13,651 Cybersecurity Engineers jobs in the United States
Sr. Cybersecurity Engineers
Posted today
Job Viewed
Job Description
Axient is seeking Senior Cyber Engineers for the Washington Navy Yard. Work is onsite four days a week. Secret clearance (minimum) is required. Salary is in the 130-155k range.
What you will do.
- Roles and Responsibilities: Provide cybersecurity expertise to surface combat system program offices.
- Lead efforts to bring platform information technology systems through the full life cycle of the Risk Management Framework (RMF) process to achieve/renew Authority to Operate (ATO).
- Develops, coordinates, and reviews detailed Assessment & Authorization documentation in accordance with DoD Instruction 8510.01.
- Review systems scans/tests using the Security Content Automation Protocol (SCAP) Compliance Checker (SCC), and the Assured Content Assessment Solution (ACAS).
- Coordinate with support team to ensure the hardening of systems under test to conforms all applicable regulations from DoD and the Defense Information Systems Agency (DISA). This includes but is not limited to Security Technical Implementation Guides (STIG), Security Requirements Guides (SRG).
- Work with the NAVSEA, PEO IWS, combat system program offices to ensure DOD/DON cybersecurity regulations and best practices are followed in the design, development, and sustainment of the integrated combat systems and weapon systems.
- Work as a team player comfortable interacting with many different people and effective at verbal and written communication, supporting face-to-face meetings, phone, and email interactions with program leads, engineers, and team members.
- Advise DoD customers on secure design and implementation of systems and capabilities.
- Identify security vulnerabilities and weaknesses in SW, HW, and Architecture design for mission environments and be able to make recommended mitigations.
- Provide mentorship and training to other team members.
- Build briefs to convey critical information to decision makers.
- Track and report status of RMF packages in portfolio.
- Advise leadership and stakeholders on the cybersecurity integration, alignment, and implementation of capabilities and systems.
- Identify security vulnerabilities and weaknesses in SW, HW, and Architecture design for mission environments and recommend mitigations.
- Provide general cybersecurity and RMF expertise and support to DoD programs.
Skills you will need.
Qualifications:
- Must have an active DoD SECRET security clearance and must be able to maintain one.
- Ability to work independently in a fast-paced environment with competing priorities.
- Technical IT and cyber security background.
- Excellent written skills since the validator develops and/or updates written system authorization supporting artifacts.
- Excellent verbal skills since the validator works directly with the program offices and leadership to communicate progress, status, recommendations, and related information.
- Excellent teamwork skills since the validator works in cooperation with program offices, different ISEAs and other support organizations.
- Excellent organizational skills since the validator may work several packages at once.
- Knowledge of DoD and DON cyber policies and procedures and/or NIST 800-53, DoDI 8500.01, and DoDI 8510.01.
- A high school degree, or a GED, and more than twenty (20) years of relevant experience in cyber security, information system management, software development, design or authorization OR
- A bachelor's degree in a relevant field and fifteen (15) years of relevant experience in cyber security, information system management, software development, design or authorization OR
- A master's degree in a relevant field and ten (10) years of relevant experience in cyber security, information system management, software development, design or authorization.
- At least one or more of the following is preferred: A+, Sec+, CAP, IAM, CISSP, CEH.
Desired:
- Certification: DoD 8570 (IAT Level III/IAM Level III), Navy Qualified Validator.
- Knowledge of PEO IWS Instruction 5239.1.
- Familiarity with PEO IWS organization and systems.
Information Security Architect
Posted 4 days ago
Job Viewed
Job Description
This is a remote role that may be hired in several markets across the United States.
**Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as needed basis.
This position is responsible for delivering architecture intent to enterprise stakeholders and the Information Security organization at-large, that ensures the secure realization of business initiatives in a manner consistent with the Bank's current and future risk appetite.
Responsibilities-
- Security Strategy: assists in designing and implementing security strategies for assigned subject matter domain (e.g., Identity and Access Management, Compute) and Information Security, at-large based on knowledge of the assigned-domain; bank policies and standards; current, and anticipated, regulatory requirements; and expected threats and associated risks.
