Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
09/30/2026
Full time
Job Description Job Description Palo Alto Firewall Engineer / SME (PCNSE) Cyber Security Engineering Specialist III - Firewall Services Location: Springfield, VA - on site Time Type: Full time, Exempt Clearance Required to Start: Active TS/SCI (U.S. citizenship required) Additional Requirement: Must be able to obtain and maintain a U.S. Government polygraph Travel: Up to 15%, local and CONUS Salary Range: $117,000 - $128,000 Own the Palo Alto estate - legacy iron through Prisma and Panorama. RISA is hiring a Palo Alto SME to be the focal point for every Palo Alto task, operation, and project on the Network Security Services team supporting an Intelligence Community customer. The work spans both ends of the estate: PA-3000 and PA-5000 hardware refreshes and legacy CLI on one side, Prisma Access, VM-Series, and Cortex on the other. You will talk to the owner here, not a recruiting queue. What You Will Do Serve as the lead technical authority for administering, configuring, and troubleshooting Palo Alto NGFWs across a hybrid enterprise. Lead the design, analysis, testing, and implementation of secure network architectures on the Palo Alto stack. Manage the full hardware and software lifecycle, including complex refreshes and PAN-OS upgrades on legacy platforms. Run Panorama for centralized policy management across a fleet of physical and virtual firewalls. Configure master-level security profiles - App-ID, User-ID, Content-ID, SSL Decryption, and WildFire. Own configuration management processes and SOPs for all Palo Alto platforms. Mentor junior engineers and act as the escalation point for complex troubleshooting. Liaise with contract, customer, and government DAA on network security status, policies, and procedures. What You'll Bring S. citizenship and an active TS/SCI. Ability to successfully obtain and maintain a U.S. Government polygraph. Education and experience, per the contract labor category criteria: Bachelor's degree in a field applicable to the position plus 6 years of relevant experience. Equivalents accepted - Master's plus 4, Associate's plus 8, or High School diploma/GED plus 10. 7+ years hands-on administering, configuring, and troubleshooting Palo Alto NGFWs in large-scale enterprise or global environments. Active PCNSE certification. DoD 8140.01 and 8570.01-M IAT Level II (e.g. Security+ CE), and CSSP Infrastructure Support within 120 days of start. Deep practical knowledge of legacy Gen 2/Gen 3 hardware - PA-3000 and PA-5000 series, legacy CLI, physical troubleshooting, line-card replacement. Prisma Access (SASE), Prisma SD-WAN, and VM-Series in AWS, Azure, or GCP. Panorama template and device-group inheritance across a hybrid fleet. Advanced BGP, OSPF, IPSec VPN, and NAT. Nice to Have PCNSC or Prisma Certified SASE Professional (PCSAE). Python, plus firewall automation with Ansible, Terraform, or the Palo Alto XML/REST APIs. Cortex XDR or XSOAR; Expedition for legacy rule migration to App-ID policy. Zero Trust Network Access architecture; F5 (APM, AFM), Juniper SRX, or Cisco FTD/ASA. About RISA Rolston Information Systems Assurance (RISA) is a Service-Disabled Veteran-Owned Small Business that has supported federal defense and intelligence cybersecurity missions for more than seventeen years. We are small on purpose: direct access to leadership, a real say in how the work gets done, and none of the layers that slow large primes down. Benefits Medical, dental, and vision insurance; 401(k) and Roth; Paid Time Off; and 11 paid Federal Holidays. RISA is an Equal Opportunity Employer. Upon receiving an offer of employment, all applicants will be required to do a background check, including a criminal record check and employment/education verification.
