11,267 Security Expert jobs in the United States
Cyber Security Expert
Posted 14 days ago
Job Viewed
Job Description
What You'll Be Doing
- Develop disaster recovery strategies to meet compliance for new product releases
- Coordinate with Information Technology, Engineering, and Product teams to define resiliency requirements
- Include a resiliency backbone to all elements of digital transformation, automation, cloud migrations, virtualization and consolidation Coordinate resilience exercises and testing efforts, including tabletop exercises, event response simulations
- Identify gaps, corrective and preventive actions, mitigation strategies
- Work cross-functionally with leadership and teams across entities to coordinate and lead training and exercises
- Partner with functional leads to report on metrics, and identify program improvements
- Stay current on business continuity standards, best practices, technologies, and other resources from industry and government
- Assist in other projects/activities, as required to maintain the program
- Conduct BIAs and TIAs
- Dedicated resource for resiliency tool support
- Support product Certifications audits (SOC2 & ISO 27001)
- DR architecture
What We Look For In You
- 4+ years of Enterprise Resiliency or Business Continuity experience
- Strong technical skills (infrastructure, cloud, SaaS tools, platform)
- Experience with storage architecture
- Skilled with data analysis and visualization
- Product experience across technology vendors
- Strong project management skills, learning emerging products, and creating plans to support business growth and objectives.
- Professional relationship building and the ability to connect and collaborate with others across all levels and organizations.
- Keen focus on customer's experience, internal and external
- Intellect around situational intelligence gathering and data analytics
- An outstanding communicator, presenter, and writer with; background in drafting project plans across multiple stakeholders, holding teams accountable to their deliverables, and generating final reports.
- Ability to risk rank various high-priority items and advocate successfully for technical and business teams
- Work effectively in a fast-paced environment and self-assess conflicting priorities to make operational decisions.
- Certified Business Continuity Professional (CBCP), MBCP, Certified in Risk and Information Systems Control (CRISC) or related is preferred.
- Experience with industry-leading BCM software (e.g., Fusion Framework) is a plus.
- Solid understanding of Corporate IT and Security control policies
- Strong written, verbal communication, and interpersonal skills
- Experienced with project/process management and frameworks
- Adaptable with different frameworks and modes of work
Email Security Expert

Posted 3 days ago
Job Viewed
Job Description
The NOSC Email Security Expert monitors, analyzes, and enhances email security to protect Networks from phishing, malware, and other cyber threats. They configure and optimize email security tools, investigate suspicious email activity, and implement policies to strengthen overall cybersecurity posture.
**Responsibilities include, but are not limited to:**
+ Design, implement, and develop advanced email security solutions to protect email systems from cyber threats, including phishing, malware, and other email-borne attacks
+ Monitor and analyze email traffic for signs of malicious activity, employing advanced threat detection techniques; Provide expert guidance and recommendations on email security best practices to stakeholders
+ Develop and enforce email security policies, standards, and procedures; Conduct training and awareness programs for DHS staff on email security practices
+ Conduct regular security assessments and vulnerability scans on email systems; Prepare detailed reports on security incidents, findings, and recommended actions
+ Collaborate with vendors and other security teams to investigate and respond to security incidents and outages involving email
+ Provide expert guidance and recommendations on email security best practices to stakeholders.
+ Contributes to and executes the design, development, and implementation of the NOSC's portion of the enterprise email security program. Interacts, coordinates, and collaborates with the Microsoft Office 365 and identity teams, working with external email security vendors (e.g., Proofpoint)
**Minimum** **Qualifications:**
+ 8+ years of experience in email security, with a strong focus on threat detection and mitigation and a Bachelor's degree in computer science, information technology, cybersecurity, or a related field of study.
+ In-depth knowledge of email security protocols (e.g., SMTP, DMARC, DKIM, SPF) and encryption technologies
+ Proficiency with email security tools and platforms (e.g., Proofpoint, Mimecast, Cisco Email Security, Microsoft Defender for Office 365)
+ Experience with Security Information and Event Management (SIEM) systemsStrong understanding of cyber threat intelligence and incident response processes
**Preferred Qualifications:**
+ Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or similar are highly desirable.
