Job Description Job Description Position Overview The Network Security Engineer role sits within the Information Technology Department and exists to keep the organization's WAN, LAN, voice, and cloud infrastructure running efficiently, reliably, and securely. While the role retains the full scope of traditional network engineering, this description places heightened emphasis on cybersecurity operations and Microsoft Azure security, reflecting the organization's continued shift toward hybrid and cloud-hosted infrastructure. The successful candidate will partner with third-party providers and internal IT leadership to defend the network and cloud environment against malware, intrusion, and emerging cyber-threats; maintain firewalls, identity controls, and access policies; ensure reliable backups and disaster recovery; and act as a key contributor to the organization's overall security posture across both on-premises and Azure-hosted resources. Cybersecurity & Azure Security Responsibilities (Primary Emphasis) • Lead and support efforts to harden the network and cloud environment against malware, ransomware, and intrusion, including proactive identification of emerging cyber-threats and at-risk areas across LAN, WAN, WLAN, SD-WAN, and Azure-hosted workloads. • Design, implement, and maintain security controls within Microsoft Azure, including Azure Active Directory / Entra ID, Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Azure role-based access control (RBAC). • Monitor and respond to alerts from Microsoft Defender for Cloud, Microsoft Sentinel (or equivalent SIEM), and Helpdesk/security partner tooling, escalating high-risk issues to IT Management in a timely manner. • Configure and maintain Cisco Meraki firewall security settings, network segmentation (subnetting/VLANs), and access permission groups to enforce least-privilege principles across both on-premises and cloud resources. • Implement and maintain Azure network security components such as Network Security Groups (NSGs), Azure Firewall, Azure VPN/ExpressRoute connections, and Azure Bastion for secure remote access. • Support identity and access management initiatives, including device hardening, endpoint security, single sign-on (SSO), and Group Policy enforcement for domain-wide computer and user security baselines. • Ensure secure, regularly-tested backups of critical systems and servers, including the organization's Nutanix hyper-converged and Cohesity backup environments, with attention to ransomware-resilient and immutable backup practices. • Participate in vulnerability management and patching cycles (Microsoft Intune), prioritizing remediation of high-severity findings across servers, network devices, and cloud resources. • Maintain and continuously improve security documentation, including network topology, data flow, incident response procedures, and Azure security architecture diagrams. • Assist in security awareness initiatives and end-user training to reinforce safe computing practices and compliance with IT framework, policies, and procedures. • Support audits and compliance efforts related to data protection, access control, and cloud security standards, providing evidence and documentation as required. Core Network Engineering Responsibilities • Perform day-to-day networking tasks to ensure network reliability, availability, and serviceability with minimal interruption. • Provide technical support, respond to work orders and tickets, and analyze and resolve reported network problems. • Install and troubleshoot LAN, WAN, WLAN, and SD-WAN connectivity, including DNS, DHCP, and TCP/IP services. • Develop and maintain complex documentation for installation, network topology, and troubleshooting of communications hardware and software. • Work with the IT Team to coordinate and install server updates, patches, and certificates. • Maintain an enterprise-wide inventory of all server and network infrastructure assets, including warranty status and lifecycle management. • Provide server systems support, administration, and documentation, including Windows Server operating systems and hypervisor-based environments (Nutanix AHV). • Work with the Sr. Network Engineer to maintain and update the company's hyper-converged Nutanix solution and Cohesity backup solution. • Create and maintain IT-related end-user training documentation. • Participate in the on-call rotation as needed and required. • Demonstrate excellent time management and prioritization skills, balancing routine tasks with urgent support and security needs. • Adhere to, support, and foster compliance with the IT framework, policies, and procedures across the user base. • Act as a strong team player who continually seeks to grow technical expertise and the scope of the role. Knowledge, Skills & Experience Required Technical Skills • Strong working knowledge of cybersecurity principles, including threat detection, firewall management (Cisco Meraki and Fortigate), network segmentation, and identity-based security controls. • Hands-on experience with Microsoft Azure security tools and services (Azure AD/Entra ID, Conditional Access, MFA, NSGs, Azure Firewall, Defender for Cloud, or Sentinel). • Ability to troubleshoot current Windows and Server operating systems, including patching and hardware support. • Experience troubleshooting LAN, WAN, WLAN, and SD-WAN environments (DNS, DHCP, TCP/IP). • Solid understanding of network segmentation (sub-netting) and VLANs. • Experience with a patch management solution (WSUS and/or Microsoft Intune) and structured vulnerability remediation. • Familiarity or working knowledge of hypervisor-based servers and computing; Nutanix AHV experience a plus. • Understanding of hybrid identity and access management concepts spanning on-premises Active Directory and Azure AD. Desired Technical Skills • Microsoft Azure security certifications (e.g., SC-200, SC-300, AZ-500) or demonstrated equivalent experience. • Citrix XenApp Server support (Studio, Director, Storefront, Apps). • Active Directory domain infrastructure and Group Policy administration for domain-wide computer and user policies. • NTFS file permissions and data access governance. • Security focus on device hardening, endpoint protection, and identity management across hybrid environments. • Experience with SIEM platforms, security monitoring, and incident response workflows. Education & Experience • Minimum 10 years of experience working in an IT department performing similar duties, with demonstrated exposure to network security and cloud security practices. • Professional certifications such as MCP, A+, Network+, Security+, or Microsoft Azure security certifications (SC-200, SC-300, AZ-500) are preferred. Working Environment • No special physical requirements for this position. • General office conditions. • Some light lifting and bending. • Periods of sitting. • Travel 20% Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
09/20/2026
Full time