- Security Architecture: review existing and proposed architectures, identify security gaps - through threat modeling and/or technical risk assessment, and recommend changes and/or enhancements. Continuously enhance process(es) to drive scale, consistency, repeatability, to this end.
- Solutions Architecture: as required, function as a solutions architect for security solutions; provide the initial solutions architecture, assist with foundational integrations, and lead the initial implementation of solutions
- Business Support: serve as an Information Security subject matter expert, providing advisory and consulting services to stakeholders, as required. To this end, effectively communicate to technical and nontechnical audiences alike in both oral and written form.
- Continuous Education: maintains a strong knowledge of developments in information technology, developments in security technology, and emerging security threats. Utilizes knowledge to influence security strategy - e.g., identity technology capabilities needed to address threats; establish secure design patterns for emergent technologies
Qualifications
Bachelor's Degree and 8 years of experience in Information Technology including Information Security OR High School Diploma or GED and 12 years of experience in Information Technology including Information Security
Preferred Qualifications:
- 4+ years of providing architecture and/or security architecture subject matter expertise in a large-scale enterprise environment
- Demonstrable experience with threat modelling (e.g., PASTA, STRIDE, DREAD) and technical risk assessment in an enterprise environment
- Familiarity with one of more Industry-standard security framework - e.g., NIST RMF, NIST CSF, COBIT, ISO, CIS, CSA CCM
- Familiarity with one of more Industry-standard architectural framework - e.g., TOGAF, DODAF, Zachman
- Familiarity with one of more cyber-attack taxonomy (e.g., CAPEC, ATT&CK)
- Advanced Security Certifications, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are highly desirable.
- Experience with scripting and/or programming
- Effective communicator, capable of effectively translating and presenting complex technical concepts to both technical and non-technical management and customers, through oral presentations and written media (white papers and demonstrations)
- Exceptional interpersonal skills and a collaborative spirit that enables you to work effectively with stakeholders at all levels, agnostic of background
- Strategic planning and execution, with a talent for turning complex challenges into actionable solutions.
- Strong analytical skills with high attention to detail and accuracy with the ability to use data-driven metrics to communicate change and risk reduction.
- Large Financial Institution (LFI) experience
This job posting is expected to remain active for 14 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.
The base pay for this position is generally between $143,000 and $185,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at
#J-18808-LjbffrInformation Security Architect
Posted 4 days ago
Job Viewed
Job Description
This is a remote role that may be hired in several markets across the United States.
**Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as needed basis.
This position is responsible for delivering architecture intent to enterprise stakeholders and the Information Security organization at-large, that ensures the secure realization of business initiatives in a manner consistent with the Bank's current and future risk appetite.
Responsibilities-
- Security Strategy: assists in designing and implementing security strategies for assigned subject matter domain (e.g., Identity and Access Management, Compute) and Information Security, at-large based on knowledge of the assigned-domain; bank policies and standards; current, and anticipated, regulatory requirements; and expected threats and associated risks.
- Security Architecture: review existing and proposed architectures, identify security gaps - through threat modeling and/or technical risk assessment, and recommend changes and/or enhancements. Continuously enhance process(es) to drive scale, consistency, repeatability, to this end.
- Solutions Architecture: as required, function as a solutions architect for security solutions; provide the initial solutions architecture, assist with foundational integrations, and lead the initial implementation of solutions
- Business Support: serve as an Information Security subject matter expert, providing advisory and consulting services to stakeholders, as required. To this end, effectively communicate to technical and nontechnical audiences alike in both oral and written form.
