it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

11 jobs found

Email me jobs like this
Refine Search
Current Search
sr iam engineer
Sr. Cloud Engineer
McKesson Irving, Texas
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you. Key Responsibilities GCP Foundation, Landing Zones & Infrastructure-as-Code Cloud Architecture & Automation: Design, build, and maintain enterprise GCP infrastructure using Terraform/Terragrunt, enforcing Infrastructure-as-Code (IaC) and GitOps practices for all cloud environments. Landing Zone Governance: Own the configuration and security baseline of GCP Organization structures, Projects, Folders, Resource Hierarchies, and IAM roles/permissions using least-privilege principles. Network & Hybrid Connectivity: Configure and maintain GCP Shared VPCs, VPC Service Controls (VPC-SC), Cloud Interconnect, Cloud VPN, Cloud DNS, Firewall Rules, and load balancers to support secure, low-latency hybrid connectivity between GCP services, Apigee X, and Oracle Exadata / JDE ERP environments. Apigee X & Oracle Exadata / JDE ERP Integration Support Apigee X Platform Engineering: Provision, configure, and maintain Apigee X runtime environments, API gateways, PSC (Private Service Connect) attachments, and load balancers in accordance with enterprise security baselines. Oracle Exadata & JDE Interconnect: Engineer and maintain high-performance, resilient hybrid network topology (Cloud Interconnect/Partner Interconnect) linking GCP applications and Apigee gateways directly to Oracle Exadata database systems and JDE backend services. API Security & Traffic Controls: Work alongside Integration Architects to enforce mTLS, VPC Service Controls, rate limiting, and secure endpoints across Apigee X, GCP microservices, and Exadata/JDE integration boundaries. Containerization, Compute & Serverless GKE & Kubernetes Management: Deploy, secure, and operate Google Kubernetes Engine (GKE) clusters powering enterprise Spring Boot microservices, AI workloads, and internal developer platforms. Serverless Execution: Configure and support serverless workloads using Cloud Run, Cloud Functions, and App Engine, optimizing performance and latency for transactional database and API flows. Platform Reliability: Build automated deployment pipelines using GitHub Actions or Cloud Build to support seamless infrastructure provisioning and application cutovers. FinOps & Cloud Cost Optimization Cost Allocation & Visibility: Establish FinOps standards across GCP projects, implementing label/tagging enforcement, budget alerts, and showback/chargeback reporting for business units. Resource Tuning: Analyze resource utilization (Compute Engine, GKE, Cloud SQL, BigQuery) to right-size instances, optimize committed use discounts (CUDs), and eliminate unused infrastructure. Security, Compliance & Observability Cloud Security Posture: Implement CISO security standards, including GCP Secret Manager, KMS, mTLS, SAST/DAST container vulnerability scanning, and binary authorization. Observability Baseline: Build and maintain centralized logging, monitoring, and distributed tracing across all GCP environments, Apigee instances, and Exadata/JDE connectivity paths using Google Cloud Operations Suite (Cloud Logging, Cloud Monitoring, Cloud Trace). Minimum Requirements Experience: 10+ years of enterprise IT/infrastructure experience, with at least 4+ years dedicated to designing, engineering, and operating production environments on Google Cloud Platform (GCP). Apigee & Database/ERP Interconnect: Hands-on experience provisioning and supporting Apigee X / Apigee Edge environments and managing hybrid interconnectivity to high-performance database infrastructure (Oracle Exadata) and enterprise ERP systems (JD Edwards). IaC & Automation Mastery: Expert-level hands-on skills with Terraform, Git, and CI/CD pipelines (GitHub Actions, Cloud Build, or GitLab CI). Kubernetes & Containers: Strong experience deploying and managing production Google Kubernetes Engine (GKE) clusters and Docker containerized applications. GCP Networking & Security: Deep understanding of GCP VPC networking, Shared VPCs, Private Service Connect (PSC), VPC Service Controls, Cloud Interconnect, IAM, and GCP security controls. Scripting: Proficiency in Python, Bash, or Go for cloud automation and tooling development. FinOps Understanding: Practical experience implementing cloud cost optimization, quota management, and resource right-sizing strategies. Technical Skills Google Cloud Services: GKE, Cloud Run, Cloud SQL, BigQuery, Cloud Storage, VPC Service Controls, Secret Manager, IAM, Cloud Logging, Cloud Monitoring, Cloud Trace. API Management & Hybrid Database/ERP: Apigee X, Apigee Edge, Private Service Connect (PSC), Cloud Interconnect, Oracle Exadata database connectivity, JD Edwards (JDE) hybrid interconnectivity. Infrastructure-as-Code: Terraform, Terragrunt, Helm, Docker, Kubernetes. Networking & Security: Shared VPC, Cloud VPN, Cloud Interconnect, Firewalls, mTLS, OAuth 2.0, KMS, Least Privilege IAM. CI/CD & DevOps: GitHub Actions, Cloud Build, GitHub Advanced Security (GHAS), Git, Linux/Unix administration. Scripting & Tooling: Python, Bash, Go, gcloud CLI. Certifications & Education Certifications: Google Professional Cloud Architect or Google Professional Cloud DevOps Engineer (required or to be obtained within 6 months). Education: Bachelor's degree in Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience. About McKesson Medical-Surgical McKesson Medical-Surgical (MMS), which is expected to become Wellverse in early 2027, is a subsidiary and publicly reported segment of the McKesson Corporation. MMS distributes medical-surgical supplies, pharmaceuticals, diagnostic equipment and supplies, along with other solutions and services to virtually every type of healthcare setting and provider outside of the traditional hospital. These markets - often referred to as Alternate Care or Non-Acute Care - include physician offices, surgery centers, long-term care providers, laboratories, home health and hospice agencies, health systems, government facilities and online marketplaces and retailers. Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space. With a team of approximately 8,000 employees, a network of 15 distribution centers and approximately 900 delivery vehicles, we collaborate with more than 2,200 leading manufacturers and serve over 200,000 customer accounts across the U.S. Our catalog includes more than 270,000 SKUs of branded and private-label medical-surgical products - from bandages to specialty pharmaceuticals and COVID-19 tests. We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here. Our Base Pay Range for this position $115,300 - $192,100 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson's (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: . McKesson is an Equal Opportunity Employer McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page. McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities . click apply for full job details
09/27/2026
Full time
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you. Key Responsibilities GCP Foundation, Landing Zones & Infrastructure-as-Code Cloud Architecture & Automation: Design, build, and maintain enterprise GCP infrastructure using Terraform/Terragrunt, enforcing Infrastructure-as-Code (IaC) and GitOps practices for all cloud environments. Landing Zone Governance: Own the configuration and security baseline of GCP Organization structures, Projects, Folders, Resource Hierarchies, and IAM roles/permissions using least-privilege principles. Network & Hybrid Connectivity: Configure and maintain GCP Shared VPCs, VPC Service Controls (VPC-SC), Cloud Interconnect, Cloud VPN, Cloud DNS, Firewall Rules, and load balancers to support secure, low-latency hybrid connectivity between GCP services, Apigee X, and Oracle Exadata / JDE ERP environments. Apigee X & Oracle Exadata / JDE ERP Integration Support Apigee X Platform Engineering: Provision, configure, and maintain Apigee X runtime environments, API gateways, PSC (Private Service Connect) attachments, and load balancers in accordance with enterprise security baselines. Oracle Exadata & JDE Interconnect: Engineer and maintain high-performance, resilient hybrid network topology (Cloud Interconnect/Partner Interconnect) linking GCP applications and Apigee gateways directly to Oracle Exadata database systems and JDE backend services. API Security & Traffic Controls: Work alongside Integration Architects to enforce mTLS, VPC Service Controls, rate limiting, and secure endpoints across Apigee X, GCP microservices, and Exadata/JDE integration boundaries. Containerization, Compute & Serverless GKE & Kubernetes Management: Deploy, secure, and operate Google Kubernetes Engine (GKE) clusters powering enterprise Spring Boot microservices, AI workloads, and internal developer platforms. Serverless Execution: Configure and support serverless workloads using Cloud Run, Cloud Functions, and App Engine, optimizing performance and latency for transactional database and API flows. Platform Reliability: Build automated deployment pipelines using GitHub Actions or Cloud Build to support seamless infrastructure provisioning and application cutovers. FinOps & Cloud Cost Optimization Cost Allocation & Visibility: Establish FinOps standards across GCP projects, implementing label/tagging enforcement, budget alerts, and showback/chargeback reporting for business units. Resource Tuning: Analyze resource utilization (Compute Engine, GKE, Cloud SQL, BigQuery) to right-size instances, optimize committed use discounts (CUDs), and eliminate unused infrastructure. Security, Compliance & Observability Cloud Security Posture: Implement CISO security standards, including GCP Secret Manager, KMS, mTLS, SAST/DAST container vulnerability scanning, and binary authorization. Observability Baseline: Build and maintain centralized logging, monitoring, and distributed tracing across all GCP environments, Apigee instances, and Exadata/JDE connectivity paths using Google Cloud Operations Suite (Cloud Logging, Cloud Monitoring, Cloud Trace). Minimum Requirements Experience: 10+ years of enterprise IT/infrastructure experience, with at least 4+ years dedicated to designing, engineering, and operating production environments on Google Cloud Platform (GCP). Apigee & Database/ERP Interconnect: Hands-on experience provisioning and supporting Apigee X / Apigee Edge environments and managing hybrid interconnectivity to high-performance database infrastructure (Oracle Exadata) and enterprise ERP systems (JD Edwards). IaC & Automation Mastery: Expert-level hands-on skills with Terraform, Git, and CI/CD pipelines (GitHub Actions, Cloud Build, or GitLab CI). Kubernetes & Containers: Strong experience deploying and managing production Google Kubernetes Engine (GKE) clusters and Docker containerized applications. GCP Networking & Security: Deep understanding of GCP VPC networking, Shared VPCs, Private Service Connect (PSC), VPC Service Controls, Cloud Interconnect, IAM, and GCP security controls. Scripting: Proficiency in Python, Bash, or Go for cloud automation and tooling development. FinOps Understanding: Practical experience implementing cloud cost optimization, quota management, and resource right-sizing strategies. Technical Skills Google Cloud Services: GKE, Cloud Run, Cloud SQL, BigQuery, Cloud Storage, VPC Service Controls, Secret Manager, IAM, Cloud Logging, Cloud Monitoring, Cloud Trace. API Management & Hybrid Database/ERP: Apigee X, Apigee Edge, Private Service Connect (PSC), Cloud Interconnect, Oracle Exadata database connectivity, JD Edwards (JDE) hybrid interconnectivity. Infrastructure-as-Code: Terraform, Terragrunt, Helm, Docker, Kubernetes. Networking & Security: Shared VPC, Cloud VPN, Cloud Interconnect, Firewalls, mTLS, OAuth 2.0, KMS, Least Privilege IAM. CI/CD & DevOps: GitHub Actions, Cloud Build, GitHub Advanced Security (GHAS), Git, Linux/Unix administration. Scripting & Tooling: Python, Bash, Go, gcloud CLI. Certifications & Education Certifications: Google Professional Cloud Architect or Google Professional Cloud DevOps Engineer (required or to be obtained within 6 months). Education: Bachelor's degree in Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience. About McKesson Medical-Surgical McKesson Medical-Surgical (MMS), which is expected to become Wellverse in early 2027, is a subsidiary and publicly reported segment of the McKesson Corporation. MMS distributes medical-surgical supplies, pharmaceuticals, diagnostic equipment and supplies, along with other solutions and services to virtually every type of healthcare setting and provider outside of the traditional hospital. These markets - often referred to as Alternate Care or Non-Acute Care - include physician offices, surgery centers, long-term care providers, laboratories, home health and hospice agencies, health systems, government facilities and online marketplaces and retailers. Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space. With a team of approximately 8,000 employees, a network of 15 distribution centers and approximately 900 delivery vehicles, we collaborate with more than 2,200 leading manufacturers and serve over 200,000 customer accounts across the U.S. Our catalog includes more than 270,000 SKUs of branded and private-label medical-surgical products - from bandages to specialty pharmaceuticals and COVID-19 tests. We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here. Our Base Pay Range for this position $115,300 - $192,100 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson's (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: . McKesson is an Equal Opportunity Employer McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page. McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities . click apply for full job details
