Visa Technology and Operations LLC
Foster City, California
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Visa's Cyber Security team is seeking a Cyber Security Engineer to design, build, and operate large scale, cloud native and AI driven security platforms that protect Visa's global brand, networks, products, and data. This role combines hands on engineering, automation first security design, and technical leadership in a highly dynamic, high impact environment. The ideal candidate is a strong security engineer and problem solver with deep experience in Python based services, cloud security engineering, API driven architectures, and automation, and who is excited to apply GenAI and autonomous agent technologies to modern security challenges. This role plays a critical part in reducing time to detect (TTD) and time to remediate (TTR) by driving intelligent automation, threat intelligence enrichment, and policy as code across Visa's multi cloud ecosystem. Key Responsibilities: Security Engineering & Platform Development: Design, develop, and operate large scale cyber security platforms that deliver detection, prevention, and response capabilities across cloud and hybrid environments. Build cloud native, API first security services using Python and modern web service frameworks. Develop and expand security integration frameworks to interconnect SIEM, CSPM, CNAPP, IAM, network security, and threat intelligence platforms. Drive security automation to minimize manual intervention and accelerate incident response workflows. GenAI & Agentic Security Capabilities: Design and implement GenAI powered security workflows, including: Autonomous agents for cloud misconfiguration analysis, policy validation, and remediation recommendations AI assisted threat triage, alert summarization, and root cause analysis Intelligent enrichment of security signals using applied threat intelligence Build and operate agentic systems that can reason across telemetry, policies, and infrastructure state to propose or execute remediation actions safely. Evaluate and adopt emerging LLM, agent orchestration, and AI governance frameworks for enterprise grade security use cases. Ensure secure, compliant, and auditable use of GenAI, including data handling, prompt safety, access controls, and model risk considerations. Cloud Security & Automation: Engineer and enforce cloud security controls across AWS, Azure, and/or GCP in large scale enterprise environments. Implement Infrastructure as Code (IaC) and automation frameworks to provision and manage security controls using tools such as Terraform. Drive Policy as Code and Guardrails, authoring and maintaining policies using: OPA/Rego or Sentinel, AWS Service Control Policies (SCP), Azure Policy, GCP Organization Policies Integrate GitOps based promotion pipelines (dev test prod) with secure remote state management and drift detection. Threat Detection, Response & Posture Management: Reduce time to detect and time to remediate by automating: Threat intelligence ingestion and correlation Sensor enrichment and contextual risk scoring Design and operate cloud security posture management (CSPM/CNAPP) capabilities using platforms such as Wiz, Prisma Cloud, or Microsoft Defender for Cloud. Work across multiple security domains including: Cloud firewalls and security groups, DDoS protection, Network proxies, Cloud native SIEM platforms (e.g., ADX, Sumo Logic) Architecture, Innovation & Leadership: Lead technical design discussions and translate business requirements into secure, scalable architectures. Conduct proof of concepts (POCs) for new technologies, tools, and architectures, evaluate feasibility and drive production adoption. Stay current with emerging cloud, security, and AI technologies, proactively assessing their applicability within Visa. Act as a technical leader and mentor, raising the engineering and security maturity of the team. Contribute to project planning, including cost estimation, timelines, and risk assessment for new security initiatives. This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager. Qualifications Basic Qualifications • 8+ years of relevant work experience with a Bachelor's Degree or at least 5 years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 2 years of work experience with a PhD, OR 11+ years of relevant work experience. Preferred Qualifications • 9 or more years of relevant work experience with a Bachelor Degree or 7 or more relevant years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 3 or more years of experience with a PhD • Cloud & Security Expertise • Strong domain expertise in cloud security engineering within multi cloud enterprise environments (AWS, Azure, and/or GCP). • Expert level certification in at least one major cloud platform. • Hands on experience migrating applications to the cloud and implementing cloud native security controls at scale. • Proven ability to design and implement new security controls based on risk assessments, gaps, and regulatory requirements. GenAI, Automation & Engineering: • Demonstrated experience building GenAI solutions and autonomous agents for cloud security engineering or security operations. • Strong programming skills in Python (preferred) or Go, with experience in building production grade services. • Expertise in IaC, automation, and GitOps workflows, including secure state management and drift detection. • Experience with policy as code and enterprise guardrail enforcement. Operational & Leadership Skills: • Ability to independently drive POCs, own implementations end to end, and transition solutions into production. • Experience assisting with cost modeling, timelines, and delivery planning for security initiatives. • Strong understanding of threat management, vulnerability management, and cloud security posture management. • Excellent communication, collaboration, and technical leadership skills, with the ability to influence across teams. U.S. Applicants Only The estimated salary range for this position is $180,600.00 to $ 289,300.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
08/05/2026
Full time