Job Description Job Description Position Overview The Network Security Engineer role sits within the Information Technology Department and exists to keep the organization's WAN, LAN, voice, and cloud infrastructure running efficiently, reliably, and securely. While the role retains the full scope of traditional network engineering, this description places heightened emphasis on cybersecurity operations and Microsoft Azure security, reflecting the organization's continued shift toward hybrid and cloud-hosted infrastructure. The successful candidate will partner with third-party providers and internal IT leadership to defend the network and cloud environment against malware, intrusion, and emerging cyber-threats; maintain firewalls, identity controls, and access policies; ensure reliable backups and disaster recovery; and act as a key contributor to the organization's overall security posture across both on-premises and Azure-hosted resources. Cybersecurity & Azure Security Responsibilities (Primary Emphasis) • Lead and support efforts to harden the network and cloud environment against malware, ransomware, and intrusion, including proactive identification of emerging cyber-threats and at-risk areas across LAN, WAN, WLAN, SD-WAN, and Azure-hosted workloads. • Design, implement, and maintain security controls within Microsoft Azure, including Azure Active Directory / Entra ID, Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Azure role-based access control (RBAC). • Monitor and respond to alerts from Microsoft Defender for Cloud, Microsoft Sentinel (or equivalent SIEM), and Helpdesk/security partner tooling, escalating high-risk issues to IT Management in a timely manner. • Configure and maintain Cisco Meraki firewall security settings, network segmentation (subnetting/VLANs), and access permission groups to enforce least-privilege principles across both on-premises and cloud resources. • Implement and maintain Azure network security components such as Network Security Groups (NSGs), Azure Firewall, Azure VPN/ExpressRoute connections, and Azure Bastion for secure remote access. • Support identity and access management initiatives, including device hardening, endpoint security, single sign-on (SSO), and Group Policy enforcement for domain-wide computer and user security baselines. • Ensure secure, regularly-tested backups of critical systems and servers, including the organization's Nutanix hyper-converged and Cohesity backup environments, with attention to ransomware-resilient and immutable backup practices. • Participate in vulnerability management and patching cycles (Microsoft Intune), prioritizing remediation of high-severity findings across servers, network devices, and cloud resources. • Maintain and continuously improve security documentation, including network topology, data flow, incident response procedures, and Azure security architecture diagrams. • Assist in security awareness initiatives and end-user training to reinforce safe computing practices and compliance with IT framework, policies, and procedures. • Support audits and compliance efforts related to data protection, access control, and cloud security standards, providing evidence and documentation as required. Core Network Engineering Responsibilities • Perform day-to-day networking tasks to ensure network reliability, availability, and serviceability with minimal interruption. • Provide technical support, respond to work orders and tickets, and analyze and resolve reported network problems. • Install and troubleshoot LAN, WAN, WLAN, and SD-WAN connectivity, including DNS, DHCP, and TCP/IP services. • Develop and maintain complex documentation for installation, network topology, and troubleshooting of communications hardware and software. • Work with the IT Team to coordinate and install server updates, patches, and certificates. • Maintain an enterprise-wide inventory of all server and network infrastructure assets, including warranty status and lifecycle management. • Provide server systems support, administration, and documentation, including Windows Server operating systems and hypervisor-based environments (Nutanix AHV). • Work with the Sr. Network Engineer to maintain and update the company's hyper-converged Nutanix solution and Cohesity backup solution. • Create and maintain IT-related end-user training documentation. • Participate in the on-call rotation as needed and required. • Demonstrate excellent time management and prioritization skills, balancing routine tasks with urgent support and security needs. • Adhere to, support, and foster compliance with the IT framework, policies, and procedures across the user base. • Act as a strong team player who continually seeks to grow technical expertise and the scope of the role. Knowledge, Skills & Experience Required Technical Skills • Strong working knowledge of cybersecurity principles, including threat detection, firewall management (Cisco Meraki and Fortigate), network segmentation, and identity-based security controls. • Hands-on experience with Microsoft Azure security tools and services (Azure AD/Entra ID, Conditional Access, MFA, NSGs, Azure Firewall, Defender for Cloud, or Sentinel). • Ability to troubleshoot current Windows and Server operating systems, including patching and hardware support. • Experience troubleshooting LAN, WAN, WLAN, and SD-WAN environments (DNS, DHCP, TCP/IP). • Solid understanding of network segmentation (sub-netting) and VLANs. • Experience with a patch management solution (WSUS and/or Microsoft Intune) and structured vulnerability remediation. • Familiarity or working knowledge of hypervisor-based servers and computing; Nutanix AHV experience a plus. • Understanding of hybrid identity and access management concepts spanning on-premises Active Directory and Azure AD. Desired Technical Skills • Microsoft Azure security certifications (e.g., SC-200, SC-300, AZ-500) or demonstrated equivalent experience. • Citrix XenApp Server support (Studio, Director, Storefront, Apps). • Active Directory domain infrastructure and Group Policy administration for domain-wide computer and user policies. • NTFS file permissions and data access governance. • Security focus on device hardening, endpoint protection, and identity management across hybrid environments. • Experience with SIEM platforms, security monitoring, and incident response workflows. Education & Experience • Minimum 10 years of experience working in an IT department performing similar duties, with demonstrated exposure to network security and cloud security practices. • Professional certifications such as MCP, A+, Network+, Security+, or Microsoft Azure security certifications (SC-200, SC-300, AZ-500) are preferred. Working Environment • No special physical requirements for this position. • General office conditions. • Some light lifting and bending. • Periods of sitting. • Travel 20% Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
09/19/2026
Full time
Job Description An exciting career awaits you At MPC, we're committed to being a great place to work - one that welcomes new ideas, encourages diverse perspectives, develops our people, and fosters a collaborative team environment. Position Summary The GRC Automation & Continuous Controls Monitoring (CCM) Senior Cybersecurity Engineer is a strategic and technical role, responsible or helping turn GRC into a trust engine for the business: reducing audit friction, improving business risk exposure visibility, accelerating evidence readiness, and enabling stronger operational confidence. The role serves as the technical focal for GRC automation, developing automated evidence collection, control testing, risk intelligence, and AI-enabled governance capabilities across cloud, on-premises, identity, operational technology (OT), and security platforms. The role collaborates closely with Cyber Fusion, Enterprise Architecture, and Cyber Engineering, to design and build deterministic control-testing logic where deterministic approaches are enough; and AI agents and LLM-backed workflows where reasoning, summarization, or judgment is required, such as evidence-to-control mapping, attestation drafting, drift detection, and audit-package assembly. This position belongs to a family of jobs with increasing responsibility, competency, and skill level. Actual position title and pay grade will be based on the selected candidate's experience and qualifications. Key Responsibilities Conducts detailed analyses on changes to cybersecurity solutions and its relationship to internal and external systems to assess control effectiveness and cybersecurity risk. Resolves complex multi-functional technical issues. Leverages cybersecurity assessments, standards, control testing methodologies, and compliance frameworks to ensure compliance across security systems. Improves the efficiency and effectiveness of Security solutions, governance processes, automated controls, and monitoring capabilities. Analyzes existing processes and procedures and leads efforts for implementing improvements, automation opportunities, or remediation activities. Responsible for development and submission of Standard Operating Procedures. Analyzes business impacting events, performs initial investigation, and evaluates control performance, exceptions, and risk indicators through continuous monitoring activities. Investigates and analyzes the nature and scope of cyber incidents, control failures, and compliance exceptions. Assists in the development of risk mitigation and remediation plans to ensure regulatory and internal compliance. compliance. Leads implementation of global security initiatives, policies, compliance requirements, and continuous control monitoring practices. Collects, validates, and reports security metrics, control performance results, and remediation efforts associated with them. Manages cyber security-related consulting, guidance, and support to customers and stakeholders. Translates security principles to assist configuration teams with incorporating security and compliance requirements into build and configuration processes. Monitors emerging IT/OT, cybersecurity, automation, and artificial intelligence technologies as well as their impact on the security, risk, and compliance landscape. Education and Experience Bachelor's Degree in Information Technology, related field or equivalent experience. 