Sr. Cloud Engineer
McKesson Richmond, Virginia
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you. Key Responsibilities GCP Foundation, Landing Zones & Infrastructure-as-Code Cloud Architecture & Automation: Design, build, and maintain enterprise GCP infrastructure using Terraform/Terragrunt, enforcing Infrastructure-as-Code (IaC) and GitOps practices for all cloud environments. Landing Zone Governance: Own the configuration and security baseline of GCP Organization structures, Projects, Folders, Resource Hierarchies, and IAM roles/permissions using least-privilege principles. Network & Hybrid Connectivity: Configure and maintain GCP Shared VPCs, VPC Service Controls (VPC-SC), Cloud Interconnect, Cloud VPN, Cloud DNS, Firewall Rules, and load balancers to support secure, low-latency hybrid connectivity between GCP services, Apigee X, and Oracle Exadata / JDE ERP environments. Apigee X & Oracle Exadata / JDE ERP Integration Support Apigee X Platform Engineering: Provision, configure, and maintain Apigee X runtime environments, API gateways, PSC (Private Service Connect) attachments, and load balancers in accordance with enterprise security baselines. Oracle Exadata & JDE Interconnect: Engineer and maintain high-performance, resilient hybrid network topology (Cloud Interconnect/Partner Interconnect) linking GCP applications and Apigee gateways directly to Oracle Exadata database systems and JDE backend services. API Security & Traffic Controls: Work alongside Integration Architects to enforce mTLS, VPC Service Controls, rate limiting, and secure endpoints across Apigee X, GCP microservices, and Exadata/JDE integration boundaries. Containerization, Compute & Serverless GKE & Kubernetes Management: Deploy, secure, and operate Google Kubernetes Engine (GKE) clusters powering enterprise Spring Boot microservices, AI workloads, and internal developer platforms. Serverless Execution: Configure and support serverless workloads using Cloud Run, Cloud Functions, and App Engine, optimizing performance and latency for transactional database and API flows. Platform Reliability: Build automated deployment pipelines using GitHub Actions or Cloud Build to support seamless infrastructure provisioning and application cutovers. FinOps & Cloud Cost Optimization Cost Allocation & Visibility: Establish FinOps standards across GCP projects, implementing label/tagging enforcement, budget alerts, and showback/chargeback reporting for business units. Resource Tuning: Analyze resource utilization (Compute Engine, GKE, Cloud SQL, BigQuery) to right-size instances, optimize committed use discounts (CUDs), and eliminate unused infrastructure. Security, Compliance & Observability Cloud Security Posture: Implement CISO security standards, including GCP Secret Manager, KMS, mTLS, SAST/DAST container vulnerability scanning, and binary authorization. Observability Baseline: Build and maintain centralized logging, monitoring, and distributed tracing across all GCP environments, Apigee instances, and Exadata/JDE connectivity paths using Google Cloud Operations Suite (Cloud Logging, Cloud Monitoring, Cloud Trace). Minimum Requirements Experience: 10+ years of enterprise IT/infrastructure experience, with at least 4+ years dedicated to designing, engineering, and operating production environments on Google Cloud Platform (GCP). Apigee & Database/ERP Interconnect: Hands-on experience provisioning and supporting Apigee X / Apigee Edge environments and managing hybrid interconnectivity to high-performance database infrastructure (Oracle Exadata) and enterprise ERP systems (JD Edwards). IaC & Automation Mastery: Expert-level hands-on skills with Terraform, Git, and CI/CD pipelines (GitHub Actions, Cloud Build, or GitLab CI). Kubernetes & Containers: Strong experience deploying and managing production Google Kubernetes Engine (GKE) clusters and Docker containerized applications. GCP Networking & Security: Deep understanding of GCP VPC networking, Shared VPCs, Private Service Connect (PSC), VPC Service Controls, Cloud Interconnect, IAM, and GCP security controls. Scripting: Proficiency in Python, Bash, or Go for cloud automation and tooling development. FinOps Understanding: Practical experience implementing cloud cost optimization, quota management, and resource right-sizing strategies. Technical Skills Google Cloud Services: GKE, Cloud Run, Cloud SQL, BigQuery, Cloud Storage, VPC Service Controls, Secret Manager, IAM, Cloud Logging, Cloud Monitoring, Cloud Trace. API Management & Hybrid Database/ERP: Apigee X, Apigee Edge, Private Service Connect (PSC), Cloud Interconnect, Oracle Exadata database connectivity, JD Edwards (JDE) hybrid interconnectivity. Infrastructure-as-Code: Terraform, Terragrunt, Helm, Docker, Kubernetes. Networking & Security: Shared VPC, Cloud VPN, Cloud Interconnect, Firewalls, mTLS, OAuth 2.0, KMS, Least Privilege IAM. CI/CD & DevOps: GitHub Actions, Cloud Build, GitHub Advanced Security (GHAS), Git, Linux/Unix administration. Scripting & Tooling: Python, Bash, Go, gcloud CLI. Certifications & Education Certifications: Google Professional Cloud Architect or Google Professional Cloud DevOps Engineer (required or to be obtained within 6 months). Education: Bachelor's degree in Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience. About McKesson Medical-Surgical McKesson Medical-Surgical (MMS), which is expected to become Wellverse in early 2027, is a subsidiary and publicly reported segment of the McKesson Corporation. MMS distributes medical-surgical supplies, pharmaceuticals, diagnostic equipment and supplies, along with other solutions and services to virtually every type of healthcare setting and provider outside of the traditional hospital. These markets - often referred to as Alternate Care or Non-Acute Care - include physician offices, surgery centers, long-term care providers, laboratories, home health and hospice agencies, health systems, government facilities and online marketplaces and retailers. Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space. With a team of approximately 8,000 employees, a network of 15 distribution centers and approximately 900 delivery vehicles, we collaborate with more than 2,200 leading manufacturers and serve over 200,000 customer accounts across the U.S. Our catalog includes more than 270,000 SKUs of branded and private-label medical-surgical products - from bandages to specialty pharmaceuticals and COVID-19 tests. We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here. Our Base Pay Range for this position $115,300 - $192,100 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson's (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: . McKesson is an Equal Opportunity Employer McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page. McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities . click apply for full job details
09/27/2026
Full time
McKesson is an impact-driven, Fortune 10 company that touches virtually every aspect of healthcare. We are known for delivering insights, products, and services that make quality care more accessible and affordable. Here, we focus on the health, happiness, and well-being of you and those we serve - we care. What you do at McKesson matters. We foster a culture where you can grow, make an impact, and are empowered to bring new ideas. Together, we thrive as we shape the future of health for patients, our communities, and our people. If you want to be part of tomorrow's health today, we want to hear from you. Key Responsibilities GCP Foundation, Landing Zones & Infrastructure-as-Code Cloud Architecture & Automation: Design, build, and maintain enterprise GCP infrastructure using Terraform/Terragrunt, enforcing Infrastructure-as-Code (IaC) and GitOps practices for all cloud environments. Landing Zone Governance: Own the configuration and security baseline of GCP Organization structures, Projects, Folders, Resource Hierarchies, and IAM roles/permissions using least-privilege principles. Network & Hybrid Connectivity: Configure and maintain GCP Shared VPCs, VPC Service Controls (VPC-SC), Cloud Interconnect, Cloud VPN, Cloud DNS, Firewall Rules, and load balancers to support secure, low-latency hybrid connectivity between GCP services, Apigee X, and Oracle Exadata / JDE ERP environments. Apigee X & Oracle Exadata / JDE ERP Integration Support Apigee X Platform Engineering: Provision, configure, and maintain Apigee X runtime environments, API gateways, PSC (Private Service Connect) attachments, and load balancers in accordance with enterprise security baselines. Oracle Exadata & JDE Interconnect: Engineer and maintain high-performance, resilient hybrid network topology (Cloud Interconnect/Partner Interconnect) linking GCP applications and Apigee gateways directly to Oracle Exadata database systems and JDE backend services. API Security & Traffic Controls: Work alongside Integration Architects to enforce mTLS, VPC Service Controls, rate limiting, and secure endpoints across Apigee X, GCP microservices, and Exadata/JDE integration boundaries. Containerization, Compute & Serverless GKE & Kubernetes Management: Deploy, secure, and operate Google Kubernetes Engine (GKE) clusters powering enterprise Spring Boot microservices, AI workloads, and internal developer platforms. Serverless Execution: Configure and support serverless workloads using Cloud Run, Cloud Functions, and App Engine, optimizing performance and latency for transactional database and API flows. Platform Reliability: Build automated deployment pipelines using GitHub Actions or Cloud Build to support seamless infrastructure provisioning and application cutovers. FinOps & Cloud Cost Optimization Cost Allocation & Visibility: Establish FinOps standards across GCP projects, implementing label/tagging enforcement, budget alerts, and showback/chargeback reporting for business units. Resource Tuning: Analyze resource utilization (Compute Engine, GKE, Cloud SQL, BigQuery) to right-size instances, optimize committed use discounts (CUDs), and eliminate unused infrastructure. Security, Compliance & Observability Cloud Security Posture: Implement CISO security standards, including GCP Secret Manager, KMS, mTLS, SAST/DAST container vulnerability scanning, and binary authorization. Observability Baseline: Build and maintain centralized logging, monitoring, and distributed tracing across all GCP environments, Apigee instances, and Exadata/JDE connectivity paths using Google Cloud Operations Suite (Cloud Logging, Cloud Monitoring, Cloud Trace). Minimum Requirements Experience: 10+ years of enterprise IT/infrastructure experience, with at least 4+ years dedicated to designing, engineering, and operating production environments on Google Cloud Platform (GCP). Apigee & Database/ERP Interconnect: Hands-on experience provisioning and supporting Apigee X / Apigee Edge environments and managing hybrid interconnectivity to high-performance database infrastructure (Oracle Exadata) and enterprise ERP systems (JD Edwards). IaC & Automation Mastery: Expert-level hands-on skills with Terraform, Git, and CI/CD pipelines (GitHub Actions, Cloud Build, or GitLab CI). Kubernetes & Containers: Strong experience deploying and managing production Google Kubernetes Engine (GKE) clusters and Docker containerized applications. GCP Networking & Security: Deep understanding of GCP VPC networking, Shared VPCs, Private Service Connect (PSC), VPC Service Controls, Cloud Interconnect, IAM, and GCP security controls. Scripting: Proficiency in Python, Bash, or Go for cloud automation and tooling development. FinOps Understanding: Practical experience implementing cloud cost optimization, quota management, and resource right-sizing