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Visa's Cyber Security team is seeking a Cyber Security Engineer to design, build, and operate large scale, cloud native and AI driven security platforms that protect Visa's global brand, networks, products, and data. This role combines hands on engineering, automation first security design, and technical leadership in a highly dynamic, high impact environment. The ideal candidate is a strong security engineer and problem solver with deep experience in Python based services, cloud security engineering, API driven architectures, and automation, and who is excited to apply GenAI and autonomous agent technologies to modern security challenges. This role plays a critical part in reducing time to detect (TTD) and time to remediate (TTR) by driving intelligent automation, threat intelligence enrichment, and policy as code across Visa's multi cloud ecosystem. Key Responsibilities: Security Engineering & Platform Development: Design, develop, and operate large scale cyber security platforms that deliver detection, prevention, and response capabilities across cloud and hybrid environments. Build cloud native, API first security services using Python and modern web service frameworks. Develop and expand security integration frameworks to interconnect SIEM, CSPM, CNAPP, IAM, network security, and threat intelligence platforms. Drive security automation to minimize manual intervention and accelerate incident response workflows. GenAI & Agentic Security Capabilities: Design and implement GenAI powered security workflows, including: Autonomous agents for cloud misconfiguration analysis, policy validation, and remediation recommendations AI assisted threat triage, alert summarization, and root cause analysis Intelligent enrichment of security signals using applied threat intelligence Build and operate agentic systems that can reason across telemetry, policies, and infrastructure state to propose or execute remediation actions safely. Evaluate and adopt emerging LLM, agent orchestration, and AI governance frameworks for enterprise grade security use cases. Ensure secure, compliant, and auditable use of GenAI, including data handling, prompt safety, access controls, and model risk considerations. Cloud Security & Automation: Engineer and enforce cloud security controls across AWS, Azure, and/or GCP in large scale enterprise environments. Implement Infrastructure as Code (IaC) and automation frameworks to provision and manage security controls using tools such as Terraform. Drive Policy as Code and Guardrails, authoring and maintaining policies using: OPA/Rego or Sentinel, AWS Service Control Policies (SCP), Azure Policy, GCP Organization Policies Integrate GitOps based promotion pipelines (dev test prod) with secure remote state management and drift detection. Threat Detection, Response & Posture Management: Reduce time to detect and time to remediate by automating: Threat intelligence ingestion and correlation Sensor enrichment and contextual risk scoring Design and operate cloud security posture management (CSPM/CNAPP) capabilities using platforms such as Wiz, Prisma Cloud, or Microsoft Defender for Cloud. Work across multiple security domains including: Cloud firewalls and security groups, DDoS protection, Network proxies, Cloud native SIEM platforms (e.g., ADX, Sumo Logic) Architecture, Innovation & Leadership: Lead technical design discussions and translate business requirements into secure, scalable architectures. Conduct proof of concepts (POCs) for new technologies, tools, and architectures, evaluate feasibility and drive production adoption. Stay current with emerging cloud, security, and AI technologies, proactively assessing their applicability within Visa. Act as a technical leader and mentor, raising the engineering and security maturity of the team. Contribute to project planning, including cost estimation, timelines, and risk assessment for new security initiatives. This is a hybrid position. Expectation of days in office will be confirmed by your hiring manager. Qualifications Basic Qualifications • 8+ years of relevant work experience with a Bachelor's Degree or at least 5 years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 2 years of work experience with a PhD, OR 11+ years of relevant work experience. Preferred Qualifications • 9 or more years of relevant work experience with a Bachelor Degree or 7 or more relevant years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 3 or more years of experience with a PhD • Cloud & Security Expertise • Strong domain expertise in cloud security engineering within multi cloud enterprise environments (AWS, Azure, and/or GCP). • Expert level certification in at least one major cloud platform. • Hands on experience migrating applications to the cloud and implementing cloud native security controls at scale. • Proven ability to design and implement new security controls based on risk assessments, gaps, and regulatory requirements. GenAI, Automation & Engineering: • Demonstrated experience building GenAI solutions and autonomous agents for cloud security engineering or security operations. • Strong programming skills in Python (preferred) or Go, with experience in building production grade services. • Expertise in IaC, automation, and GitOps workflows, including secure state management and drift detection. • Experience with policy as code and enterprise guardrail enforcement. Operational & Leadership Skills: • Ability to independently drive POCs, own implementations end to end, and transition solutions into production. • Experience assisting with cost modeling, timelines, and delivery planning for security initiatives. • Strong understanding of threat management, vulnerability management, and cloud security posture management. • Excellent communication, collaboration, and technical leadership skills, with the ability to influence across teams. U.S. Applicants Only The estimated salary range for this position is $180,600.00 to $ 289,300.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