+ Master's degree
+ Experience working in a government or defense environment (familiarity with DHS policies and procedures a plus)
+ Knowledge of broader cybersecurity frameworks (e.g., NIST, ISO 27001)
**Clearance Requirements:**
+ Must have a current/active Secret clearance with the ability to obtain and maintain a TS/SCI.
+ The ability to obtain and maintain a DHS EOD suitability is required prior to starting this position.
**Physical Requirements:**
+ Must be able to work in an office environment and maneuver in data center and other IT equipment installation locations.
+ Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer
+ Ability to lift and carry 75 lbs for distances up to 50 feet
ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
If you are a qualified individual with a disability and require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please email us at and provide your name and contact information.
Email Security Expert

Posted 4 days ago
Job Viewed
Job Description
The NOSC Email Security Expert monitors, analyzes, and enhances email security to protect Networks from phishing, malware, and other cyber threats. They configure and optimize email security tools, investigate suspicious email activity, and implement policies to strengthen overall cybersecurity posture.
**Responsibilities include, but are not limited to:**
+ Design, implement, and develop advanced email security solutions to protect email systems from cyber threats, including phishing, malware, and other email-borne attacks
+ Monitor and analyze email traffic for signs of malicious activity, employing advanced threat detection techniques; Provide expert guidance and recommendations on email security best practices to stakeholders
+ Develop and enforce email security policies, standards, and procedures; Conduct training and awareness programs for DHS staff on email security practices
+ Conduct regular security assessments and vulnerability scans on email systems; Prepare detailed reports on security incidents, findings, and recommended actions
+ Collaborate with vendors and other security teams to investigate and respond to security incidents and outages involving email
+ Provide expert guidance and recommendations on email security best practices to stakeholders.
+ Contributes to and executes the design, development, and implementation of the NOSC's portion of the enterprise email security program. Interacts, coordinates, and collaborates with the Microsoft Office 365 and identity teams, working with external email security vendors (e.g., Proofpoint)
**Minimum** **Qualifications:**
+ 8+ years of experience in email security, with a strong focus on threat detection and mitigation and a Bachelor's degree in computer science, information technology, cybersecurity, or a related field of study.
+ In-depth knowledge of email security protocols (e.g., SMTP, DMARC, DKIM, SPF) and encryption technologies
+ Proficiency with email security tools and platforms (e.g., Proofpoint, Mimecast, Cisco Email Security, Microsoft Defender for Office 365)
+ Experience with Security Information and Event Management (SIEM) systems
+ Strong understanding of cyber threat intelligence and incident response processes
**Preferred Qualifications:**
+ Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Ethical Hacker (CEH), or similar are highly desirable.
+ Master's degree
+ Experience working in a government or defense environment (familiarity with DHS policies and procedures a plus)
+ Knowledge of broader cybersecurity frameworks (e.g., NIST, ISO 27001)
**Clearance Requirements:**
+ Must have a current/active Secret clearance with the ability to obtain and maintain a TS/SCI.
+ The ability to obtain and maintain a DHS EOD suitability is required prior to starting this position.
**Physical Requirements:**
+ Must be able to work in an office environment and maneuver in data center and other IT equipment installation locations.
+ Constantly operates a computer and other office productivity machinery, such as a calculator, copy machine and computer printer
+ Ability to lift and carry 75 lbs for distances up to 50 feet
ManTech International Corporation, as well as its subsidiaries proactively fulfills its role as an equal opportunity employer. We do not discriminate against any employee or applicant for employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
If you are a qualified individual with a disability and require a reasonable accommodation to apply for a position with ManTech through its online applicant system, please email us at and provide your name and contact information.
IAM Cyber Security Expert
Posted 21 days ago
Job Viewed
Job Description
Location: Chicago, IL (Local Only)
Duration : Contract
Requirements/Responsibilities
- Lead Identity centric Workforce Security solutions team to develop authentication and access management solutions
- Drive the development of identity solutions, access patterns, modern security protocols, practicing Zero trust, least privileged, defense in depth principles
- Review and provide feedback on Identity and access management related security solutions proposed by stakeholders and can provide consultation to the partners and IT Management
- In-depth knowledge and experience on Entra ID, EPM, Sentinel, Azure, AWS Security
- Knowledge on Okta, PingFederate, Entitlement management solutions
- Strong knowledge on Identities management on Azure AD with OAuth, OIDC, SAML, SSO, MFA, Conditional access policies, MFA, Kerberos, LDAP, Identity Federations etc.