strategies. Technical Skills Google Cloud Services: GKE, Cloud Run, Cloud SQL, BigQuery, Cloud Storage, VPC Service Controls, Secret Manager, IAM, Cloud Logging, Cloud Monitoring, Cloud Trace. API Management & Hybrid Database/ERP: Apigee X, Apigee Edge, Private Service Connect (PSC), Cloud Interconnect, Oracle Exadata database connectivity, JD Edwards (JDE) hybrid interconnectivity. Infrastructure-as-Code: Terraform, Terragrunt, Helm, Docker, Kubernetes. Networking & Security: Shared VPC, Cloud VPN, Cloud Interconnect, Firewalls, mTLS, OAuth 2.0, KMS, Least Privilege IAM. CI/CD & DevOps: GitHub Actions, Cloud Build, GitHub Advanced Security (GHAS), Git, Linux/Unix administration. Scripting & Tooling: Python, Bash, Go, gcloud CLI. Certifications & Education Certifications: Google Professional Cloud Architect or Google Professional Cloud DevOps Engineer (required or to be obtained within 6 months). Education: Bachelor's degree in Computer Science, Information Technology, Engineering, or a related technical field, or equivalent practical experience. About McKesson Medical-Surgical McKesson Medical-Surgical (MMS), which is expected to become Wellverse in early 2027, is a subsidiary and publicly reported segment of the McKesson Corporation. MMS distributes medical-surgical supplies, pharmaceuticals, diagnostic equipment and supplies, along with other solutions and services to virtually every type of healthcare setting and provider outside of the traditional hospital. These markets - often referred to as Alternate Care or Non-Acute Care - include physician offices, surgery centers, long-term care providers, laboratories, home health and hospice agencies, health systems, government facilities and online marketplaces and retailers. Alternate Care markets are growing rapidly and MMS is proud to be a leader in this space. With a team of approximately 8,000 employees, a network of 15 distribution centers and approximately 900 delivery vehicles, we collaborate with more than 2,200 leading manufacturers and serve over 200,000 customer accounts across the U.S. Our catalog includes more than 270,000 SKUs of branded and private-label medical-surgical products - from bandages to specialty pharmaceuticals and COVID-19 tests. We are proud to offer a competitive compensation package at McKesson as part of our Total Rewards. This is determined by several factors, including performance, experience and skills, equity, regular job market evaluations, and geographical markets. The pay range shown below is aligned with McKesson's pay philosophy, and pay will always be compliant with any applicable regulations. In addition to base pay, other compensation, such as an annual bonus or long-term incentive opportunities may be offered. For more information regarding benefits at McKesson, please click here. Our Base Pay Range for this position $115,300 - $192,100 McKesson has become aware of online recruiting-related scams in which individuals who are not affiliated with or authorized by McKesson are using McKesson's (or affiliated entities, like CoverMyMeds or RxCrossroads) name in fraudulent emails, job postings or social media messages. In light of these scams, please bear the following in mind: McKesson Talent Advisors will never solicit money or credit card information in connection with a McKesson job application. McKesson Talent Advisors do not communicate with candidates via online chatrooms or using email accounts such as Gmail or Hotmail. Note that McKesson does rely on a virtual assistant (Gia) for certain recruiting-related communications with candidates. McKesson job postings are posted on our career site: . McKesson is an Equal Opportunity Employer McKesson provides equal employment opportunities to applicants and employees, without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, protected veteran status, disability, age, genetic information, or any other legally protected category. For additional information on McKesson's full Equal Employment Opportunity policies, visit our Equal Employment Opportunity page. McKesson is committed to being an Equal Employment Opportunity Employer and offers opportunities to all job seekers including job seekers with disabilities . click apply for full job details
Security Control Assessor/Representatives
Dark Wolf Solutions Arlington, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Offensive Security Control Assessor Security Control Assessor Representative
Dark Wolf Solutions Herndon, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Assessor (SCA)
LV8D Solutions Chantilly, Virginia
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
09/26/2026
Full time
Job Description Job Description Mission Context LV8D Solutions supports national security space and intelligence customers delivering next-generation sensing and exploitation capabilities. The role of a Security Control Assessor (SCA) is focused on providing information security Assessment and Authorization (A&A) support throughout the mission program's lifecycle. Position Overview LV8D Solutions is seeking a SCA to conduct independent assessments of the management, operational, and technical security controls employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the security controls. A Security Control Assessor (SCA) performs comprehensive INFOSEC assessment of management, operational, and technical security controls to determine overall effectiveness of the controls for A&A determination throughout a program's system lifecycle. SCAs provide an assessment of the severity of weakness or deficiencies discovered in the Information System (IS) and its environment of operation and recommend corrective actions to address identified vulnerabilities. Prior to initiating the security control assessment, the SCA reviews the System Security Plan (SSP) to ensure the plan provides a set of security controls for the ISs that meet the stated security requirements. Additionally, the SCA must verify that all allocated controls have an acceptable status (i.e., implemented, excepted, or inherited) with appropriate documented details and provides responses in the Government's Risk Management Framework (RMF) tools. Interested candidates need to thrive in an innovative, fast-paced environment; are highly motivated and not afraid to take on uncharted territory; possess strong communication, leadership, and organizational skills; and be able to prioritize their time to be effective in a dynamic environment. Requirements Key Responsibilities Reviews IS for compliance with applicable Intelligence Community (IC), Department of War (DoW), and National Directorate (ND) guidance, and make recommendations to the Government. Provides ISs security advice and guidance Joint Analytical Workstation (JAW) applicable IC, DoW, and NDs and guidance to Government and industry partners for the protection of data at all classification levels including Sensitive Compartmented Information (SCI). Evaluates threats and vulnerabilities to ISs to ascertain the need for additional safeguards and recommend approval, disapproval, or waiver(s) for IS processing national security data at industry and/or Government facilities. Supports development and implementation of directives and guidance for policies. Provides input for consideration in the promulgation of future ISs security policy. Supports and/or conduct site visits and assessments to inspect and verify IS reports. Ensures security control assessments are completed for each IS. Supports the preparation and delivery of presentations, briefings, reports, and memoranda associated with the RMF process. Uses the RMF system of record to complete RMF workflow duties and maintain the asset documentation repository. Establishes and maintains means and methods to track RMF process workflow activities to inform task volume, velocity, and duration of activities. Prepares the final Security Assessment Report (SAR) containing the results and findings from the assessment at the conclusion of each security control assessment activity and the Authorization Recommendation. Ensures appropriate IS security requirements including applicable Interface Control Documents (ICDs), DoW Instructions, NDs and other guidance are addressed and applied and appropriate documentation is prepared by the system owners or programs. The documentation will be contained in the Security Assessment Package, including, but not limited to, the Concept of Operations (CONOP), SSP, Systems Requirements Traceability Matrix, Risk Management Matrix, Test Results, interface control documents, requests for changes, test plans, and other related program security documentation. Collaborates with Information Security Officers (ISOs) and Common Control Providers to initiate Plan of Action and Milestones (POAMs) for ISs based on findings and recommendations from the SAR. Reviews and approves the IS Security Assessment Plan which is comprised of the Security Controls Traceability Matrix and the Security Control Assessment Procedures. Tracks the completion of the SAR. Reviews, coordinates, and responds to security issues as requested by the Government. Provides A&A support to the Government for the protection of special programs and tactical operations related activities. Supplies the effort needed to conduct the reviews and write reports to support Integrated Security Assessment Program (ISAP) or Technical Information Systems Security Reviews (TISSRs). Required Qualifications Practical experience performing information systems A&A as defined in applicable ICDs and guidance Practical experience utilizing risk management strategies for information technology solutions Technical understanding of emerging technologies and their implementation within Government system and network environments Knowledge of information technology concepts used in the evaluation of security performance and integrity of state-of-the-art applications, communications systems, hardware, software, satellite control systems, and information processing systems Technical understanding of information technology systems, software, and networks Ability to effectively coordinate A&A activities of industry and Government information systems to meet acquisition milestone requirements Effective technical report and general correspondence writing ability Ability to manage and track systems or programs involved in the A&A process Experience developing and implementing security related directives and guidance for Information Assurance, Information Technology, and Information Management Experience working with a mixed level skill team to ensure that appropriate knowledge and skill transfer occurs High school's degree and 7+ years of relevant experience, or Associate's degree and 7+ years of relevant experience, or Bachelor's degree and 5+ years of relevant experience, or Master's degree and 3+ years of relevant experience Certifications Must have one of the following IAM Level 2 Certification: CGRC (Previously CAP) CASP CISM CISSP GSLC CCISO Security Requirements U.S. Citizenship Active Top Secret/Sensitive Compartmented Information (TS/SCI) clearance Active Counterintelligence (CI) or Full Scope (FS) Polygraph Work Environment On-site work in a government or contractor facility Occasional travel (up to 10%) This position is dependent on a contract seat being awarded. About LV8D Solutions LV8D Solutions is an elite Systems Engineering and Technical Advisory (SETA) company that delivers advanced systems engineering, integration, acquisition, mission operations, network communications, and cybersecurity support to our defense and intelligence customers. Founded in 2019, we apply our deep technical expertise, understanding, and mission-first mindset to design, acquire, and implement complex, high-impact solutions for our Intelligence Community (IC) and Department of War (DoW) customers. We specialize in every aspect of our customers' space and ground mission systems while offering exceptional work-life balance and an exemplary compensation and total rewards package designed to recruit, train, and retain top talent and committed to national defense and career growth. Equal Employment Opportunity Statement LV8D Solutions LLC is an Equal Opportunity Employer committed to diversity and inclusion. All qualified applicants will receive consideration without regard to race, religion, gender, national origin, disability, veteran status, or other protected categories. Benefits Performance & Recognition Period of Performance (PoP) Bonus Opportunities Performance-based bonus opportunities tied to contract or organizational performance. Retention Incentive Benefit Bounty Receive a payout for unused annual company contributions designated for health insurance premiums and professional training. Referral Bonus Earn up to $5,000 for each successful employee referral. Customer Recognition Letter of Appreciation (LoA) Bonus Opportunities Bonus opportunities based on customer recognition received through Letters of Appreciation. Milestone Rewards Celebrate your career achievements with anniversary awards on your 1st, 5th, 10th, and 20th years of service. Financial & Retirement Benefits Profit Sharing Receive an annual contribution equal to 4% of your W-2 gross earnings into your 401 (k), with immediate vesting. 401(k) Company Match The company matches your 401 (k) contributions dollar-for-dollar up to 6% of your monthly contribution, with immediate vesting. Career Development The company invests in your professional growth through: Annual financial support for professional training and industry certifications. Enhanced financial support for employees actively pursuing a degree at an accredited institution. Work-Life Balance . click apply for full job details
