Manager Information Security & Risk Management

43201 Columbus, Ohio Highmark Health

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

**Company :**
Highmark Health
**Job Description :**
**JOB SUMMARY**
This job provides Information Security and Risk Management services for the Organization. Works with peers within security, HM Health Solutions customers and application teams to ensure alignment with current and future security needs. Manages activities of various Information Security personnel. Makes decisions on personnel actions (promotions, hiring, terminations, etc.). Develops talent, addresses resource management, cultivates capabilities of staff, planning and coordination of work, and managing performance. Conducts the oversight of security technology products for network, systems, and data. Controls expenses within the operating unit and is responsible for meeting budget goals. Actively contributes to the Information Security ans Risk Management (ISRM) strategic planning process by working with the Directors to develop and implement department strategic plans and action steps that support the corporate strategic objectives. Actively involved in the coordination, implementation, problem solving, communication, and training of new technologies and processes, as they are developed and moved into the environment. Develops and presents Information Security awareness and training programs.
**ESSENTIAL RESPONSIBILITIES**
+ Perform management responsibilities including, but not limited to: involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.
+ Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.
+ Provide oversight of all aspects of project management to ensure continuous improvement of processes: negotiate and collaborate with leadership and staff to develop security solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management.
+ Provide leadership to the department: lead and champion organizational change; encourage participation in activities that support relationship development; champion information security innovation; encourage and enforce proper training in regards to security issues.
+ Ensure compliance to Corporate and Information Security policies, standards and procedures.
+ Communicate effectively with all levels of the organization: facilitate meetings; plan, design and provide presentations; represent HM Health Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence; spread awareness of new and existing security threats; provide oversight regarding metrics, funding, budgets and resources.
+ Other duties as assigned or requested.
**EDUCATION**
**Required**
+ Bachelor's Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field
**Substitutions**
+ 6 years of relevant experience substitution for a Bachelor's Degree
**Preferred**
+ Master's Degree in Computer Science, Information Security or related field
**EXPERIENCE**
**Required**
+ 7 - 10 years in Information Security and/or Information Risk Management and/or Information Technology
+ 7 - 10 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
+ 1 - 3 years in mentoring others in a leadership role
+ 1 - 3 years in Staff Management
+ 1 - 3 years in developing and executing strategic plans to realize business objectives
**Preferred**
+ 10 - 15 years in Information Security and/or Information Risk Management and/or Information Technology
+ Experience managing an information security function using the HITRUST Common Security Framework (HITRUST CSF), or the NIST 800-83 cyber security framework
+ Experience supporting SSAE 16 or SOC 2 Security Trust Principle audits
+ Experience establishing budgets and meeting fiduciary goals
+ Security industry organization participation/leadership (HITRUST, ISACA, InfraGard, ISC2, ISSA, etc.)
**LICENSES AND CERTIFICATIONS**
**Required**
+ None
**Preferred**
+ Certified Information Systems Security Professional (CISSP) **OR**
+ Certified Information Security Manager (CISM) **OR**
+ Certified in Risk and Information Systems Controls (CRISC) **OR**
+ Information Technology Infrastructure Library (ITIL)
**SKILLS**
+ Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140
+ Strong teamwork and interpersonal skills
+ Experience in leading process improvement initiatives
+ Ability to motivate high performance, multi-discipline teams
+ Demonstrated competency in project execution
+ Demonstrated abilities in relationship management
**Languages (Other than English)**
None
**Travel Requirement**
0% - 25%
**PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS**
**Position Type**
Office-Based
Teaches/Trains others regularly
Frequently
Travels regularly from the office to various work sites or from site-to-site
Occasionally
Works primarily out-of-the office selling products/services (Sales employees)
Does Not Apply
Physical Work Site Required
Yes
Lifting: up to 10 pounds
Does Not Apply
Lifting: 10 to 25 pounds
Does Not Apply
Lifting: 25 to 50 pounds
Does Not Apply
**_Disclaimer:_** _The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job._
**_Compliance Requirement_** _: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies._
_As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy._
_Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements._
**Pay Range Minimum:**
$108,000.00
**Pay Range Maximum:**
$201,800.00
_Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets._
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J
View Now

