it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

6 jobs found

Email me jobs like this
Refine Search
Current Search
security architect vulnerability exposure management
Network Security Engineer
Liquid Env Solutions of Texas Irving, Texas
Job Description Job Description Position Overview The Network Security Engineer role sits within the Information Technology Department and exists to keep the organization's WAN, LAN, voice, and cloud infrastructure running efficiently, reliably, and securely. While the role retains the full scope of traditional network engineering, this description places heightened emphasis on cybersecurity operations and Microsoft Azure security, reflecting the organization's continued shift toward hybrid and cloud-hosted infrastructure. The successful candidate will partner with third-party providers and internal IT leadership to defend the network and cloud environment against malware, intrusion, and emerging cyber-threats; maintain firewalls, identity controls, and access policies; ensure reliable backups and disaster recovery; and act as a key contributor to the organization's overall security posture across both on-premises and Azure-hosted resources. Cybersecurity & Azure Security Responsibilities (Primary Emphasis) • Lead and support efforts to harden the network and cloud environment against malware, ransomware, and intrusion, including proactive identification of emerging cyber-threats and at-risk areas across LAN, WAN, WLAN, SD-WAN, and Azure-hosted workloads. • Design, implement, and maintain security controls within Microsoft Azure, including Azure Active Directory / Entra ID, Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Azure role-based access control (RBAC). • Monitor and respond to alerts from Microsoft Defender for Cloud, Microsoft Sentinel (or equivalent SIEM), and Helpdesk/security partner tooling, escalating high-risk issues to IT Management in a timely manner. • Configure and maintain Cisco Meraki firewall security settings, network segmentation (subnetting/VLANs), and access permission groups to enforce least-privilege principles across both on-premises and cloud resources. • Implement and maintain Azure network security components such as Network Security Groups (NSGs), Azure Firewall, Azure VPN/ExpressRoute connections, and Azure Bastion for secure remote access. • Support identity and access management initiatives, including device hardening, endpoint security, single sign-on (SSO), and Group Policy enforcement for domain-wide computer and user security baselines. • Ensure secure, regularly-tested backups of critical systems and servers, including the organization's Nutanix hyper-converged and Cohesity backup environments, with attention to ransomware-resilient and immutable backup practices. • Participate in vulnerability management and patching cycles (Microsoft Intune), prioritizing remediation of high-severity findings across servers, network devices, and cloud resources. • Maintain and continuously improve security documentation, including network topology, data flow, incident response procedures, and Azure security architecture diagrams. • Assist in security awareness initiatives and end-user training to reinforce safe computing practices and compliance with IT framework, policies, and procedures. • Support audits and compliance efforts related to data protection, access control, and cloud security standards, providing evidence and documentation as required. Core Network Engineering Responsibilities • Perform day-to-day networking tasks to ensure network reliability, availability, and serviceability with minimal interruption. • Provide technical support, respond to work orders and tickets, and analyze and resolve reported network problems. • Install and troubleshoot LAN, WAN, WLAN, and SD-WAN connectivity, including DNS, DHCP, and TCP/IP services. • Develop and maintain complex documentation for installation, network topology, and troubleshooting of communications hardware and software. • Work with the IT Team to coordinate and install server updates, patches, and certificates. • Maintain an enterprise-wide inventory of all server and network infrastructure assets, including warranty status and lifecycle management. • Provide server systems support, administration, and documentation, including Windows Server operating systems and hypervisor-based environments (Nutanix AHV). • Work with the Sr. Network Engineer to maintain and update the company's hyper-converged Nutanix solution and Cohesity backup solution. • Create and maintain IT-related end-user training documentation. • Participate in the on-call rotation as needed and required. • Demonstrate excellent time management and prioritization skills, balancing routine tasks with urgent support and security needs. • Adhere to, support, and foster compliance with the IT framework, policies, and procedures across the user