Intermediate AV/VTC Specialist
BTI Washington, Washington DC
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Intermediate AV/VTC Specialist will provide audiovisual, video teleconferencing, collaboration-platform, and multimedia production support for the Equal Employment Opportunity Commission. This position supports the configuration, operation, maintenance, and troubleshooting of AV/VTC systems within a distributed enterprise environment similar in size and complexity to the EEOC. The ideal candidate will have at least six years of relevant experience supporting audiovisual technologies, video production equipment, conferencing platforms, and integrated multimedia systems. The specialist will support live meetings, virtual conferences, presentations, broadcasts, and other mission-related events while ensuring high-quality audio, video, and collaboration services. Key Responsibilities Configure, operate, maintain, and troubleshoot audiovisual, video teleconferencing, and multimedia production equipment. Provide technical and operational support for Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing systems and endpoints. Set up and support virtual meetings, hybrid meetings, executive conferences, presentations, live events, and video teleconferences. Perform pre-event system checks and confirm that cameras, microphones, displays, speakers, conferencing platforms, and network connections are operating correctly. Monitor live meetings and events, quickly identifying and resolving audio, video, connectivity, or equipment issues. Provide video editing and post-production services for recorded meetings, training materials, presentations, and organizational communications. Operate video switchers, professional cameras, recording equipment, and related production technologies. Support camera placement, framing, lighting, recording, and live video production activities. Develop and edit graphics, animations, motion graphics, presentation materials, and other visual media. Perform audio mixing and configure microphones, speakers, amplifiers, and other sound-reinforcement equipment. Configure and support digital signal processing systems used for audio routing, optimization, and control. Operate and maintain AV control systems, projection systems, video walls, digital displays, and LED display technologies. Diagnose and resolve hardware, software, signal-routing, audio-quality, video-quality, and platform-integration issues. Perform preventive maintenance, firmware updates, equipment testing, and routine system inspections. Coordinate with IT, networking, facilities, communications, and event-support personnel to ensure reliable service delivery. Assist end users, presenters, executives, and meeting organizers with the proper use of AV/VTC systems. Maintain equipment inventories, system configurations, maintenance records, technical documentation, and standard operating procedures. Escalate complex technical issues to senior AV/VTC personnel, vendors, or appropriate support teams. Follow EEOC security, accessibility, operational, and information-technology policies and procedures. Minimum Qualifications A minimum of six years of experience providing AV/VTC support in an enterprise or federal environment similar in size, scope, and complexity to the EEOC. Demonstrated experience configuring, operating, maintaining, and troubleshooting AV and multimedia production equipment. Hands-on experience supporting Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing technologies. Experience with video editing, post-production, video switching, and camera operations. Experience with graphic design, animation, and motion-graphics development. Knowledge of professional audio mixing, microphone systems, signal routing, and sound-reinforcement technologies. Experience with digital signal processing, AV control systems, projection systems, video displays, and LED display technologies. Ability to support live, virtual, and hybrid meetings in a time-sensitive environment. Strong troubleshooting, customer-service, organization, and communication skills. Ability to communicate technical information clearly to both technical and nontechnical users. Ability to work independently and collaboratively with IT teams, government personnel, vendors, and other stakeholders. Ability to lift, move, install, and position AV equipment as required. Preferred Qualifications Associate's or bachelor's degree in Audiovisual Technology, Broadcast Production, Communications, Information Technology, Multimedia Production, or a related discipline. Experience supporting a federal government agency or a geographically distributed organization. Experience with enterprise conference rooms, executive briefing rooms, training rooms, auditoriums, and live-event environments. AVIXA Certified Technology Specialist certification, such as CTS, CTS-I, or CTS-D. Manufacturer certifications involving Poly, Cisco, Crestron, Extron, QSC, Biamp, or similar AV technologies. Familiarity with Section 508 accessibility requirements and federal information-security standards. Core Competencies AV/VTC system operation and troubleshooting Microsoft Teams, Zoom, Poly, and Cisco support Live and hybrid meeting support Video editing and post-production Video switching and camera operation Graphic design and motion graphics Professional audio mixing Digital signal processing AV control and projection systems LED and digital display technologies Preventive maintenance and documentation Customer and executive-level support Choose a Description from the Library LocationCountry - Multiple Countries -AfghanistanAland IslandsAlbaniaAlbertaAlgeriaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia and HerzegovinaBotswanaBouvet IslandBrazilBritish ColumbiaBritish Indian Ocean TerritoryBrunei DarussalamBulgariaBurkina FasoBurundiCambodiaCameroonCanadaCape VerdeCayman IslandsCentral African RepublicChadChileChinaChristmas IslandCocos (Keeling) IslandsColombiaComorosCongoCongo, The Democratic Republic of theCook IslandsCosta RicaCôte d' IvoireCroatiaCubaCyprusCzech RepublicDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFalkland Islands (Malvinas)Faroe IslandsFederated States Of MicronesiaFijiFinlandFranceFrench GuianaFrench PolynesiaFrench Southern TerritoriesGabonGambiaGeorgiaGermanyGhanaGibraltarGreat BritainGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuernseyGuineaGuinea - BissauGuyanaHaitiHeard Island and McDonald IslandsHoly See (Vatican City State)HondurasHong KongHungaryIcelandIndiaIndonesiaIran, Islamic Republic ofIraqIrelandIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKorea, Democratic People's Republic ofKosovoKuwaitKyrgyzstanLao People's Democratic RepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia, Republic ofMadagascarMalawiMalaysiaMaldivesMaliMaltaManitobaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMoldovaMonacoMongoliaMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNetherlands AntillesNew BrunswickNew CaledoniaNew ZealandNewfoundland and LabradorNicaraguaNigerNigeriaNiueNorfolk IslandNorthern Mariana IslandsNorthwest TerritoriesNorwayNova ScotiaNunavutOmanOntarioPakistanPalauPalestinian Territory, OccupiedPanamaPapua New GuineaParaguayPeruPhilippinesPitcairnPolandPortugalPrince Edward IslandPuerto RicoQatarQuebecReunionRomaniaRussian FederationRwandaSaint BarthélemySaint HelenaSaint Kitts and NevisSaint LuciaSaint Martin (French part)Saint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaskatchewanSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth Georgia and the South Sandwich IslandsSouth KoreaSouth SudanSpainSri LankaSudanSurinameSvalbard and Jan MayenSwazilandSwedenSwitzerlandSyrian Arab RepublicTaiwanTajikistanTanzania, United Republic ofThailandTimor- LesteTogoTokelauTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTurks and Caicos IslandsTuvaluUgandaUkraineUnited Arab EmiratesUnited KingdomUnited StatesUnited States Minor Outlying IslandsUruguayUzbekistanVanuatuVenezuelaViet NamVirgin IslandsWallis and FutunaWestern SaharaYemenYukonZambiaZimbabwe Street Address Powered by JazzHR ktfBlmglPp
09/26/2026
Full time
Job Description Job Description Business Technology Integrators (BTI) is a Service-Disabled Veteran-Owned Small Business (SDVOSB) with more than 25 years of experience delivering innovative and reliable IT and engineering solutions to the Federal Government. BTI supports mission-critical programs across defense and civilian agencies, with core expertise in cybersecurity, program management, enterprise IT, and technical oversight services. Position Overview The Intermediate AV/VTC Specialist will provide audiovisual, video teleconferencing, collaboration-platform, and multimedia production support for the Equal Employment Opportunity Commission. This position supports the configuration, operation, maintenance, and troubleshooting of AV/VTC systems within a distributed enterprise environment similar in size and complexity to the EEOC. The ideal candidate will have at least six years of relevant experience supporting audiovisual technologies, video production equipment, conferencing platforms, and integrated multimedia systems. The specialist will support live meetings, virtual conferences, presentations, broadcasts, and other mission-related events while ensuring high-quality audio, video, and collaboration services. Key Responsibilities Configure, operate, maintain, and troubleshoot audiovisual, video teleconferencing, and multimedia production equipment. Provide technical and operational support for Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing systems and endpoints. Set up and support virtual meetings, hybrid meetings, executive conferences, presentations, live events, and video teleconferences. Perform pre-event system checks and confirm that cameras, microphones, displays, speakers, conferencing platforms, and network connections are operating correctly. Monitor live meetings and events, quickly identifying and resolving audio, video, connectivity, or equipment issues. Provide video editing and post-production services for recorded meetings, training materials, presentations, and organizational communications. Operate video switchers, professional cameras, recording equipment, and related production technologies. Support camera placement, framing, lighting, recording, and live video production activities. Develop and edit graphics, animations, motion graphics, presentation materials, and other visual media. Perform audio mixing and configure microphones, speakers, amplifiers, and other sound-reinforcement equipment. Configure and support digital signal processing systems used for audio routing, optimization, and control. Operate and maintain AV control systems, projection systems, video walls, digital displays, and LED display technologies. Diagnose and resolve hardware, software, signal-routing, audio-quality, video-quality, and platform-integration issues. Perform preventive maintenance, firmware updates, equipment testing, and routine system inspections. Coordinate with IT, networking, facilities, communications, and event-support personnel to ensure reliable service delivery. Assist end users, presenters, executives, and meeting organizers with the proper use of AV/VTC systems. Maintain equipment inventories, system configurations, maintenance records, technical documentation, and standard operating procedures. Escalate complex technical issues to senior AV/VTC personnel, vendors, or appropriate support teams. Follow EEOC security, accessibility, operational, and information-technology policies and procedures. Minimum Qualifications A minimum of six years of experience providing AV/VTC support in an enterprise or federal environment similar in size, scope, and complexity to the EEOC. Demonstrated experience