Genesis10 is currently seeking a Platform Engineer - Hybrid position with a Global Financial Institution located in Charlotte, NC. This is a 6+ month contract opportunity. As a Cyber Security Automation Engineer, you will play a pivotal role in enhancing our client's cybersecurity posture by designing, implementing, and maintaining automated security solutions. This role is part of a dynamic team specializing in detecting, investigating, and responding to cyber events. The ideal candidate will be a cybersecurity professional with sharp development skills to optimize and automate SOC workflows, fortifying defenses against emerging threats and ensuring the protection of sensitive financial data. Responsibilities: Develop and implement automated security solutions to monitor, detect, and respond to cybersecurity threats across the bank's infrastructure Collaborate with cross-functional teams to identify security requirements and integrate automated security measures into the development and deployment lifecycle Design and maintain security orchestration and automation workflows for incident response, vulnerability management, and compliance monitoring Continuously improve and optimize existing security automation processes to enhance efficiency and accuracy in threat detection and response Stay up-to-date with the latest security trends, vulnerabilities, and attack techniques to proactively identify potential risks and recommend mitigation strategies Contribute to the development of custom scripts, tools, and frameworks for security testing, data analysis, and threat intelligence Participate in security assessments, penetration testing, and red teaming exercises to identify vulnerabilities and assess the effectiveness of security controls Collaborate with internal teams to implement and integrate security tools and technologies that align with the bank's security strategy Requirements: Bachelor's degree in Computer Science, Information Security, or related field (Master's preferred) Proven experience (3+ years) as a Security Engineer, Automation Engineer, or similar role within the financial industry or a comparable environment In-depth knowledge of security principles, practices, and frameworks, including threat modeling, risk assessment, and security architecture Proficiency in programming and scripting languages such as Python, C#, PowerShell, SQL, or JavaScript Strong understanding of cloud security principles and experience with securing cloud-based environments (e.g., AWS, Azure, GCP) Familiarity with DevSecOps practices and integrating security into CI/CD pipelines Knowledge of network and system security, including firewalls, intrusion detection/prevention systems, and endpoint security solutions Hands-on experience with security orchestration and automation tools, such as SOAR platforms (e.g., Service Now SecOps, Demisto, Phantom) Excellent problem-solving skills, attention to detail, and the ability to work in a fast-paced, dynamic environment Pay range: Up to $64.81 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10: Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average.) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website. Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
08/05/2026
Full time
Genesis10 is currently seeking a Platform Engineer - Hybrid position with a Global Financial Institution located in Charlotte, NC. This is a 6+ month contract opportunity. As a Cyber Security Automation Engineer, you will play a pivotal role in enhancing our client's cybersecurity posture by designing, implementing, and maintaining automated security solutions. This role is part of a dynamic team specializing in detecting, investigating, and responding to cyber events. The ideal candidate will be a cybersecurity professional with sharp development skills to optimize and automate SOC workflows, fortifying defenses against emerging threats and ensuring the protection of sensitive financial data. Responsibilities: Develop and implement automated security solutions to monitor, detect, and respond to cybersecurity threats across the bank's infrastructure Collaborate with cross-functional teams to identify security requirements and integrate automated security measures into the development and deployment lifecycle Design and maintain security orchestration and automation workflows for incident response, vulnerability management, and compliance monitoring Continuously improve and optimize existing security automation processes to enhance efficiency and accuracy in threat detection and response Stay up-to-date with the latest security trends, vulnerabilities, and attack techniques to proactively identify potential risks and recommend mitigation strategies Contribute to the development of custom scripts, tools, and frameworks for security testing, data analysis, and threat intelligence Participate in security assessments, penetration testing, and red teaming exercises to identify vulnerabilities and assess the effectiveness of security controls Collaborate with internal teams to implement and integrate security tools and technologies that align with the bank's security strategy Requirements: Bachelor's degree in Computer Science, Information Security, or related field (Master's preferred) Proven experience (3+ years) as a Security Engineer, Automation Engineer, or similar role within the financial industry or a comparable environment In-depth knowledge of security principles, practices, and frameworks, including threat modeling, risk assessment, and security architecture Proficiency in programming and scripting languages such as Python, C#, PowerShell, SQL, or JavaScript Strong understanding of cloud security principles and experience with securing cloud-based environments (e.g., AWS, Azure, GCP) Familiarity with DevSecOps practices and integrating security into CI/CD pipelines Knowledge of network and system security, including firewalls, intrusion detection/prevention systems, and endpoint security solutions Hands-on experience with security orchestration and automation tools, such as SOAR platforms (e.g., Service Now SecOps, Demisto, Phantom) Excellent problem-solving skills, attention to detail, and the ability to work in a fast-paced, dynamic environment Pay range: Up to $64.81 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10: Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average.) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website. Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
08/05/2026
Full time
