The successful candidate will work with Database Administrators, ISSOs and System Teams to support the client in ensuring the security of its databases across the enterprise. By collaborating with other stakeholders (Federal and Contractor), the candidate will support the ISD Security Tools Team and System DBAs in establishing the initial configuration of database scans using TIO (Tenable Nessus). The candidate will also monitor successful application of security patching for all databases and troubleshoot where necessary, review database-related POA&Ms and provide input into POA&M milestones and associated remediation plans, review artifacts for POA&M closure relating to documented database weaknesses and advise on closure, assist the team in hardening databases throughout the enterprise, and assist DBAs in onboarding database logs to the organization's SIEM tool. The candidate must be a self-starter.
The client environment is diverse and currently contains Oracle, Postgres, SQL Server, and mySQL databases.
Responsibilities
- Review output of database scans using Tenable io (TIO), work with System DBAs to remediate findings, including vulnerabilities and hardening.
- Provide input and recommendations into approved security configuration baselines for database types including Oracle, Postgres, SQL Server, and mySQL.
- Provide input and recommendations into approved database versions based on database type.
- Work with members of the POA&M Management Support Team to review artifacts submitted as evidence of POA&M closure for database-related weaknesses.
- Review, validate, and track false positives and known deviations in scan results to provide assurance that IT systems meet established configuration baseline(s) for approved database types.
- Review documentation submitted in support of requesting a waiver for compliance with specified security requirements per the NIST SP 800-53 and provide recommendations to client for approval and acceptance of associated risk. Specific to security requirements relating to databases and the database layer of a system.
- Participate in process improvement initiatives to mature the client's internal business processes in areas including, but not limited to, vulnerability remediation, patch remediation efforts, STIG compliance, and approved database instances.
- Work with Database Administrators, ISSOs, and System Admin Teams to configure database assets to send the appropriate logging data to Splunk/ designated SIEM tool.
- Provide recommendations for database logging standards across the enterprise for each database type within the enterprise to facilitate establishing new and enhancing existing logging standards.
- Perform other duties as assigned by the Government.
- Ability to work efficiently and effectively in a dynamic and fast-paced environment.
- Determine the clearest and most logical way to present information and instructions for greatest reader comprehension and write and edit technical information accordingly.
- Meet with other Technical SMEs (Federal and Contractor) to ensure specialized topics are appropriately addressed, discussed, and understood.
Basic Qualifications
- Bachelor's Degree in Information Technology, Computer Science, or related field or 10 years of overall experience.
- Minimum of 5 years of experience as a Database Administrator for Oracle and/or Postg res databases in the federal government, including configuring databases to comply with Industry-Standard configuration baselines.
- Database certification such as Oracle Database Administrator Certified Professional, Certified PostgreSQL Database Administrator, or similar.
- 5 years of experience with Oracle and Postgres.
- 5 years of experience in troubleshooting complex issues involving database security settings and engaging in complex root causes analysis.
- 5 years of experience with cloud-based environments and cloud infrastructure.
- 3 years of experience using Tenable.io, specifically to review scan results, search, and create custom reports.
- 3 years of experience one or more of the following tools: tenable.io, Nexus IQ Server, Splunk Enterprise v 7.3 and higher, DoJ CSAM, JIRA/ Confluence, CloudCheckr, PrismaCloud
- General awareness of the NIST SP 800-37 Risk Management Framework.
- Must have previous client-engagement experience.
- Must be a US Citizen with suitable eligibility for Public Trust position.
Preferred Qualifications
- Experience with other database types including, but not limited to Postgres, SQL Server, or mySQL preferred, but not required.
- Previous experience supporting Department of Homeland Security federal clients preferred.
- Working knowledge of secure configuration guidelines for Oracle databases, specifically CIS Benchmarks.
- General awareness of the NIST SP 800-53, specifically as the controls apply to database security.
- Ability to work independently and possesses a solid understanding of database and cyber security concepts.
- Ability to communicate clearly and effectively via written and verbal communication in both formal and informal situations.
- Ability to clearly articulate database-related weaknesses for the purpose of documenting POA&M descriptions.
- Ability to clearly articulate remediation strategies and/or compensating controls specific to database weaknesses.
- Ability to clearly communicate complex technical concepts to Information Technology Project Managers, Database Administrators, Application Developers, and Security Compliance Analysts, as well as non-technical POCs such as Branch Chiefs and Business System Owners.
- Ability to adapt to frequent changes in priorities, follow project schedules, meet established deadlines, and proactively communicate risks and issues to the Contractor PM and/or Federal Leads.
- Ability to adapt to an Agile environment and provide quality, professional deliverables in a short timeframe with little to no guidance from the Government.
- Possess good listening skills and the ability to detect explicit and implicit needs and wants of the client.
- Demonstrated ability to exercise good judgment, prioritize multiple tasks, and problem solve under pressure of deadlines and resource constraints.
- Possess strong analytical and critical thinking skills with the ability to apply them to the client/ contract workspace.
Evolver Federal is an equal opportunity employer and welcomes all job seekers. It is the policy of Evolver Federal not to discriminate based on race, color, ancestry, religion, gender, age, national origin, gender identity or expression, sexual orientation, genetic factors, pregnancy, physical or mental disability, military/veteran status, or any other factor protected by law.