configuring, operating, maintaining, and troubleshooting AV and multimedia production equipment. Hands-on experience supporting Microsoft Teams, Zoom, Poly RealPresence, and Cisco video conferencing technologies. Experience with video editing, post-production, video switching, and camera operations. Experience with graphic design, animation, and motion-graphics development. Knowledge of professional audio mixing, microphone systems, signal routing, and sound-reinforcement technologies. Experience with digital signal processing, AV control systems, projection systems, video displays, and LED display technologies. Ability to support live, virtual, and hybrid meetings in a time-sensitive environment. Strong troubleshooting, customer-service, organization, and communication skills. Ability to communicate technical information clearly to both technical and nontechnical users. Ability to work independently and collaboratively with IT teams, government personnel, vendors, and other stakeholders. Ability to lift, move, install, and position AV equipment as required. Preferred Qualifications Associate's or bachelor's degree in Audiovisual Technology, Broadcast Production, Communications, Information Technology, Multimedia Production, or a related discipline. Experience supporting a federal government agency or a geographically distributed organization. Experience with enterprise conference rooms, executive briefing rooms, training rooms, auditoriums, and live-event environments. AVIXA Certified Technology Specialist certification, such as CTS, CTS-I, or CTS-D. Manufacturer certifications involving Poly, Cisco, Crestron, Extron, QSC, Biamp, or similar AV technologies. Familiarity with Section 508 accessibility requirements and federal information-security standards. Core Competencies AV/VTC system operation and troubleshooting Microsoft Teams, Zoom, Poly, and Cisco support Live and hybrid meeting support Video editing and post-production Video switching and camera operation Graphic design and motion graphics Professional audio mixing Digital signal processing AV control and projection systems LED and digital display technologies Preventive maintenance and documentation Customer and executive-level support Choose a Description from the Library LocationCountry - Multiple Countries -AfghanistanAland IslandsAlbaniaAlbertaAlgeriaAndorraAngolaAnguillaAntarcticaAntigua and BarbudaArgentinaArmeniaArubaAustraliaAustriaAzerbaijanBahamasBahrainBangladeshBarbadosBelarusBelgiumBelizeBeninBermudaBhutanBoliviaBosnia and HerzegovinaBotswanaBouvet IslandBrazilBritish ColumbiaBritish Indian Ocean TerritoryBrunei DarussalamBulgariaBurkina FasoBurundiCambodiaCameroonCanadaCape VerdeCayman IslandsCentral African RepublicChadChileChinaChristmas IslandCocos (Keeling) IslandsColombiaComorosCongoCongo, The Democratic Republic of theCook IslandsCosta RicaCôte d' IvoireCroatiaCubaCyprusCzech RepublicDenmarkDjiboutiDominicaDominican RepublicEcuadorEgyptEl SalvadorEquatorial GuineaEritreaEstoniaEthiopiaFalkland Islands (Malvinas)Faroe IslandsFederated States Of MicronesiaFijiFinlandFranceFrench GuianaFrench PolynesiaFrench Southern TerritoriesGabonGambiaGeorgiaGermanyGhanaGibraltarGreat BritainGreeceGreenlandGrenadaGuadeloupeGuamGuatemalaGuernseyGuineaGuinea - BissauGuyanaHaitiHeard Island and McDonald IslandsHoly See (Vatican City State)HondurasHong KongHungaryIcelandIndiaIndonesiaIran, Islamic Republic ofIraqIrelandIsle of ManIsraelItalyJamaicaJapanJerseyJordanKazakhstanKenyaKiribatiKorea, Democratic People's Republic ofKosovoKuwaitKyrgyzstanLao People's Democratic RepublicLatviaLebanonLesothoLiberiaLibyaLiechtensteinLithuaniaLuxembourgMacaoMacedonia, Republic ofMadagascarMalawiMalaysiaMaldivesMaliMaltaManitobaMarshall IslandsMartiniqueMauritaniaMauritiusMayotteMexicoMoldovaMonacoMongoliaMontenegroMontserratMoroccoMozambiqueMyanmarNamibiaNauruNepalNetherlandsNetherlands AntillesNew BrunswickNew CaledoniaNew ZealandNewfoundland and LabradorNicaraguaNigerNigeriaNiueNorfolk IslandNorthern Mariana IslandsNorthwest TerritoriesNorwayNova ScotiaNunavutOmanOntarioPakistanPalauPalestinian Territory, OccupiedPanamaPapua New GuineaParaguayPeruPhilippinesPitcairnPolandPortugalPrince Edward IslandPuerto RicoQatarQuebecReunionRomaniaRussian FederationRwandaSaint BarthélemySaint HelenaSaint Kitts and NevisSaint LuciaSaint Martin (French part)Saint Pierre and MiquelonSaint Vincent and the GrenadinesSamoaSan MarinoSao Tome and PrincipeSaskatchewanSaudi ArabiaSenegalSerbiaSeychellesSierra LeoneSingaporeSlovakiaSloveniaSolomon IslandsSomaliaSouth AfricaSouth Georgia and the South Sandwich IslandsSouth KoreaSouth SudanSpainSri LankaSudanSurinameSvalbard and Jan MayenSwazilandSwedenSwitzerlandSyrian Arab RepublicTaiwanTajikistanTanzania, United Republic ofThailandTimor- LesteTogoTokelauTongaTrinidad and TobagoTunisiaTurkeyTurkmenistanTurks and Caicos IslandsTuvaluUgandaUkraineUnited Arab EmiratesUnited KingdomUnited StatesUnited States Minor Outlying IslandsUruguayUzbekistanVanuatuVenezuelaViet NamVirgin IslandsWallis and FutunaWestern SaharaYemenYukonZambiaZimbabwe Street Address Powered by JazzHR ktfBlmglPp
Principal DevOps Engineer
Ursa Major Berthoud, Colorado
Job Description Job Description The future of aerospace and defense starts here. Ursa Major was founded to revolutionize how America and its allies access and apply high-performance propulsion, from hypersonics to solid rocket motors, satellite maneuvering and launch. We design and deliver propulsion and defense systems that solve the most urgent and critical national security demands. Ursa Major is bringing a new model to propulsion and defense technology: one where performance and access are no longer constrained by legacy systems. We design, build, and deploy advanced propulsion systems that power national security missions, hypersonic capabilities, and the future of space access. Our mission requires an extraordinary team-one that will mold tomorrow's critical technologies while deploying today's best. We are an intrinsically motivated team with a passion for solving complex technical problems and empowering each other every day, knowing that there is always room for growth. As a Principal DevOps Engineer within our Digital Operations team, you won't just be managing servers or responding to deployment tickets. You will be a principal technical leader and system architect responsible for owning and shaping Ursa Major's platform engineering, infrastructure automation, and software deployment strategies across cloud, on-premise, and manufacturing environments. Sitting at the vital intersection of Software Engineering, IT, Zero-Trust Networking, Digital Manufacturing, and Cybersecurity, you will build the foundational platforms that empower our engineering and manufacturing teams to design, test, and deliver mission-critical systems faster and more reliably. As Ursa Major expands, you will decompose complex technical challenges, author clear architecture designs, and drive pragmatic, high-impact solutions that connect our cloud environments directly to physical manufacturing and test-bench hardware. Responsibilities: Platform Architecture & Developer Experience Lead the research, design, and continuous improvement of platform infrastructure, software deployment, and Developer Experience (DX) across the enterprise. Decompose complex infrastructure problems into maintainable systems; author clear technical design documents and lead cross-functional teams through execution. Act as a strategic connector between Software Engineering, IT, and Networking to unify tooling, share infrastructure patterns, and eliminate operational silos. Infrastructure-as-Code (IaC), GitOps & High Availability (HA) Advance our declarative Infrastructure-as-Code (IaC) and GitOps practices (using Terraform, Helm, and ArgoCD/Flux) to deliver fully automated, drift-free application lifecycles across Azure GovCloud and AWS GovCloud. Extend containerization and orchestration (Kubernetes, Docker) beyond cloud environments into on-premise test benches, shop-floor PCs, and edge manufacturing hardware in alignment with our CMMC Level 2 hybrid strategy. Own Disaster Recovery (DR) and Business Continuity (BC) architecture-maintaining automated backup and failover capabilities that keep critical system recovery times measured in minutes, not days. DevSecOps & AI Pipeline Integration Partner with Cybersecurity and Zero-Trust teams to integrate automated vulnerability scanning, secrets management, and policy-as-code guardrails directly into CI/CD workflows without introducing developer friction. Architect and support automated pipelines for hosted and private AI models, enabling software and engineering teams to leverage high-throughput AI capabilities safely within our secure compliance boundary. Maintain continuous telemetry, metrics, and alerting frameworks (Prometheus, Grafana) to give engineers real-time visibility into application performance and pipeline health. Leadership, Mentorship & Impact Frame all technical initiatives in terms of maximum impact on overall business health, execution speed, and system reliability. Mentor and elevate engineers across the software and IT organizations, fostering a culture of analytical, value-driven problem-solving. Function as a top-level technical decision-maker, managing high-ambiguity challenges with high autonomy while maintaining psychological safety and clear standards of excellence Minimum Qualifications: 8+ years of professional DevOps, SRE, or Infrastructure/Platform Engineering experience, with a proven track record of principal-level technical leadership and system architecture. Hands-on mastery of Azure GovCloud and/or AWS GovCloud environments, with deep expertise in VPC networking, IAM, and cloud-native security controls. Advanced proficiency in Terraform, Docker, Kubernetes, Helm, and continuous delivery via GitOps patterns (ArgoCD, GitHub Actions, or Flux). Direct experience architecting high-availability systems, automated DR solutions, and telemetry suites (Prometheus, Grafana). Practical experience configuring automated container/code and centralized secrets management (AWS/Azure Key Vaults, HashiCorp Vault). Experience automating, deploying, or supporting hosted AI model integrations within production CI/CD pipelines. A proactive problem solver who builds trust across teams, rejects black-and-white thinking, and focuses on enabling business outcomes. Preferred Qualifications: Familiarity with NIST SP 800-171 / CMMC Level 2 compliance standards and securing CUI data flows. Experience with Artifactory, SonarQube, Open Policy Agent (OPA), Kyverno, or automated Software Bill of Materials (SBOM) tooling. Experience automating physical hardware, edge nodes, or shop-floor environments using Packer, Ansible, K3s, or Rancher. Experience orchestrating self-hosted or private AI model execution frameworks. Ability to obtain and maintain a U.S. Government Security Clearance. Colorado law requires us to tell you the base compensation range of this role, which is $175,000 - $215,000, determined by your education, experience, knowledge, skills, and abilities. The salary range for this role is intentionally wide as we are evaluating individuals based on their unique experience and abilities to fit our needs. Most importantly, we are excited to meet you and see if you are a great fit for our team. What we can't quantify for you are the exciting challenges, supportive team, and amazing culture we enjoy. Classification: Full-Time, Exempt Benefits Include: (Please note, Interns are not eligible for benefits) Unlimited PTO - Vacation, Sick, Personal, and Bereavement Paid Parental and Adoptive Leave Medical, Dental and Vision Insurance Tax Advantage Accounts (HSA/FSA) Employer Paid Short and Long Term Disability, Basic Life, AD&D Additional Benefit Options Including Voluntary Life and Emergency Medical Transport EAP Program Retirement Savings Plan - 401k with Company Match Equity Grants in the Company How To Apply: Interested candidates are encouraged to apply by filling out the application below and clicking "Submit Application". This position will be posted for a minimum of 3 days and will remain open until filled or adjusted based on the volume of applicants. NOTE: Research suggests that women and BIPOC individuals may self-select out of opportunities if they don't meet 100% of the job requirements. We encourage anyone who believes they have the skills and the drive necessary to succeed here to apply for this role. Must be a U.S. Person (this includes U.S. Citizens and Permanent Residents). Eligibility to obtain and maintain a U.S. Security Clearance. We're an equal-opportunity employer. You will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status. No outside recruiters, please.