Position - Security Engineer Location - Fort Worth, TX (Hybrid) Job ID - 178604 Position Overview We are seeking a Directory Services Engineer to support critical cybersecurity initiatives focused on identity infrastructure security, Tier 0 protection, and resiliency. This role is hands-on and execution-focused, working across Active Directory, Microsoft Entra ID (Azure AD), and hybrid identity environments. The engineer will play a key role in hardening identity systems, identifying attack paths, and implementing remediation actions to reduce enterprise risk. Key Responsibilities Identity Engineering & Operations • Administer and support Active Directory (AD) and Microsoft Entra ID (Azure AD) environments. • Implement and manage Azure AD Connect / Entra Connect for hybrid identity synchronization. • Support domain controllers, forests, trusts, and authentication services. • Execute identity-related changes, configurations, and deployments. Security Hardening & Tier 0 Protection • Implement security controls for Tier 0 assets (AD, Entra ID, domain controllers). • Perform system hardening in alignment with cybersecurity standards. • Support initiatives for privileged access restrictions and identity protection. • Remediate identified security gaps and misconfigurations. Attack Path Identification & Remediation • Analyze and identify identity-based attack paths across on-prem and cloud environments. • Support remediation efforts to eliminate: o Privilege escalation paths o Excessive permissions o Identity misconfigurations • Partner with cybersecurity teams to reduce identity attack surface. Resiliency & Recovery Support • Implement and validate Active Directory forest recovery procedures. • Support backup, restore, and testing activities for identity systems. • Assist in improving resiliency and recoverability of Tier 0 infrastructure. Integration Support • Assist in integration and configuration of identity with: o MFA / Conditional Access o PAM (e.g., CyberArk) o IGA (e.g., Saviynt) o Secrets and certificate platforms (e.g., HashiCorp, Keyfactor) • Support identity governance and access control initiatives. Automation & Execution • Use PowerShell and scripting to automate identity tasks and remediation. • Execute predefined engineering tasks, runbooks, and operational procedures. • Document configurations, changes, and implementation steps. Job Description: Operationalize automated data discovery, classification, and inventory; apply sensitivity labels and consistent taxonomy across data stores, pipelines, and collaboration systems. Engineer DSPM capabilities with tools (e.g., Securiti, BigID) to surface data posture risks (overexposure, shadow data, stale sensitive data) and drive remediation workflows. Implement and support encryption, tokenization, masking, anonymization/pseudonymization for data at rest and in transit; integrate with cloud key management systems and enforce approved cryptographic standards; define crypto baselines and policy-as-code guardrails. Configure and govern access controls with RBAC/ABAC and purpose-based authorization; perform least-privilege and fine-grained access reviews across data platforms. Deploy, tune, and operate DLP and DAM solutions (e.g., Microsoft Purview DLP, Imperva/Guardium); build detections for PII/PCI/PHI and reduce false positives with policy and context improvements. Integrate and tune UEBA and Insider Risk signals to detect anomalous data access and exfiltration, partner on response workflows and preventive control changes. Integrate data protection telemetry with SIEM/SOAR; build detections, correlation rules, and automated response playbooks for data-related threats and policy violations. Implement data minimization and retention/ROT enforcement patterns; automate monitoring of lifecycle actions (archive, delete, redact) aligned to policy and legal holds. Implement DSAR (data subject access request) orchestration and fulfillment with SLA monitoring; automate data collection, redaction, and secure delivery with audit trails. Contribute to cookie/tag governance and catalog assurance; validate consent signals, storage durations, and vendor script behavior against policy. Support privacy platform capabilities and integrate with identity, ticketing, data catalogs/lineage, and evidence repositories. Embed data protection and privacy-by-design controls into services and CI/CD (pre-commit/CI privacy code scanning, secret scanning, schema checks for sensitive fields, data egress policies). Produce compliance evidence and reports for GDPR/CCPA/CPRA, PCI DSS, HIPAA, and internal audits; maintain controls health dashboards, regulatory tracking, and program KPIs. Investigate data-related incidents and privacy events in partnership with IR/SOC/Privacy Office. Collect artifacts, support forensics, document findings, and drive preventive engineering fixes. Conduct platform hardening and vulnerability remediation for data control tooling (misconfigurations, exposed buckets, weak crypto, excessive permissions). Participate in red teaming/tabletop exercises for data scenarios (insider misuse, public link exposures, unintended AI training data); translate findings into control improvements. Partner with Cybersecurity, Privacy Office, Enterprise Data, Legal, and product/platform teams to align designs and deliver privacy- and data protection-by-design outcomes. Document engineering patterns, runbooks, and reference architectures; create training and technical guidance that strengthen secure data handling practices across teams. Communicate clearly and concisely with technical and non?technical audiences - summarize incidents, risks, and recommended actions with accurate, complete context. Required Skills & Experience 3-7 years of hands-on experience in: Active Directory administration/engineering Microsoft Entra ID (Azure AD) Azure AD Connect / hybrid identity environments Experience with: AD security hardening Identity-related attack techniques (privilege escalation, lateral movement) Attack path analysis or remediation activities Strong working knowledge of: Tier 0 concepts and identity as a control plane Authentication protocols (Kerberos, NTLM, SAML, OAuth) Preferred Experience Exposure to: CyberArk or other PAM tools Saviynt or similar IGA platforms Ping Identity or federation solutions HashiCorp Vault, Keyfactor, or PKI environments Experience supporting AD forest recovery exercises Familiarity with Zero Trust principles Key Traits for Success Strong execution and delivery focus Security and resiliency mindset Ability to quickly identify and remediate risks Works effectively in a cross-functional cybersecurity environment Comfortable working in fast-paced, project-driven (contract) engagements Pay Range: $65 - $70/Hr The specific compensation for this position will be determined by a number of factors, including the scope, complexity and location of the role as well as the cost of labor in the market; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. Our full-time consultants have access to benefits including medical, dental, vision and 401K contributions as well as any other PTO, sick leave, and other benefits mandated by appliable state or localities where you reside or work.