base. • Act as a strong team player who continually seeks to grow technical expertise and the scope of the role. Knowledge, Skills & Experience Required Technical Skills • Strong working knowledge of cybersecurity principles, including threat detection, firewall management (Cisco Meraki and Fortigate), network segmentation, and identity-based security controls. • Hands-on experience with Microsoft Azure security tools and services (Azure AD/Entra ID, Conditional Access, MFA, NSGs, Azure Firewall, Defender for Cloud, or Sentinel). • Ability to troubleshoot current Windows and Server operating systems, including patching and hardware support. • Experience troubleshooting LAN, WAN, WLAN, and SD-WAN environments (DNS, DHCP, TCP/IP). • Solid understanding of network segmentation (sub-netting) and VLANs. • Experience with a patch management solution (WSUS and/or Microsoft Intune) and structured vulnerability remediation. • Familiarity or working knowledge of hypervisor-based servers and computing; Nutanix AHV experience a plus. • Understanding of hybrid identity and access management concepts spanning on-premises Active Directory and Azure AD. Desired Technical Skills • Microsoft Azure security certifications (e.g., SC-200, SC-300, AZ-500) or demonstrated equivalent experience. • Citrix XenApp Server support (Studio, Director, Storefront, Apps). • Active Directory domain infrastructure and Group Policy administration for domain-wide computer and user policies. • NTFS file permissions and data access governance. • Security focus on device hardening, endpoint protection, and identity management across hybrid environments. • Experience with SIEM platforms, security monitoring, and incident response workflows. Education & Experience • Minimum 10 years of experience working in an IT department performing similar duties, with demonstrated exposure to network security and cloud security practices. • Professional certifications such as MCP, A+, Network+, Security+, or Microsoft Azure security certifications (SC-200, SC-300, AZ-500) are preferred. Working Environment • No special physical requirements for this position. • General office conditions. • Some light lifting and bending. • Periods of sitting. • Travel 20% Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
09/22/2026
Full time
Job Description Job Description Position Overview The Network Security Engineer role sits within the Information Technology Department and exists to keep the organization's WAN, LAN, voice, and cloud infrastructure running efficiently, reliably, and securely. While the role retains the full scope of traditional network engineering, this description places heightened emphasis on cybersecurity operations and Microsoft Azure security, reflecting the organization's continued shift toward hybrid and cloud-hosted infrastructure. The successful candidate will partner with third-party providers and internal IT leadership to defend the network and cloud environment against malware, intrusion, and emerging cyber-threats; maintain firewalls, identity controls, and access policies; ensure reliable backups and disaster recovery; and act as a key contributor to the organization's overall security posture across both on-premises and Azure-hosted resources. Cybersecurity & Azure Security Responsibilities (Primary Emphasis) • Lead and support efforts to harden the network and cloud environment against malware, ransomware, and intrusion, including proactive identification of emerging cyber-threats and at-risk areas across LAN, WAN, WLAN, SD-WAN, and Azure-hosted workloads. • Design, implement, and maintain security controls within Microsoft Azure, including Azure Active Directory / Entra ID, Conditional Access policies, Multi-Factor Authentication (MFA), Privileged Identity Management (PIM), and Azure role-based access control (RBAC). • Monitor and respond to alerts from Microsoft Defender for Cloud, Microsoft Sentinel (or equivalent SIEM), and Helpdesk/security partner tooling, escalating high-risk issues to IT Management in a timely manner. • Configure and maintain Cisco Meraki firewall security settings, network segmentation (subnetting/VLANs), and access permission groups to enforce least-privilege principles across both on-premises and cloud resources. • Implement and maintain Azure network security components such as Network Security Groups (NSGs), Azure Firewall, Azure VPN/ExpressRoute connections, and Azure Bastion for secure remote access. • Support identity and access management initiatives, including device hardening, endpoint security, single sign-on (SSO), and Group Policy enforcement for domain-wide computer and user security baselines. • Ensure secure, regularly-tested backups of critical systems and servers, including the organization's Nutanix hyper-converged and Cohesity backup environments, with attention to ransomware-resilient and immutable backup practices. • Participate