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
09/28/2026
Full time
Job Description Job Description Network Security Engineer II Location - Onsite, Irvine, CA Grade: 8 Company Overview Hyundai AutoEver America (HAEA), the dynamic IT powerhouse behind Hyundai Motor Corporation, a Fortune 500 global leader in the automotive industry. As a key affiliate, we provide cutting-edge IT services and support to top brands including Kia, Genesis, Hyundai Translead, Hyundai Mobis, Hyundai Capital, and Glovis. HAEA offers a truly global and collaborative environment. Here, you'll drive innovation, boost operational efficiency, and help shape the future of mobility for the Hyundai Motor Group. At HAEA, we understand that IT is the cornerstone of today's fast-evolving digital world. By uniting all IT resources under one roof, we deliver consistent, top-quality solutions while serving as the crucial information link between Hyundai's Global Headquarters and North American operations. If you're passionate about technology and eager to make a real impact at a world-class company, Hyundai AutoEver America is the place to grow your career. Join us and be part of the transformation that's driving the future of automotive innovation. What You Will Be Doing The Security Architecture and Engineering team within the CISO organization is seeking a Network Security Engineer II to help design, implement, operate, and continuously improve enterprise network security controls. This role will focus on technologies including Web Application Firewalls, Network Access Control, IDS, and IPS, while partnering closely with the IT Networking team to ensure secure, reliable, and scalable network services. This is an onsite role, five days per week, based in our Irvine office. The key responsibilities of this role are as described below: The Network Security Engineer II will be responsible for supporting and maintaining critical network security platforms across the enterprise. Responsibilities include: Administer, monitor, and optimize Web Application Firewall platforms to protect internet-facing and internal applications. Support and maintain Network Access Control technologies, including device profiling, policy enforcement, segmentation support, and exception handling. Operate and tune Intrusion Detection and Intrusion Prevention Systems to improve detection accuracy and reduce false positives. Partner with the IT Networking team on secure network design, routing, switching, firewall, segmentation, and connectivity initiatives. Assist other Security and IT teams by reviewing security events, alerts, logs, and traffic patterns to identify potential threats or misconfigurations. Assist with the implementation of network security architecture standards, hardening guidelines, and secure configuration baselines. Participate in incident response activities related to network-based threats, unauthorized access, or suspicious traffic. Develop and maintain documentation, including network security diagrams, platform runbooks, standard operating procedures, and change records. Support vulnerability remediation efforts related to network infrastructure, application exposure, and security control gaps. Perform policy reviews and rulebase hygiene for WAF, NAC, IDS, and IPS technologies. Participate in change management activities, including risk assessment, implementation planning, testing, and post-change validation. Collaborate with security operations, infrastructure, application, and compliance teams to support business and regulatory requirements. Assist with lifecycle management for network security tools, including upgrades, patching, certificate management, integrations, and capacity planning. Provide technical recommendations to improve visibility, segmentation, access control, and threat prevention across the environment. Basic Qualifications: Experience: 8+ years of network security, infrastructure security, and/or security engineering. Practical and demonstrated experience working Web Application Firewalls, Network Access Control platforms, IDS/IPS technologies, Firewalls or secure network gateways in platforms by Cisco, Palo Alto, Trend Micro, Gigamon, Trellix, etc. Education: Bachelor's degree in Cybersecurity, Information Technology, Computer science or a related field. Technical Expertise: Advanced level knowledge of networking concepts, including TCP/IP, DNS, DHCP, VLANs, routing, switching, NAT, VPNs, and network segmentation. Experience analyzing logs, packet captures, alerts, and network traffic to troubleshoot issues or investigate security events. Familiarity with common network and application-layer attack techniques. Experience supporting production environments and following change management processes. Strong troubleshooting, documentation, and