Genesis10 is currently seeking a Cyber Security Engineer - Threat Detection with a Global Financial Institution. This is a hybrid 6+ month contract opportunity. This role is part of a high-performing Security Operations team responsible for advancing the organization's security monitoring, detection engineering, and cyber defense capabilities. The successful candidate will focus on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. Responsibilities: Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry Partner with threat intelligence teams to translate emerging threats and attacker techniques into actionable detection strategies Collaborate with security analysts, incident responders, and technology teams to investigate detections and reduce time to detect and respond Develop and fine-tune detection rules, signatures, correlation logic, and alerting thresholds to reduce false positives Map detections and coverage to relevant frameworks, including MITRE ATT&CK Use automation, scripting, and detection-as-code practices to improve the lifecycle management of detection content Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities for enhancement Ensure detection engineering practices align with applicable compliance and regulatory requirements Create and maintain clear documentation for detection logic, data sources, and operational procedures Continuously assess the effectiveness of cybersecurity monitoring controls Requirements: Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience Hands-on experience analyzing logs and security telemetry from multiple sources, including endpoint, network, identity, cloud, infrastructure, and application platforms Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies Strong knowledge of query languages and data analysis techniques Experience developing detection-as-code pipelines, automation, or scripts Ability to translate threat intelligence and adversary behaviors into practical detections Experience mapping detections to MITRE ATT&CK or similar security frameworks Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments Strong troubleshooting, analytical, and problem-solving skills Strong documentation, communication, and collaboration skills Desired skills: Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus Pay range: up to $64.82 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10: Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average.) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website. Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
08/05/2026
Full time
Genesis10 is currently seeking a Cyber Security Engineer - Threat Detection with a Global Financial Institution. This is a hybrid 6+ month contract opportunity. This role is part of a high-performing Security Operations team responsible for advancing the organization's security monitoring, detection engineering, and cyber defense capabilities. The successful candidate will focus on building, tuning, and maintaining effective detections across cloud and on-premises environments to proactively identify, investigate, and respond to threats. Responsibilities: Design, develop, tune, and maintain threat detection logic across cloud and on-premises environments to improve visibility, alert quality, and response effectiveness Build and maintain efficient data ingestion and log onboarding pipelines for security-relevant telemetry Partner with threat intelligence teams to translate emerging threats and attacker techniques into actionable detection strategies Collaborate with security analysts, incident responders, and technology teams to investigate detections and reduce time to detect and respond Develop and fine-tune detection rules, signatures, correlation logic, and alerting thresholds to reduce false positives Map detections and coverage to relevant frameworks, including MITRE ATT&CK Use automation, scripting, and detection-as-code practices to improve the lifecycle management of detection content Evaluate security monitoring technologies, data sources, and analytics capabilities to identify opportunities for enhancement Ensure detection engineering practices align with applicable compliance and regulatory requirements Create and maintain clear documentation for detection logic, data sources, and operational procedures Continuously assess the effectiveness of cybersecurity monitoring controls Requirements: Minimum of 3 years of relevant cybersecurity, detection engineering, SOC engineering, security analytics, or security operations experience Hands-on experience analyzing logs and security telemetry from multiple sources, including endpoint, network, identity, cloud, infrastructure, and application platforms Experience with cloud SIEM, UEBA, EDR, SOAR, data lake, or related detection and monitoring technologies Strong knowledge of query languages and data analysis techniques Experience developing detection-as-code pipelines, automation, or scripts Ability to translate threat intelligence and adversary behaviors into practical detections Experience mapping detections to MITRE ATT&CK or similar security frameworks Working knowledge of Windows and Linux operating systems, common enterprise infrastructure, and cloud environments Strong troubleshooting, analytical, and problem-solving skills Strong documentation, communication, and collaboration skills Desired skills: Additional cybersecurity experience in incident response, threat intelligence, vulnerability management, security engineering, or cloud security is a plus Pay range: up to $64.82 per hour Only candidates available and ready to work directly as Genesis10 employees will be considered for this position. If you have the described qualifications and are interested in this exciting opportunity, please apply! Ranked a Top Staffing Firm in the U.S. by Staffing Industry Analysts for six consecutive years, Genesis10 puts thousands of consultants and employees to work across the United States every year in contract, contract-for-hire, and