Director Information Security & Risk Management

43201 Columbus, Ohio Highmark Health

Posted 23 days ago

Job Viewed

Tap Again To Close

Job Description

**Company :**
Highmark Health
**Job Description :**
**JOB SUMMARY**
***CANDIDATE MUST BE US Citizen (due to contractual/access requirements)***
This job directs and manages Identity and Access Management (IAM) services for the Enterprise. Provides leadership to the Organization's IAM program, including developing and managing the related policies, standards, architectures, and controls. Partners with Information Security, IT Infrastructure, Application Development, and business units to ensure secure and appropriate access to systems and data. Develops talent, addresses resource management, cultivates capabilities of staff, plans and coordinates work, and manages performance. Actively contributes to the IAM strategic planning process to develop and implement department strategic plans and action steps that support corporate strategic objectives. Defines service levels and monitors adherence. Sets budgets and controls expenses within the operating unit. Creates a team environment that promotes cooperation, empowerment, accountability, customer focus, and effective work relationships in order to realize business goals.
**ESSENTIAL RESPONSIBILITIES**
+ Perform management responsibilities including, but not limited to: involved in hiring and termination decisions; coaching and development; rewards and recognition; performance management and staff productivity.
+ Plan, organize, staff, direct and control the day-to-day operations of the department; develop and implement policies and programs as necessary; may have budgetary responsibility and authority.
+ Communicate effectively with all levels of the organization: facilitate meetings; plan, design and provide presentations; represent HM Health Solutions with outside entities; prepare divisional procedures, policies, reports and correspondence.
+ Provide Leadership to the Department: lead and champion organizational change; encourage participation in activities that support relationship development; champion information security and risk management innovation; demonstrate and champion the following characteristics in fulfilling the responsibilities of the job - passion, empowerment, accountability, collaboration and ethics.
+ Provide oversight of all aspects of project management to ensure continuous improvement of processes: negotiate and collaborate with senior executives and staff to develop solutions and options; develop and adhere to internal standards and strategies; ensure adherence to approved methodologies; coordinate resources, time, contingency plans and risk management; provide oversight regarding metrics, funding, budgets and resources.
+ Other duties as assigned or requested.
**EDUCATION**
**Required**
+ Bachelor's Degree in Information Security, Information Systems, Information Assurance, Computer Science or related field, or relevant experience and/or education as determined by the company in lieu of bachelor's degree
**Preferred**
+ Master's Degree in Information Security, or a related field with a focus on Identity and Access Management.
**EXPERIENCE**
**Required**
+ 10 - 15 years in Information Security and/or Information Risk Management and/or Information Technology
+ 10 - 15 years in developing, communicating and presenting Information Security and Risk Management concepts to varying audiences
+ 7 - 10 years in mentoring others in a leadership role
+ 5 - 7 years in Staff Management
+ 5 - 7 years in developing and executing strategic plans to realize business objectives
+ 5 - 7 years establishing budgets and meeting fiduciary goals
**Preferred**
+ Experience managing an Identity and Access Management program using industry-standard frameworks.
+ Experience with cloud-based IAM solutions.
+ Experience with implementing and managing role-based access control (RBAC), attribute-based access control (ABAC), and policy-based access control (PBAC).
+ Experience with Zero Trust security models and their application to Identity and Access Management.
+ Experience with the application of Artificial Intelligence (AI) and Machine Learning (ML) to Identity and Access Management.
+ Experience with Identity Governance technologies (e.g., SailPoint).
+ Experience with Public Key Infrastructure (PKI).
+ Experience with Federated Identity Management (SAML, OAuth, OpenID Connect).
+ Experience with enterprise directory services such as Active Directory and LDAP.
+ Experience with securing APIs using IAM principles and technologies.
+ Experience with cloud-based identity providers like Azure AD, AWS IAM, and Google Cloud Identity.
**LICENSES AND CERTIFICATIONS**
**Required**
+ None
**Preferred** (any of the following)
+ Certified Information Systems Security Professional (CISSP)
+ Certified Information Security Manager (CISM)
+ Certified in Risk and Information Systems Controls (CRISC)
+ Information Technology Infrastructure Library (ITIL)
**SKILLS**
+ Knowledge of regulatory requirements such as Health Insurance Portability and Accountability Act (HIPPA), HITECH, Payment Card Industry Data Security Standards (PCI DSS), and FIPS-140
+ Strong executive communication and presenting skills
+ Strong teamwork and interpersonal skills
+ Experience in leading process improvement initiatives
+ Ability to motivate high performance, multi-discipline teams
+ Demonstrated competency in project execution
+ Demonstrated abilities in relationship management
**Language (Other than English):**
None
**Travel Requirement:**
0% - 25%
**PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS**
**Position Type**
Office-based
Teaches / trains others regularly
Occasionally
Travel regularly from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
Yes
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
**_Disclaimer:_** _The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job._
**_Compliance Requirement_** _: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies._
_As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy._
_Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements._
**Pay Range Minimum:**
$126,400.00
**Pay Range Maximum:**
$236,000.00
_Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets._
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J
View Now

Staff Security Engineer, Network Security

43201 Columbus, Ohio Coinbase

Posted 24 days ago

Job Viewed

Tap Again To Close

Job Description

Ready to be pushed beyond what you think you're capable of?
At Coinbase, our mission is to increase economic freedom in the world. It's a massive, ambitious opportunity that demands the best of us, every day, as we build the emerging onchain platform - and with it, the future global financial system.
To achieve our mission, we're seeking a very specific candidate. We want someone who is passionate about our mission and who believes in the power of crypto and blockchain technology to update the financial system. We want someone who is eager to leave their mark on the world, who relishes the pressure and privilege of working with high caliber colleagues, and who actively seeks feedback to keep leveling up. We want someone who will run towards, not away from, solving the company's hardest problems.
Our is intense and isn't for everyone. But if you want to build the future alongside others who excel in their disciplines and expect the same from you, there's no better place to be.
While many roles at Coinbase are remote-first, we are not remote-only. In-person participation is required throughout the year. Team and company-wide offsites are held multiple times annually to foster collaboration, connection, and alignment. Attendance is expected and fully supported.
Coinbase Cloud Security (CloudSec) is looking for a Staff Security Engineer to enhance our network security across multiple cloud environments. This role involves leading the design, implementation, and continuous improvement of our security posture. You will leverage your extensive skills in WAF management, DDoS protection, network segmentation, and firewall policy management to enforce robust security measures while enabling developer efficiency.
*What you'll be doing (ie. job duties):*
* Design, implement, and maintain network security controls across multi-cloud (AWS, GCP, etc.) and on-prem infrastructure
* Own and optimize Web Application Firewalls (WAF) and DDoS protection services for scalability and resilience.
* Enforce network segmentation and firewall rules that minimize blast radius without impairing productivity.
* Review configuration changes and write policies to detect security invariants.
* Drive continuous improvement of secure-by-default network patterns for developers.
* Write code for automations that support security requirements like threat detection, incident containment, and network access management.
* Partner with engineering teams to review network and routing architecture design changes.
*What we look for in you (ie. job requirements):*
* At least 8 years of experience in network security with deep expertise in AWS and cloud edge security experience.
* An ability to deploy cloud infrastructure with Terraform and to develop automations or guardrails with Golang.
* An execution-focused mindset, capable of navigating through ambiguity and delivering results.
* Your passion for building an open financial system that brings the world together drives you to excel in this role.
*Nice to haves:*
* Proficiency in crafting Rego rules for Open Policy Agent (OPA) or comparable policy-as-code solutions.
* Proven experience implementing AWS Network Firewall or GCP Cloud Firewall in large-scale production environments.
* Demonstrated expertise in managing Cloudflare.
* Experience with both GCP and/or on-premise infrastructure.
Position ID: P72327
#LI-Remote
*Pay Transparency Notice:* Depending on your work location, the target annual salary for this position can range as detailed below. Full time offers from Coinbase also include bonus eligibility + equity eligibility**+ benefits (including medical, dental, vision and 401(k)).
Pay Range:
$218,025-$256,500 USD
Please be advised that each candidate may submit a maximum of four applications within any 30-day period. We encourage you to carefully evaluate how your skills and interests align with Coinbase's roles before applying.
Commitment to Equal Opportunity
Coinbase is proud to be an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, creed, gender, national origin, age, disability, veteran status, sex, gender expression or identity, sexual orientation or any other basis protected by applicable law. Coinbase will also consider for employment qualified applicants with criminal histories in a manner consistent with applicable federal, state and local law. For US applicants, you may view the in certain locations, as required by law.
Coinbase is also committed to providing reasonable accommodations to individuals with disabilities. If you need a reasonable accommodation because of a disability for any part of the employment process, please contact us at accommodations Data Privacy Notice for Job Candidates and Applicants
Depending on your location, the General Data Protection Regulation (GDPR) and California Consumer Privacy Act (CCPA) may regulate the way we manage the data of job applicants. Our full notice outlining how data will be processed as part of the application procedure for applicable locations is available Disclosure
For select roles, Coinbase is piloting an AI tool based on machine learning technologies to conduct initial screening interviews to qualified applicants. The tool simulates realistic interview scenarios and engages in dynamic conversation. A human recruiter will review your interview responses, provided in the form of a voice recording and/or transcript, to assess them against the qualifications and characteristics outlined in the job description.
For select roles, Coinbase is also piloting an AI interview intelligence platform to transcribe and summarize interview notes, allowing our interviewers to fully focus on you as the candidate.
*The above pilots are for testing purposes and Coinbase will not use AI to make decisions impacting employment*. To request a reasonable accommodation due to disability, please contact accommodations(at)coinbase.com
View Now