Actual salary will depend on factors such as skills, qualifications, experience, market and work location. Evolver Federal offers competitive benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies.
Database Security Analyst

Posted 15 days ago
Job Viewed
Job Description
Responsibilities:
- Develop and implement security protocols to protect databases and sensitive information.
- Monitor systems for potential vulnerabilities and respond promptly to security incidents.
- Analyze and interpret data from SIEM tools to identify and mitigate risks.
- Collaborate with teams to enforce cybersecurity policies and ensure compliance with industry standards.
- Conduct regular audits to assess the effectiveness of security measures.
- Provide guidance on application security and recommend improvements.
- Stay updated on emerging threats and adapt security strategies accordingly.
- Train staff on best practices for data protection and security awareness.
- Assist in the evaluation of new tools and technologies to enhance security measures. Requirements - Proven experience in cybersecurity, with a focus on database and application security.
- CompTIA Security+ certification or an equivalent credential.
- Proficiency in using SIEM tools to monitor and manage security threats.
- Strong knowledge of cybersecurity policies and their implementation.
- Familiarity with application security practices and protocols.
- Ability to analyze complex data and provide actionable insights.
- Excellent problem-solving skills and attention to detail.
- Strong communication skills to collaborate effectively across teams. Technology Doesn't Change the World, People Do.®
Robert Half is the world's first and largest specialized talent solutions firm that connects highly qualified job seekers to opportunities at great companies. We offer contract, temporary and permanent placement solutions for finance and accounting, technology, marketing and creative, legal, and administrative and customer support roles.
Robert Half works to put you in the best position to succeed. We provide access to top jobs, competitive compensation and benefits, and free online training. Stay on top of every opportunity - whenever you choose - even on the go. Download the Robert Half app ( and get 1-tap apply, notifications of AI-matched jobs, and much more.
All applicants applying for U.S. job openings must be legally authorized to work in the United States. Benefits are available to contract/temporary professionals, including medical, vision, dental, and life and disability insurance. Hired contract/temporary professionals are also eligible to enroll in our company 401(k) plan. Visit roberthalf.gobenefits.net for more information.
© 2025 Robert Half. An Equal Opportunity Employer. M/F/Disability/Veterans. By clicking "Apply Now," you're agreeing to Robert Half's Terms of Use ( .
Database Security Analyst / Imperva
Posted 3 days ago
Job Viewed
Job Description
A national bank is looking for a Database Security Analyst to join their growing team! supply-chain logistics company is looking for a Truckmate Configuration Analyst. You'll work with Imperva, specifically DAM and Securesphere to ensure the security of their enterprise databases. You'll help protect their databases, identify vulnerabilities, implement security measures, and monitor threats utilizing Imperva security products.
This role has the ability to be fully remote, though local candidates in the Houston, TX area are preferred. Required Skills & Experience
- 2+ years of experience with database security
- Experience working in financial institutions or enterprise environments
- Experience with Imperva, ideally DAM, Securesphere, or Data Security Fabric
- Strong communication and collaboration skills
- You will receive the following benefits:
- Medical, Dental, and Vision Insurance
- Vacation Time
- More
Posted by: Chip Chang
Specialization :
- System Administration
Database Security Specialist Lead, Vice President
Posted today
Job Viewed
Job Description
Do you want your voice heard and your actions to count?
Discover your opportunity with Mitsubishi UFJ Financial Group (MUFG), one of the world's leading financial groups. Across the globe, we're 120,000 colleagues, striving to make a difference for every client, organization, and community we serve. We stand for our values, building long-term relationships, serving society, and fostering shared and sustainable growth for a better world.
With a vision to be the world's most trusted financial group, it's part of our culture to put people first, listen to new and diverse ideas and collaborate toward greater innovation, speed and agility. This means investing in talent, technologies, and tools that empower you to own your career.
Join MUFG, where being inspired is expected and making a meaningful impact is rewarded.
The selected colleague will work at an MUFG office or client sites four days per week and work remotely one day. A member of our recruitment team will provide more details.
Job Summary
The Database Security Engineer Lead is responsible for implementing and maintaining security systems that provide detection, prevention, containment and deterrence mechanisms to protect the integrity of relational database systems, AWS cloud native databases, NoSQL and big data platforms, and the data they contain. Using security principles and best practice, the engineer will work with a team of other security professionals to provide guidance and support to operational, business and regulatory teams and will perform expert level database security incident response and investigation.
The Database Security Engineer Lead is a key position for providing protection and assurance on the controls safeguarding the bank's information assets.
Major Responsibilities
-
Designing, developing, testing, documenting, monitoring, and implementing information and database security solutions to enforce security strategies and support to new/existing systems in accordance with policies, standards, guidelines and procedures.
-
Serve as a trusted partner to business, operations, development, risk and compliance teams providing database security subject matter expert (SME) guidance and analysis.
-
Managing a database activity monitoring (DAM) platform for security and audit compliance, including policy creation, event and trend analysis, performance monitoring and infrastructure maintenance.