5+ years of relevant experience required Experience designing, implementing, and scaling GRC, CCM, or compliance automation solutions within a regulated environment required Experience in Python or comparable automation technologies, proficient in developing, integrating, and supporting automated workflows and REST API-based data integrations across multiple enterprise systems required. Hands-on experience integrating security-control data sources into a GRC / CCM evidence pipeline for continuous control testing required. This includes normalizing API, telemetry, configuration, vulnerability, identity, ticketing, and assessment data into control-level evidence, exception logic, ownership, frequency, and audit-ready records across at least three domains such as CNAPP / CSPM, SIEM / security data lake / XDR, CTEM / VM / ASPM, DSPM, ITSM, IAM, GRC / CCM, or AI/agent governance required. Experience building LLM-backed agentic workflows on Azure AI Foundry, GitHub, or open-source frameworks preferred. Familiarity with NIST AI RMF, the OWASP LLM Top 10, or comparable AI risk frameworks preferred. Skills Adaptability - Maintaining effectiveness when experiencing major changes in work responsibilities or environment (e.g., people, processes, structure, or culture); adjusting effectively to change by exploring the benefits, trying new approaches, and collaborating with others to make the change successful. AI Fundamentals - Understanding of core AI concepts and methods, ability to apply AI to job-relevant use cases and capacity to contribute to organizational AI reimagination. Change Management - Change Management refers to a systematic approach for defining and implementing procedures and/or technologies to deal with changes in the environment. It can mean adapting to change, controlling change and/or effecting change. Authentic Communicator - Expresses ideas and information, both verbally and in writing, clearly and credibly. Listens to understand and fosters constructive dialogue. Cybersecurity Risk Management - The process of developing cyber risk assessment and treatment techniques that can effectively pre-empt and identify significant security loopholes and weaknesses, demonstrating the business risks associated with these loopholes and providing risk treatment and prioritization strategies to effectively address the cyber-related risks, threats and vulnerabilities, ensuring appropriate levels of protection, confidentiality, integrity and privacy in alignment with the security framework. General Programming - Applies a computer language to communicate with computers using a set of instructions and to automate the execution of tasks. Intrusion Detection - The use of security analytics, including the outputs from intelligence analysis, predictive research and root cause analysis in order to search for and detect potential breaches or identify recognized indicators and warnings. Also, monitoring and collating external vulnerability reports for organizational relevance, ensuring that relevant vulnerabilities are rectified through formal change processes. Penetration Testing - The practice of testing a computer system, network or web application to find security vulnerabilities that an attacker could exploit. Penetration testing can be automated with software applications or performed manually. Relationship Management - Relationship Management is the conscious aim to develop and manage long-term and/or trusting relationships with internal or external customers, distributors, suppliers, or other parties in an environment which can include marketing, selling, servicing and other areas where a relationship is crucial to on-going success. At a senior level, it includes C-level relationships with senior management. Security Controls - Manages and maintains an information system that focuses on the management of risk and the management of information systems security. Security Governance - The process of developing and disseminating corporate security policies, frameworks and guidelines to ensure that day-to-day business operations are guarded and well protected against risks, threats and vulnerabilities. Security Information & Event Management (SIEM) - A set of tools and services offering real-time visibility across an organization's information security systems, and event log management that consolidates data from numerous sources. Security Policy Management - The process of identifying, implementing, and managing the rules and procedures that all individuals must follow when accessing and using an organization's IT assets and resources. Threat Analysis - Monitor intelligence-gathering and anticipate potential threats to an IT/OT systems proactively. This involves the pre-emptive analysis of potential perpetrators, anomalous activities and evidence-based knowledge and inferences on perpetrators' motivations and tactics. Threat Hunting - Searches through networks, endpoints, and datasets to detect and isolate cyber threats that evade existing security solutions. Vulnerability Management - The process of defining, identifying, classifying and prioritizing vulnerabilities in computer systems, applications and network infrastructures and providing the organization with the necessary knowledge, awareness and risk background to understand the threats to its business MINIMUM QUALIFICATIONS: Bachelor's Degree in Information Technology, related field or equivalent experience. Professional certification, e.g. Security+, Network+, OSCP, GIAC, CEH preferred. 5+ years of relevant experience required As an energy industry leader, our career opportunities fuel personal and professional growth. Location: San Antonio, Texas Additional locations: Findlay, Ohio, Houston, Texas Job Requisition ID: Location Address: 19100 Ridgewood Pkwy Education: Employee Group: Full time Employee Subgroup: . click apply for full job details
Edward Jones seeks a Senior Security Engineer to safeguard critical financial systems and client data. In this role, you will design and implement secure architectures, harden cloud and on prem environments, and lead threat modeling for key platforms. You will evaluate and deploy security tools, manage SIEM alerts, and drive incident response and root cause analysis. Partnering with infrastructure, development, and compliance teams, you will ensure regulatory alignment, embed security by design, and mentor junior engineers while supporting a culture of integrity, collaboration, and continuous improvement. Responsibilities Design and implement secure architectures for cloud and on prem systems Harden servers, networks, and applications to protect client and firm data Lead threat modeling and security risk assessments for critical platforms Administer and optimize security tools, including SIEM, EDR, and IAM solutions Monitor, triage, and respond to security alerts and incidents Conduct root cause analysis and drive remediation and prevention efforts Ensure alignment with financial regulations and internal security policies Collaborate with infrastructure, development, and compliance teams on secure solutions Develop and maintain security standards, runbooks, and technical documentation Mentor junior security staff and champion security best practices across teams Required Skills Network security engineering Cloud security (AWS/Azure/GCP) SIEM configuration and tuning Endpoint detection and response (EDR) Identity and access management (IAM) Threat modeling and risk assessment Incident response and forensics Vulnerability management and remediation Secure configuration and hardening (servers, networks, applications) Scripting/automation (Python, Power Shell, or similar)