09/26/2026
Full time
Job Description Job Description The future of aerospace and defense starts here. Ursa Major was founded to revolutionize how America and its allies access and apply high-performance propulsion, from hypersonics to solid rocket motors, satellite maneuvering and launch. We design and deliver propulsion and defense systems that solve the most urgent and critical national security demands. Ursa Major is bringing a new model to propulsion and defense technology: one where performance and access are no longer constrained by legacy systems. We design, build, and deploy advanced propulsion systems that power national security missions, hypersonic capabilities, and the future of space access. Our mission requires an extraordinary team-one that will mold tomorrow's critical technologies while deploying today's best. We are an intrinsically motivated team with a passion for solving complex technical problems and empowering each other every day, knowing that there is always room for growth. As a Principal DevOps Engineer within our Digital Operations team, you won't just be managing servers or responding to deployment tickets. You will be a principal technical leader and system architect responsible for owning and shaping Ursa Major's platform engineering, infrastructure automation, and software deployment strategies across cloud, on-premise, and manufacturing environments. Sitting at the vital intersection of Software Engineering, IT, Zero-Trust Networking, Digital Manufacturing, and Cybersecurity, you will build the foundational platforms that empower our engineering and manufacturing teams to design, test, and deliver mission-critical systems faster and more reliably. As Ursa Major expands, you will decompose complex technical challenges, author clear architecture designs, and drive pragmatic, high-impact solutions that connect our cloud environments directly to physical manufacturing and test-bench hardware. Responsibilities: Platform Architecture & Developer Experience Lead the research, design, and continuous improvement of platform infrastructure, software deployment, and Developer Experience (DX) across the enterprise. Decompose complex infrastructure problems into maintainable systems; author clear technical design documents and lead cross-functional teams through execution. Act as a strategic connector between Software Engineering, IT, and Networking to unify tooling, share infrastructure patterns, and eliminate operational silos. Infrastructure-as-Code (IaC), GitOps & High Availability (HA) Advance our declarative Infrastructure-as-Code (IaC) and GitOps practices (using Terraform, Helm, and ArgoCD/Flux) to deliver fully automated, drift-free application lifecycles across Azure GovCloud and AWS GovCloud. Extend containerization and orchestration (Kubernetes, Docker) beyond cloud environments into on-premise test benches, shop-floor PCs, and edge manufacturing hardware in alignment with our CMMC Level 2 hybrid strategy. Own Disaster Recovery (DR) and Business Continuity (BC) architecture-maintaining automated backup and failover capabilities that keep critical system recovery times measured in minutes, not days. DevSecOps & AI Pipeline Integration Partner with Cybersecurity and Zero-Trust teams to integrate automated vulnerability scanning, secrets management, and policy-as-code guardrails directly into CI/CD workflows without introducing developer friction. Architect and support automated pipelines for hosted and private AI models, enabling software and engineering teams to leverage high-throughput AI capabilities safely within our secure compliance boundary. Maintain continuous telemetry, metrics, and alerting frameworks (Prometheus, Grafana) to give engineers real-time visibility into application performance and pipeline health. Leadership, Mentorship & Impact Frame all technical initiatives in terms of maximum impact on overall business health, execution speed, and system reliability. Mentor and elevate engineers across the software and IT organizations, fostering a culture of analytical, value-driven problem-solving. Function as a top-level technical decision-maker, managing high-ambiguity challenges with high autonomy while maintaining psychological safety and clear standards of excellence Minimum Qualifications: 8+ years of professional DevOps, SRE, or Infrastructure/Platform Engineering experience, with a proven track record of principal-level technical leadership and system architecture. Hands-on mastery of Azure GovCloud and/or AWS GovCloud environments, with deep expertise in VPC networking, IAM, and cloud-native security controls. Advanced proficiency in Terraform, Docker, Kubernetes, Helm, and continuous delivery via GitOps patterns (ArgoCD, GitHub Actions, or Flux). Direct experience architecting high-availability systems, automated DR solutions, and telemetry suites (Prometheus, Grafana). Practical experience configuring automated container/code and centralized secrets management (AWS/Azure Key Vaults, HashiCorp Vault). Experience automating, deploying, or supporting hosted AI model integrations within production CI/CD pipelines. A proactive problem solver who builds trust across teams, rejects black-and-white thinking, and focuses on enabling business outcomes. Preferred Qualifications: Familiarity with NIST SP 800-171 / CMMC Level 2 compliance standards and securing CUI data flows. Experience with Artifactory, SonarQube, Open Policy Agent (OPA), Kyverno, or automated Software Bill of Materials (SBOM) tooling. Experience automating physical hardware, edge nodes, or shop-floor environments using Packer, Ansible, K3s, or Rancher. Experience orchestrating self-hosted or private AI model execution frameworks. Ability to obtain and maintain a U.S. Government Security Clearance. Colorado law requires us to tell you the base compensation range of this role, which is $175,000 - $215,000, determined by your education, experience, knowledge, skills, and abilities. The salary range for this role is intentionally wide as we are evaluating individuals based on their unique experience and abilities to fit our needs. Most importantly, we are excited to meet you and see if you are a great fit for our team. What we can't quantify for you are the exciting challenges, supportive team, and amazing culture we enjoy. Classification: Full-Time, Exempt Benefits Include: (Please note, Interns are not eligible for benefits) Unlimited PTO - Vacation, Sick, Personal, and Bereavement Paid Parental and Adoptive Leave Medical, Dental and Vision Insurance Tax Advantage Accounts (HSA/FSA) Employer Paid Short and Long Term Disability, Basic Life, AD&D Additional Benefit Options Including Voluntary Life and Emergency Medical Transport EAP Program Retirement Savings Plan - 401k with Company Match Equity Grants in the Company How To Apply: Interested candidates are encouraged to apply by filling out the application below and clicking "Submit Application". This position will be posted for a minimum of 3 days and will remain open until filled or adjusted based on the volume of applicants. NOTE: Research suggests that women and BIPOC individuals may self-select out of opportunities if they don't meet 100% of the job requirements. We encourage anyone who believes they have the skills and the drive necessary to succeed here to apply for this role. Must be a U.S. Person (this includes U.S. Citizens and Permanent Residents). Eligibility to obtain and maintain a U.S. Security Clearance. We're an equal-opportunity employer. You will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran, or disability status. No outside recruiters, please.
Network Security Engineer
MDVIP LLC Boca Raton, Florida
Job Description Job Description Description: MDVIP: Transforming Primary Care, One Patient at a Time MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work since 2018, MDVIP is committed to excellence in patient care and employee satisfaction. Position Summary The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers. This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization's on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations - including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score - while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule. Key Responsibilities Security Remediation & Compliance Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery. Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments. Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere). Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements. Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score. Core Platform & Infrastructure Ownership Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders. Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications. Utilize automation tools to deploy required machine certificates across the organization. Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team's SIEM ingestion, correlation, and compliance reporting needs. Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning. Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks. Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass. Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls. Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices. Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure. Operational Reliability & Risk Reduction Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables. Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions. Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives. Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership. Key Competencies Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data. Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships. Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively. Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared. Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions. Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects. Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours. Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed. Requirements: Qualifications Required Qualifications Bachelor's degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience. Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments. Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent). Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure. Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms). Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings. Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass). This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S. Preferred Qualifications Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification. Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks. Why Join MDVIP? Be part of a mission-driven organization leading innovation in personalized healthcare. Drive transformation and growth in a dynamic, fast-paced environment. Competitive Compensation: Attractive base salary complemented by performance-based incentives. Comprehensive Benefits: Health, dental, vision insurance, and retirement plans. Professional Development: Access to ongoing training and leadership development programs. Positive Work Environment: Consistently recognized as a Great Place to Work , fostering a culture of collaboration and excellence. MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture. If you require accommodations during the application or interview process, please let us know, and we will be happy to assist. Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements . click apply for full job details
09/26/2026
Full time
Job Description Job Description Description: MDVIP: Transforming Primary Care, One Patient at a Time MDVIP is a national leader in personalized healthcare, empowering over 425,000 members to achieve their health and wellness goals through a network of more than 1,400 concierge primary care physicians. Our program emphasizes preventive medicine, offering comprehensive screenings, advanced diagnostics, and individualized wellness plans. Recognized as a Great Place to Work since 2018, MDVIP is committed to excellence in patient care and employee satisfaction. Position Summary The Network Security Engineer is an individual contributor role reporting to the Sr. Network Operations Manager. This is a contract-to-perm position (6-month contract), based in Boca Raton, FL (Hybrid), supporting the Boca Raton and Atlanta (ATL) data centers. This role provides dedicated engineering capacity for the ownership, hardening, and reliability of the organization's on-premises and hybrid infrastructure. The Network Security Engineer sustains a predictable remediation cadence across recurring security obligations - including monthly patching, zero-day response, vulnerability remediation, OS hardening, and cloud security score - while maintaining core platform services that underpin 24/7 operational reliability. This role is critical to reducing key-person risk, closing the capacity gap between rising compliance/audit workloads and existing staffing, and ensuring remediation tied to penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments is completed on schedule. Key Responsibilities Security Remediation & Compliance Execute remediation for findings from penetration tests, annual Security Risk Assessments (SRAs), and HIPAA assessments, ensuring items are tracked to closure within defined SLAs; work with Project Managers, technology stack owners, and third-party resources to ensure timely delivery. Lead monthly patching cycles and rapid zero-day response across on-prem and hybrid server environments. Apply security remediations on infrastructure appliances including Cisco switches, firewalls (Palo Alto, Fortinet, Cisco Meraki), Linux appliances, and the virtual server environment and SANs (VMware, vSphere). Perform vulnerability remediation and OS/system hardening in line with established security baselines and audit requirements. Maintain a remediation burndown and support reporting on patch/vulnerability KPIs, including critical remediation timelines and cloud security score. Core Platform & Infrastructure Ownership Track Azure Security Score trends and drive remediation of flagged recommendations, providing regular posture reporting to leadership and audit stakeholders. Manage the full PKI infrastructure/SSL certificate lifecycle, including issuance, renewal, tracking, and remediation of expiring or non-compliant certificates, and manage key vault rotations for critical cloud-hosted applications. Utilize automation tools to deploy required machine certificates across the organization. Manage syslog retention and forwarding across on-premises and cloud infrastructure, supporting the Security team's SIEM ingestion, correlation, and compliance reporting needs. Administer network micro-segmentation using Illumio, including policy design, enforcement, and ongoing tuning. Review and administer security tools to harden network edge security, including next generation firewalls, SD-WAN, and switching, striving for zero trust networks. Manage wireless security, including network access control (NAC), utilizing Cisco wireless and HPE Aruba ClearPass. Administer Identity and Access Management/Privileged Access Management (IAM/PAM) using BeyondTrust for remote server access, including access reviews and privileged session controls. Manage and review Azure RBAC roles and access privileges, and perform Active Directory hardening in compliance with discovered vulnerabilities and best practices. Review and secure SDLC servers and hosted applications, both on-premises and in Azure, applying measures to keep all public endpoints secure. Operational Reliability & Risk Reduction Balance day-to-day operational demands (SSL renewals/rotations, security remediation, configuration hardening, troubleshooting) with planned, time-bound deliverables. Identify and reduce single-point-of-failure risk by documenting procedures and cross-training across PKI, AD, cloud access, segmentation, and patching