permanent placement roles. With more than 300 active clients, Genesis10 provides access to many of the Fortune 100 firms and a variety of mid-market organizations across the full spectrum of industry verticals. For contract roles, Genesis10 offers the benefits listed below. If this is a perm-placement opportunity, our recruiter can talk you through the unique benefits offered for that particular client. Benefits of Working with Genesis10: Access to hundreds of clients, most who have been working with Genesis10 for 5-20+ years. The opportunity to have a career-home in Genesis10; many of our consultants have been working exclusively with Genesis10 for years. Access to an experienced, caring recruiting team (more than 7 years of experience, on average.) Behavioral Health Platform Medical, Dental, Vision Health Savings Account Voluntary Hospital Indemnity (Critical Illness & Accident) Voluntary Term Life Insurance 401K Sick Pay (for applicable states/municipalities) Commuter Benefits (Dallas, NYC, SF, and Illinois) For multiple years running, Genesis10 has been recognized as a Top Staffing Firm in the U.S., as a Best Company for Work-Life Balance, as a Best Company for Career Growth, for Diversity, and for Leadership, amongst others. To learn more and to view all our available career opportunities, please visit us at our website. Genesis10 is an Equal Opportunity Employer. Candidates will receive consideration without regard to their race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Date Posted: 2026-07-27 Country: United States of America Location: US-CO-AURORA-S E Centretech Pkwy BLDG S75 Position Role Type: Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance Security Clearance Type: TS/SCI - Current Security Clearance Status: Active and existing security clearance required on day 1 At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world's most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. Raytheon brings the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. We deliver solutions that help our nation and allies defend freedoms and deter aggression, creating a safer, more secure world. Join us and help shape the future of aerospace and defense. At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world. Raytheon's Air & Space Defense Systems (ASDS) strategic business unit (SBU) specializes in multi-domain integrated air and missile defense, advanced sensors, space-based systems, hypersonics, effectors and cyber solutions. Focused on program execution, business growth and the highest level of customer satisfaction, the ASDS team provides customers with unmatched capabilities of detection and sensing, command and control, and air-to-air, air-to-surface, and surface-to-air munitions to accomplish air, space and missile defense missions. Within ASDS, Space Intelligence, Surveillance & Reconnaissance is our Sub-SBU that delivers information superiority from space, multi-mission automation and orchestration, multiple intelligence (Multi-INT) and resilient operations, secure processing, and data management. This position is an onsite role in Aurora, CO What You Will Do Design, develop, test, deliver, and maintain software for satellite ground systems. Work with talented teams of engineers, architects, and leaders in an Agile environment. What You Will Learn A breadth of advanced software technologies and techniques including multi-tiered architectures, AWS web services, and microservice software design Modern DevSecOps and Continuous Integration/Continuous Delivery techniques Satellite ground system technologies including command & telemetry, flight dynamics, planning and scheduling, and spacecraft operations Qualifications You Must Have Typically requires a Bachelor's degree in Science, Technology, Engineering or Mathematics (STEM) and 5 years of relevant software engineering experience Experience developing software using Java and C++ Red Hat 8 Linux OS and Windows 2019 OS experience or similar experience An active and transferable U.S. government issued TS/SCI security clearance is required prior to start date. An active and transferable U.S. government issued Top Secret security clearance that can be crossed over to a TS/SCI security clearance is also acceptable. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance Qualifications We Prefer Experience with containerization using Docker, Kubernetes, and Helm Experience developing software using Python Experience developing software using ActiveMQ Experience developing software using WineHQ Experience with the Raytheon Eclipse Command & Telemetry Product Line What We Offer Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value, Safety, Trust, Respect, Accountability, Collaboration, and Innovation. Relocation eligible. Relocation assistance is available for this role. Learn More & Apply Now! Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products. Location Information: Aurora, CO: As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote. The salary range for this role is 86,800 USD - 165,200 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills. Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement. Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply. RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act. Privacy Policy and Terms: Click on this link to read the Policy and Terms
08/04/2026
Full time