- Continuous Education: maintains a strong knowledge of developments in information technology, developments in security technology, and emerging security threats. Utilizes knowledge to influence security strategy - e.g., identity technology capabilities needed to address threats; establish secure design patterns for emergent technologies
Qualifications
Bachelor's Degree and 8 years of experience in Information Technology including Information Security OR High School Diploma or GED and 12 years of experience in Information Technology including Information Security
Preferred Qualifications:
- 4+ years of providing architecture and/or security architecture subject matter expertise in a large-scale enterprise environment
- Demonstrable experience with threat modelling (e.g., PASTA, STRIDE, DREAD) and technical risk assessment in an enterprise environment
- Familiarity with one of more Industry-standard security framework - e.g., NIST RMF, NIST CSF, COBIT, ISO, CIS, CSA CCM
- Familiarity with one of more Industry-standard architectural framework - e.g., TOGAF, DODAF, Zachman
- Familiarity with one of more cyber-attack taxonomy (e.g., CAPEC, ATT&CK)
- Advanced Security Certifications, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are highly desirable.
- Experience with scripting and/or programming
- Effective communicator, capable of effectively translating and presenting complex technical concepts to both technical and non-technical management and customers, through oral presentations and written media (white papers and demonstrations)
- Exceptional interpersonal skills and a collaborative spirit that enables you to work effectively with stakeholders at all levels, agnostic of background
- Strategic planning and execution, with a talent for turning complex challenges into actionable solutions.
- Strong analytical skills with high attention to detail and accuracy with the ability to use data-driven metrics to communicate change and risk reduction.
- Large Financial Institution (LFI) experience
This job posting is expected to remain active for 14 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants.
The base pay for this position is generally between $143,000 and $185,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment.
Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at
#J-18808-LjbffrInformation Security Architect
Posted 7 days ago
Job Viewed
Job Description
Overview This is a remote role that may be hired in several markets across the United States. **Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as needed basis. This position is responsible for delivering architecture intent to enterprise stakeholders and the Information Security organization at-large , that ensures the secure realization of business initiatives in a manner consistent with the Bank’s current and future risk appetite. Responsibilities Security Strategy: assists in designing and implementing security strategies for assigned subject matter domain (e.g., Identity and Access Management, Compute) and Information Security, at-large based on knowledge of the assigned-domain; bank policies and standards; current, and anticipated, regulatory requirements; and expected threats and associated risks. Security Architecture: review existing and proposed architectures, identify security gaps – through threat modeling and/or technical risk assessment, and recommend changes and/or enhancements. Continuously enhance process(es) to drive scale, consistency, repeatability, to this end. Solutions Architecture: as required, function as a solutions architect for security solutions; provide the initial solutions architecture, assist with foundational integrations, and lead the initial implementation of solutions Business Support: serve as an Information Security subject matter expert, providing advisory and consulting services to stakeholders, as required. To this end, effectively communicate to technical and nontechnical audiences alike in both oral and written form. Continuous Education: maintains a strong knowledge of developments in information technology, developments in security technology, and emerging security threats. Utilizes knowledge to influence security strategy – e.g., identity technology capabilities needed to address threats; establish secure design patterns for emergent technologies Qualifications Bachelor's Degree and 8 years of experience in Information Technology including Information Security OR High School Diploma or GED and 12 years of experience in Information Technology including Information Security Preferred Qualifications: 4+ years of providing architecture and/or security architecture subject matter expertise in a large-scale enterprise environment Demonstrable experience with threat modelling (e.g., PASTA, STRIDE, DREAD) and technical risk assessment in an enterprise environment Familiarity with one of more Industry-standard security framework – e.g., NIST RMF, NIST CSF, COBIT, ISO, CIS, CSA CCM Familiarity with one of more Industry-standard architectural framework – e.g., TOGAF, DODAF, Zachman Familiarity with one of more cyber-attack taxonomy (e.g., CAPEC, ATT&CK) Advanced Security Certifications, such as Certified Information Systems Security Professional (CISSP) or Certified Information Security Manager (CISM) are highly desirable. Experience with scripting and/or programming Effective