09/18/2026
Full time
Edward Jones seeks a Senior Security Engineer to safeguard critical financial systems and client data. In this role, you will design and implement secure architectures, harden cloud and on prem environments, and lead threat modeling for key platforms. You will evaluate and deploy security tools, manage SIEM alerts, and drive incident response and root cause analysis. Partnering with infrastructure, development, and compliance teams, you will ensure regulatory alignment, embed security by design, and mentor junior engineers while supporting a culture of integrity, collaboration, and continuous improvement. Responsibilities Design and implement secure architectures for cloud and on prem systems Harden servers, networks, and applications to protect client and firm data Lead threat modeling and security risk assessments for critical platforms Administer and optimize security tools, including SIEM, EDR, and IAM solutions Monitor, triage, and respond to security alerts and incidents Conduct root cause analysis and drive remediation and prevention efforts Ensure alignment with financial regulations and internal security policies Collaborate with infrastructure, development, and compliance teams on secure solutions Develop and maintain security standards, runbooks, and technical documentation Mentor junior security staff and champion security best practices across teams Required Skills Network security engineering Cloud security (AWS/Azure/GCP) SIEM configuration and tuning Endpoint detection and response (EDR) Identity and access management (IAM) Threat modeling and risk assessment Incident response and forensics Vulnerability management and remediation Secure configuration and hardening (servers, networks, applications) Scripting/automation (Python, Power Shell, or similar)
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
09/17/2026
Full time
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
09/17/2026
Full time
Job Description Job Description On our expert team, you'll perform work focused on implementing and operating next generation security solutions for government and commercial clients. You'll perform hands-on evaluation, implementation, and operation of leading security cyber defense tools and technologies, and apply in-depth defense strategies to large and complex networks to rapidly identify vulnerabilities and threats, prioritize response actions, and develop effective countermeasures. You'll apply thought leadership in a highly collaborative and innovative work environment to solve complex security challenges. You will lead a team as they engineer solutions to complex challenges for customers using knowledge network engineering, Active Directory, and system administration. In this role, you'll closely impact mission success, protecting data and networks from malicious payloads and actors. With mentoring, challenging hands-on problem-solving, and opportunities to learn new tools and skills, we focus on growing as a team to make the best solutions for our customers. Work with us as we secure and protect our nation's most sensitive capabilities. What You'll Work On: Develop relationships quickly and easily with other teams, communicating the complexities of security with a wide variety of audiences, including senior management. Manage infrastructure and cybersecurity controls, including enhanced detection and vulnerability capabilities and improved event correlation in large enterprises. Contribute to risk and vulnerability assessments in network, system, and application areas, and leverage big data analytics and traditional security event types to identify advanced threats or indicators of compromise. Requirements Experience with the deployment or daily maintenance of Forescout CounterACT appliances 5+ years of experience performing systems administration for Windows or Linux, including performing basic troubleshooting and installation or configuration, monitoring system performance or availability, and performing security upgrades Experience architecting and designing IP networks, including developing and documenting network topologies Experience with network engineering, including physical or logical such as installation and activation of ports, configuration of switches, and LANS, VLANS, and network FW, or appliances or network administration services such as Active Directory, Guests LANS, and domain management Knowledge of multi-domain architectures, including data center, WAN, and LAN in virtualized architectures Active TS/SCI clearance; willingness to take a polygraph exam Associate's degree and 10+ years of experience supporting IT projects and activities, Bachelor's degree and 8+ years of experience supporting IT projects and activities, or Master's degree and 6+ years of experience supporting IT projects and activities DoD 8570 IAT Level II Certification such as Security+ CE, CCNA-Security, GSEC, SSCP, CySA+, GICSP, or CND Certification Ability to obtain a DoD 8570 Cybersecurity Service Provider - Infrastructure Support Certification such as CEH, CySA+, GICSP, SSCP, CHFI, CFR, Cloud+, or CND Certification, within 30 days of start date Nice If You Have: Knowledge of federal information security policies, standards, procedures, directives, frameworks, federal security authorizations, assessment, and risk management processes for enterprise systems Ability to install and deploy Forescout in a customer environment Ability to integrate cybersecurity data using enterprise or custom tools data aggregation and analysis tools, including Splunk Ability to provide support in a Tier II IT operations and maintenance role, including ticket work information updates, issue responses, and remediation Ability to be a self-starter, work without considerable direction, and work with a team Possession of excellent verbal and written communication skills, including for coordinating efforts and establishing customer relations Benefits Essential Network Security (ENS) Solutions, LLC is a service-disabled veteran owned, highly regarded IT consulting and management firm. ENS consults for the Department of Defense (DoD) and Intelligence Community (IC) providing innovative solutions in the core competency area of Identity, Credential and Access Management (ICAM), Software Development, Cyber and Network Security, System Engineering, Program/Project Management, IT support, Solutions, and Services that yield enduring results. Our strong technical and management experts have been able to maintain a standard of excellence in their relationships while delivering innovative, scalable and collaborative infrastructure to our clients. Why ENS? Free Platinum-Level Medical/Dental/Vision coverage, 100% paid for by ENS 401k Contribution from Day 1 PTO + 11 Paid Federal Holidays Long & Short Term Disability Insurance Group Term Life Insurance Tuition, Certification & Professional Development Assistance Workers' Compensation Relocation Assistance Candidate AI Usage Policy AI tools are an important part of daily work at ENS Solutions, and we are committed to their responsible and ethical use. To ensure a fair and equitable candidate evaluation based on individual skills, knowledge, and experience, candidates are not permitted to use artificial intelligence or other assistive tools during interviews, whether in person or virtual, unless explicit permission has been granted in advance.