-
Developing and maintaining database security standards, guidelines and procedures for hardening database configurations, users and roles, profiles, etc.
-
Refining and enhancing existing controls, policies, standards, procedures, and guidelines to prevent the unauthorized use, release, modification, or destruction of data.
-
Evaluating updates to new/existing database security controls by determining the strengths/weaknesses and coordinate the testing and implementation of the new/enhanced controls with all business partners that are affected.
-
Identifying weak links in information security products and determine how to mitigate the control deficiencies.
-
Enhancing preventive systems used to stop and/or deter security breaches.
-
Evaluating database security patches from vendors and assesses potential risk and work with stakeholders to address vulnerabilities.
-
Respond to security Incidents and assist with Tier-1 and Tier-2 incident investigations.
-
Performing root cause analysis of security violations to determine if they are the result of misconfiguration or malfunction or if they are malicious, and taking appropriate action depending on circumstances.
-
Serve as technical lead on projects within area of responsibility.
-
Working with database custodians at different levels of the organization to understand their respective security needs and assist with implementing practices and procedures consistent with the bank information security policy.
-
Working with internal and external auditors to demonstrate and provide evidence of security controls are adherence to regulatory compliance.
-
Executing and enhancing monitoring systems used to detect and report security violations.
-
Identify weak links in information security products and determine how to mitigate the control deficiencies.
-
Maintain familiarity with industry trends and current security practices.
-
Demonstrate ability to manage complex projects in an effective manner. This includes the ability to prepare detailed task plans outlining all requirements to complete the given assignment.
-
Evaluate business process and application software, which effect the integrity, functionality, and reliability of the Bank's network and systems.
Qualifications
-
Degree or equivalent work experience equally preferable
-
Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or Related Fields or relevant industry certifications and comparable experience
-
Master's Degree (preferred)
-
5-7+ years of technical experience in cybersecurity, insider threat, incident response, security operations, or related information security field
-
Experience in the banking or finance industries preferred
-
Database security, monitoring and protection
-
Database activity monitoring platforms such as Imperva Data Security and Data Risk Analytics (DRA) and Imperva Data Security Fabric (DSF / Sonar)
-
Imperva Data Security Specialist (IDSS) certification strongly preferred
-
In-depth working knowledge of databases and database technologies
-
Familiarity with AWS technologies and methods including RDS (Relational Database Service)
-
Data protection especially with regard to cybersecurity tools and methods
-
Database Firewall, Data Classification
-
Vulnerability detection and mitigation
-
Cybersecurity experience in regulated banking or financial environment
-
Penetration testing and attack forensics
-
IS audit
-
GRC Tools & Processes
-
Ability to understand security risks and controls, to analyze various methods of controlling information security problems, determine the strengths and weaknesses of each method and implement the best cost-justified solution.
-
Advanced experience with DAM, SIEM, UEBA and related tools.
-
Detailed knowledge of major database platforms such as Oracle, SQLSERVER, MySQL, etc.
-
Working knowledge of at least two or more operating systems and corresponding security systems (Linux, Unix, Windows, etc.)
-
Proficient with development of documentation, presentations and architecture diagrams.
-
Working knowledge of regulatory requirements affecting data integrity, protection and monitoring, such as GLBA, SOX, PCI, etc.
-
These certification are a plus - Imperva Database Security Specialist (IDSS),Certified Information Systems Auditor (CISA), Certified Ethical Hacker (CEH), Certified in Governance, Risk and Compliance (CGRC), formerly Certified Authorization Professional (CAP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM)
The typical base pay range for this role is between $137K - $176K depending on job-related knowledge, skills, experience and location. This role may also be eligible for certain discretionary performance-based bonus and/or incentive compensation. Additionally, our Total Rewards program provides colleagues with a competitive benefits package (in accordance with the eligibility requirements and respective terms of each) that includes comprehensive health and wellness benefits, retirement plans, educational assistance and training programs, income replacement for qualified employees with disabilities, paid maternity and parental bonding leave, and paid vacation, sick days, and holidays. For more information on our Total Rewards package, please click the link below.
MUFG Benefits Summary (
We will consider for employment all qualified applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws (including (i) the San Francisco Fair Chance Ordinance, (ii) the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance, (iii) the Los Angeles County Fair Chance Ordinance, and (iv) the California Fair Chance Act) to the extent that (a) an applicant is not subject to a statutory disqualification pursuant to Section 3(a)(39) of the Securities and Exchange Act of 1934 or Section 8a(2) or 8a(3) of the Commodity Exchange Act, and (b) they do not conflict with the background screening requirements of the Financial Industry Regulatory Authority (FINRA) and the National Futures Association (NFA). The major responsibilities listed above are the material job duties of this role for which the Company reasonably believes that criminal history may have a direct, adverse and negative relationship potentially resulting in the withdrawal of conditional offer of employment, if any.
The above statements are intended to describe the general nature and level of work being performed. They are not intended to be construed as an exhaustive list of all responsibilities duties and skills required of personnel so classified.