communicator, capable of effectively translating and presenting complex technical concepts to both technical and non-technical management and customers, through oral presentations and written media (white papers and demonstrations) Exceptional interpersonal skills and a collaborative spirit that enables you to work effectively with stakeholders at all levels, agnostic of background Strategic planning and execution, with a talent for turning complex challenges into actionable solutions. Strong analytical skills with high attention to detail and accuracy with the ability to use data-driven metrics to communicate change and risk reduction. Large Financial Institution (LFI) experience This job posting is expected to remain active for 14 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants. The base pay for this position is generally between $143,000 and $185,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment. Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at #J-18808-Ljbffr
Information Security Architect
Posted 7 days ago
Job Viewed
Job Description
This is a remote role that may be hired in several markets across the United States. - - Remote with ability to travel to Raleigh, North Carolina, Phoenix, Arizona or Morristown, New Jersey, on an as needed basis. This position is responsible for del Security, Architect, Solutions Architect, Information Technology, Information, Technical, Banking
Information Security Architect
Posted 8 days ago
Job Viewed
Job Description
Job Description We are looking for a Lead Information Security Architect who will be responsible for developing and maintaining a comprehensive information security architecture program. The role involves representing information security requirements across all technology solutions and business processes, covering multiple disciplines such as systems & networking infrastructure, DevOps, security, business applications, cloud security, and data architecture. The role oversees cybersecurity for our company's digital products, including software, firmware, or products containing code. This includes implementing a product security program designed to address cybersecurity throughout the product lifecycle. The role also involves identifying and mitigating technical and operational threats, analyzing the security, supportability, and feasibility of new technology, and ensuring compliance with regulatory guidelines and industry best practices. This position requires high-level analytical problem-solving skills to diagnose and resolve complex technical issues, along with excellent process management and communication skills. Note: U.S. and those authorized to work in the U.S. are encouraged to apply. We are unable to sponsor at this time. To be Successful in this Role Develop an architectural vision to support the growth of the product suite. Knowledge of Data Security Best Practices: At Rest, In Flight, In Use. Experience with privacy-enhancing technologies and encryption techniques. Understanding of cloud security architecture strategies, frameworks, and reference models. Ability to develop effective partnerships with senior management and peers, and explain technical concepts to non-technical executives. Build Risk Models and analyze security weaknesses in complex deployments. Provide security expertise on cloud architecture, design, implementation, maintenance, governance, and risk management projects. Work with governance teams to establish automated processes and best practices for AWS, Azure IAM policies, roles, federation, etc. Conduct automated or manual security validation of cloud templates and infrastructure. Collaborate with business units to ensure solutions align with organizational policies and standards. Develop and enforce standards and guidelines for infrastructure solutions, development processes, hardware, and data design. Partner with stakeholders to build scalable, agile security architecture. Assess current IT portfolios and design future strategies to meet business objectives. Make strategic technology recommendations and incorporate them into roadmaps. Ensure alignment with long-term business requirements and provide thought leadership. Optimize architectural components for cost, flexibility, reliability, and security. Balance strategic planning with urgent delivery in a fast-paced environment. Manage influence and demonstrate credibility as a thought leader. Build long-term relationships with internal customers and stakeholders. Document architecture designs and relationships comprehensively. You Will Have 8+ years of experience in information security architecture, with expertise in defense-in-depth reference architectures. Industry security certifications such as CISSP, CISM, CISA, CCSP, etc. Knowledge of information management, SDLC, ITSM, agile/lean methodologies, infrastructure, and operations. Familiarity with SaaS, IaaS, PaaS, SOA, APIs, microservices, event-driven IT, and analytics. Hands-on experience with AWS, Azure, and GCP. Understanding of security solutions like IDS, IPS, SIEM, vulnerability scanning, and compliance. Experience with attack mitigation, network protocols, OS internals, web security, penetration testing, cryptography, intrusion detection, incident response, and automation frameworks. Proven ability to manage and contribute to incident response plans. Experience in developing strategic security plans, standards, and requirements documentation. #J-18808-Ljbffr