- Experience in providing security solutions for Java based Micro services, React based frontends and Android/iOS based mobile applications on the Azure
- Hands-of experience in JWT, session handling, Code signing, Certificate authentication, TLS/SSL, API Security, Application registration, application integration scenarios etc.
- wareness of API Management, Firewalls, DLP, VPNs, DNS, Azure Defender, MCAS, Sentinel, WAFs, Application Gateways, NSGs, App Proxy, Radius clusters, CDN etc.
- Good understanding of Cloud Infrastructure Entitlement Management solution (CIEM) to ensure smooth remediation of toxic combinations, high risk entitlements etc.
- Understanding and application of threat modeling concepts and methodologies
- Understanding of Applications security, OWASP standards, security best practices, browser compatibilities/storages/cookies
- cts as IAM cybersecurity expert to in solutions spanning end user computing, proxy solutions, MFA, SSO, conditional accesses, Passwordless, Yubikey, bio-metric solutions, identity and governance scenarios, Secrets Management, automation, role-based access control, Privileged identity management, just in time accesses etc.
- Participates in solutions to support- token handling, OIDC/ OAuth flows, authorization patterns, identity federation, cloud architectures, cryptography, cloud native services, cloud security etc.
- Deeper understanding on Cloud Security areas such as Policies, RBAC, activities, identities, privileged access management etc.
- bility to support operations in troubleshooting complex identity scenarios with hands-on experience on Sentinel/KQL/Audit logs etc.
- Good understanding of concepts related to docker Security, container orchestrations/Kubernetes
Qualifications
- Bachelor's degree in computer science or a related discipline and experience in information security, or an equivalent combination of education and work experience.
- Deep knowledge of application or infrastructure systems architecture, usually having experience with multiple system technologies.
- Excellent consultative and communication skills, and the ability to work effectively with client, partner, and IT management and st.
Enterprise Security Architect - Information Security Expert - Vice President
Posted 14 days ago
Job Viewed
Job Description
J ob Title Enterprise Security Architect - Information Security Expert
Corporate Title Vice President
Location Arlington, VA
Overview
Our Enterprise Security Architecture team supports the Group Security Strategy for all of Deutsche Bank. You'll be managing the Security Capability framework, driving delivery and managing a small global team as well as working with stakeholders throughout the Bank. To provide best practices for new technologies and integration the cloud into our overall Enterprise Security Architecture. As a future-thinking team, we are looking for professionals like you to help operationalize Deutsche Bank's target Enterprise Security Architecture. Our team of experts ensure the integration of advanced technologies and tools into our environment.
What We Offer You
A diverse and inclusive environment that embraces change, innovation, and collaboration
A hybrid working model, allowing for in-office / work from home flexibility, generous vacation, personal and volunteer days
Employee Resource Groups support an inclusive workplace for everyone and promote community engagement
Competitive compensation packages including health and wellbeing benefits, retirement savings plans, parental leave, and family building benefits
Educational resources, matching gift and volunteer programs
What You'll Do
Manage the Enterprise Security Architecture team, which includes ownership of the security capability framework to ensure alignment with industry trends, Bank security needs, threats, and general organizational requirements and work with the Security Pillar Domain Architecture team to ensure alignment of domain strategies and roadmaps with ESA Capability framework and Group Security Strategy
Ownership of security reference architectures, including target and current state understandings of capability delivery via people, process, and technology to contribute to metrics development for security capabilities and technologies, contributing to comprehensive risk reporting
Oversee CSO's contribution to the Bank's Enterprise Process Model (EPM). This includes ensuring accurate process information for CSO is available for legal purposes
Accountable for functional requirements and conceptual models contributing to security capabilities and contribute to central architectural and technology processes and programs on behalf of CSO
Facilitate proper channels of communication with internal and external stakeholders to properly discuss and understand interdependencies, facilitate architecture and technology reviews of major programs, and drive alignment across the various architectural teams in and outside of CSO