Date Posted: 2026-07-27 Country: United States of America Location: US-CO-AURORA-S E Centretech Pkwy BLDG S75 Position Role Type: Onsite U.S. Citizen, U.S. Person, or Immigration Status Requirements: Active and transferable U.S. government issued security clearance is required prior to start date. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance Security Clearance Type: TS/SCI - Current Security Clearance Status: Active and existing security clearance required on day 1 At RTX, the world largest aerospace and defense company, 185,000 great minds are united by purpose and inspired to make a difference solving the world's most complex problems. With our three market leading businesses, world-class operations and investments in research and development, we offer capabilities and opportunity no one else can. Together, we push the boundaries of known science and find new ways to connect and protect our world. Raytheon brings the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. We deliver solutions that help our nation and allies defend freedoms and deter aggression, creating a safer, more secure world. Join us and help shape the future of aerospace and defense. At Raytheon, the foundation of everything we do is rooted in our values and a higher calling - to help our nation and allies defend freedoms and deter aggression. We bring the strength of more than 100 years of experience and renowned engineering expertise to meet the needs of today's mission and stay ahead of tomorrow's threat. Our team solves tough, meaningful problems that create a safer, more secure world. Raytheon's Air & Space Defense Systems (ASDS) strategic business unit (SBU) specializes in multi-domain integrated air and missile defense, advanced sensors, space-based systems, hypersonics, effectors and cyber solutions. Focused on program execution, business growth and the highest level of customer satisfaction, the ASDS team provides customers with unmatched capabilities of detection and sensing, command and control, and air-to-air, air-to-surface, and surface-to-air munitions to accomplish air, space and missile defense missions. Within ASDS, Space Intelligence, Surveillance & Reconnaissance is our Sub-SBU that delivers information superiority from space, multi-mission automation and orchestration, multiple intelligence (Multi-INT) and resilient operations, secure processing, and data management. This position is an onsite role in Aurora, CO What You Will Do Design, develop, test, deliver, and maintain software for satellite ground systems. Work with talented teams of engineers, architects, and leaders in an Agile environment. What You Will Learn A breadth of advanced software technologies and techniques including multi-tiered architectures, AWS web services, and microservice software design Modern DevSecOps and Continuous Integration/Continuous Delivery techniques Satellite ground system technologies including command & telemetry, flight dynamics, planning and scheduling, and spacecraft operations Qualifications You Must Have Typically requires a Bachelor's degree in Science, Technology, Engineering or Mathematics (STEM) and 5 years of relevant software engineering experience Experience developing software using Java and C++ Red Hat 8 Linux OS and Windows 2019 OS experience or similar experience An active and transferable U.S. government issued TS/SCI security clearance is required prior to start date. An active and transferable U.S. government issued Top Secret security clearance that can be crossed over to a TS/SCI security clearance is also acceptable. U.S. citizenship is required, as only U.S. citizens are eligible for a security clearance Qualifications We Prefer Experience with containerization using Docker, Kubernetes, and Helm Experience developing software using Python Experience developing software using ActiveMQ Experience developing software using WineHQ Experience with the Raytheon Eclipse Command & Telemetry Product Line What We Offer Our values drive our actions, behaviors, and performance with a vision for a safer, more connected world. At RTX we value, Safety, Trust, Respect, Accountability, Collaboration, and Innovation. Relocation eligible. Relocation assistance is available for this role. Learn More & Apply Now! Onsite: Employees who are working in Onsite roles will work primarily onsite. This includes all production and maintenance employees, as they are essential to the development of our products. Location Information: Aurora, CO: As part of our commitment to maintaining a secure hiring process, candidates may be asked to attend select steps of the interview process in-person at one of our office locations, regardless of whether the role is designated as on-site, hybrid or remote. The salary range for this role is 86,800 USD - 165,200 USD. The salary range provided is a good faith estimate representative of all experience levels. RTX considers several factors when extending an offer, including but not limited to, the role, function and associated responsibilities, a candidate's work experience, location, education/training, and key skills. Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, short-term disability, long-term disability, 401(k) match, flexible spending accounts, flexible work schedules, employee assistance program, Employee Scholar Program, parental leave, paid time off, and holidays. Specific benefits are dependent upon the specific business unit as well as whether or not the position is covered by a collective-bargaining agreement. Hired applicants may be eligible for annual short-term and/or long-term incentive compensation programs depending on the level of the position and whether or not it is covered by a collective-bargaining agreement. Payments under these annual programs are not guaranteed and are dependent upon a variety of factors including, but not limited to, individual performance, business unit performance, and/or the company's performance. This role is a U.S.-based role. If the successful candidate resides in a U.S. territory, the appropriate pay structure and benefits will apply. RTX anticipates the application window closing approximately 40 days from the date the notice was posted. However, factors such as candidate flow and business necessity may require RTX to shorten or extend the application window. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans' Readjustment Assistance Act. Privacy Policy and Terms: Click on this link to read the Policy and Terms
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
08/04/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.