We are proud to be an Equal Opportunity Employer and committed to leveraging the diverse backgrounds, perspectives and experience of our workforce to create opportunities for our colleagues and our business. We do not discriminate on the basis of race, color, national origin, religion, gender expression, gender identity, sex, age, ancestry, marital status, protected veteran and military status, disability, medical condition, sexual orientation, genetic information, or any other status of an individual or that individual's associates or relatives that is protected under applicable federal, state, or local law.
At MUFG, our colleagues are our greatest assets. Our Culture Principles provide a roadmap for how each of our colleagues must think and act to become more client-obsessed, inclusive and innovative. They reflect who we are, who we want to be and what we expect from one another. We are excited to see you take the next step in exploring a career with us and encourage you to spend more time reviewing them!
Our Culture Principles
-
Client Centric
-
People Focused
-
Listen Up. Speak Up.
-
Innovate & Simplify
-
Own & Execute
DB2 - Mainframe Database Security and Audit Governance Engineer

Posted 7 days ago
Job Viewed
Job Description
Plano, Texas
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge
Refer a friend
**To proceed with your application, you must be at least 18 years of age.**
Acknowledge ( Description:**
At Bank of America, we are guided by a common purpose to help make financial lives better through the power of every connection. We do this by driving Responsible Growth and delivering for our clients, teammates, communities and shareholders every day.
Being a Great Place to Work is core to how we drive Responsible Growth. This includes our commitment to being an inclusive workplace, attracting and developing exceptional talent, supporting our teammates' physical, emotional, and financial wellness, recognizing and rewarding performance, and how we make an impact in the communities we serve.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations.
At Bank of America, you can build a successful career with opportunities to learn, grow, and make an impact. Join us!
**Job Description:**
This job is responsible for tool and service designs within a technical domain that enable business strategies in accordance with architectural governance, standards and policies. Key responsibilities include creating infrastructure tools and their integration as a service, facilitating deployment of technical solutions by developing templates, playbooks and automation used during implementation. Job expectations include looking for opportunities to improve efficiency when implementing and maintaining tools/services and embracing a culture of innovation and continuous improvement.
**Position Summary**
+ Participates in design, development and implementation of complex Database related security, often using new technologies and emerging methodologies.
+ Serves as a fully seasoned/proficient technical resource.
+ Manages multiple, moderately complex projects and may direct activities of a team related to special initiatives or operations.
+ Routine accountability is for technical knowledge and capabilities as a team member or as an individual contributor.
+ Works under minimal supervision, with general guidance from more seasoned consultants or managers.
+ May also assist and help train more junior analysts - includes guiding and providing technical peer reviews.
+ Works on complex problems where analysis of situations or data requires an in-depth evaluation of various factors and participates in implementation of security changes.
+ May require on call support function.
+ Exercises judgment within broadly defined practices and policies in selecting methods, techniques, and evaluation criterion for obtaining results.
+ Able to communicate effectively with peers, management, and other technical support personnel in a diverse global environment.
+ Knowledge of mainframe Security Manager Software(RACF), Database technologies (DB2/IMS), JCL, TSO, and fundamental problem analysis utilizing diagnostics tools; exposure to sysplex and data sharing helpful. Proficient in MS Office tools - Excel, PowerPoint, and Word. Typically 7-9 years of IT experience, with knowledge of mainframe database (DB2/IMS).
**Responsibilities:**
+ Provides subject matter expertise and consulting services on a range of technologies and assists Technical Analysts and Infrastructure Engineers to ensure that technology solutions comply with enterprise system design and engineering standards
+ Assists with translating business requirements into technical definitions, reference models, blueprints, and playbooks for deployment in compliance with architecture standards and policies
+ Assists in the evaluation of reference models, blueprints and playbooks to ensure they are fit for purpose
+ Develops software solutions to address manual and repeatable work or inefficient processes
+ Conducts on-site evaluations of third-party products being considered for firm adoption
+ Promotes an inclusive and healthy working environment and helps to resolve organizational impediments/blockers
+ Contributes to the creation/selection of functional and non-functional product evaluation requirements within and across domains
**Required Qualifications**
+ Position requires in-depth Mainframe Db2 (DB2 on Z/OS) and/or IMS DBA knowledge with a focus on database security. Individual should have minimum of 7-9 years of Mainframe DBA experience on z/OS supporting a large financial institution.
+ Job stability is a key requirement.
+ In depth working knowledge of DB2 and/or IMS Utilities including IBM and BMC
+ Working knowledge of BMC tools including change manager, catalog manager, recovery manager, Mainview, and SQL performance.
+ Solid understanding of mainframe database recovery process.
+ Broad understanding of RACF2 managed security for DB2 and/or IMS Access.
+ Working knowledge of ISPW
+ Working knowledge of ITSM Processes and tools including BMC Remedy
+ Background in database design for 24x7 availability.
**Desired Qualifications**
+ In-depth knowledge of Db2 and/or IMS Security under RACF is a plus.