Develop and implement data-driven methodology to incorporate IS Risk Management into the Bank's core Security Strategy to support simplification of the CSO Technology Lifecycle by identifying overlapping / duplicative technology across pillars and ensure alignment with the CSO Technology lifecycle and where necessary help develop/maintain position papers which offer guidelines and resources relating to relevant hot security topics
How You'll Lead
Lead the Enterprise Security Architecture team. Collaborate, guide and actively engage with the Security Pillar Domain Architects and be the delegate Domain Architect for CSO
Own the security capability framework for the Bank, it's strategies for all security domains and capability roadmaps and Accountable for the review, analysis, and approval of all new security technologies requested within the Bank
Lead the continued maturity of the Bank's threat framework as it pertains to architecture and reporting and alignment with the MITRE ATT&CK framework
Skills You'll Need
Bachelor's degree or equivalent required
Significant Experience in cyber security disciplines
Strong knowledge of cyber capabilities - including designing and deploying security solutions
Cyber certifications are an advantage (i.e. CISSP, Security+, SABSA)
Skills That Will Help You Excel
Excellent communication and presentation skills
Proven record of grasping highly complex problems and turning them into actionable plans to deliver solutions
Familiarity with working in a large, complex enterprise
Expectations
The Arlington office is 100% remote for those local to Arlington, although some collaboration days at the team's space in the Ballston We Work are expected. Flexibility to accommodate virtual meetings with global stakeholders (UK, Germany, Romania, India, Singapore) is required.
The salary range for this position in Arlington is $125,000 to $203,000.Actual salaries may be based on a number of factors including, but not limited to, a candidate's skill set, experience, education, work location and other qualifications. Posted salary ranges do not include incentive compensation or any other type of remuneration.
Deutsche Bank Benefits
At Deutsche Bank, we recognize that our benefit programs have a profound impact on our colleagues. That's why we are focused on providing benefits and perks that enable our colleagues to live authentically and be their whole selves, at every stage of life. We provide access to physical, emotional, and financial wellness benefits that allow our colleagues to stay financially secure and strike balance between work and home. Click here to learn more!
Learn more about your life at Deutsche Bank through the eyes of our current employees
The California Consumer Privacy Act outlines how companies can use personal information. If you are interested in receiving a copy of Deutsche Bank's California Privacy Notice please
#LI-REMOTE
We strive for a culture in which we are empowered to excel together every day. This includes acting
responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We strive for a culture in which we are empowered to excel together every day. This includes acting responsibly, thinking commercially, taking initiative and working collaboratively.
Together we share and celebrate the successes of our people. Together we are Deutsche Bank Group.
We welcome applications from all people and promote a positive, fair and inclusive work environment.
We are an Equal Opportunity Employer - Veterans/Disabled and other protected categories. Click these links to view the following notices:EEOC Know Your Rights;Employee Rights and Responsibilities under the Family and Medical Leave Act;Employee Polygraph Protection ActandPay Transparency Nondiscrimination Provision.
Cyber Security Expert III (A)
Posted 9 days ago
Job Viewed
Job Description
ONSITE
Who We Are: Founded in 2007, SimIS Inc. is an innovative information technology solution Veteran Owned Small Business (VOSB) that models future environments, requirements, and capabilities, and then secures the enterprise from internal and external threats compliant with Federal, State, and industry standard governance to ensure client mission success. Our performance standard is “excellence,” with an outcomes-based, quality focus in our services and products, guided by our core values of honesty (in word and deed), relationships (confidence and trust with clients and partners), teamwork (shared goals, mission, and purpose), loyalty (allegiance to our client and team), and importance of others (work and win as a team).
SimIS is currently recruiting for the below listed position and this position is contingent upon award.