Edward Jones seeks an Application Security Architect to design and implement secure application architectures for a leading finance and insurance firm. You will define security patterns, conduct threat modeling, review designs and code, and guide development teams to build secure, resilient systems that protect client data and financial transactions. Partnering with architecture, engineering, risk, and compliance, you'll champion secure SDLC practices, evaluate security tools, and drive remediation of vulnerabilities. This role offers growth, influence on enterprise security strategy, and the chance to support clients' long-term financial goals. Responsibilities Design and maintain secure application architectures and patterns Lead threat modeling and risk assessments for key applications Perform security design and code reviews with development teams Define and promote secure SDLC standards and best practices Evaluate, implement, and tune application security tools (SAST/DAST/SCA) Collaborate with architecture, engineering, risk, and compliance teams Provide security guidance for cloud-native and API-based solutions Drive remediation of vulnerabilities and track risk reduction Develop security reference architectures and technical standards Mentor engineers on application security concepts and practices Required Skills Application security architecture Threat modeling Secure SDLCSecure coding (Java/. NET/Java Script or similar) SAST/DAST/SCA tooling API and microservices security Cloud security (AWS/Azure/GCP) Identity and access management (OAuth2/OIDC) Vulnerability management and remediation Security standards and frameworks (OWASP, NIST)
09/17/2026
Full time
Edward Jones seeks an Application Security Architect to design and implement secure application architectures for a leading finance and insurance firm. You will define security patterns, conduct threat modeling, review designs and code, and guide development teams to build secure, resilient systems that protect client data and financial transactions. Partnering with architecture, engineering, risk, and compliance, you'll champion secure SDLC practices, evaluate security tools, and drive remediation of vulnerabilities. This role offers growth, influence on enterprise security strategy, and the chance to support clients' long-term financial goals. Responsibilities Design and maintain secure application architectures and patterns Lead threat modeling and risk assessments for key applications Perform security design and code reviews with development teams Define and promote secure SDLC standards and best practices Evaluate, implement, and tune application security tools (SAST/DAST/SCA) Collaborate with architecture, engineering, risk, and compliance teams Provide security guidance for cloud-native and API-based solutions Drive remediation of vulnerabilities and track risk reduction Develop security reference architectures and technical standards Mentor engineers on application security concepts and practices Required Skills Application security architecture Threat modeling Secure SDLCSecure coding (Java/. NET/Java Script or similar) SAST/DAST/SCA tooling API and microservices security Cloud security (AWS/Azure/GCP) Identity and access management (OAuth2/OIDC) Vulnerability management and remediation Security standards and frameworks (OWASP, NIST)
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/15/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/15/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
09/15/2026
Full time
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/15/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/15/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/15/2026
Full time
Job Description Job Description Zoox's Network Security team architects and defends the digital borders of the company - from corporate offices to engineering labs and product/mission environments. As a Network Security Engineer, you will design, implement, and operate security controls across Zoox's enterprise, OT networks, and cloud infrastructure spanning on-premises data centers and public cloud environments (AWS, GCP), partnering closely with Network Engineering, IT, Product Security, and Software Engineering teams. In This Role, You Will Design, implement, and maintain secure hybrid/multi-cloud network architectures (AWS/GCP, CloudWAN); enforce zero-trust access controls and network segmentation across corporate, data center, lab, and edge environments; develop and maintain related policies, standards, and architecture diagrams Own and operate next-generation firewall platforms (Palo Alto Networks, Fortinet), managing policy architecture, segmentation, NAT, URL filtering, SSL/TLS decryption, and threat prevention tuning Architect, operate, and own the lifecycle of secure remote access solutions (VPN, ZTNA, site-to-site tunnels), ensuring high availability, certificate-based authentication, and integration with identity providers (SAML, Entra ID) Drive automation and Infrastructure-as-Code (IaC) using Terraform, Python, CI/CD, and REST APIs for configuration management, firewall policies, and security baselines; integrate LLM-based tools to streamline operational tasks and reduce manual toil Oversee security operations including 24/7 network security monitoring, traffic analysis, threat detection, vulnerability assessments, and remediation; support compliance requirements by conducting security reviews for new projects and infrastructure changes Drive 802.1X/certificate-based Network Access Control (NAC) initiatives across wired and wireless environments Collaborate with team members and contribute to cross-functional security initiatives with Product Security, SRE, IT, and Software Engineering teams Qualifications 6+ years of network security engineering experience securing enterprise, cloud, and OT/lab environments Platform Expertise: Deep, hands-on expertise in next-gen firewalls (Palo Alto, Fortinet), AWS NFW, WAFs, IDS/IPS, NAC/802.1X, PKI, VPN, and ZTNA solutions (Zscaler, Netskope, Prisma Access, or equivalent) Technical Knowledge: Strong understanding of core network protocols (TCP/IP, BGP, OSPF, VLAN, 802.1X, TLS/PKI) and cloud networking security principles (AWS, GCP, or Azure) Automation: Hands-on experience with IaC and automation tooling including Terraform, Python, CI/CD pipelines, and REST APIs Security Operations: Experience with network security monitoring, threat detection, and security operations tooling (SIEM, IDS/IPS, vulnerability management platforms), including integration with network controls Compliance: Proven experience supporting major compliance initiatives (NIST 800-53, CSF 2.0, ISO 27001), including control implementation and evidence collection Bonus Qualifications Experience in autonomous vehicle, robotics, IT/OT or automotive environments Certifications: PCNSE, AWS Security Specialty, CCNA Experience experimenting with or deploying AI/ML-based security capabilities (e.g., anomaly