Cyber SDC - WAM Penetration Tester - Senior - Location OPEN

43201 Columbus, Ohio EY

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Location: Anywhere in Country
At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
**Title: Cybersecurity - Attack and Penetration Tester**
**Practice Description**
Cyber threats, social media, massive data storage, privacy requirements and continuity of the business as usual require heavy information security measures. As an information security specialist, you will lead the implementation of security solutions for our clients and support the clients in their desire to protect the business. You will belong to an international team of cybersecurity specialists helping our clients with their most complex information security needs and contributing toward their business resilience. You will be working with our Advanced Security Centers to access the most sophisticated tools available to fight against cybercrime.
**The Opportunity**
Our security professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team works together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients.
We will support you with career-long training and coaching to develop your skills. As EY is a global leading service provider in this space, you will be working with the best of the best in a collaborative environment. So, whenever you join, however long you stay, the exceptional EY experience lasts a lifetime.
**Your Key Responsibilities**
Our security professionals possess diverse industry knowledge, along with unique technical expertise and specialized skills. The team stays highly relevant by researching and discovering the newest security vulnerabilities, attending and speaking at top security conferences around the world, and sharing knowledge on a variety of cybersecurity topics with key industry groups. The team frequently provides thought leadership and information exchanges through traditional and less conventional communications channels such as speaking at conferences and publishing white papers.
As part of our Penetration Testing team, you'll identify potential threats and vulnerabilities to operational environments. Projects here could include penetration testing and simulating physical breaches to identify vulnerabilities.
Our professionals work together in planning, pursuing, delivering and managing engagements to assess, improve, build, and in some cases operate integrated security operations for our clients.
**Skills and Attributes to success:**
+ Perform penetration testing which includes, web application, API, and Thick client penetration testing
+ Ability to work both independently as well as lead a team of technical testers on penetration testing and red team engagements
+ Provide technical leadership and advise junior team members on attack and penetration test engagements
+ Identify and exploit security vulnerabilities in a wide array of systems in a variety of situations
+ Perform in-depth analysis of penetration testing results and create report that describes findings, exploitation procedures, risks and recommendations
+ Execute penetration testing projects using the established methodology, tools and rules of engagements
+ Convey complex technical security concepts to technical and non-technical audiences including executives
**To Qualify for the Role, You Must Have**
+ A bachelor's degree and at least 5+ years of related work experience
+ Experience with manual attack and penetration testing
+ Experience with scripting / programming skills (eg, Bash, Python, PowerShell, Java, Perl, Rust, Golang, J2EE, .NET, JavaScript, etc)
+ Updated and familiarized with the latest exploits and security trends
+ Any two of the following certifications: OSCP, OSWP, OSEP, OSCE, OSEE, GPEN, GWAPT, GMOB, GCPN, GXPN, GRTP, GDAT, CRTO, CRTP, CRTE, CREST CRT, CCSAS, CWEE, Burp Suite Certified Practitioner, CBBH, eWPTX, OSWA, eWPT, eMAPT
**Ideally, you'll also have**
+ A bachelor's degree in Computer Science, Cybersecurity, Information Systems, Information Technology, Engineering, or a related field with at least 3+ years of related work experience or a master's degree and at least 2+ years of related work experience in penetration testing which includes internet, intranet, web application penetration tests, wireless, social engineering, and red team assessments
+ Contributions to the security community, including research, public CVE disclosures, bug bounty acknowledgments, open-source project involvement, blog posts, publications, and similar activities
+ An understanding of web-based application vulnerabilities (OWASP Top 10)
+ Strong analytical and problem-solving abilities
+ Excellent communication skills, both written and verbal
+ Ability to work collaboratively in a team environment
**What We Look For**
We're interested in intellectually curious people with a genuine passion for cyber security. With your specialization in attack and penetration testing, we'll turn to you to speak up with innovative new ideas that could make a lasting difference not only to us - but also to the industry as a whole. If you have the confidence in both your presentation and technical abilities to grow into a leading expert here, this is the role for you.
**What we offer you**
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $72,500 to $40,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 92,900 to 160,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. 
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
View Now