Job Description:
The ideal candidate (will be expected to perform) represents a critical senior-level role responsible for architecting and maintaining robust cybersecurity solutions across both contractor and government operations, managing complex security initiatives. This position requires an experienced cybersecurity professional who will lead threat hunting operations, develop comprehensive security frameworks, and serve as the primary technical authority for all cybersecurity matters while collaborating closely with various engineering teams and government stakeholders. The selected candidate will be responsible for designing and implementing advanced security controls, conducting sophisticated penetration testing, leading incident response activities, and providing strategic direction for security operations center (SOC) activities. This role demands an individual who can effectively balance hands-on technical leadership with program-level security governance, including developing security policies, maintaining compliance with DoD security requirements, and mentoring junior security personnel. The position requires someone who can translate complex technical concepts for executive stakeholders while maintaining deep expertise in emerging threats, cutting-edge security technologies, and evolving compliance frameworks, all while working within a classified environment that demands the highest levels of discretion and security awareness.
The candidate performs the following specific assignments:
-
Minimum 10 years of experience in cyber security
-
Support the PM and provide direction for complex technical programs
-
Leads cyber security initiatives and provides technical direction
-
Develops security architecture and frameworks
-
CISSP, IAT Level I certification required
-
Conducts security assessments and audits
-
Develops security policies and procedures
-
Manages incident response and recovery
Advanced proficiency in:
- Developing security policies aligned with NIST SP 800-53, RMF, and CMMC frameworks, maintaining compliance with DoD security requirements, and mentoring junior security personnel in the use of tools like Wireshark, TCPDump, and various IDS/IPS systems.
Experience Required:
-
Bachelor’s degree in Engineering from an accredited college or university with a concentration in Cybersecurity, Computer, Electrical, or Electronics Engineering, or a Bachelor’s degree from an accredited college or university in Mathematics with a concentration in Computer Science
-
At least Ten (10) years of post-college full-time experience with at least 8 years managing complex technical programs
-
Ten (10) years of professional experience in cybersecurity engineering
-
Ten (10) years of technical and program management experience in the operation, maintenance, design, or testing of Command, Control, Communications, Computers, Intelligence, Surveillance, Reconnaissance (C4ISR) systems and equipment
-
Technical and program management experience in the operation, maintenance, design, or testing of Command, Control, Communications, Computers, Intelligence, Surveillance, Reconnaissance (C4ISR) systems and equipment
-
CISSP, IAT Level I certification required
-
Motivated to independently achieve results
-
Active clearance (SECRET/ Top Secret preferred)
Experience Desired:
- A Master’s degree in Engineering from an accredited college or university preferred
Benefits:
-
Medical, Dental, and Vision
-
Short Term Disability (at no cost to you) and Long Term Disability
-
Life Insurance
-
Flex Spending Accounts (FSA)
-
401(k) Savings Plan
-
Tuition Assistance Program
-
Paid Time Off (PTO)
-
11 Federal Holidays each year
SimIS, Inc. is an EOE / M / F / Disability / VET / Drug Free Employer
Powered by JazzHR
Security Analyst - Expert
Posted 21 days ago
Job Viewed
Job Description
Provide a short description of the Position: An application security engineer ensures software security by identifying vulnerabilities, implementing protective measures, collaborating with development teams, monitoring for suspicious activities, and staying updated on security trends.
Provide a list of the day-to-day tasks to be performed by the Selected Candidate: Conduct security analysis and documentation of PeopleSoft roles and permission lists. Map and migrate security roles to Workday, ensuring Role-Based Access Control (RBAC) best practices. Implement security policies, governance frameworks, and compliance controls (SOX, GDPR, NIST). Conduct security risk assessments and develop mitigation strategies. Provide training and documentation on Workday security policies.
Mindlance is an Equal Opportunity Employer and does not discriminate in employment on the basis of - Minority/Gender/Disability/Religion/LGBTQI/Age/Veterans.
Be The First To Know
About the latest Security expert Jobs in United States !
Blockchain Security Expert Intern - AI Track
Posted 14 days ago
Job Viewed
Job Description
Founded in 2018 by professors of Yale University and Columbia University, CertiK is a pioneer in blockchain security, utilizing best-in-class AI technology to secure and monitor blockchain protocols and smart contracts. CertiK's mission is to secure the cyber world. Starting with blockchain, CertiK applies cutting-edge innovations from academia into enterprise, enabling mission-critical applications to be built with security and correctness. CertiK is one of the fastest growing and most trusted companies in blockchain security and has become a true market leader. Our clients include leading projects such as Aave, Polygon, Binance Smart Chain, Yearn, and Chiliz. Our investors include top VCs like Tiger Global, Coatue Management, Shunwei Capital and Hillhouse Capital as well as industry leaders like Coinbase Ventures and Binance.