functions. Partner with the Azure DevOps and Security teams to align on-prem/hybrid remediation with broader cloud governance and security initiatives. Escalate emerging risks, audit exceptions, and outage-driving conflicts between operational and remediation priorities to leadership. Key Competencies Analytical: synthesizes complex or diverse technical information, using intuition and experience to complement data. Collaboration: openly partners with security operations, DevOps, and business stakeholders, valuing diverse perspectives and building productive relationships. Communication: listens and responds effectively to stakeholder needs; writes and speaks clearly and persuasively. Initiative and personal accountability: identifies and creates solutions independently, sets and meets deadlines, and reports timely and prepared. Problem solving/decision making: thinks strategically, drawing on diverse sources to identify issues, risks, and trends and determine optimal, timely solutions. Strong troubleshooting skills and the ability to manage competing priorities between reactive operational work and scheduled remediation projects. Ability to support 24/7 platform reliability, including scheduled evening and weekend work for monthly patching cycles, zero-day response, and maintenance outside normal business hours. Ability to travel periodically between the Boca Raton, FL and Atlanta (ATL) data centers as needed. Requirements: Qualifications Required Qualifications Bachelor's degree in Computer Science, Information Security, or a related field; at least five (5) years of related business experience in network security, systems engineering, or infrastructure operations in an enterprise environment, or an equivalent combination of education and professional experience. Hands-on experience with both on-premises and cloud infrastructure platforms, including vulnerability management, patch management, and OS hardening across Windows and/or Linux server environments. Experience with PKI/SSL certificate lifecycle management and IAM/PAM tools (e.g., BeyondTrust or equivalent). Experience partnering with security operations/SIEM teams to onboard new log sources and ensure reliable syslog delivery from network infrastructure. Working knowledge of hybrid Active Directory/Microsoft Entra ID environments and familiarity with network segmentation concepts and tools (e.g., Illumio or comparable micro-segmentation platforms). Experience supporting audit and compliance remediation cycles, such as HIPAA assessments, SRAs, or penetration test findings. Proficiency with firewalls and network security appliances (Palo Alto, Fortinet, Cisco Meraki, Cisco switches), SD-WAN/next-generation firewall administration, and wireless security/NAC (Cisco wireless, HPE Aruba ClearPass). This is a hybrid role based in Boca Raton, FL, with periodic on-site support required at the Boca Raton and Atlanta (ATL) data centers. At no time may work be performed, or computer systems accessed, from outside of the U.S. Preferred Qualifications Vendor-specific certifications, Microsoft Azure, Security+, CISSP, GIAC, or an equivalent security certification. Scripting/automation experience (e.g., PowerShell) for remediation and hardening tasks. Why Join MDVIP? Be part of a mission-driven organization leading innovation in personalized healthcare. Drive transformation and growth in a dynamic, fast-paced environment. Competitive Compensation: Attractive base salary complemented by performance-based incentives. Comprehensive Benefits: Health, dental, vision insurance, and retirement plans. Professional Development: Access to ongoing training and leadership development programs. Positive Work Environment: Consistently recognized as a Great Place to Work , fostering a culture of collaboration and excellence. MDVIP is an Equal Opportunity Employer and is committed to fostering an inclusive and diverse workplace. We welcome applicants of all backgrounds and do not discriminate based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, veteran status, or any other protected status. We believe that diversity and inclusion drive innovation and strengthen our company culture. If you require accommodations during the application or interview process, please let us know, and we will be happy to assist. Pay Transparency: Our compensation reflects the cost of labor across appropriate US geographic markets. Pay is based on several factors including but not limited to market location and may vary depending on job-related knowledge, skills, and education/training and a candidate's work experience. Hired applicants are offered annual incentive compensation programs, subject to applicable eligibility requirements . click apply for full job details
Cyber Security Manager
Vaco LLC Kerrville, Texas
Cyber Security Manager We are seeking a highly technical Cyber Security Manager to lead security architecture, engineering, and security operations across a complex enterprise environment. This is a true player-coach role for someone who enjoys leading a team but still wants to remain hands-on and close to the technology. The ideal candidate will have deep experience across cloud and on-prem security, security engineering, automation, incident response, and emerging AI security. This person should be equally comfortable providing technical direction to a security team and jumping in to troubleshoot complex security challenges. Responsibilities Lead security architecture and engineering across on-premise, AWS, and Azure environments. Establish security standards and guardrails for AI/ML and LLM technologies, including RAG pipelines, API security, prompt injection, and emerging AI threats. Lead and participate in threat hunting, incident response, vulnerability management, and remediation. Serve as a senior technical escalation point for complex cybersecurity issues. Develop and maintain DevSecOps practices, including CI/CD security controls, infrastructure-as-code scanning, and automated compliance. Provide technical direction around security architecture, tooling, infrastructure, and technical debt. Identify security risks and translate highly technical issues into actionable recommendations for technical and business leadership. Lead, mentor, and develop a high-performing cybersecurity team. Partner with infrastructure, cloud, application development, and business teams to implement security best practices across the organization. Required Qualifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; equivalent professional experience considered. 8+ years of hands-on cybersecurity experience. 5+ years of technical leadership or management experience. Strong knowledge of the MITRE ATT&CK framework. Deep experience with cloud-native security across AWS and/or Azure. Hands-on experience securing and troubleshooting Kubernetes, IAM, Windows, and Linux environments. Strong understanding of Active Directory, SMB, Kerberos, memory protection, and other enterprise security concepts. Hands-on PKI management experience. Strong scripting/development experience with Python and/or Go, including security automation and custom tooling. Understanding of AI/LLM security, including the ability to evaluate Python-based AI frameworks and integrations. Strong communication skills with the ability to work effectively with both technical teams and executive leadership. Preferred Qualifications CISSP or CISM OSCP or similar hands-on technical security certification AWS Certified Security Google Professional Cloud Security Engineer Experience securing enterprise AI/ML implementations By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
09/26/2026
Full time
Cyber Security Manager We are seeking a highly technical Cyber Security Manager to lead security architecture, engineering, and security operations across a complex enterprise environment. This is a true player-coach role for someone who enjoys leading a team but still wants to remain hands-on and close to the technology. The ideal candidate will have deep experience across cloud and on-prem security, security engineering, automation, incident response, and emerging AI security. This person should be equally comfortable providing technical direction to a security team and jumping in to troubleshoot complex security challenges. Responsibilities Lead security architecture and engineering across on-premise, AWS, and Azure environments. Establish security standards and guardrails for AI/ML and LLM technologies, including RAG pipelines, API security, prompt injection, and emerging AI threats. Lead and participate in threat hunting, incident response, vulnerability management, and remediation. Serve as a senior technical escalation point for complex cybersecurity issues. Develop and maintain DevSecOps practices, including CI/CD security controls, infrastructure-as-code scanning, and automated compliance. Provide technical direction around security architecture, tooling, infrastructure, and technical debt. Identify security risks and translate highly technical issues into actionable recommendations for technical and business leadership. Lead, mentor, and develop a high-performing cybersecurity team. Partner with infrastructure, cloud, application development, and business teams to implement security best practices across the organization. Required Qualifications Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field; equivalent professional experience considered. 8+ years of hands-on cybersecurity experience. 5+ years of technical leadership or management experience. Strong knowledge of the MITRE ATT&CK framework. Deep experience with cloud-native security across AWS and/or Azure. Hands-on experience securing and troubleshooting Kubernetes, IAM, Windows, and Linux environments. Strong understanding of Active Directory, SMB, Kerberos, memory protection, and other enterprise security concepts. Hands-on PKI management experience. Strong scripting/development experience with Python and/or Go, including security automation and custom tooling. Understanding of AI/LLM security, including the ability to evaluate Python-based AI frameworks and integrations. Strong communication skills with the ability to work effectively with both technical teams and executive leadership. Preferred Qualifications CISSP or CISM OSCP or similar hands-on technical security certification AWS Certified Security Google Professional Cloud Security Engineer Experience securing enterprise AI/ML implementations By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets, experience and training; licensure and certification requirements; office location and other geographic considerations; other business and organizational needs. With that said, as required by local law, Vaco by Highspring believes that the following salary range referenced above reasonably estimates the base compensation for an individual hired into this position in geographies that require salary range disclosure. The individual may also be eligible for discretionary bonuses.
Security Architect
Vaco LLC Addison, Texas
Security Architect DETAILS Location: Remote Position Type: 12M+ Contract Hourly / Salary: to 120W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Security Architect for a 12M+ Contract opportunity that is remote. The Security Architect will lead Enterprise Security Architecture initiatives focused on strengthening the organization's security posture across applications, cloud platforms, infrastructure, APIs, and data environments. The Security Architect will partner with engineering, infrastructure, and business teams to embed secure-by-design principles throughout the solution lifecycle by conducting security architecture reviews, cloud and data security assessments, and application security evaluations. The Security Architect will define and recommend security controls spanning identity and access management, network security, vulnerability management, API protection, and data governance while developing security standards, reference architectures, and best practices that improve resilience, reduce risk, and ensure compliance with organizational and industry security requirements. Security Architecture Reviews - Conducting End-to-End Security Architecture Reviews for Applications / SaaS Platforms / Infrastructure Projects Evaluating Designs Against Established Security Standards / Identifying Security Gaps / Recommending Practical Risk Mitigations / Applying Secure-by-Design Principles Early in the Solution Lifecycle Data Risk / Protection - Assessing Data Flows / Storage / Access Patterns / Sensitive Data Controls Recommending Improvements to Encryption / Data Masking / Access Governance / Monitoring / Databricks Security Configurations / Varonis Data Classification / Access Auditing / Insider Threat Monitoring Cloud Security Assessments - Leading Security Assessments Across Cloud Environments / Workloads Evaluating Configurations / Network Segmentation / Identity Boundaries / Logging / Workload Protections / Recommending Hardening Measures Aligned with Cloud Provider Best Practices / Organizational Cloud Security Frameworks Application / API Security - Providing Architectural Oversight for Penetration Testing / SAST / DAST Activities Reviewing Findings / Recommending Remediation Strategies / Validating Secure Development Practices / Assessing API Authentication / Authorization / Rate Limiting / API Key / Secret / Token Management Identity / Access / Endpoint Security - Applying IAM / PAM Principles Supporting Least Privilege / Separation of Duties / Strong Authentication Championing Phishing-Resistant MFA Using FIDO2 / Hardware-Backed Authenticators / Guiding MDM / MAM Strategies for Secure Mobile / Endpoint Access Network Security / Vulnerability Management - Evaluating Network Architectures / Segmentation Strategies / Perimeter Controls / Zero-Trust Controls Partnering with Infrastructure / Operations Teams to Prioritize Vulnerability Remediation / Recommend Architectural Changes Reducing Security Exposure Security Advisory / Governance - Serving as a Trusted Advisor on Enterprise Security Architecture Documenting Architectural Decisions / Maintaining Reference Architectures / Developing Reusable Security Patterns / Contributing to Security Standards / Policies JOB REQUIREMENTS Security Architecture Reviews - Performing Security Architecture Reviews Across Applications / SaaS Solutions / Infrastructure Environments Data Security - Conducting Data Flow Analysis / Data Risk Assessments / Sensitive Data Protection using Databricks / Varonis Cloud Security - Assessing Cloud Environments / Cloud-Native Security Controls / Cloud Security Best Practices API Security - Designing Secure API Architectures / Authentication / Authorization / API Key / Secret / Token Management IAM / PAM - Applying IAM / PAM Concepts Supporting Authentication / Authorization / Privilege Management / Identity Governance Modern Authentication - Implementing Phishing-Resistant MFA / FIDO2 / Modern Authentication Standards Mobile / Endpoint Security - Supporting MDM / MAM Platforms / Secure Mobile / Endpoint Management Strategies Network Security - Applying TCP/IP / Network Segmentation / Firewalls / Proxies / DNS / Vulnerability Remediation Practices Application Security - Supporting Penetration Testing / SAST / DAST Processes / Secure Application Development Practices Cyber Resilience / Disaster Recovery - Supporting Cyber Resilience Capabilities / Disaster Recovery Technologies / Business Continuity Strategies PREFERRED (not required) Security Certifications - CISSP / CCSP / SABSA / AWS Security / MS Azure Security / Google Cloud Security Certifications, etc. Security Frameworks - Applying NIST CSF / ISO 27001 / CIS Controls / Zero-Trust Reference Models to Security Architecture Initiatives Regulatory Compliance - Supporting Security Architecture within HIPAA / PCI / SOX / GDPR, etc. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring . click apply for full job details
09/24/2026
Full time