GRC Security Architect

43201 Columbus, Ohio PSI Services

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

**Description**
**Title:** GRC Security Architect
**Location:** Remote-US
**Salary:** Up to $150K
**About PSI**
Join Us at PSI - Where You Belong, Grow, and Thrive!
At PSI, we believe that people achieve their best when they feel they truly belong. That's why fairness and opportunity are at the heart of everything we do - not just words, but values deeply embedded in our culture and the full employee experience.
We're proud to foster an environment where everyone is supported to reach their full potential. From your first day through every step of your journey with us, you'll feel the difference in how we work, grow, and succeed together.
What You Can Expect From Us - We know that great work starts with feeling valued. That's why we've benchmarked all our roles against local market rates and why you'll always see salary details in our job postings. We believe in transparency, and we want you to feel confident that your next move aligns with your expectations.
**About the Role**
The GRC Security Architect plays a key role in supporting PSI's commitment to data security, privacy, and compliance. This role is responsible for driving core activities across quality, risk management, Information Security, data protection, and audit readiness to ensure the organization meets ISO, PCI, SOC 2, and other relevant standards. The position helps deliver assurance to stakeholders that PSI prioritizes the security and privacy of its data and systems.
This is a full-time, permanent role, Monday to Friday, with flexible working hours around a standard 09:00 - 17:30 schedule. The role reports to the Snr Director of Information Security, Governance, Risk and Compliance and may be performed remotely, with occasional travel to offices and test centres as required for audits and assessments.
This role requires that the successful applicant have experience working on Federal projects, be a United States resident and be able to obtain Federal clearance.
  **Role Responsibilities**
+ Collaborating with Internal teams to ensure that secure systems and networks are designed and implemented.
+ Identify potential security vulnerabilities within existing and prospective systems and devise strategies to address them.
+ Working with internal teams ensure that our infrastructure and applications adhere to established security measures.
+ Identify security risks in our organization and come up with possible preventative measures.
+ Assess the organization's security status in order to identify areas that need improvement.
+ Stay up-to-date with the emergence of new security threats while continuously adopting the industry's best practices.
+ Collaborate with internal teams to embed Security by Design principles in Infrastructure, Development and DevOps practices, implementing a framework to ensure that security controls are documented for all systems as part of standard operating procedures.
+ Collaborate with internal teams to support an integrated end-to-end GRC approach across the organization.
+ Maintain and update security policies, standards, procedures, and guidelines, ensuring they align with current business and IT practices.
+ Monitor and assess the effectiveness of security controls across business systems and processes.
+ Ensure alignment with client, regulatory, and internal compliance requirements.
+ Support the automation and continual improvement of GRC processes and tools.
+ Generate and present GRC-related metrics and reports to internal stakeholders and executive leadership.
+ Support internal and external audits (e.g., ISO27001, SOC2, etc.), including gathering evidence and managing responses.
+ Build and maintain cross-functional relationships with teams such as Legal, IT, Audit, Finance, and Business Operations to ensure GRC practices support overall business objectives.
+ Support ongoing compliance initiatives, including security incident reviews, risk memos, and policy exceptions.
+ Participate in the development of operational reports, metrics dashboards, and trend analysis related to security and compliance activities.
+ Support audit plans and compliance documentation for internal or external stakeholders.
  **Knowledge, Skills and Experience Requirements**
+ Experience working within, achieving and/or maintaining third-party attestations such as FedRAMP, SOC2, ISO27001
+ Solid understanding of common security tools (e.g., vulnerability scanners, firewalls, IDS/IPS, AV software) strongly recommended
+ Experience working on a Federal Program is essential and contributing to core document set eg SSP, ConMon reporting, POAMs, System Narrative, SCP, SIA
+ Experience implementing or maintaining FedRAMP Moderate Authorization is desirable.
+ Experience documenting security controls in Architecture diagrams is essential
+ Extensive training and experience in IT disciplines such as application and data security, systems programming, systems design, computer technology or software disciplines
+ Familiarity with OneTrust or ServiceNow GRC and Privacy tools desired
+ Certified training in security management, risk and compliance solutions and practices. CISSP, ISSAP, CISA, CISM, GSEC, or related certification(s) desirable.
+ Experience in a fast-paced GRC function (desirable).
  **Benefits & Culture**
Alongside a competitive salary, we offer a comprehensive benefits package designed to support your well-being, your future, and your sense of purpose:  
+ Retirement Benefits: 401(k), pension, or country-specific retirement plans with employer contributions
+ Generous Time Off: Enhanced paid time off/annual leave policies
+ Health & Wellbeing Coverage: Medical insurance tailored to your region, plus:
+ US: Dental, vision, life, and short-term disability insurance
+ UK: Medical cashback plan including dental, vision, and income protection
+ Flexible Spending Accounts (US)
+ Employee Assistance Program (EAP): Confidential support whenever you need it
+ Work-Life Balance: We understand life happens outside of work, and we fully support flexibility
+ Wellness Culture: Regular global wellness initiatives to help you stay healthy and inspired
+ Future Planning: Tools and support to help you grow personally and professionally
+ Giving Back: Enjoy a Volunteer Day each year and opportunities to support our communities and industry
At PSI, we're more than just a workplace - we're a global team driven by shared values and real impact. If you're ready to be part of a company that's committed to your growth and well-being, we'd love to hear from you.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights ( notice from the Department of Labor.
View Now

Senior Penetration Tester (Web/API/Thick-Clients) - Assessments & Exercises Vice President