About the Position
The primary focus of this role is to pioneer the development of an intelligent AI agent powered by large language models (LLMs) to enhance our security audit tools in the blockchain space. As a Blockchain Security Expert intern, you will work closely with our blockchain security team to bridge cutting-edge academic research with practical applications. Your efforts will be dedicated to designing, fine-tuning, and integrating LLM-driven AI agents that automatically analyze smart contracts and identify potential vulnerabilities. In this role, you'll be immersed in research and experimentation, exploring new methods to improve threat detection and risk assessment within our security audit platform, thereby directly contributing to more secure blockchain infrastructures.
Responsibilities
- Collaborate with our blockchain security team to design and implement a large language model (LLM)-based AI agent for security audit tools.
- Experiment with novel AI techniques to enhance threat detection and risk assessment in blockchain environments.
- Assist in transforming cutting-edge research on AI agents into practical, scalable security auditing solutions.
- Continuously research emerging trends in LLMs, AI agent architectures, and cybersecurity, and proactively propose improvements.
- Currently pursuing or recently completed a PhD in Artificial Intelligence, Computer Science, or a related field, with a strong emphasis on machine learning, natural language processing, and/or cybersecurity.
- Deep understanding of LLM architectures (e.g., transformers) and hands-on experience in training or fine-tuning such models.
- Proficiency in Python and experience with deep learning frameworks (e.g., PyTorch or TensorFlow).
- Basic familiarity with blockchain technology and smart contract development is a plus.
- Excellent analytical skills, problem-solving capabilities, and the ability to thrive in a fast-paced, innovative startup environment.
- Strong written and verbal communication skills in English.
- Prior research or project experience in developing AI agents or automated security analysis tools.
- Exposure to security audit methodologies and vulnerability assessment, particularly in blockchain or smart contract environments.
- Familiarity with blockchain programming languages (e.g., Solidity) and platforms (e.g., Ethereum).
- Publications or contributions to leading conferences/journals in AI, NLP, or cybersecurity.
- Demonstrated ability to translate research insights into effective, production-ready tools.
Target monthly salary for this role performed is $6,000 - $8,000 if based in the US. The exact compensation at which this job is filled will be determined by the skills and experience of qualified candidates.
CertiK accepts applications for this position on an ongoing basis.
CertiK is proud to offer medical, vision, and dental insurance, 401(k) plan with company matching, life and accidental death and dismemberment insurance, HSA (with high deductible plan), FSA, and other benefits to all full-time employees, along with flexible paid time off and holidays. CertiK also offers a variable commission program for business development sales roles.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.
CertiK is proud to be an equal opportunity employer. We will not discriminate against any applicant or employee on the basis of age, race, color, creed, religion, sex, sexual orientation, gender, gender identity or expression, medical condition, national origin, ancestry, citizenship, marital status or civil partnership/union status, physical or mental disability, pregnancy, childbirth, genetic information, military and veteran status, or any other basis prohibited by applicable federal, state or local law.
CertiK will consider for employment qualified applicants with criminal histories in a manner consistent with local and federal requirements.
All CertiK employees are expected to actively support diversity on their teams, and in the Company.
Cyber Security Consultant/Expert
Posted 21 days ago
Job Viewed
Job Description
Cyber Security Consultant/Expert #1029028
Job Description:
- The IT Security and Compliance Analyst provides oversight of IT Security and controls, supports the IT compliance and regulatory requirements.
- You will play a key role in our Second Line of Defense, supporting our IT assessments, and remediate gaps.
- Our company Technology is on an exciting transformation journey, and you will have a great opportunity to help us transform the Security area as well.
- Compliance and Regulatory requirements.