08/04/2026
Full time
Consultant, Insider Threat Enterprise Cyber Security Full Time, Springfield MA (Hybrid) The Opportunity MassMutual is advancing an enterprise Insider Threat program focused on identifying and managing human-driven cyber risk. The Insider Threat Consultant will play a key role in developing the asset intelligence, monitoring strategies, detection capabilities, and investigative processes necessary to identify and manage insider-driven risk. This role combines deep technical expertise, critical asset analysis, behavioral risk assessment, and investigative discipline to understand how people interact with sensitive assets and to identify patterns of activity that may indicate elevated risk. The consultant will partner with cybersecurity operations, detection engineering, HR, Legal, Privacy, and business stakeholders to align monitoring and investigative capabilities with asset sensitivity and business impact. This position is suited for an experienced practitioner who can operate across technical, analytical, and investigative domains while helping build and mature an enterprise-scale insider threat program. The Team The Insider Threat team is a specialized cybersecurity function responsible for understanding and managing the risks that trusted individuals may pose to MassMutual's critical assets, systems, information, and operations. The team operates at the intersection of critical asset protection, identity and access management, behavioral analytics, cyber defense, investigations, and workforce risk. Team members develop the intelligence, monitoring strategies, detection capabilities, investigative processes, and analytical frameworks necessary to identify and reduce insider-driven risk. The team partners closely with Cyber Operations, Detection Engineering, Human Resources, Legal, Privacy, Compliance, Fraud Operations, and business stakeholders to ensure insider risk is identified, assessed, and managed in a consistent, defensible, and risk-informed manner. The Impact The Insider Threat Consultant will: Identify and prioritize critical assets requiring enhanced monitoring and protection. Analyze how critical assets are accessed, used, and shared across the enterprise. Map relationships between identities, access privileges, business processes, and critical assets. Analyze behavioral and technical indicators associated with insider risk. Identify patterns of activity that may indicate misuse or mishandling of critical assets. Conduct and support complex insider threat investigations. Correlate identity, access, asset, and behavioral signals across multiple data sources. Monitor and analyze deception environments and adversary interaction signals. Partner with detection engineering and security operations to develop and refine insider threat detection logic. Contribute to tuning enterprise security tooling to improve identification of insider-driven risk. Support development of early-warning frameworks and proactive risk identification. Produce clear, defensible analytical findings and case documentation. Support executive reporting and enterprise risk visibility. The consultant's work will improve visibility into critical assets, strengthen understanding of user-to-asset trust relationships, increase the fidelity of insider threat detections, and help prevent compromise of the confidentiality, integrity, and availability of MassMutual's most important information and systems. The Minimum Qualifications 8+ years of experience in cybersecurity, insider threat, investigations, intelligence analysis, data protection, enterprise architecture, or related disciplines. 2+ years of experience working cross-functionally with security, HR, Legal, Privacy, business, or investigative stakeholders. Preferred Qualifications Experience supporting or building an Insider Threat Program. Experience supporting Critical Asset Protection, Information Protection, Data Protection, or Human Risk Management initiatives. Experience conducting cyber, digital, fraud, employee misconduct, or insider threat investigations. Experience analyzing logs, endpoint telemetry, identity activity, access patterns, and behavioral signals. Hands-on experience contributing to detection use cases, monitoring strategies, investigative workflows, or security content development. Experience identifying, classifying, mapping, or protecting sensitive information or critical assets. Strong understanding of identity and access management concepts, privileged access, trust relationships, and access governance. Experience with SIEM, EDR, UEBA, DLP, insider risk management, identity security, and security analytics platforms. Experience developing, tuning, or validating detection logic across endpoint, identity, network, and data protection technologies. Experience analyzing user behavior and identifying anomalous or high-risk activity through the correlation of multiple data sources. Familiarity with deception technologies, cyber deception strategies, or adversary engagement techniques. Experience supporting highly regulated environments such as financial services. Professional certifications such as CISSP, CISM, GIAC, CDLP, GCFA, GCIH, or equivalent. Degree in cybersecurity, intelligence studies, psychology, criminal justice, information systems, or related field. What You Can Expect at MassMutual MassMutual offers the opportunity to do meaningful work within a purpose-driven organization that values long-term impact over short-term outcomes. In this role, you can expect: Clear areas of ownership and accountability, with work that connects directly to company and customer outcomes A collaborative environment where perspectives are welcomed Access to learning, development, and internal networks that support continuous growth and skill-building over time Employee-led communities and forums that foster connection, learning, and inclusion across the organization A culture grounded in integrity, responsibility, and stewardship-supported by a company with a strong legacy and a future-focused mindset MassMutual is an equal employment opportunity employer. We welcome all persons to apply. If you need an accommodation to complete the application process, please contact us and share the specifics of the assistance you need. California residents: For detailed information about your rights under the California Consumer Privacy Act (CCPA), please visit our California Consumer Privacy Act Disclosures page.