43201 Columbus, Ohio JPMorgan Chase

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Contribute to leading-edge security and resilience efforts, advancing protective strategies and propelling continuous improvement.
As an Assessments & Exercises Vice President in the Cybersecurity and Technology Controls line of business, you will contribute significantly to enhancing the firm's cybersecurity or resiliency posture by using industry-standard assessment methodologies and techniques to proactively identify risks and vulnerabilities in people, processes, and technology. Design and deploy risk-driven tests and simulations (or manage a highly-skilled team that does) and inform analysis to clearly outline root-causes. In this role, you will evaluate preventative controls, incident response processes, and detection capabilities, and advise cross-functional teams on security strategy and risk management.
**Job responsibilities**
+ Design and execute testing and simulations - such as penetration tests, technical controls assessments, cyber exercises, or resiliency simulations, and contribute to the development and refinement of assessment methodologies, tools, and frameworks to ensure alignment with the firm's strategy and compliance with regulatory requirements
+ Evaluate controls for effectiveness and impact on operational risk, as well as opportunities to automate control evaluation
+ Collaborate closely with cross-functional teams to develop comprehensive assessment reports - including detailed findings, risk assessments, and remediation recommendations - making data-driven decisions that encourage continuous improvement
+ Utilize threat intelligence and security research to stay informed about emerging threats, vulnerabilities, industry best practices, and regulations. Apply this knowledge to enhance the firm's assessment strategy and risk management. Engage with peers and industry groups that share threat intelligence analytics
**Required qualifications, capabilities, and skills**
+ 5+ years of experience in cybersecurity or resiliency, with demonstrated exceptional organizational skills to plan, design, and coordinate the development of offensive security testing, assessments, or simulation exercises
+ Significant experience conducting manual penetration tests against a wide variety of applications and technologies **with a focus on web, API, and thick-clients**
+ Proficiency in software development and debugging
+ Understanding of local data storage, encryption, and application security
+ Knowledge of US financial services sector cybersecurity or resiliency organization practices, operations risk management processes, principles, regulations, threats, risks, and incident response methodologies
+ Ability to identify systemic security or resiliency issues as they relate to threats, vulnerabilities, or risks, with a focus on recommendations for enhancements or remediation, and proficiency in multiple security assessment methodologies (e.g., Open Worldwide Application Security Project (OWASP) Top Ten, National Institute of Standards and Technology (NIST) Cybersecurity Framework), offensive testing tools, or resiliency testing equivalents
+ Excellent communication, collaboration, and report writing skills, with the ability to influence and engage stakeholders across various functions and levels
**Preferred qualifications, capabilities, and skills**
+ Proficiency in security concepts for both Windows and Unix-like Operating Systems
+ Experience in source code review and/or building software with multiple programming languages (i.e. Python, Java, Rust, etc.)
+ Experience in reverse engineering standalone, thick client and mobile applications
+ Experience with hardware hacking tools and techniques
+ Ability to analyze binary firmware images and reverse engineer code
+ Certifications like OSWE, CREST (CRT, CCT), OSCP, OSCE, GXPN, GWAPT, GPEN, BSCP
This role is also open to Atlanta GA | Chicago IL | Washington, DC | Houston TX | Jersey City NJ | McLean VA | Plano TX | Tampa FL | Brooklyn, NY | Wilmington DE.
JPMorganChase, one of the oldest financial institutions, offers innovative financial solutions to millions of consumers, small businesses and many of the world's most prominent corporate, institutional and government clients under the J.P. Morgan and Chase brands. Our history spans over 200 years and today we are a leader in investment banking, consumer and small business banking, commercial banking, financial transaction processing and asset management.
We offer a competitive total rewards package including base salary determined based on the role, experience, skill set and location. Those in eligible roles may receive commission-based pay and/or discretionary incentive compensation, paid in the form of cash and/or forfeitable equity, awarded in recognition of individual achievements and contributions. We also offer a range of benefits and programs to meet employee needs, based on eligibility. These benefits include comprehensive health care coverage, on-site health and wellness centers, a retirement savings plan, backup childcare, tuition reimbursement, mental health support, financial coaching and more. Additional details about total compensation and benefits will be provided during the hiring process.
We recognize that our people are our strength and the diverse talents they bring to our global workforce are directly linked to our success. We are an equal opportunity employer and place a high value on diversity and inclusion at our company. We do not discriminate on the basis of any protected attribute, including race, religion, color, national origin, gender, sexual orientation, gender identity, gender expression, age, marital or veteran status, pregnancy or disability, or any other basis protected under applicable law. We also make reasonable accommodations for applicants' and employees' religious practices and beliefs, as well as mental health or physical disability needs. Visit our FAQs for more information about requesting an accommodation.
JPMorgan Chase & Co. is an Equal Opportunity Employer, including Disability/Veterans
**Base Pay/Salary**
Jersey City,NJ $152,000.00 - $60,000.00 / year; Brooklyn,NY 152,000.00 - 260,000.00 / year; Washington,DC 152,000.00 - 260,000.00 / year; Chicago,IL 133,000.00 - 225,000.00 / year
View Now