in vulnerability management and patching cycles (Microsoft Intune), prioritizing remediation of high-severity findings across servers, network devices, and cloud resources. • Maintain and continuously improve security documentation, including network topology, data flow, incident response procedures, and Azure security architecture diagrams. • Assist in security awareness initiatives and end-user training to reinforce safe computing practices and compliance with IT framework, policies, and procedures. • Support audits and compliance efforts related to data protection, access control, and cloud security standards, providing evidence and documentation as required. Core Network Engineering Responsibilities • Perform day-to-day networking tasks to ensure network reliability, availability, and serviceability with minimal interruption. • Provide technical support, respond to work orders and tickets, and analyze and resolve reported network problems. • Install and troubleshoot LAN, WAN, WLAN, and SD-WAN connectivity, including DNS, DHCP, and TCP/IP services. • Develop and maintain complex documentation for installation, network topology, and troubleshooting of communications hardware and software. • Work with the IT Team to coordinate and install server updates, patches, and certificates. • Maintain an enterprise-wide inventory of all server and network infrastructure assets, including warranty status and lifecycle management. • Provide server systems support, administration, and documentation, including Windows Server operating systems and hypervisor-based environments (Nutanix AHV). • Work with the Sr. Network Engineer to maintain and update the company's hyper-converged Nutanix solution and Cohesity backup solution. • Create and maintain IT-related end-user training documentation. • Participate in the on-call rotation as needed and required. • Demonstrate excellent time management and prioritization skills, balancing routine tasks with urgent support and security needs. • Adhere to, support, and foster compliance with the IT framework, policies, and procedures across the user base. • Act as a strong team player who continually seeks to grow technical expertise and the scope of the role. Knowledge, Skills & Experience Required Technical Skills • Strong working knowledge of cybersecurity principles, including threat detection, firewall management (Cisco Meraki and Fortigate), network segmentation, and identity-based security controls. • Hands-on experience with Microsoft Azure security tools and services (Azure AD/Entra ID, Conditional Access, MFA, NSGs, Azure Firewall, Defender for Cloud, or Sentinel). • Ability to troubleshoot current Windows and Server operating systems, including patching and hardware support. • Experience troubleshooting LAN, WAN, WLAN, and SD-WAN environments (DNS, DHCP, TCP/IP). • Solid understanding of network segmentation (sub-netting) and VLANs. • Experience with a patch management solution (WSUS and/or Microsoft Intune) and structured vulnerability remediation. • Familiarity or working knowledge of hypervisor-based servers and computing; Nutanix AHV experience a plus. • Understanding of hybrid identity and access management concepts spanning on-premises Active Directory and Azure AD. Desired Technical Skills • Microsoft Azure security certifications (e.g., SC-200, SC-300, AZ-500) or demonstrated equivalent experience. • Citrix XenApp Server support (Studio, Director, Storefront, Apps). • Active Directory domain infrastructure and Group Policy administration for domain-wide computer and user policies. • NTFS file permissions and data access governance. • Security focus on device hardening, endpoint protection, and identity management across hybrid environments. • Experience with SIEM platforms, security monitoring, and incident response workflows. Education & Experience • Minimum 10 years of experience working in an IT department performing similar duties, with demonstrated exposure to network security and cloud security practices. • Professional certifications such as MCP, A+, Network+, Security+, or Microsoft Azure security certifications (SC-200, SC-300, AZ-500) are preferred. Working Environment • No special physical requirements for this position. • General office conditions. • Some light lifting and bending. • Periods of sitting. • Travel 20% Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Senior Cloud Security Assessor
Spry Methods Washington, Washington DC
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/22/2026
Full time
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Security Control Assessor
Apavo Corporation Arlington, Virginia
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/21/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Information Systems Security Engineer (ISSE) with DoD Clearance - mid-level
VETS, Inc Scott Air Force Base, Illinois