Security Architect DETAILS Location: Remote Position Type: 12M+ Contract Hourly / Salary: to 120W2+ (based on experience level) JOB SUMMARY Vaco is currently seeking a Security Architect for a 12M+ Contract opportunity that is remote. The Security Architect will lead Enterprise Security Architecture initiatives focused on strengthening the organization's security posture across applications, cloud platforms, infrastructure, APIs, and data environments. The Security Architect will partner with engineering, infrastructure, and business teams to embed secure-by-design principles throughout the solution lifecycle by conducting security architecture reviews, cloud and data security assessments, and application security evaluations. The Security Architect will define and recommend security controls spanning identity and access management, network security, vulnerability management, API protection, and data governance while developing security standards, reference architectures, and best practices that improve resilience, reduce risk, and ensure compliance with organizational and industry security requirements. Security Architecture Reviews - Conducting End-to-End Security Architecture Reviews for Applications / SaaS Platforms / Infrastructure Projects Evaluating Designs Against Established Security Standards / Identifying Security Gaps / Recommending Practical Risk Mitigations / Applying Secure-by-Design Principles Early in the Solution Lifecycle Data Risk / Protection - Assessing Data Flows / Storage / Access Patterns / Sensitive Data Controls Recommending Improvements to Encryption / Data Masking / Access Governance / Monitoring / Databricks Security Configurations / Varonis Data Classification / Access Auditing / Insider Threat Monitoring Cloud Security Assessments - Leading Security Assessments Across Cloud Environments / Workloads Evaluating Configurations / Network Segmentation / Identity Boundaries / Logging / Workload Protections / Recommending Hardening Measures Aligned with Cloud Provider Best Practices / Organizational Cloud Security Frameworks Application / API Security - Providing Architectural Oversight for Penetration Testing / SAST / DAST Activities Reviewing Findings / Recommending Remediation Strategies / Validating Secure Development Practices / Assessing API Authentication / Authorization / Rate Limiting / API Key / Secret / Token Management Identity / Access / Endpoint Security - Applying IAM / PAM Principles Supporting Least Privilege / Separation of Duties / Strong Authentication Championing Phishing-Resistant MFA Using FIDO2 / Hardware-Backed Authenticators / Guiding MDM / MAM Strategies for Secure Mobile / Endpoint Access Network Security / Vulnerability Management - Evaluating Network Architectures / Segmentation Strategies / Perimeter Controls / Zero-Trust Controls Partnering with Infrastructure / Operations Teams to Prioritize Vulnerability Remediation / Recommend Architectural Changes Reducing Security Exposure Security Advisory / Governance - Serving as a Trusted Advisor on Enterprise Security Architecture Documenting Architectural Decisions / Maintaining Reference Architectures / Developing Reusable Security Patterns / Contributing to Security Standards / Policies JOB REQUIREMENTS Security Architecture Reviews - Performing Security Architecture Reviews Across Applications / SaaS Solutions / Infrastructure Environments Data Security - Conducting Data Flow Analysis / Data Risk Assessments / Sensitive Data Protection using Databricks / Varonis Cloud Security - Assessing Cloud Environments / Cloud-Native Security Controls / Cloud Security Best Practices API Security - Designing Secure API Architectures / Authentication / Authorization / API Key / Secret / Token Management IAM / PAM - Applying IAM / PAM Concepts Supporting Authentication / Authorization / Privilege Management / Identity Governance Modern Authentication - Implementing Phishing-Resistant MFA / FIDO2 / Modern Authentication Standards Mobile / Endpoint Security - Supporting MDM / MAM Platforms / Secure Mobile / Endpoint Management Strategies Network Security - Applying TCP/IP / Network Segmentation / Firewalls / Proxies / DNS / Vulnerability Remediation Practices Application Security - Supporting Penetration Testing / SAST / DAST Processes / Secure Application Development Practices Cyber Resilience / Disaster Recovery - Supporting Cyber Resilience Capabilities / Disaster Recovery Technologies / Business Continuity Strategies PREFERRED (not required) Security Certifications - CISSP / CCSP / SABSA / AWS Security / MS Azure Security / Google Cloud Security Certifications, etc. Security Frameworks - Applying NIST CSF / ISO 27001 / CIS Controls / Zero-Trust Reference Models to Security Architecture Initiatives Regulatory Compliance - Supporting Security Architecture within HIPAA / PCI / SOX / GDPR, etc. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring . click apply for full job details
Sr. ML Engineer
Visa Austin, Texas
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Role Summary: The Sr. ML Engineer is responsible for building and maintaining ML platform infrastructure that powers AI/ML applications across the organization. This role is suited for a hands-on engineer with practical experience in AWS, SageMaker, Kubernetes, GPU orchestration, Infrastructure as Code, and MLOps, with a passion for building scalable, secure, and reliable platforms. The position requires an experienced ML platform engineer who can design cloud and on-prem infrastructure, manage model deployment environments, modernize legacy ML pipelines, and enable Data Scientists and AI Engineers to move models from research to production. The team is tasked with building scalable ML infrastructure and platform tooling, and the successful candidate will contribute to architectural decisions, implementation standards, and best practices across the ML platform. All roles require digital fluency, including the ability to work with emerging technologies such as Generative AI tools, Microsoft Copilot, ChatGPT, GitHub Copilot, and other AI-enabled productivity platforms to support everyday work. Key Responsibilities: Lead and deliver specific platform engineering deliverables as a Sr. ML Engineer. Provide guidance to the engineering team on building scalable ML infrastructure, deployment patterns, and platform capabilities. Improve the productivity of Data Scientists and AI Engineers by developing tooling that simplifies model deployment and productionization. Act as a platform design authority and shape best practices and methodologies within the ML platform team. Design and build scalable ML pipelines, orchestration frameworks, and model serving infrastructure. Collaborate with Data Scientists, AI Engineers, infrastructure teams, and security partners to integrate AI/ML solutions into production systems. Build and operate secure cloud and on-prem infrastructure using AWS, Kubernetes, SageMaker, Terraform, and related platform technologies. Support GPU-enabled infrastructure and serving frameworks for AI/ML, GenAI, and LLM workloads. Modernize legacy ML pipelines and adopt emerging technologies to improve reliability, scalability, and operational efficiency. Communicate technical concepts, platform capabilities, and architectural decisions to technical and non-technical stakeholders. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications: 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience Preferred Qualifications: Specialist: 4 or more years of relevant work experience. Experience designing, building, and maintaining scalable ML platform infrastructure for AI/ML applications. Experience with AWS services such as EC2, S3, EKS, SageMaker, IAM, VPC, and CloudWatch. Experience managing Kubernetes clusters and containerized ML workloads using Docker. Experience with ML pipeline and orchestration tools such as Kubeflow, Airflow, MLflow, or similar platforms. Experience building infrastructure automation using Terraform, CloudFormation, or other Infrastructure as Code tools. Experience developing CI/CD pipelines for ML model deployment and infrastructure changes. Experience implementing secure cloud architectures using IAM roles, VPCs, least-privilege access, and secure networking patterns. Experience with Python and shell scripting for automation, tooling, and platform operations. Experience collaborating with Data Scientists, AI Engineers, and cross-functional teams to move models from research to production. Experience with generative AI, large language models, LLMOps, or GenAI infrastructure. Experience with GPU orchestration for ML training, inference, capacity management, and workload optimization. Experience with ML serving frameworks such as vLLM, TensorRT-LLM, KServe, Triton, or similar technologies. Experience building and operating hybrid cloud or on-prem/cloud ML infrastructure. Experience with distributed computing frameworks such as Spark or distributed ML workloads. Experience improving infrastructure productivity using AI-assisted tools such as GitHub Copilot, ChatGPT, or similar tools. Experience developing robust, secure, and scalable platforms in enterprise or regulated environments. Experience conducting research, experimentation, or proof-of-concept work with emerging AI/ML infrastructure technologies. Experience mentoring junior engineers and leading implementation of key platform modules. Information for US Applicants For roles located in the US, the estimated salary range for this position is $123,400.00 to $ 191,100.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.
09/24/2026
Full time
About Us Visa is a world leader in payments technology, facilitating transactions between consumers, merchants, financial institutions and government entities across more than 200 countries and territories, dedicated to uplifting everyone, everywhere by being the best way to pay and be paid. At Visa, you'll have the opportunity to create impact at scale - tackling meaningful challenges, growing your skills and seeing your contributions impact lives around the world. Join Visa and do work that matters - to you, to your community, and to the world. Progress starts with you. Job Description Role Summary: The Sr. ML Engineer is responsible for building and maintaining ML platform infrastructure that powers AI/ML applications across the organization. This role is suited for a hands-on engineer with practical experience in AWS, SageMaker, Kubernetes, GPU orchestration, Infrastructure as Code, and MLOps, with a passion for building scalable, secure, and reliable platforms. The position requires an experienced ML platform engineer who can design cloud and on-prem infrastructure, manage model deployment environments, modernize legacy ML pipelines, and enable Data Scientists and AI Engineers to move models from research to production. The team is tasked with building scalable ML infrastructure and platform tooling, and the successful candidate will contribute to architectural decisions, implementation standards, and best practices across the ML platform. All roles require digital fluency, including the ability to work with emerging technologies such as Generative AI tools, Microsoft Copilot, ChatGPT, GitHub Copilot, and other AI-enabled productivity platforms to support everyday work. Key Responsibilities: Lead and deliver specific platform engineering deliverables as a Sr. ML Engineer. Provide guidance to the engineering team on building scalable ML infrastructure, deployment patterns, and platform capabilities. Improve the productivity of Data Scientists and AI Engineers by developing tooling that simplifies model deployment and productionization. Act as a platform design authority and shape best practices and methodologies within the ML platform team. Design and build scalable ML pipelines, orchestration frameworks, and model serving infrastructure. Collaborate with Data Scientists, AI Engineers, infrastructure teams, and security partners to integrate AI/ML solutions into production systems. Build and operate secure cloud and on-prem infrastructure using AWS, Kubernetes, SageMaker, Terraform, and related platform technologies. Support GPU-enabled infrastructure and serving frameworks for AI/ML, GenAI, and LLM workloads. Modernize legacy ML pipelines and adopt emerging technologies to improve reliability, scalability, and operational efficiency. Communicate technical concepts, platform capabilities, and architectural decisions to technical and non-technical stakeholders. Visa requires at least 3 days in office, expectations of these days will be confirmed by your Hiring Manager. Qualifications Basic Qualifications: 2+ years of relevant work experience and a Bachelors degree, OR 5+ years of relevant work experience Preferred Qualifications: Specialist: 4 or more years of relevant work experience. Experience designing, building, and maintaining scalable ML platform infrastructure for AI/ML applications. Experience with AWS services such as EC2, S3, EKS, SageMaker, IAM, VPC, and CloudWatch. Experience managing Kubernetes clusters and containerized ML workloads using Docker. Experience with ML pipeline and orchestration tools such as Kubeflow, Airflow, MLflow, or similar platforms. Experience building infrastructure automation using Terraform, CloudFormation, or other Infrastructure as Code tools. Experience developing CI/CD pipelines for ML model deployment and infrastructure changes. Experience implementing secure cloud architectures using IAM roles, VPCs, least-privilege access, and secure networking patterns. Experience with Python and shell scripting for automation, tooling, and platform operations. Experience collaborating with Data Scientists, AI Engineers, and cross-functional teams to move models from research to production. Experience with generative AI, large language models, LLMOps, or GenAI infrastructure. Experience with GPU orchestration for ML training, inference, capacity management, and workload optimization. Experience with ML serving frameworks such as vLLM, TensorRT-LLM, KServe, Triton, or similar technologies. Experience building and operating hybrid cloud or on-prem/cloud ML infrastructure. Experience with distributed computing frameworks such as Spark or distributed ML workloads. Experience improving infrastructure productivity using AI-assisted tools such as GitHub Copilot, ChatGPT, or similar tools. Experience developing robust, secure, and scalable platforms in enterprise or regulated environments. Experience conducting research, experimentation, or proof-of-concept work with emerging AI/ML infrastructure technologies. Experience mentoring junior engineers and leading implementation of key platform modules. Information for US Applicants For roles located in the US, the estimated salary range for this position is $123,400.00 to $ 191,100.00 USD per year, which may include potential sales incentive payments (if applicable). Salary may vary depending on job-related factors which may include knowledge, skills, experience, and location. In addition, this position may be eligible for bonus and equity.Visa has a comprehensive benefits package for which this position may be eligible that includes Medical, Dental, Vision, 401(k), FSA/HSA, Life Insurance, Paid Time Off, and Wellness Program. Work Hours Varies upon the needs of the department. Travel Requirements This position requires travel 5-10% of the time. Mental/Physical Requirements This position will be performed in an office setting. The position will require the incumbent to sit and stand at a desk, communicate in person and by telephone, frequently operate standard office equipment, such as telephones and computers. Visa is an EEO Employer Qualified applicants will receive consideration for employment without regard to race, color religion, sex, national origin, sexual orientation, gender identity, disability or protect veteran status. Visa will also consider for employment qualified applicants with criminal histories in a manner consistent with the EEOC guidelines and applicable local law.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board