+ Computer Science degree preferred or substantially equivalent technology degree
**Skills:**
+ Analytical Thinking
+ Application Development
+ Automation
+ Production Support
+ Risk Management
+ Adaptability
+ Business Acumen
+ DevOps Practices
+ Solution Delivery Process
+ Solution Design
+ Architecture
+ Collaboration
+ Innovative Thinking
+ Stakeholder Management
+ Technical Strategy Development
**Shift:**
1st shift (United States of America)
**Hours Per Week:**
40
Bank of America and its affiliates consider for employment and hire qualified candidates without regard to race, religious creed, religion, color, sex, sexual orientation, genetic information, gender, gender identity, gender expression, age, national origin, ancestry, citizenship, protected veteran or disability status or any factor prohibited by law, and as such affirms in policy and practice to support and promote the concept of equal employment opportunity, in accordance with all applicable federal, state, provincial and municipal laws. The company also prohibits discrimination on other bases such as medical condition, marital status or any other factor that is irrelevant to the performance of our teammates.
To view the "Know your Rights" poster, CLICK HERE ( .
View the LA County Fair Chance Ordinance ( .
Bank of America aims to create a workplace free from the dangers and resulting consequences of illegal and illicit drug use and alcohol abuse. Our Drug-Free Workplace and Alcohol Policy ("Policy") establishes requirements to prevent the presence or use of illegal or illicit drugs or unauthorized alcohol on Bank of America premises and to provide a safe work environment.
Bank of America is committed to an in-office culture with specific requirements for office-based attendance and which allows for an appropriate level of flexibility for our teammates and businesses based on role-specific considerations. Should you be offered a role with Bank of America, your hiring manager will provide you with information on the in-office expectations associated with your role. These expectations are subject to change at any time and at the sole discretion of the Company. To the extent you have a disability or sincerely held religious belief for which you believe you need a reasonable accommodation from this requirement, you must seek an accommodation through the Bank's required accommodation request process before your first day of work.
This communication provides information about certain Bank of America benefits. Receipt of this document does not automatically entitle you to benefits offered by Bank of America. Every effort has been made to ensure the accuracy of this communication. However, if there are discrepancies between this communication and the official plan documents, the plan documents will always govern. Bank of America retains the discretion to interpret the terms or language used in any of its communications according to the provisions contained in the plan documents. Bank of America also reserves the right to amend or terminate any benefit plan in its sole discretion at any time for any reason.
Principal Cybersecurity Architect - Database Security | Product Security Lead

Posted 15 days ago
Job Viewed
Job Description
As a Principal Cybersecurity Architect at JPMorganChase within the Cybersecurity and Technology Controls line of business, you provide expertise to enhance and develop architecture platforms based on modern cloud-based technologies as well as support the adoption of strategic global solutions. Leverage your advanced architecture capabilities to identify, communicate, and mitigate risk, and collaborate with colleagues across the organization to drive best-in-class outcomes.
This role serves as a Product Security Lead (PSL) for the database product line, you will work proactively with your technology and business colleagues to identify and quantify security issues within their products and empower them to take decisive risk decisions at speed and scale. You are a security expert with a strong mix of database technology and communication skills and are passionate about enabling safe and secure innovation to make database products secure. You will work with some of the best and brightest cybersecurity and technology engineers to solve complex problems which will both challenge you and help you develop your skills in one of the most innovative and respected companies in the world.
**Job responsibilities**
+ Cultivate security culture. Products that have the right security culture will strive to prioritize sustainable controls and driving real risk reduction outcomes.
+ Embed threat modeling, security architecture, secure code review into product and application teams so they adopt our control products and create products that are secure from the start.
+ Know database products across their breadth and depth. Be fluent in your product's strategy and roadmap as well as its key investment programs.
+ Be your product's security thought leader. Learn from your product and cybersecurity teams and share best practice in both directions. Be recognized in your product as the clear point of escalation and subject matter expert for IT Risk and Cyber domains.
+ Proactively monitor Key Risk Indicators to ensure issues are identified, quantified, communicated, and managed in a timely manner, including recommendations for resolution, and identifying the root cause
+ Work collaboratively with product, technology, and business colleagues on an on-going basis for business-as-usual audit and regulatory engagements, risk activities and project initiatives.
+ Advises cross-functional teams on technology selections and decisions to achieve target state cybersecurity on improvements to current cybersecurity parameters
+ Develops multi-year roadmaps aligned with business and architecture strategy and priorities
+ Serves as the function's go-to subject matter expert and drives thought leadership within the product line
+ Contributes to the development of technical methods in cybersecurity in line with the latest product development methodologies
+ Participates in the firm's culture of diversity, opportunity, inclusion, and respect
**Required qualifications, capabilities, and skills**
+ Formal training or certification on cybersecurity architecture concepts and 10+ years applied experience
+ Experience in a successful security and risk organization with strong security and technical skills. Experience of operating in a regulated organization with a 3LoD (Line of defense) model is also needed
+ Delivery excellence mixed with strategic vision.
+ Able to communicate effectively and authoritatively with technical and non-technical stakeholders at all levels of the organization.and clearly explain complex technical concepts in simple terms.
+ Demonstrated success in influencing peers inside and outside your department.
+ Ability to drive change across organizations, collaborating with partners across Global Tech and other Lines of Business,identify challenges and engage resources across all roles and levels to identify and implement innovative solutions, and quickly digest new information/technologies and apply diverse experience and principles to be able to quickly come up to speed and add value in product security discussions.