detection, behavioral analytics, LLM-driven copilots) in network or cloud security workflows There are three major components to compensation for this position: salary, Amazon Restricted Stock Units (RSUs), and Zoox Stock Appreciation Rights. A sign-on bonus may be offered as part of the compensation package. The listed range applies only to the base salary. Compensation will vary based on geographic location and level. Leveling, as well as positioning within a level, is determined by a range of factors, including, but not limited to, a candidate's relevant years of experience, domain knowledge, and interview performance. The salary range listed in this posting is representative of the range of levels Zoox is considering for this position. Zoox also offers a comprehensive package of benefits, including paid time off (e.g. sick leave, vacation, bereavement), unpaid time off, Zoox Stock Appreciation Rights, Amazon RSUs, health insurance, long-term care insurance, long-term and short-term disability insurance, and life insurance. About Zoox Zoox is developing the first ground-up, fully autonomous vehicle fleet and the supporting ecosystem required to bring this technology to market. Sitting at the intersection of robotics, machine learning, and design, Zoox aims to provide the next generation of mobility-as-a-service in urban environments. We're looking for top talent that shares our passion and wants to be part of a fast-moving and highly execution-oriented team. Follow us on LinkedIn Accommodations If you need an accommodation to participate in the application or interview process please reach out to or your assigned recruiter. A Final Note: You do not need to match every listed expectation to apply for this position. Here at Zoox, we know that diverse perspectives foster the innovation we need to be successful, and we are committed to building a team that encompasses a variety of backgrounds, experiences, and skills. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/15/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
09/15/2026
Full time
Job Description Job Description Benefits: 401(k) 401(k) matching Dental insurance Health insurance Paid time off Profit sharing Training & development Tuition assistance Vision insurance Job Description SarelaTech is seeking an experienced Network Engineer (SME) to join our Integrated Information Technology Support Services (I3TS) team, who will support an extensive digital modernization program critical to Defense Threat Reduction Agency (DTRA) in Fort Belvoir, VA. The Network Engineer will work closely with the Leidos and Government technical leadership team to help drive innovation, growth, and efficiencies within the I3TS portfolio. Primary Responsibilities: The Commercial Solutions for Classified (CSfC) Network & Security Engineer will architect and operate secure, dual-layer cryptographic boundaries utilizing Cisco and Aruba IPsec/SSL VPNs and dynamic routing (BGP/OSPF) in strict compliance with NSA Capability Packages. In this role, you will author and tune Palo Alto NGFW security policies and IDS/IPS threat prevention signatures, implement enterprise network access control and 802.1X policies via Cisco ISE and Aruba ClearPass, integrate enterprise PKI/OCSP services and hardened NTP, and generate key engineering artifacts required for NSA CSfC PMO registration and compliance auditing. Architect, deploy, and maintain CSfC infrastructure operating within Black/Gray/Red networks. Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Mobile Access (MA), Multi-Sight (MSC) Capability Packages, with Campus Wireless LAN (WLAN) experience a bonus. Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Understanding of NIAP approved list and monitors for changes Design, configure, and maintain multi-layered Commercial Solutions for Classified (CSfC) architectures in alignment with NSA Capability Packages (MSC, MA, and CWLAN). Ensure strict compliance with vendor diversity and dual-tunnel encryption mandates. Implement enterprise routing protocols (BGP, OSPF) alongside redundant outer and inner IPsec VPN tunnels across Cisco and Aruba appliances. Configure remote access SSL VPNs and ensure end-to-end traffic separation. Author, optimize, and audit Palo Alto Next-Generation Firewall (NGFW) security policies, App-ID, User-ID, and URL filtering. Configure and tune Palo Alto IDS/IPS threat signatures, anti-spyware, and vulnerability protection. Architect and manage Cisco Identity Services Engine (ISE) and Aruba ClearPass policy managers for 802.1X network access control, RADIUS/TACACS+ administration, posture assessment, and endpoint profiling. Integrate enterprise Public Key Infrastructure (PKI) components, managing X.509 certificate lifecycles, Certificate Authorities (CAs), CRL/OCSP validation, and hardened, authenticated Network Time Protocol (NTP) infrastructure. Prepare CSfC compliance artifacts, Key Management Plans (KMPs), Continuous Monitoring Plans (CMPs), and registration packages for NSA CSfC PMO submission. Required Qualifications: Bachelor's degree or higher in Computer Science, Information Technology, Engineering, Engineering Management, Management Information Systems, or related STEM degree program, and 12-15 years of relevant experience. Specific experience, education and training may be considered in lieu of degree. 12+ years of progressive network engineering experience within DoD/DoW, federal, or defense contractor enterprise environments Active TS/SCI Clearance Active DoD 8570.01-M / DoD 8140 IAT Level II or III baseline certification (e.g., Security+ CE, CySA+, CASP+, or CISSP). Active Computing Environment certification, including one or more of: Cisco CCNA, CCNP, Aruba ACSA or ACSP Proven expertise configuring Cisco (IOS-XE/ASR) and Aruba (Mobility Controllers/Gateways) IPsec and SSL VPNs, including IKEv2, Suite B/CNSA cryptography, and dynamic routing (BGP, OSPF). Demonstrated engineering experience with Palo Alto Networks firewalls (PAN-OS), Panorama central management, and advanced IDS/IPS inspection profiles. Hands-on deployment experience with both Cisco ISE and/or Aruba ClearPass implementing 802.1X, EAP-TLS authentication, and role-based access policies. Strong working knowledge of X.509 certificates, CA hierarchy integration, certificate revocation lists (CRLs), OCSP, and secure NTP stratum synchronization. Direct prior experience preparing and successfully registering NSA CSfC Capability Package solutions (Mobile Access, Multi-Site Connectivity, or Campus WLAN). Deep understanding of Commercial National Security Algorithm (CNSA) Suite requirements, post-quantum readiness considerations, and hardware security modules (HSMs). Familiarity with Ansible, for automating network device configuration backups, policy compliance checks, and certificate rotations. Certified in any of the following - Cisco CCNP/CCIE (Security or Enterprise), Palo Alto PCNSE, Aruba Certified ClearPass Expert (ACCX), or Aruba Certified Mobility Expert (ACMX).