Data Protection and Security - Principal Architect

43201 Columbus, Ohio Highmark Health

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

**Company :**
Highmark Health
**Job Description :**
**JOB SUMMARY**
The Data Protection and Security - Principal Architect is a leadership role responsible for defining, implementing, and maintaining enterprise-wide data security and protection strategies. The incumbent will work with other stakeholders to embed sound security practices, principals, and controls in their strategies, programs, and operations. This includes, but is not limited to, specific focus on addressing the unique data and asset protection challenges and opportunities presented by Artificial Intelligence (AI) and Machine Learning (ML) technologies. This role will ensure the confidentiality, integrity, and availability of digital assets across all services, functions, projects, and deliverables, with a strong emphasis on data access control, preventing data leakage and ensuring responsible data handling practices. The Data Protection and Security - Principal Architect is responsible for the evaluation of technologies, use cases, and tools to enhance and to mature data security and protection capabilities and supporting services. Mentors other information security and data professionals and provides guidance on data security and protection leading practices.
**ESSENTIAL RESPONSIBILITIES**
+ Develop systems and component architectures and APIs that meet the test of time. Articulate and evangelize architectural principles reciprocally with engineering, architecture and product teams that ensure system components fit securely, are sustainable, and align with company's business direction. Analyze and recommend novel technologies, architectural solutions (and associated business cases) to the various technology executives across the company which simultaneously optimize value, risk, spend & design footprints.
+ Influence enterprise solutions architects and engineers to define, develop, maintain, and communicate the technology and platform strategy, guidelines, and re-usable design patterns to all levels including the Highmark Health executive team.
+ Work with external and internal engineering teams to provide continuous architecture and design mentorship/leadership and be a source of support that ensures successful product delivery and operational excellence in production, including leadership and support for application development and change management activities.
+ Establish relationships with key architects and executive technology leadership across the enterprise technology organization and collaborate on promoting architectural standard methodologies.
+ Collaborate with key internal and external partners such as security, developers, development managers, product and program management and senior technical and business executives to drive the Architecture strategy, reference enterprise architecture documents, functional specifications, designs, and architectural libraries.
+ Resolve approaches for new areas by quickly investigating and synthesizing the state of the art and available technologies including leading the development of enterprise solutions which meet current and future business requirements.
+ Take a consultative approach to develop, present and share the value and vision of proposed architectures and solutions to a wide audience
+ Promote architecture standard methodologies and mentor key technical people within the Data Product organization.
+ Champion a culture of innovation in an environment that requires high levels of scalability, security and reliability for our most critical enterprise cloud and 'on premise' applications and infrastructure.
+ Other duties as assigned or requested.
**EXPERIENCE**
**Required**
+ 10 years of experience in Information Security.
+ 4 years of experience as Information Security Architect with deep understanding of domains of security (e.g. zero trust, data protection, identity & access mgmt., threat mgmt., etc.)
+ 3 years of experience with data management, query processing, distributed processing, high availability, statistical and machine learning and operational excellence of production systems.
**Preferred**
+ 3 years of experience in Mergers and Acquisitions (evaluation, integration, etc.)
+ 3 years of experience managing and leading teams.
**SKILLS**
+ Outstanding verbal, written, presentation, facilitation, and interaction skills, including ability to effectively communicate architectural issues and concepts to technical and non-technical people at multiple organization levels
+ Outstanding technical acumen across a broad range of cloud and on premise technologies, architectures, applications and APIs
+ Demonstrated ability to initiate and guide enterprise technical programs and/or products and services business cases to successful outcomes at scale
+ Demonstrated ability to both navigate technical details for enterprise security programs and services, and guide staff through solution development
+ Outstanding judgement and ability to methodically analyze cyber risk, and intelligence and both offer risk appropriate advice and make risk appropriate decisions
**Preferred Skills Experience**
+ Significant knowledge and experience with data architecture concepts, practices, tools, and strategies
+ AI Security Expertise: Serve as the subject matter expert on data security and protection best practices for AI/ML systems, including but not limited to:
+ Data privacy in AI model development and deployment.
+ Security of AI algorithms and models against adversarial attacks.
+ Bias detection and mitigation in AI systems.
+ Secure data handling and storage for AI training data.
+ Ensuring compliance with ethical AI principles.
**EDUCATION**
**Required**
+ Bachelor's degree in Computer Science or related field of studyor relevant experience and/or education as determined by the company in lieu of bachelor's degree.
**Preferred**
+ Masters Computer Science or related field of study.
**LICENSES or CERTIFICATIONS**
**Required**
+ None
**Preferred**
+ Security certifications (e.g. The Open Group Architecture Framework Certification (TOGAF), Certified Information Security Professional (CISSP), Certified Information Security Manager (CISM), etc.)

**Language (Other than English):**
None
**Travel Requirement:**
0% - 25%
**PHYSICAL, MENTAL DEMANDS and WORKING CONDITIONS**
**Position Type**
Office- or Remote-based
Teaches / trains others
Occasionally
Travel from the office to various work sites or from site-to-site
Rarely
Works primarily out-of-the office selling products/services (sales employees)
Never
Physical work site required
No
Lifting: up to 10 pounds
Constantly
Lifting: 10 to 25 pounds
Occasionally
Lifting: 25 to 50 pounds
Rarely
**_Disclaimer:_** _The job description has been designed to indicate the general nature and essential duties and responsibilities of work performed by employees within this job title. It may not contain a comprehensive inventory of all duties, responsibilities, and qualifications required of employees to do this job._
**_Compliance Requirement_** _: This job adheres to the ethical and legal standards and behavioral expectations as set forth in the code of business conduct and company policies._
_As a component of job responsibilities, employees may have access to covered information, cardholder data, or other confidential customer information that must be protected at all times. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company's Handbook of Privacy Policies and Practices and Information Security Policy._
_Furthermore, it is every employee's responsibility to comply with the company's Code of Business Conduct. This includes but is not limited to adherence to applicable federal and state laws, rules, and regulations as well as company policies and training requirements._
**Pay Range Minimum:**
$108,000.00
**Pay Range Maximum:**
$201,800.00
_Base pay is determined by a variety of factors including a candidate's qualifications, experience, and expected contributions, as well as internal peer equity, market, and business considerations. The displayed salary range does not reflect any geographic differential Highmark may apply for certain locations based upon comparative markets._
Highmark Health and its affiliates prohibit discrimination against qualified individuals based on their status as protected veterans or individuals with disabilities and prohibit discrimination against all individuals based on any category protected by applicable federal, state, or local law.
We endeavor to make this site accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process, please contact the email below.
For accommodation requests, please contact HR Services Online at
California Consumer Privacy Act Employees, Contractors, and Applicants Notice
Req ID: J
View Now
Be The First To Know

About the latest Information security Jobs in Columbus !