+ Demonstrated experience / understanding with platform technologies including but not limited to: 1) A detailed, technical understanding of Public Cloud computing (GCP/AWS). Especially how Public Cloud services are hardened, and controls are applied to secure data, ensure resiliency/availability as well as prevent unauthorized access. 2) APIs/ micro-services 3) Database Technology 4) Identity & Access Management as well as Secrets Management, 5) Securing Software as a Service (SaaS) tool, 6) Securing Containerized workloads at build and runtime
+ Advanced knowledge of cybersecurity architecture, applications, and technical processes with considerable, in-depth knowledge in one or more technical disciplines (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
+ Experience applying expertise and new methods to determine solutions for complex architecture problems in one or more technical disciplines
+ Ability to present and effectively communicate with senior leaders and executives
+ Understanding of the business and knowledgeable of latest risk trends in the internal and external environments
**Preferred qualifications, capabilities, and skills**
+ Demonstrated ability to collaborate on, and/or lead, ad hoc teams for control architecture and design.
+ Experience within Line of Business teams with ability to leverage business perspectives when solving technology challenges
+ Experience fulfilling audit requests, challenging observations/findings and driving successful outcomes in technology audits
+ Proven ability to drive change in policy and control requirements at a firmwide level
+ Experience translating firmwide policy or regulatory requirements into control design and definition for Software Engineers and Solutions Architects
+ Experience in financial services consumer businesses (i.e., Mortgages, Cards or Digital) preferred but not required
+ Thinks in terms of risks and outcomes, and able to translate those into actions required to achieve business and technology goals. Proven experience of upskilling and learning modern technologies.
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Principal Cybersecurity Architect - Database Security | Product Security Lead
Posted 7 days ago
Job Viewed
Job Description
As a Principal Cybersecurity Architect at JPMorganChase within the Cybersecurity and Technology Controls line of business, you provide expertise to enhance and develop architecture platforms based on modern cloud-based technologies as well as support the adoption of strategic global solutions. Leverage your advanced architecture capabilities to identify, communicate, and mitigate risk, and collaborate with colleagues across the organization to drive best-in-class outcomes.
This role serves as a Product Security Lead (PSL) for the database product line, you will work proactively with your technology and business colleagues to identify and quantify security issues within their products and empower them to take decisive risk decisions at speed and scale. You are a security expert with a strong mix of database technology and communication skills and are passionate about enabling safe and secure innovation to make database products secure. You will work with some of the best and brightest cybersecurity and technology engineers to solve complex problems which will both challenge you and help you develop your skills in one of the most innovative and respected companies in the world.
Job responsibilities
- Cultivate security culture. Products that have the right security culture will strive to prioritize sustainable controls and driving real risk reduction outcomes.
- Embed threat modeling, security architecture, secure code review into product and application teams so they adopt our control products and create products that are secure from the start.
- Know database products across their breadth and depth. Be fluent in your product's strategy and roadmap as well as its key investment programs.
- Be your product's security thought leader. Learn from your product and cybersecurity teams and share best practice in both directions. Be recognized in your product as the clear point of escalation and subject matter expert for IT Risk and Cyber domains.
- Proactively monitor Key Risk Indicators to ensure issues are identified, quantified, communicated, and managed in a timely manner, including recommendations for resolution, and identifying the root cause
- Work collaboratively with product, technology, and business colleagues on an on-going basis for business-as-usual audit and regulatory engagements, risk activities and project initiatives.
- Advises cross-functional teams on technology selections and decisions to achieve target state cybersecurity on improvements to current cybersecurity parameters
- Develops multi-year roadmaps aligned with business and architecture strategy and priorities
- Serves as the function's go-to subject matter expert and drives thought leadership within the product line
- Contributes to the development of technical methods in cybersecurity in line with the latest product development methodologies
- Participates in the firm's culture of diversity, opportunity, inclusion, and respect
Required qualifications, capabilities, and skills
- Formal training or certification on cybersecurity architecture concepts and 10+ years applied experience
- Experience in a successful security and risk organization with strong security and technical skills. Experience of operating in a regulated organization with a 3LoD (Line of defense) model is also needed
- Delivery excellence mixed with strategic vision.
- Able to communicate effectively and authoritatively with technical and non-technical stakeholders at all levels of the organization.and clearly explain complex technical concepts in simple terms.
- Demonstrated success in influencing peers inside and outside your department.
- Ability to drive change across organizations, collaborating with partners across Global Tech and other Lines of Business,identify challenges and engage resources across all roles and levels to identify and implement innovative solutions, and quickly digest new information/technologies and apply diverse experience and principles to be able to quickly come up to speed and add value in product security discussions.
- Demonstrated experience / understanding with platform technologies including but not limited to: 1) A detailed, technical understanding of Public Cloud computing (GCP/AWS). Especially how Public Cloud services are hardened, and controls are applied to secure data, ensure resiliency/availability as well as prevent unauthorized access. 2) APIs/ micro-services 3) Database Technology 4) Identity & Access Management as well as Secrets Management, 5) Securing Software as a Service (SaaS) tool, 6) Securing Containerized workloads at build and runtime
- Advanced knowledge of cybersecurity architecture, applications, and technical processes with considerable, in-depth knowledge in one or more technical disciplines (e.g., public cloud, artificial intelligence, machine learning, mobile, etc.)