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
09/15/2026
Full time
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
Leidos is seeking a Cyber Defense Analyst to safeguard critical government and commercial systems. You will monitor security events, investigate threats, and respond to incidents across complex networks and cloud environments. Responsibilities include threat hunting, log analysis, tuning security tools, and recommending enhancements to architectures and controls. You'll collaborate with engineering and operations teams, produce clear reports, and support compliance with cybersecurity standards. Leidos offers flexible work options, strong benefits, and extensive training to grow your skills in a mission-driven environment. Responsibilities Continuously monitor SIEM and security tools to detect suspicious activity and indicators of compromise. Investigate security alerts, perform triage, and lead incident containment, eradication, and recovery. Conduct threat hunting using logs, network data, and endpoint telemetry to identify hidden threats. Analyze vulnerabilities and support remediation planning with infrastructure and application teams. Tune and optimize security tools, detection rules, and playbooks to reduce false positives and improve coverage. Collaborate with engineering, operations, and program teams to design and maintain secure architectures. Document investigations, produce incident reports, and communicate findings to technical and non-technical stakeholders. Support compliance with relevant cybersecurity frameworks and government or commercial standards. Contribute to continuous improvement of security operations processes and automation. Stay current on emerging threats, tools, and best practices and share knowledge with the team. Required Skills Security Information and Event Management (SIEM) Intrusion detection and prevention Incident response and handling Network security monitoring and analysis Threat hunting and threat intelligence Log and packet analysis Endpoint detection and response (EDR) Cloud security (AWS/Azure) Vulnerability assessment and remediation Scripting/automation (Python, Power Shell)
09/15/2026
Full time
Leidos is seeking a Cyber Defense Analyst to safeguard critical government and commercial systems. You will monitor security events, investigate threats, and respond to incidents across complex networks and cloud environments. Responsibilities include threat hunting, log analysis, tuning security tools, and recommending enhancements to architectures and controls. You'll collaborate with engineering and operations teams, produce clear reports, and support compliance with cybersecurity standards. Leidos offers flexible work options, strong benefits, and extensive training to grow your skills in a mission-driven environment. Responsibilities Continuously monitor SIEM and security tools to detect suspicious activity and indicators of compromise. Investigate security alerts, perform triage, and lead incident containment, eradication, and recovery. Conduct threat hunting using logs, network data, and endpoint telemetry to identify hidden threats. Analyze vulnerabilities and support remediation planning with infrastructure and application teams. Tune and optimize security tools, detection rules, and playbooks to reduce false positives and improve coverage. Collaborate with engineering, operations, and program teams to design and maintain secure architectures. Document investigations, produce incident reports, and communicate findings to technical and non-technical stakeholders. Support compliance with relevant cybersecurity frameworks and government or commercial standards. Contribute to continuous improvement of security operations processes and automation. Stay current on emerging threats, tools, and best practices and share knowledge with the team. Required Skills Security Information and Event Management (SIEM) Intrusion detection and prevention Incident response and handling Network security monitoring and analysis Threat hunting and threat intelligence Log and packet analysis Endpoint detection and response (EDR) Cloud security (AWS/Azure) Vulnerability assessment and remediation Scripting/automation (Python, Power Shell)
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
09/15/2026
Full time
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
This job posting is anticipated to remain open for 30 days, from 28-Aug-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview: The Technical Architect will be responsible for working across all areas of Information Systems (IS), providing leadership on technology selection and operational processes for running Threat and Vulnerability Management services and solutions in a mixed on-prem and cloud environment. What You'll Do: Development of Information Security solutions in cloud to meet the needs of the firm. Lead the adoption of cloud infrastructure platforms and the integration of a hybrid architecture Creating and managing relationships with teams across the department Work with distributed teams to ensure that application services are properly instrumented to be reliably monitored and debugged Automate manual, repeatable system processes to reduce Tier 1 efforts Collaborate with project teams to deploy new solutions for proof-of-concept efforts What Experience You'll Need: Minimum 8 years' experience in cybersecurity as a practitioner. Experience with architecting secure system. Must be experienced in creating a strategic cyber security technology direction, aligning it with tactical activities, and communicating plans broadly across the organization. Experience working across multiple large scale cloud providers, including AWS, Azure, and Google Cloud. Must be able to communicate effectively across multiple audiences, including firm-wide business units, senior leaders, associates, external vendors. Working knowledge in network, storage, application development, Operating Systems, IAM (Authentication/authorization), PAM, SSO, encryption standards, and contract negotiations. Familiarity with tools such as Git, Jenkins, Ansible, and Chef. Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) and Gramm-Leach-Bliley Act (GLBA). Additionally, experience in one or more of the following: ISO 27001/2, ITIL or NIST is preferred. Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page .
09/14/2026
Full time
This job posting is anticipated to remain open for 30 days, from 28-Aug-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview: The Technical Architect will be responsible for working across all areas of Information Systems (IS), providing leadership on technology selection and operational processes for running Threat and Vulnerability Management services and solutions in a mixed on-prem and cloud environment. What You'll Do: Development of Information Security solutions in cloud to meet the needs of the firm. Lead the adoption of cloud infrastructure platforms and the integration of a hybrid architecture Creating and managing relationships with teams across the department Work with distributed teams to ensure that application services are properly instrumented to be reliably monitored and debugged Automate manual, repeatable system processes to reduce Tier 1 efforts Collaborate with project teams to deploy new solutions for proof-of-concept efforts What Experience You'll Need: Minimum 8 years' experience in cybersecurity as a practitioner. Experience with architecting secure system. Must be experienced in creating a strategic cyber security technology direction, aligning it with tactical activities, and communicating plans broadly across the organization. Experience working across multiple large scale cloud providers, including AWS, Azure, and Google Cloud. Must be able to communicate effectively across multiple audiences, including firm-wide business units, senior leaders, associates, external vendors. Working knowledge in network, storage, application development, Operating Systems, IAM (Authentication/authorization), PAM, SSO, encryption standards, and contract negotiations. Familiarity with tools such as Git, Jenkins, Ansible, and Chef. Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) and Gramm-Leach-Bliley Act (GLBA). Additionally, experience in one or more of the following: ISO 27001/2, ITIL or NIST is preferred. Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page .
This job posting is anticipated to remain open for 30 days, from 28-Aug-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview: The Technical Architect will be responsible for working across all areas of Information Systems (IS), providing leadership on technology selection and operational processes for running Threat and Vulnerability Management services and solutions in a mixed on-prem and cloud environment. What You'll Do: Development of Information Security solutions in cloud to meet the needs of the firm. Lead the adoption of cloud infrastructure platforms and the integration of a hybrid architecture Creating and managing relationships with teams across the department Work with distributed teams to ensure that application services are properly instrumented to be reliably monitored and debugged Automate manual, repeatable system processes to reduce Tier 1 efforts Collaborate with project teams to deploy new solutions for proof-of-concept efforts What Experience You'll Need: Minimum 8 years' experience in cybersecurity as a practitioner. Experience with architecting secure system. Must be experienced in creating a strategic cyber security technology direction, aligning it with tactical activities, and communicating plans broadly across the organization. Experience working across multiple large scale cloud providers, including AWS, Azure, and Google Cloud. Must be able to communicate effectively across multiple audiences, including firm-wide business units, senior leaders, associates, external vendors. Working knowledge in network, storage, application development, Operating Systems, IAM (Authentication/authorization), PAM, SSO, encryption standards, and contract negotiations. Familiarity with tools such as Git, Jenkins, Ansible, and Chef. Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) and Gramm-Leach-Bliley Act (GLBA). Additionally, experience in one or more of the following: ISO 27001/2, ITIL or NIST is preferred. Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page .