Information Security Architect
Posted 13 days ago
Job Viewed
Job Description
At the forefront of the staffing industry, Artech is a women-owned business enterprise (WBE) committed to maximizing global workforce solutions on behalf of its clients. Artech's deep heritage, proven expertise, and insightful market intelligence have secured long-term partnerships with Fortune 500 and government clients seeking world-class professional resources. Artech employs over 7000 industry professionals supported by over 25 national and global locations coast-to-coast across India, the US, and China. Artech's Fortune 500 and government clients leverage this expansive reach by engaging Artech as a preferred go-to supplier across multiple regions and countries in order to receive consistent deliverables, terms, rates, and cost savings. Job Description Info Security Engineer: Position Overview: This Information Security Engineer position is part of the Technology Services Group in the Information Technology division at Freddie Mac. The role will lead efforts to install, configure, and manage the centralized policy management solution like CA Control Minder. It will require shift work (including day and night). Responsibilities include: Tool Management – Manage/Operate the existing tools like CA Control Minder (CA PIM)/CA Access Control in order to manage the security policy in Freddie Mac. Basic Requirements: 5-7 years of professional IT experience, at least 3 years of information security experience. Bachelor’s degree in Information Security, Information Technology, Management Information Systems, or equivalent work experience. Solid knowledge of CA Control Minder (CA PIM) including Installation, Configuration, Administration, Policy Development, and Troubleshooting. UNIX shell scripting skill is a plus. Strong technical writing skills required. Preferred Skills: Previous experience managing UNIX administration is a plus. Must be able to work independently and in a team environment. Ability to understand and write the security rules/policies for the tools, troubleshoot, and resolve issues in a timely manner. Shell scripting experience would be a plus. Additional Information All your information will be kept confidential according to EEO guidelines. #J-18808-Ljbffr
Be The First To Know
About the latest Cybersecurity engineers Jobs in United States !
Information Security Architect
Posted 14 days ago
Job Viewed
Job Description
We have an opening for an Information Security Architect to join the organization. The Information Security Architect will directly report to the CISO and will play a pivotal role in shaping the firm's security architecture as we transition from traditional on-premises environments to a cloud-first model centered on Microsoft 365. This position requires a deep understanding of cloud security, enterprise-scale cyber technologies, and strong collaboration with cross-functional teams. We are ideally seeking candidates with strong cloud experience coupled with a strong general cyber architecture background and experience with cyber controls and network. Candidates must have cloud experience. This position is 100% Onsite and not open for Remote.
Information Security Architect Responsibilities:
- Design and oversee the firm's information security architecture, focusing on cloud-first solutions (e.g., Microsoft 365, Azure, etc.) while ensuring seamless integration with on-premises environments.
- Evaluate, recommend, and implement cutting-edge tools to enhance the firm's cyber defense capabilities, including areas such as CSPM (Cloud Security Posture Management) and SSPM (SaaS Security Posture Management).
- Architect and design solutions that align with the principles of Zero Trust including SASE (secure access service edge) and ZTNA (zero trust network access).
- Collaborate closely with the Cyber Engineering and Operations teams to ensure the architecture supports operational needs and aligns with security objectives.
- Conduct security assessments of existing and proposed systems, identifying gaps and recommending solutions that meet compliance, legal, and risk management requirements.
- Develop and maintain comprehensive documentation of security architecture, design principles, and system configurations.
- Act as the subject matter expert on cloud security, network, endpoint, mobile, and data security by providing guidance and mentorship to teams across the organization.
- Stay current with emerging security threats, trends, and technologies, ensuring the firm's architecture remains robust and adaptive to evolving risks.
- Engage with stakeholders, including IT, legal, and compliance teams, to align security objectives with broader organizational goals.
Information Security Architect Qualifications:
- Bachelor's degree in computer science, Information Security or a related field is preferred; master's degree is preferred.
- 10+ years of progressive experience in information security, with at least 5 years in a senior architect or equivalent role is required.
- Must have cloud experience.
- Need strong general cyber architecture background and experience with cyber controls and network.
- Strong knowledge of modern cyber technologies and tools, including but not limited to CSPM, SSPM, EDR, SIEM, and CASB.