Security Engineer II

43201 Columbus, Ohio Trustmark

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Trustmark's mission is to improve wellbeing - for everyone. It is a mission grounded in a belief in equality and born from our caring culture. It is a culture we can only realize by building trust. Trust established by ensuring associates feel respected, valued and heard. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture of diversity and inclusion where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves. At Trustmark, we have a commitment to welcoming people, no matter their background, identity or experience, to a workplace where they feel safe being their whole, authentic selves. A workplace made up of diverse, empowered individuals that allows ideas to thrive and enables us to bring the best to our colleagues, clients and communities.
We are seeking a highly skilled Cyber Security Engineer to join our team and play a pivotal role in safeguarding our organization's digital assets. The ideal candidate will possess a deep understanding of cybersecurity principles, a strong technical background, and a passion for protecting sensitive information.
You will be responsible for engineering, implementing and monitoring security measures for the protection of Trustmark's computer systems, networks and information. The role helps identify and define system security requirements as well as develop detailed cyber security designs.
**Responsibilities:**
+ Design, implement, and maintain security architectures, systems, and solutions to protect critical infrastructure and data.
+ Conduct vulnerability assessments and penetration testing to identify and mitigate risks.
+ Develop and implement security policies, standards, and procedures.
+ Monitor security systems and respond to incidents promptly and effectively.
+ Stay up-to-date with the latest cybersecurity threats and trends.
+ Collaborate with cross-functional teams to ensure security is integrated into all aspects of the business.
+ Provide technical guidance and support to internal stakeholders.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, or a related field or
+ 3-5 Years of network engineering or cyber engineering experience
+ Strong understanding of cybersecurity frameworks and standards (e.g., NIST, ISO 27001).
+ Proficiency in network security, systems security, application security, and data security.
+ Hands-on experience with security tools and technologies (e.g., firewalls, intrusion detection systems, encryption, SIEM).
+ Excellent problem-solving and analytical skills.
+ Strong communication and interpersonal skills.
+ Ability to work independently and as part of a team.
**Preferred Qualifications:**
+ Certifications such as CISSP, CISA, or CEH.
+ Experience with cloud security (e.g., AWS, Azure, GCP).
+ Knowledge of scripting and programming languages (e.g., Python, PowerShell).
Brand: Trustmark
Come join a team at Trustmark that will not only utilize your current skills but will enhance them as well. Trustmark benefits include health/dental/vision, life insurance, FSA and HSA, 401(k) plan, Employee Assistant Program, Back-up Care for Children, Adults and Elders and many health and wellness initiatives. We also offer a Wellness program that enables employees to participate in health initiatives to reduce their insurance premiums.
**For the fourth consecutive year we were selected as a Top Workplace by the Chicago Tribune.** The award is based exclusively on Trustmark associate responses to an anonymous survey. The survey measured 15 key drivers of engaged cultures that are critical to the success of an organization.
All qualified applicants will receive consideration for employment without regard to race, religion, color, national origin, sex, sexual orientation, sexual identity, age, veteran or disability.
Join a passionate and purpose-driven team of colleagues who contribute to Trustmark's mission of helping people increase wellbeing through better health and greater financial security. At Trustmark, you'll work collaboratively to transform lives and help people, communities and businesses thrive. Flourish in a culture where appreciation, mutual respect and trust are constants, not just for our customers but for ourselves.
Introduce yourself to our recruiters and we'll get in touch if there's a role that seems like a good match.
When you join Trustmark, you become part of an organization that makes a positive difference in people's lives. You will play a vital role in delivering on our mission of helping people increase wellbeing through better health and greater financial security. Our customers tell us they simply appreciate the personal attention and knowledgeable service. Others tell us we've changed their lives.
At Trustmark, you'll be part of a close-knit team. You'll enjoy abundant opportunities to grow your career. That's why so many of our associates stay at Trustmark and thrive. Trustmark benefits from more than 100 years of experience but pairs that rich history with a palpable sense of optimism, growth and excitement for what's ahead - and beyond. This is a place where associates bring their whole selves to work each day. A place where you can be yourself. Whatever your beyond is, you can achieve it at Trustmark.
View Now

Principal Security Engineer - Hardware Security

43201 Columbus, Ohio Oracle

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

**Job Description**
The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive scale, integrated cloud services in a broadly distributed, multi-tenant cloud environment. OCI is committed to providing the best in cloud products that meet the needs of our customers who are tackling some of the world's biggest challenges.
We offer unique opportunities for smart, hands-on security engineers with the expertise and passion to solve difficult problems in distributed highly available services and virtual infrastructure. At every level, our engineers have a significant technical and business impact designing and building innovative new systems to power our customer's business critical applications. Our customers run their businesses on our cloud, and our mission is to provide them with the most secure cloud services.
The OCI Hardware Security group conducts Security assessments of the production hardware that runs our cloud, and develops the requirements for future Networking, Storage, Compute components. We work closely across Oracle, with third party vendors, and with standards organization to influence the next generation of hardware platform security. In addition to defining the best hardware, OCI HW Security knows that platform security also depends on how that hardware is used. To that end, HW Security also works closely with OCI's operations and engineering teams, constantly striving to improve Oracle Cloud's overall operational security posture by defining the supply chain and operational requirements to establish best practices for managing security for every device in our data centers.
A security-focused engineer at any level can have significant technical and business impact. Come shape the future of one of the largest clouds on earth with us. Overall, the OCI Security Architecture team performs a variety of work ranging from cloud security, application security, vulnerability analysis, threat modeling, and hacking/enterprise network penetration.
The biggest challenges for the team are the dynamic and fast growth of the business, driving us to improve our systems, tools, and automation to scale to our security expertise several orders of magnitude greater than what we can support today. We understand that software is living and needs investment. The challenge is making the right tradeoffs, communicating those decisions effectively, and crisp execution.
**Responsibilities**
Career Level - IC4
+ Develop and communicate requirements for new vendors and hardware (compute, storage, networking)
+ Perform architectural reviews, penetration testing, vulnerability analysis of compute infrastructure hardware such as
o Servers (Intel, AMD and ARM)
o Baseboard Management Controllers such as Oracle's ILOM
o UEFI and platform firmware
o Smart NICS
o Storage devices
o Network controllers and other peripherals
Network hardware/firmware, topology, and security expertise
+ Provide consulting on security risk associated with compute hardware and firmware in the context of cloud usage.
+ Provide consulting and review of device sanitization as per NIST-800-88 R1 standards.
+ Provide standard operating procedures for safe use of compute hardware through its lifecycle i.e., provisioning, operations and reuse/decommission.
Skills
+ Engage with Oracle Hardware Division and third-party vendors to understand their roadmaps.
+ Create planning roadmaps to drive multi-year security improvements across the OCI Infrastructure
+ Review or assess engineering changes, or revisions of, an existing component. E.g.: new firmware for a device, vendor revision of an existing device Identify and participate in external standards groups to drive improvements across the industry
+ Consult development teams and third-party vendors in design and architecture of secure systems.
+ Champion and consult on secure development life cycle practices.
+ Communicate and educate Senior Management on key Security topics and directions.
Disclaimer:
**Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.**
**Range and benefit information provided in this posting are specific to the stated locations only**
US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
Career Level - IC4
**About Us**
As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing or by calling in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
View Now