communication skills. Language Skills: Excellent stakeholder management and communication skills. Proficient in English for effective communication and coordination. Schedule: This is an onsite position requiring presence in the Irvine office five days per week. Some after-hours or weekend work may be required for planned maintenance, incident response, or critical security changes. Preferred Qualifications: Experience: Experience with enterprise WAF policy tuning, bot protection, API protection, or application security rule sets. Experience with NAC deployment models, including 802.1X, MAC authentication bypass, posture assessment, guest access, and device profiling. Familiarity with SIEM, SOAR, vulnerability management, endpoint security, or cloud security tools. Scripting or automation experience using Python, PowerShell, APIs, or infrastructure-as-code tools. Education and Certifications: Masters degree in Cybersecurity, Information Technology, Computer Science or a related discipline is preferred. Industry-recognized credentials such as Security+, Network+, CCNA, CCNP Security, PCNSE, CISSP, GSEC, GCIH, or vendor-specific certifications. Language Skills: Bi-lingual in English and Korean language proficiency is preferred to support global coordination and communication. Team Culture: The team fosters a high-performance, collaborative environment centered around proactive technology risk management and excellent customer service. Members are expected to lead with accountability, communicate effectively across functions, and adapt to dynamic challenges. The culture values technical excellence, continuous improvement, and global coordination, ensuring technology risks are well managed. Base Salary Range: $100,000 - 130,000 Powered by JazzHR FgOdYKZ9EK
Job Description Job Description "A World of Opportunities" Committed to an industry that combines innovation and responsibility, we embody our slogan on a daily basis: "A World of Opportunities". Trust, Reputation, Integrity and Rise are strong values that make up Clayens' DNA! Job Summary: The Network and Cybersecurity Engineer is responsible for the design, deployment, administration, and security of the organization's network and IT infrastructure. This role ensures the availability, performance, and protection of LAN, WAN, cloud, and hybrid environments while leading cybersecurity initiatives across multiple sites. The engineer works closely with local IT teams, business stakeholders, and group's cybersecurity team to implement secure technologies, investigate security incidents, manage network operations, and support strategic infrastructure projects. Supervisory Responsibilities: None Keys Responsibilities: Design, deploy, and maintain LAN/WAN/VLAN and wireless network infrastructure. Configure and support firewalls, VPNs, SASE, NAC, and network security solutions. Monitor, investigate, and remediate cybersecurity threats, incidents, and vulnerabilities. Maintain and improve cybersecurity controls, including EDR, PAM. Create and maintain network diagrams, technical documentation, and operational procedures. Provide technical support and guidance for network and security-related issues. Collaborate with regional and global IT teams on infrastructure and cybersecurity projects. Lead cybersecurity improvements for all North America locations. Required Qualifications and Experience: Degree in Information Technology, Computer Science, Cybersecurity, or related field. Experience administering enterprise networks, firewalls, routing, switching, and wireless technologies. Experience in cybersecurity investigation such as incident response, phishing, unusual sign-in, suspicious activities or any security alerts. Experience with Microsoft Windows Server, virtualization platforms, Azure and Microsoft Entra ID / Active Directory. Strong troubleshooting, analytical, and documentation skills. Excellent communication and collaboration skills, with the ability to provide clear insights and recommendations to leadership and cross-functional teams. Ability to work independently, exercise sound judgment, maintain confidentiality, and ensure alignment with organizational policies and compliance requirements. Preferred Qualifications and Experience Hands-on experience deploying Meraki wireless access points and FortiGate firewalls. Experience supporting HPE, Aruba switches. Experience with SASE, SIEM, SOAR, EDR, and PAM solutions. Familiarity with cybersecurity frameworks and compliance requirements, including NIS2, ISO 27001, ITAR, and CMMC. Expertise in Microsoft Entra ID and on-premises Active Directory within hybrid environments. Relevant networking or cybersecurity certifications. Experience supporting multi-site manufacturing environments and collaborating with international teams.