- Familiarity with security frameworks such as NIST CSF, ISO 27001, and CIS Critical Security Controls.
- Proven expertise in designing and implementing cloud security controls, particularly within Microsoft 365 and Azure environments.
- Hands-on experience with threat modeling, risk assessments, and vulnerability management in hybrid IT environments.
- Exceptional communication and collaboration skills, with the ability to engage effectively with both technical and non-technical stakeholders.
- Strong analytical and problem-solving abilities.
- A proactive mindset with a focus on driving security innovation and operational excellence.
- Self-starter with the ability to work independently and lead strategic initiatives.
- Detail-oriented with a commitment to delivering high-quality results.
- Adaptability to a fast-paced and dynamic work environment.
- Relevant certifications such as CISSP, CISM, CCSP, or Azure Security Engineer are strongly preferred.
- Experience in legal or other highly regulated industries is a plus but not required.
Benefits include Medical, Dental, Vision, Life/AD&D, Long Term Care, and Short- and Long-Term Disability, Flexible Spending Account, Health Savings Account, Lifestyle Spending Account, Voluntary 401(k) Plan, Profit Sharing, etc.
Keywords: Washington, DC Jobs, Information Security Architect, Senior Architect, Information Security, Cloud, Cyber Controls, Network, EDR, SIEM, CASB, NIST CSF, ISO 27001, CIS Critical Security Controls, Security Frameworks, Microsoft 365, Azure, CSPM, Cloud Security Posture Management, SSPM, SaaS Security Posture Management, SASE, Secure Access Service Edge, ZTNA, Zero Trust Network Access, Networking, Washington, DC Recruiters, Information Technology Jobs, IT Jobs, Washington, DC Recruiting
Looking to hire for similar positions in Washington, DC or in other cities? Our IT recruiting agencies and staffing companies can help.
We help companies that are looking to hire Information Security Architects for jobs in Washington, DC and in other cities too. Please contact our IT recruiting agencies and IT staffing companies today! Phone ext. 11 or email us at Click here to submit your resume for this job and others.
Atlanta Georgia IT Recruiters, Austin TX IT Recruiters, Baltimore Executive Staffing, Boston IT Recruiters, Charlotte IT Recruiters, Chicago Recruiting Agency, Cincinnati Executive Search Firms, Cleveland Executive Tech Recruiting, Columbus Technical Recruiters, Dallas Recruiters for IT, Denver Technology Headhunters, Detroit IT Headhunters, Fort Lauderdale Information Technology Recruiters, Houston IT Recruiters, Indianapolis IT Recruiters, Jacksonville IT Recruiters, Kansas City IT Recruiters, Los Angeles IT Recruiters, Miami IT Recruiters, Minneapolis IT Recruiters, Nashville IT Recruiters, New Jersey Tech Recruiters, New York IT Recruiters, Phoenix IT Recruiters, Raleigh IT Recruiters, Salt Lake City IT Recruitment, San Antonio Information Technology Recruiters, San Diego Executive Staffing, San Francisco Executive Search Firms, San Jose Executive Tech Recruiting, Seattle Technical Recruiters, Silicon Valley Tech Recruiters, St. Louis Technology Headhunters, Tampa Technology Headhunters, Washington DC IT Recruiters
Home"Information Security Architect
Senior Information Security Architect
Posted today
Job Viewed
Job Description
The Senior Information Security Architec t is responsible for developing and maintaining robust security architectures and strategies for safeguarding the organization's cloud-based infrastructure, applications, and data. This role requires a deep understanding of cloud security technologies, compliance standards, and best practices to ensure the confidentiality, integrity, and availability of sensitive information. The Information Security Architect will collaborate with cross-functional teams to design, implement, and manage security solutions in cloud environments.
Essential Functions Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Security Infrastructure Architecture:
- Develop and implement a comprehensive security architecture for on-premises and cloud technologies that are aligned with the CISO's overall strategy for the information security organization.'.