- Experience applying expertise and new methods to determine solutions for complex architecture problems in one or more technical disciplines
- Ability to present and effectively communicate with senior leaders and executives
- Understanding of the business and knowledgeable of latest risk trends in the internal and external environments
Preferred qualifications, capabilities, and skills
- Demonstrated ability to collaborate on, and/or lead, ad hoc teams for control architecture and design.
- Experience within Line of Business teams with ability to leverage business perspectives when solving technology challenges
- Experience fulfilling audit requests, challenging observations/findings and driving successful outcomes in technology audits
- Proven ability to drive change in policy and control requirements at a firmwide level
- Experience translating firmwide policy or regulatory requirements into control design and definition for Software Engineers and Solutions Architects
- Experience in financial services consumer businesses (i.e., Mortgages, Cards or Digital) preferred but not required
- Thinks in terms of risks and outcomes, and able to translate those into actions required to achieve business and technology goals. Proven experience of upskilling and learning modern technologies.
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
Be The First To Know
About the latest Database security Jobs in United States !
Information Security Engineer
Posted today
Job Viewed
Job Description
***Must sit in Charlotte, NC, but will be remote!***
Position: Information Security Engineer
Duration: FTE
Compensation: 90-100k with 7.5% bonus
Location: REMOTE but must sit in Charlotte, NC
Summary:
The Information Security Engineer will conduct vulnerability assessments, threat hunting activities, and evaluate deviations from security configurations or policies. The team member also develops and/or recommends appropriate mitigation countermeasures in operational and non-operational situations.
Essential Functions:
Expertise in Information Security Programs
- Conduct Vulnerability Assessments
- Company Security Policy and Procedure Upkeep
- Risk Assessments
- Threat Hunting
- Security Awareness Training
- Operational Security Oversight
Desired Qualifications:
- Degree in Computer Science or related work experience
- 2 years in direct related work experience
- Passion and vision
- Strong communication and presentation skills
Desired Experience:
- Intermediate knowledge of risk management processes
- Intermediate knowledge of information security regulations
- Intermediate knowledge of information technology (IT) supply chain security/risk management policies, requirements, and procedures.
- Experience in Payment Card Industry, Data Security Standards (PCI-DSS), Graham Leach Bliley (GLBA), Healthcare Insurance Portability and Accounting and Accounting Act (HIPAA), Sarbanes-Oxley (SOX)
- Demonstrated real world experience performing grey and black box penetration testing as well as cyber threat emulation services (opposing force)
- Have an understanding of common Web Application vulnerabilities like XSS, CSRF, and others.
- Must be proficient in several of the following tools: PowerShell, Metasploit Framework/Pro, Nexpose, Burp, and the Social Engineering Toolkit
- Must have solid working experience and knowledge of Windows and Unix/Linux operating system, mobile platforms a plus
- Firm understanding of networks, systems and data center architecture
- (Certified Ethical Hacker (CEH)) and (Licensed Penetration Tester (LPT), GIAC Penetration Tester (GPEN), Certified Penetration Tester (CPT)) OSCP or equivalent desired
Information Security Engineer
Posted today
Job Viewed
Job Description
MUST HAVES
- Azure and/or AWS
- Cloud Incident Response
Role Overview
The Information Security Engineer II – Cloud Incident Responder tackles moderately complex security engineering challenges within their domain. They maintain and enhance existing security controls while actively participating in the design and development of new solutions. They proactively identify and address vulnerabilities or deficiencies within their domain, develop and implement robust controls to mitigate these risks, create detailed documentation, and implement mechanisms to ensure the effectiveness of solutions.
The Engineer II – Cloud Incident Responder will focus on building and operationalizing cloud-specific incident response processes, playbooks, and procedures across Azure, AWS, and GCP environments. This role requires strong technical expertise in cloud security and incident response, and will be instrumental in improving MGB’s ability to detect, respond to, and recover from cloud-based threats.
The Engineer II – Cloud Incident Responder is expected to work independently on moderately complex problems within their domain and provide guidance to junior team members to support their development. They will regularly engage with external stakeholders and partners to support the development of effective solutions.
Responsibilities
- Takes ownership of specific modules or components within projects or tools, from design to implementation.
- Reviews and provides constructive feedback on build/code contributions from team members.
- Participates in architectural discussions and contributes to the design of complex solutions.
- Proactively identifies and optimizes improvement in existing processes.
- Mentors junior team members, sharing knowledge and best practices.
- Cross-Functional collaboration with other teams to ensure successful solution delivery.
- Designs and maintains cloud incident response playbooks tailored to Azure, AWS, and GCP environments.
- Develops and documents cloud-specific IR procedures, including detection, triage, containment, eradication, and recovery workflows.
- Collaborates with cloud engineering, SOC, and threat intelligence teams to ensure alignment of IR capabilities with cloud architecture and threat landscape.