VETS, Inc., is looking to add a mid-level (3-5 years experience) Information Systems Security Engineer (ISSE) to our growing team at Scott AFB, IL. This is a full time, permanent position with full benefits working onsite at SAFB. Due to contractual requirements, this position requires US Citizenship and an active/current DoD Security clearance. The successful candidate will: Apply hands-on security engineering skills across a complex mix of on-premise and cloud DoD systems Work alongside dedicated GRC, operations, and architecture teams to implement real security controls Develop deep expertise in STIG compliance, vulnerability management, and PAM security Build your technical toolkit across STIGviewer, SCAP, Tenable, and CyberArk Grow toward senior engineering roles with strong mentorship and technical challenge Responsibilities Implement and document STIG configurations across assigned systems and platforms Conduct Security Impact Analyses (SIAs) for proposed system changes Execute automated configuration validation using SCAP Compliance Checker Manage vulnerability tracking and remediation workflows in Tenable SC Assess cloud infrastructure security posture using Tenable Cloud Security Support CyberArk PAM configuration and privileged access management Develop and maintain security configuration baselines Author technical security control implementation guides Support the Cybersecurity Architect with technical security implementations Qualifications Required: Active Secret or TS clearance 35 years of experience in security engineering or system hardening Hands-on experience with STIGviewer and SCAP Compliance Checker Working experience with Tenable SC or equivalent vulnerability management tools Knowledge of secure configuration management principles DoD 8140.03M DCWF Basic tier certification CEH DoD 8140 Interim Education Options Desired Certification: DoD 8140.03M DCWF Intermediate tier certification one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ Bachelors degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering Experience with CyberArk PAM administration Familiarity with Tenable Cloud Security or equivalent cloud assessment tooling Exposure to DoD cloud environments (IL2IL6)
09/16/2026
VETS, Inc., is looking to add a mid-level (3-5 years experience) Information Systems Security Engineer (ISSE) to our growing team at Scott AFB, IL. This is a full time, permanent position with full benefits working onsite at SAFB. Due to contractual requirements, this position requires US Citizenship and an active/current DoD Security clearance. The successful candidate will: Apply hands-on security engineering skills across a complex mix of on-premise and cloud DoD systems Work alongside dedicated GRC, operations, and architecture teams to implement real security controls Develop deep expertise in STIG compliance, vulnerability management, and PAM security Build your technical toolkit across STIGviewer, SCAP, Tenable, and CyberArk Grow toward senior engineering roles with strong mentorship and technical challenge Responsibilities Implement and document STIG configurations across assigned systems and platforms Conduct Security Impact Analyses (SIAs) for proposed system changes Execute automated configuration validation using SCAP Compliance Checker Manage vulnerability tracking and remediation workflows in Tenable SC Assess cloud infrastructure security posture using Tenable Cloud Security Support CyberArk PAM configuration and privileged access management Develop and maintain security configuration baselines Author technical security control implementation guides Support the Cybersecurity Architect with technical security implementations Qualifications Required: Active Secret or TS clearance 35 years of experience in security engineering or system hardening Hands-on experience with STIGviewer and SCAP Compliance Checker Working experience with Tenable SC or equivalent vulnerability management tools Knowledge of secure configuration management principles DoD 8140.03M DCWF Basic tier certification CEH DoD 8140 Interim Education Options Desired Certification: DoD 8140.03M DCWF Intermediate tier certification one of: CEH(P), RCCE Level 1, Cloud+, CPTE, FITSP-A, GCED, GCIH, GCSA, GICSP, GSEC, PenTest+, or Security+ Bachelors degree in Computer Science, Cybersecurity, Data Science, Information Systems, Information Technology, or Software Engineering Experience with CyberArk PAM administration Familiarity with Tenable Cloud Security or equivalent cloud assessment tooling Exposure to DoD cloud environments (IL2IL6)
Network Security Engineer II
Hyundai Autoever America Irvine, California
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/15/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Network Security Engineer
Etched San Jose, California
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
09/15/2026
Full time
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board