- Stay current with emerging on-premises and cloud security threats, vulnerabilities, and trends to proactively address potential risks.
- Actively participate within ACA technology Committees where solutions are evaluated for the enterprise
- Design and document secure on-premises and cloud security architectures, considering multi-cloud and hybrid cloud environments.
- Create and maintain security reference architectures, patterns, and guidelines.
- Understand and participate in the configuration of solutions and strategies that satisfy NIST Cybersecurity Framework control objectives in collaboration with the department's GRC team.
- Implement robust IAM solutions to manage user access, roles, and permissions effectively.
- Enforce strong authentication and authorization mechanisms .
- Assist the IAM team with privileged access management (PAM) solutions and deployment architectures.
- Develop strategies for data encryption, PKI, tokenization, and masking in the cloud and on-premises.
- Architect data loss prevention (DLP) measures and systems to protect sensitive information.
- Provide architecture advisory and solutions that satisfy NIST data protection controls.
- Provide architectural design and implementation guidance to information security teams to secure network configurations in the cloud and on-premises, including firewall rules, virtual private networks, and network segmentation.
- Implement network monitoring and intrusion detection systems.
- Ensure cloud and on-premises environments comply with industry standards and regulations (e.g., HIPAA, PCI DSS, NYDFS, NIST).
- Collaborate with GRC teams to ensure proper monitoring and reporting mechanisms.
- Maintain an active role within the enterprise GRC teams within Information Security, Compliance, and Internal Audit.
- Collaborate with the security operations center (SOC) to define incident response procedures and threat hunting strategies specific to cloud and on-premises environments.
- Assist with continuous improvement of ACA SOC operations where security logs and events are monitored and analyzed to detect and respond to security incidents promptly.
- Assist the SOC teams to ensure appropriate level of alerting is configured across all environments.
- Support regular security assessments, vulnerability scanning, and penetration testing of assets.
- Advise upon identified vulnerabilities and assist with translating risk ratings to ACA risk rating.
- Assist with training programs for employees and other stakeholders.
- Promote a culture of security awareness and compliance within the organization.
- Assess security risks associated with cloud service providers and third-party integrations.
- Review and recommend security terms within cloud solution contracts (includes SaaS, IaaP solutions)
- Evaluate documented architectures and analyze trends for ways to prevent future problems
- Research and recommend innovative, and where possible, automated approaches for information security team tasks.
- Identify approaches to solutions that leverage our resources and provide economies of scale
- Keep current with the latest security technologies and coach staff regarding leading and best practice strategies and solutions
- Ability to conduct research into a wide range of computing issues as required
- Ability to absorb and retain information quickly
- Ability to present ideas in user-friendly language
- Highly self-motivated and directed
- Keen attention to detail
- Ability to effectively prioritize and execute tasks in a high-pressure environment
- Exceptional customer service orientation
- Experience working in a team-oriented, collaborative environment
- Have a strong desire to learn continually and grow professionally
- College diploma or university degree in the field of computer science or management information systems is preferred.
- A minimum of 10 years IT experience; at least three of those years focused on IT security, infrastructure, cloud or application-level vulnerability testing and remediation
- Strong understanding of enterprise, network, system, distributed application and application-level security issues.
- Knowledge of network and web related protocols (e.g., TCP/IP, UDP, IPSEC, HTTP, HTTPS, routing protocols).
- Understanding of the system hardening processes, tools, guidelines and benchmarks (including MITRE ATT&CK framework).
- Strong experience and detailed technical knowledge in security engineering, system and network security, authentication and security protocols, cryptography, and application security.
- Basic knowledge of Linux, Windows, systems
- Coding and/or scripting experience required
- Working knowledge of a range of diagnostic utilities
- Exceptional written and oral communication skills
- Exceptional interpersonal skills, with a focus on rapport-building, listening, and questioning skills
- Strong documentation skills
- CISSP Certification preferred
- Cloud Architect Certification preferred
- Cloud Security Certificate preferred
- AWS, Azure, or Google Cloud Platform experience is a requirement for the senior position within the organization
- Implementation experience with privileged access management (PAM) solutions.