09/14/2026
Full time
This job posting is anticipated to remain open for 30 days, from 28-Aug-2026. The posting may close early due to the volume of applicants. Join a financial services firm where your contributions are valued. Edward Jones is a Fortune 500 company where people come first. With over 9 million clients and 20,000 financial advisors across the U.S. and Canada, we're proud to be privately-owned, placing the focus on our clients rather than shareholder returns. Behind everything we do is our purpose: We partner for positive impact to improve the lives of our clients and colleagues, and together, better our communities and society. We are an innovative, flexible, and inclusive organization that attracts, develops, and inspires performance excellence and a sense of belonging. People are at the center of our partnership. Edward Jones associates are seen, heard, respected, and supported. This is what we believe makes us the best place to start or build your career. View our Purpose, Inclusion and Citizenship Report . Fortune 500, published June 2024, data as of December 2023. Compensation provided for using, not obtaining, the rating. Team Overview: The Technical Architect will be responsible for working across all areas of Information Systems (IS), providing leadership on technology selection and operational processes for running Threat and Vulnerability Management services and solutions in a mixed on-prem and cloud environment. What You'll Do: Development of Information Security solutions in cloud to meet the needs of the firm. Lead the adoption of cloud infrastructure platforms and the integration of a hybrid architecture Creating and managing relationships with teams across the department Work with distributed teams to ensure that application services are properly instrumented to be reliably monitored and debugged Automate manual, repeatable system processes to reduce Tier 1 efforts Collaborate with project teams to deploy new solutions for proof-of-concept efforts What Experience You'll Need: Minimum 8 years' experience in cybersecurity as a practitioner. Experience with architecting secure system. Must be experienced in creating a strategic cyber security technology direction, aligning it with tactical activities, and communicating plans broadly across the organization. Experience working across multiple large scale cloud providers, including AWS, Azure, and Google Cloud. Must be able to communicate effectively across multiple audiences, including firm-wide business units, senior leaders, associates, external vendors. Working knowledge in network, storage, application development, Operating Systems, IAM (Authentication/authorization), PAM, SSO, encryption standards, and contract negotiations. Familiarity with tools such as Git, Jenkins, Ansible, and Chef. Experience and understanding of various regulatory requirements and laws, including but not limited to: Payment Card Industry (PCI), Sarbanes-Oxley Act (SOX), Health Insurance Portability and Accountability Act (HIPAA), General Data Protection Regulation (GDPR) and Gramm-Leach-Bliley Act (GLBA). Additionally, experience in one or more of the following: ISO 27001/2, ITIL or NIST is preferred. Candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office four days per week effective June 1, 2026. Before June 1, 2026, candidates that live within a commutable distance from our Tempe, AZ and St. Louis, MO home office locations are expected to work in the office three days per week, with preference for Tuesday through Thursday. At Edward Jones, we are building a place where everyone feels like they belong. We're proud of our associates' contributions to the firm and the recognitions we have received. Check out our U.S. awards and accolades: Insights & Information Blog Postings about Edward Jones Check out our Canadian awards and accolades: Insights & Information Blog Postings about Edward Jones Edward Jones does not discriminate on the basis of race, color, gender, religion, national origin, age, disability, sexual orientation, pregnancy, veteran status, genetic information or any other basis prohibited by applicable law. Edward Jones' compensation and benefits package includes medical and prescription drug, dental, vision, voluntary benefits (such as accident, hospital indemnity, and critical illness), short- and long-term disability, basic life, and basic AD&D coverage. Short- and long-term disability, basic life, and basic AD&D coverage are provided at no cost to associates. Edward Jones offers a 401k retirement plan, and tax-advantaged accounts: health savings account, and flexible spending account. Edward Jones observes ten paid holidays and provides 15 days of vacation for new associates beginning on January 1 of each year, as well as sick time, personal days, and a paid day for volunteerism. Associates may be eligible for bonuses and profit sharing. All associates are eligible for the firm's Employee Assistance Program. For more information on the Benefits available to Edward Jones associates, please visit our benefits page .
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.
09/13/2026
Full time
Job Description Job Description Senior Network Security Engineer Location: Dallas, TX (Hybrid - Uptown) Type: Direct Hire • Base salary + performance bonus • 100% company-paid benefits Overview This organization operates at the forefront of high-performance computing (HPC) and cloud infrastructure, building and scaling mission-critical platforms that support advanced research, AI/ML workloads, and large-scale data processing. Backed by strong leadership and investment, the company is focused on delivering next-generation infrastructure that accelerates innovation and eliminates friction across compute and data environments. We are seeking a Senior Network Security Engineer to lead the design, implementation, and optimization of a hyperscale network security environment. This role combines deep technical expertise with leadership responsibilities, driving security architecture, incident response, and automation initiatives across a complex, high-availability infrastructure. You will play a key role in securing distributed HPC and cloud environments, partnering closely with network engineering, platform, and DevOps teams to embed security into every layer of the stack. Key Responsibilities Security Architecture & Engineering • Design and implement scalable network security architectures across on-prem and cloud environments • Lead segmentation strategies, Zero Trust initiatives, and secure network design for HPC and distributed systems • Manage and optimize firewalls, proxies, VPNs, and advanced threat protection platforms Technical Leadership & Escalation • Serve as a senior escalation point for complex security incidents and network threats • Mentor junior and mid-level engineers, providing guidance on troubleshooting and architecture decisions • Lead root cause analysis and drive corrective and preventative actions Automation & Infrastructure as Code • Develop and implement automation for security infrastructure provisioning and lifecycle management • Build playbooks and frameworks using Python, Terraform, Ansible, and vendor APIs • Drive adoption of automation tools such as AlgoSec, Tufin, Jenkins, and Git-based workflows Security Operations & Risk Management • Oversee vulnerability assessments, penetration testing coordination, and remediation efforts • Develop and maintain security policies, threat models, and governance frameworks • Partner with cross-functional teams to embed security best practices across infrastructure and application layers Required Experience • 8+ years of experience in network engineering and network security, including architectural responsibilities • Proven experience designing and securing trusted, untrusted, and DMZ environments • Strong expertise in TCP/IP, routing, switching, load balancing, and OSI model fundamentals • Deep knowledge of network security technologies, including firewalls, VPNs, proxies, IPsec, MACsec, TLS/HTTPS, DNS, NTP, and AAA • Hands-on experience with leading security vendors such as Palo Alto, Fortinet, Check Point, and F5 • Experience implementing Zero Trust architectures and segmentation strategies • Strong scripting/automation experience with Python, Terraform, or Ansible • Experience securing cloud environments (AWS and/or Azure) Preferred Experience • Experience with EVPN/VXLAN-based data center architectures • Background supporting hybrid or multi-cloud environments at scale • Exposure to M&A integrations and network/security consolidation efforts • Experience building or working with SOC environments or MSSPs • Firewall policy automation and orchestration experience • Relevant certifications such as CISSP, CCIE Security, GIAC (GSEC, GCIH, GXPN), or vendor-specific certifications Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies. Company Description GTN is the leader in SOW management & technical staffing, leveraging innovation to drive next-generation recruiting to Fortune 200 companies.