09/28/2026
Full time
Job Description Job Description "A World of Opportunities" Committed to an industry that combines innovation and responsibility, we embody our slogan on a daily basis: "A World of Opportunities". Trust, Reputation, Integrity and Rise are strong values that make up Clayens' DNA! Job Summary: The Network and Cybersecurity Engineer is responsible for the design, deployment, administration, and security of the organization's network and IT infrastructure. This role ensures the availability, performance, and protection of LAN, WAN, cloud, and hybrid environments while leading cybersecurity initiatives across multiple sites. The engineer works closely with local IT teams, business stakeholders, and group's cybersecurity team to implement secure technologies, investigate security incidents, manage network operations, and support strategic infrastructure projects. Supervisory Responsibilities: None Keys Responsibilities: Design, deploy, and maintain LAN/WAN/VLAN and wireless network infrastructure. Configure and support firewalls, VPNs, SASE, NAC, and network security solutions. Monitor, investigate, and remediate cybersecurity threats, incidents, and vulnerabilities. Maintain and improve cybersecurity controls, including EDR, PAM. Create and maintain network diagrams, technical documentation, and operational procedures. Provide technical support and guidance for network and security-related issues. Collaborate with regional and global IT teams on infrastructure and cybersecurity projects. Lead cybersecurity improvements for all North America locations. Required Qualifications and Experience: Degree in Information Technology, Computer Science, Cybersecurity, or related field. Experience administering enterprise networks, firewalls, routing, switching, and wireless technologies. Experience in cybersecurity investigation such as incident response, phishing, unusual sign-in, suspicious activities or any security alerts. Experience with Microsoft Windows Server, virtualization platforms, Azure and Microsoft Entra ID / Active Directory. Strong troubleshooting, analytical, and documentation skills. Excellent communication and collaboration skills, with the ability to provide clear insights and recommendations to leadership and cross-functional teams. Ability to work independently, exercise sound judgment, maintain confidentiality, and ensure alignment with organizational policies and compliance requirements. Preferred Qualifications and Experience Hands-on experience deploying Meraki wireless access points and FortiGate firewalls. Experience supporting HPE, Aruba switches. Experience with SASE, SIEM, SOAR, EDR, and PAM solutions. Familiarity with cybersecurity frameworks and compliance requirements, including NIS2, ISO 27001, ITAR, and CMMC. Expertise in Microsoft Entra ID and on-premises Active Directory within hybrid environments. Relevant networking or cybersecurity certifications. Experience supporting multi-site manufacturing environments and collaborating with international teams.
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
09/28/2026
Full time
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
Job Description Job Description Description: OCH Technologies is seeking an NCO Technical Lead responsible for leading the day-to-day operational cybersecurity and threat intelligence functions supporting the FAA's National Cybersecurity Operations mission. The lead will run the operational side: monitor threat intelligence feeds, coordinate incident response, analyze emerging threats against NAS infrastructure, and provide technical guidance to the broader cybersecurity team. This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements. Location Hybrid - Air Traffic Control System Command Center (ATCSCC) Washington, DC OR Leesburg, VA This position has the potential to travel up to 20%. Core Responsibilities & Duties Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions. Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination. Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems. Produce actionable intelligence products that inform assessment priorities and defensive posture decisions. Coordinate incident response activities when potential security events are identified. Ensure response actions follow established procedures and are documented. Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues. Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks. Brief FAA leadership on threat trends and recommended defensive actions. Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape. Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols. Manage and oversee contractor staff performing NCO functions. Ensure personnel maintain required qualifications and training. Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role. Requirements: Minimum Qualifications Education Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution Experience At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions. At least 2 years of relevant experience must be recent (performed within the last 3 years). Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment. Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products. Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools. Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments. Security Clearance Requirement Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred Certifications Security certification such as CISSP, CISM, or CASP required GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred GCFA, GNFA, or GCIA preferred for forensics/network analysis depth CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant Preferred Qualifications Prior experience supporting FAA, DoD, or other critical infrastructure cybersecurity operations. Experience with aviation-specific cyber threats or operational technology (OT/ICS) threat analysis. Familiarity with FAA Security Operations Center (SOC) operations. Experience coordinating with federal threat intelligence sharing organizations (US-CERT, CISA, sector ISACs). Modern threat intelligence platforms (MISP, OpenCTI) for structured threat data management and sharing. SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) for automated incident response workflows and playbook execution. EDR/XDR tools (CrowdStrike Falcon, SentinelOne, Carbon Black) for endpoint-level detection and response in operational environments. AI/ML-based anomaly detection and threat hunting tools for identifying novel attack patterns across complex, multi-segment network environments. Attack surface management platforms for continuous external exposure monitoring of NAS-connected assets. Other Required Skills and Abilities Understanding of federal cybersecurity policy (FISMA, NIST CSF, CDM program) and how operational cybersecurity functions support broader agency security objectives. Strong written and verbal communication skills. Ability to brief senior leadership on threat landscape and operational status. About Us : At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability. What Defines Us: Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically. Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. People-Focused - We prioritize relationships, championing growth and mutual success. Accountable - We own our outcomes, striving for excellence through continuous improvement. Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. Why Join Us? Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career-it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including: Paid time off and Holidays Medical, Dental, and Vision Insurance Paid Parental Leave Short-term disability, long-term disability, and life insurance - Employer Paid! 401(k) Additional Voluntary Life Insurance Tuition Reimbursement & More! E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees. Veteran's Preference and Accessibility Statement : At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here. We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at . OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.