- This position is responsible for providing support for internal and external audits, engage with business to conduct risk
Major Responsibilities Include:
- Partner with Credit Application Teams to Implement and manage IT Controls
- Provide Security & Control csulting to Application teams
- Internal Audit and Third-Party Audit Support
- Support Credit Internal Controls with IT related controls and deficiencies
- Management of High and Medium Comments identified by the Audit and application teams. (development, implementation, and sustainability of Control Improvement Plans)
- Conduct reviews of recently identified IT and IT related audit Comments
- Support Application teams with Detailed Risk Assessments and Threat Modeling
- Support Vendor Management and Business Owners with due diligence for supplier onboarding
- Support Credit Privacy and Compliance Attorneys with IT related regulatory requirements
- Support Third Party consulting engagements
- Maintain accurate JIRA User Stories and Backlog
Essential skills:
- Strong knowledge of our company and Industry standard IT Controls and best security practices
- Solid understanding of corporate policies (ISP, Finance Manual, Corporate Directives, etc.)
- Understand risk and implement mitigating controls
- Knowledge of risk management principles, including risk assessment, mitigation, and reporting.
- Capable and comfortable working autonomously
- Strong leadership skills and results oriented
- Demonstrates ability to work in white space
- Continuous controls process improvement mentality
- Integrity - ability to "stand ground" for correct action and do the right thing
- Demonstrated ability to take ownership and accountability of all work and responsibilities
- Strong communication skills (written and oral)
- Excellent interpersonal, collaborative and team building skills
- Internal Audit - IT Auditor
- Cyber Security Services Advisor (formerly Security Controls Champion or Security Controls Practitioner)
- Preferred candidate should have a proven track record in IT security and controls, demonstrated strong controls mindset
- Knowledge in one or more of the following areas: Security services, Database Administration, cloud security, Application development or support and Networks
- Familiarity with AI/LLM
- Industry Certifications a plus (e.g., CISA, CRISC, CISM, CISSP)
- Bachelors
- Industry Certifications a plus (e.g., CISA, CRISC, CISM, CISSP)
At FastTek Global, Our Purpose is Our People and Our Planet . We come to work each day and are reminded we are helping people find their success stories . Also, Doing the right thing is our mantra . We act responsibly, give back to the communities we serve and have a little fun along the way.
We have been doing this with pride, dedication and plain, old-fashioned hard work for 24 years !
FastTek Global is financially strong, privately held company that is 100% consultant and client focused .
We've differentiated ourselves by being fast, flexible, creative and honest . Throw out everything you've heard, seen, or felt about every other IT Consulting company. We do unique things and we do them for Fortune 10, Fortune 500, and technology start-up companies.
Our benefits are second to none and thanks to our flexible benefit options you can choose the benefits you need or want, options include:
- Medical and Dental (FastTek pays majority of the medical program)
- Vision
- Personal Time Off (PTO) Program
- Long Term Disability (100% paid)
- Life Insurance (100% paid)
- 401(k) with immediate vesting and 3% (of salary) dollar-for-dollar match
Plus, we have a lucrative employee referral program and an employee recognition culture.
FastTek Global was named one of the Top Workplaces in Michigan by the Detroit Free Press in 2013, 2014, 2015, 2016, 2017, 2018, 2019, 2020, 2021 , 2022 and 2023!
To view all of our open positions go to: Follow us on Twitter: Follow us on Instagram: Find us on LinkedIn: You can become a fan of FastTek on Facebook:
Information Security Management System Lead
Posted 23 days ago
Job Viewed
Job Description
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
The ISMS Lead coordinates and maintains the daily operations of the Information Security Management System (ISMS) Program, ensuring compliance with ISO27001 and alignment with Generac's broader cybersecurity and compliance frameworks. The ISMS lead is the central point of contact for cross-functional control owners, capability teams, and audit stakeholders-supporting evidence collection, risk and control tracking, and the orchestration of ISMS-related deliverables across both internal ISMS assessments and external ISO27001 audits.
The ISMS Lead drives operational excellence through governance coordination, audit readiness, and performance monitoring. This includes facilitating working groups, tracking the Statement of Applicability (SoA), risk register updates, and corrective action plans. The role supports both corporate and subsidiary teams in implementing and sustaining ISMS requirements, helping to foster a culture of compliance and continuous improvement across the organization.