Supervisory Responsibility
This position may have supervisory responsibilities.
Work Environment and Physical Demands
This job operates in a professional office environment. This role routinely uses standard office equipment such as computers, phones, photocopiers, filing cabinets and fax machines.
Position Type/Expected Hours of Work
This is a full-time position with a work schedule of Monday-Friday with some schedule variations of weekday, weekend, and sometimes monthly on-call duties as needed.
Travel
This position will require up to 5% local travel.
EEO Statement
ACA provides equal employment opportunities (EEO) to all applicants for employment without regard to race, color, religion, gender, sexual orientation, gender identity or expression, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran in accordance with applicable federal, state and local laws. ACA complies with applicable state and local laws governing non-discrimination in employment in every location in which the company has facilities.
California Privacy Notice
"As an employer of California residents, we are dedicated to protecting your privacy rights. Any personal information you provide during the application process will be used solely for permitted internal purposes and will be handled in accordance with applicable privacy laws. By applying to this position, you consent to the collection, use, and disclosure of your personal information as described in our Employee Privacy Notice ."
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
Information Security Architect (Cloud)
Posted 1 day ago
Job Viewed
Job Description
Overview This is a remote role that may be hired in several markets across the United States. As an Information Security Architect, you will be a key technical leader and trusted advisor for our customers, helping them architect, design, and build secure, scalable, reliable, and cost-effective Cloud-based solutions. You'll collaborate closely with customers' technical and business leadership, understanding their business goals, technical requirements, and challenges to craft optimal Cloud-based controls that drive innovation and enable accelerating time-to-market for their products. Responsibilities Work closely with customers to understand their technical requirements, business objectives, and growth plans, and then architect Cloud-based controls that align with their goals. Lead technical discussions, present best practices, and guide customers on architecture, services, and solutions to ensure security, scalability, performance, and cost-effectiveness. Collaborate with cross-functional teams including Business, IT, Product, and Support to provide comprehensive solutions, addressing their specific needs, and driving successful outcomes. Design and implement proof-of-concepts (POCs), Pilots, and reference architecture patterns to enable reusable security services and demonstrate their potential impact on the customer's business. Stay up to date with Cloud IaaS, PaaS, and SaaS services, industry trends, and best practices, share this knowledge within the team, and drive continuous improvement and innovation. Participate in workshops, webinars, and events to evangelize Cloud security solutions and contribute to the growth of the multi-Cloud ecosystem. #LI-IK1 Qualifications Bachelor's Degree and 8 years of experience in Information Technology including Information Security OR High School Diploma or GED and 12 years of experience in Information Technology including Information Security PREFERRED QUALIFICATIONS 8+ years of specific technology domain areas experience (e.g., software development, cloud computing, systems engineering, infrastructure, security, networking, data & analytics) 3+ years of design, implementation, or consulting in applications and infrastructures experience 3+ years of architecture experience in Cyber and Cloud security 5+ years of Cyber and Cloud architecture experience Understanding of NIST/ISO Frameworks Experience architecting/operating solutions built on AWS Experience architecting/operating solutions built on MS Azure Experience working with end user and developer communities AWS Certified Solutions Architect Associate and/or Professional MS Cybersecurity Architect This job posting is expected to remain active for 30 days from the initial posting date listed above. If it is necessary to extend this deadline, the posting will remain active as appropriate. Job postings may come down early due to business need or a high volume of applicants. The base pay for this position is generally between $143,000 and $185,000. Actual starting base pay will be determined based on skills, experience, location, and other non-discriminatory factors permitted by law. For some roles, total compensation may also include variable incentives, bonuses, benefits, and/or other awards as outlined in the offer of employment. Benefits are an integral part of total rewards and First Citizens Bank is committed to providing a competitive, thoughtfully designed and quality benefits program to meet the needs of our associates. More information can be found at #J-18808-Ljbffr