Cyber SDC- M365 Security Operations Lead Engineer - Senior - Consulting - Location Open

43201 Columbus, Ohio EY

Posted 5 days ago

Job Viewed

Tap Again To Close

Job Description

Location: Anywhere in Country
At EY, we're all in to shape your future with confidence.
We'll help you succeed in a globally connected powerhouse of diverse teams and take your career wherever you want it to go. Join EY and help to build a better working world.
We are seeking a skilled and motivated Microsoft Purview and Defender for Office Operations Engineer to join our cybersecurity team. The ideal candidate will be responsible for the administration, management, and optimization of Microsoft Purview and Microsoft Defender for Office platforms. This role requires a strong understanding of data governance, compliance, and security best practices, along with the ability to work collaboratively with cross-functional teams to enhance our information protection posture.
**Key Responsibilities:**
1. **Platform Administration:**
1. Administer and support Microsoft Purview and Microsoft Defender for Office, ensuring optimal performance and availability of the platforms.
2. Configure and manage security settings, policies, and compliance features within Microsoft Purview and Defender for Office.
2. **Data Governance and Compliance:**
1. Implement and maintain data governance policies and procedures to ensure compliance with regulatory requirements and organizational standards.
2. Monitor and report on compliance metrics, data classification, and data loss prevention (DLP) policies.
3. **User Support:**
1. Provide technical support to end-users regarding Microsoft Purview and Defender for Office tools and best practices.
4. **Collaboration and Communication:**
1. Work closely with IT, security, and compliance teams to integrate Microsoft Purview and Defender for Office with existing systems and workflows.
2. Communicate effectively with stakeholders to report on security incidents, compliance metrics, and recommendations for improvement.
5. **Continuous Improvement:**
1. Stay updated on the latest features, updates, and best practices related to Microsoft Purview and Defender for Office.
2. Identify opportunities for process improvements and automation within the operations of Microsoft Purview and Defender for Office.
3. Automate activities through scripting (PowerShell, Python) and automation (Tines, PowerAutomate, etc.)
6. **Documentation and Reporting:**
1. Maintain accurate documentation of configurations, processes, and procedures related to Microsoft Purview and Defender for Office operations.
2. Generate reports on platform performance, security incidents, and compliance metrics for management review.
**Qualifications:**
+ Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
+ Proven experience in managing and supporting Microsoft Purview and Microsoft Defender for Office.
+ Strong understanding of data governance, compliance frameworks, and information security best practices.
+ Excellent problem-solving skills and attention to detail.
+ Strong communication and interpersonal skills.
+ Scripting experience, including PowerShell, Python, etc.
+ Ticket and change management experience in ServiceNow
+ Relevant certifications (e.g., Microsoft Certified: Security, Compliance, and Identity Fundamentals, Microsoft Certified: Azure Security Engineer Associate) are a plus.
**Preferred Skills:**
+ Experience with data loss prevention (DLP) technologies and strategies.
+ Familiarity with compliance regulations (e.g., GDPR, HIPAA) and data protection laws.
+ Knowledge of cloud security concepts and technologies.
**Work Environment:**
This position may require occasional after-hours support and on-call availability. The Microsoft Purview and Defender for Office Operations Engineer will work in a collaborative team environment, contributing to the overall security and compliance posture of the organization.
**What we offer you**
At EY, we'll develop you with future-focused skills and equip you with world-class experiences. We'll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn more .
+ We offer a comprehensive compensation and benefits package where you'll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $77,500 to $40,900. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is 92,900 to 160,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
+ Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
+ Under our flexible vacation policy, you'll decide how much vacation time you need based on your own personal circumstances. You'll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.
**Are you ready to shape your future with confidence? Apply today.**
EY accepts applications for this position on an on-going basis.
For those living in California, please click here for additional information.
EY focuses on high-ethical standards and integrity among its employees and expects all candidates to demonstrate these qualities.
**EY | Building a better working world**
EY is building a better working world by creating new value for clients, people, society and the planet, while building trust in capital markets.
Enabled by data, AI and advanced technology, EY teams help clients shape the future with confidence and develop answers for the most pressing issues of today and tomorrow.
EY teams work across a full spectrum of services in assurance, consulting, tax, strategy and transactions. Fueled by sector insights, a globally connected, multi-disciplinary network and diverse ecosystem partners, EY teams can provide services in more than 150 countries and territories.
EY provides equal employment opportunities to applicants and employees without regard to race, color, religion, age, sex, sexual orientation, gender identity/expression, pregnancy, genetic information, national origin, protected veteran status, disability status, or any other legally protected basis, including arrest and conviction records, in accordance with applicable law. 
EY is committed to providing reasonable accommodation to qualified individuals with disabilities including veterans with disabilities. If you have a disability and either need assistance applying online or need to request an accommodation during any part of the application process, please call 1-800-EY-HELP3, select Option 2 for candidate related inquiries, then select Option 1 for candidate queries and finally select Option 2 for candidates with an inquiry which will route you to EY's Talent Shared Services Team (TSS) or email the TSS at .
View Now
 

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Information Security Jobs View All Jobs in Columbus