**Major Responsibilities**
+ Coordinates the day-to-day operations of the Information Security Management System (ISMS), ensuring alignment with ISO27001 and Generac's unified governance and compliance frameworks
+ Maintains the GRC platform, supporting timely delivery of compliance activities across policy owners, control implementers, and evidence contributors
+ Facilitates internal ISMS assessments, committee meetings, and working group sessions by preparing agendas, tracking action items, and reporting compliance progress
+ Supports capability teams, subsidiaries, and control owners by clarifying implementation expectations, audit documentation needs, and evidence quality standards
+ Tracks and manages the lifecycle of risks, controls, and corrective actions, including updates to the risk register and the Statement of Applicability (SoA)
+ Coordinate ISMS readiness efforts in preparation for external ISO27001 audits or other applicable certification assessments
+ Develops and refines ISMS-related documentation, including procedures, guidelines, control narratives, and support materials
+ Maintains dashboards and performance metrics related to audit readiness, non-conformity closure, and risk treatment activities
+ Identifies bottlenecks, overdue tasks, and control misalignments, escalating as needed to the IT GRC Capability Manager or Director of InfoSec
+ Ensures consistent version control, evidence traceability, and document quality across all submissions in support of audits or assessments
+ Collaborates with Capability Teams and subsidiaries to ensure control implementation aligns with policy and framework expectations
+ Monitors developments in ISO27001:2022, privacy regulations, and industry best practices to continuously improve the ISMS model and processes
+ Supports onboarding and enablement of new ISMS participants, including training on stakeholder roles, tool usage, and evidence responsibilities
+ Coordinates internal evidence gathering for ISMS assessments and external audits, including document requests, stakeholder interviews, and audit walkthrough preparation
**Minimum Job Requirements**
**Education**
+ Bachelor's Degree with Information Technology focus, or equivalent experience
**Work Experience**
+ 5 years experience in Information Security Management Systems or Cyber Security.
+ Proven experience supporting or coordinating ISO27001 compliance or certification efforts.
+ Experience working within a multi-framework compliance program (e.g., ISO27001, NIST, SOC 2, PCI, GDPR).
+ Understanding of risk assessment methodologies, control mapping, and evidence management practices.
+ Experience with GRC platforms, able to apply prior learnings to new GRC tools.
+ Experience with cross functional coordination, providing guidance to teams across IT and business functions
**Knowledge / Skills / Abilities**
+ Familiarity with cloud service models and control responsibilities in SaaS/PaaS/IaaS environments
+ Strong coordination, documentation, and communication skills for multi-stakeholder collaboration
+ Familiarity with unified control framework initiatives or crosswalks across security and privacy standards
+ Understanding of how compliance maps to internal business processes and capability team structures
+ Ability to coordinate evidence requests, policy updates, and SoA changes in a dynamic environment
+ Experience maintaining compliance metrics, dashboards, or remediation tracking reports
+ Knowledge of key control areas such as access control, data protection, vulnerability management, and incident response
**Preferred Job Requirements**
**Certification / License**
+ Certifications preferred: ISO27001 Lead Implementer or Auditor, CISA, CISSP, CISM, or SCF Certified Practitioner
**Physical Demands** : While performing the duties of this job, the employee is regularly required to talk and hear; and use hands to manipulate objects or controls. The employee is regularly required to stand and walk. On occasion the incumbent may be required to stoop, bend or reach above the shoulders. The employee must occasionally lift up to 25 - 50 pounds. Specific conditions of this job are typical of frequent and continuous computer-based work requiring periods of sitting, close vision and ability to adjust focus. Occasional travel.
_"We are an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, national origin, disability status, protected veteran status, or any other characteristic protected by law."_
Over the 60 plus years of Generac's history, we've been dedicated to energy innovation. From creating the home standby generator market category, to our current evolution into an energy technology solutions company, we continue to push new boundaries.
As one of the leaders and largest suppliers of power generation equipment and technology, the work we do touches millions of lives. Employees at Generac are encouraged to be innovative and are valued as an integral part of our global team. Our challenging goals develop knowledgeable employees dedicated to helping continue Generac's success. Generac provides individuals the opportunity to work in a fast-paced agile work environment where their work makes a difference in people's lives and their own.