- Participates in tabletop exercises and simulations to validate cloud IR readiness and improve response capabilities.
- Implements automation and orchestration for cloud incident response using native and third-party tools.
Qualifications
- Bachelor’s or Associate’s Degree or requisite experience
- 3+ years of relevant experience
- Experience in cloud security and incident response across Azure, AWS, and GCP
- Certifications such as AWS Certified Security – Specialty, Azure Security Engineer Associate, or Google Professional Cloud Security Engineer are preferred
Skills / Abilities / Competencies
- Strong understanding of cybersecurity concepts within their domain
- High proficiency with the tools and solutions supported by the team
- Solid understanding of system architecture and design
- Strong problem solving skills and analytical thinking to identify solutions to complex problems, and to optimize existing solutions
- Excellent prioritization capabilities, with an aptitude for breaking down work into manageable parts, effectively assessing the priority and time required to complete each part
- Excellent communication and teamwork skills to share knowledge, present ideas, and lead discussions
- Proficiency in cloud-native security tools such as AWS GuardDuty, Azure Sentinel, and GCP Security Command Center
- Experience with SIEM, SOAR, and EDR platforms in cloud environments
- Ability to analyze cloud logs and telemetry for threat detection and investigation
- Strong understanding of cloud architecture, IAM, and network security principles
Information Security Engineer
Posted 3 days ago
Job Viewed
Job Description
COMPANY OVERVIEW
Pattern Energy Group is an independent, fully integrated energy company that develops, constructs, owns and operates renewable energy projects and transmission assets across North America, Japan, and parts of Latin America. The company focuses primarily on wind, solar and transmission. The Pattern Energy Group team has a history as one of the top North American renewable energy and transmission providers in the industry. The team is dedicated to delivering the highest value for its customers, partners, financial supporters and the communities in which it works, while exhibiting a strong commitment to promoting environmental stewardship and corporate responsibility.
Pattern Energy Group operates in the United States, Canada, Japan, and Mexico with offices in San Francisco, Houston, San Diego, New York, Tokyo, and Toronto. Pattern Energy Group’s corporate headquarters is in San Francisco.
ResponsibilitiesJOB PURPOSE
As Pattern continues to expand, this newly created role is essential to strengthening our cybersecurity posture. The Security Engineer or Senior Security Engineer (based on experience) will play a critical role in minimizing the likelihood of a material impact to Pattern’s business due to cyber incidents. This position requires expertise in securing both Information Technology (IT) and Operational Technology (OT) environments and will work closely with cross-functional teams to enhance our cybersecurity defenses.
Key Accountabilities
Security Monitoring & Incident Response:
- Monitor, analyze, and investigate security alerts and incidents to mitigate potential threats.
- Act as a key member of the Cybersecurity Incident Response Team (CIRT) to contain and remediate threats.
Endpoint & Server Protection:
- Manage and monitor Microsoft Defender for Endpoint (Windows & macOS).
- Manage and monitor Microsoft Defender for Server P2 for enhanced threat detection.
Identity & Access Management (IAM):
- Manage and monitor Microsoft Entra and AD to enforce secure authentication and authorization policies.
Security Information and Event Management (SIEM):
- Manage and monitor SIEM solutions for threat detection, correlation, and response.
- Experience with Exabeam SIEM is a plus.
Compliance & Risk Management:
- Ensure compliance with NERC CIP security standards.
- Apply cybersecurity best practices following NIST CSF guidelines.
Collaboration & Communication:
- Work closely with both IT and OT teams to implement security controls.
- Provide clear written and verbal communication to technical and non-technical stakeholders.
Security Training & Awareness:
- Conduct cybersecurity training and awareness programs (Cybersecurity instructor experience is a plus).
Experience/Qualifications/Education Required
Educational Experience
Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent work experience.
Required and Preferred Work Experience
- Minimum of five years of experience on an Information Security team.
- Strong knowledge of cybersecurity monitoring and incident investigation.
- Hands-on experience with Microsoft Defender security tools.
- Experience working with SIEM platforms (Exabeam experience is a plus).
- Knowledge of NERC CIP requirements and their impact on security operations.
- Hands-on experience protecting, monitoring and investigating II and OT environments.
- Excellent written and verbal communication skills.
- Experience responding as a member of a CIRT (Cyber Incident Response Team).
Additional Requirements
- Experience with NIST Cybersecurity Framework (CSF) .
- Familiarity with Jamf for macOS and Microsoft MDM for Windows mobile device management.
- Cybersecurity certifications such as CompTIA Security+, CISSP, CISA are a plus.
The expected starting pay range for this role is $90,000 - $122,000 USD. This range is an estimate and base pay may be above or below the ranges based on several factors including but not limited to location, work experience, certifications, and education. In addition to base pay, Pattern’s compensation program includes a bonus structure for full-time employees of all levels. We also provide a comprehensive benefits package which includes medical, dental, vision, short and long-term disability, life insurance, voluntary benefits, family care benefits, employee assistance program, paid time off and bonding leave, paid holidays, 401(k)/RRSP retirement savings plan with employer contribution, and employee referral bonuses.
Pattern Energy Group is an Equal Opportunity Employer.
#LI-AN1