09/26/2026
Full time
Job Description Job Description Description: OCH Technologies is seeking an NCO Technical Lead responsible for leading the day-to-day operational cybersecurity and threat intelligence functions supporting the FAA's National Cybersecurity Operations mission. The lead will run the operational side: monitor threat intelligence feeds, coordinate incident response, analyze emerging threats against NAS infrastructure, and provide technical guidance to the broader cybersecurity team. This position supports a proposal effort and is contingent upon award, customer approval, and successful onboarding requirements. Location Hybrid - Air Traffic Control System Command Center (ATCSCC) Washington, DC OR Leesburg, VA This position has the potential to travel up to 20%. Core Responsibilities & Duties Provide day-to-day technical oversight, coordination, and guidance to contractor personnel performing operational cybersecurity and threat intelligence functions. Lead all activities supporting the National Cybersecurity Operations (NCO) mission including threat intelligence collection and analysis, threat hunting, and incident response coordination. Monitor and analyze cyber threat intelligence relevant to FAA and NAS systems. Produce actionable intelligence products that inform assessment priorities and defensive posture decisions. Coordinate incident response activities when potential security events are identified. Ensure response actions follow established procedures and are documented. Attend all Program Management Reviews with the Program Manager and report on NCO operational support activities, threat intelligence findings, deliverables, and technical issues. Maintain awareness of emerging cyber threats targeting critical infrastructure, aviation systems, and government networks. Brief FAA leadership on threat trends and recommended defensive actions. Collaborate with the Security Assessment Lead and Penetration Testing Lead to ensure assessment and testing priorities reflect the current threat landscape. Develop and maintain standard operating procedures for NCO functions including escalation criteria, reporting templates, and coordination protocols. Manage and oversee contractor staff performing NCO functions. Ensure personnel maintain required qualifications and training. Responsibilities may evolve over time to support team and organizational goals but will remain consistent with the overall scope of the role. Requirements: Minimum Qualifications Education Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Engineering, Mathematics, or Physics from an accredited institution Experience At least fifteen (15)+ years of cybersecurity experience with at least 5 years of management and supervisory responsibility over operational cybersecurity, threat intelligence teams, or SOC/CIRT functions. At least 2 years of relevant experience must be recent (performed within the last 3 years). Demonstrated experience leading incident response and threat intelligence operations in a federal or critical infrastructure environment. Strong understanding of cyber threat intelligence frameworks (MITRE ATT&CK, Diamond Model, Cyber Kill Chain) and experience producing actionable intelligence products. Experience with SIEM platforms, threat intelligence platforms, and endpoint detection and response (EDR) tools. Knowledge of network defense monitoring, log analysis, and anomaly detection in complex, multi-segment network environments. Security Clearance Requirement Candidate must have the ability to obtain and maintain a Public Trust Active Secret clearance preferred Certifications Security certification such as CISSP, CISM, or CASP required GCIH (GIAC Certified Incident Handler) or GCTI (GIAC Cyber Threat Intelligence) strongly preferred GCFA, GNFA, or GCIA preferred for forensics/network analysis depth CND, CNDA, GDAT, GDSA, GCED, GCFA are directly relevant Preferred Qualifications Prior experience supporting FAA, DoD, or other critical infrastructure cybersecurity operations. Experience with aviation-specific cyber threats or operational technology (OT/ICS) threat analysis. Familiarity with FAA Security Operations Center (SOC) operations. Experience coordinating with federal threat intelligence sharing organizations (US-CERT, CISA, sector ISACs). Modern threat intelligence platforms (MISP, OpenCTI) for structured threat data management and sharing. SOAR platforms (Cortex XSOAR, Splunk SOAR, Tines) for automated incident response workflows and playbook execution. EDR/XDR tools (CrowdStrike Falcon, SentinelOne, Carbon Black) for endpoint-level detection and response in operational environments. AI/ML-based anomaly detection and threat hunting tools for identifying novel attack patterns across complex, multi-segment network environments. Attack surface management platforms for continuous external exposure monitoring of NAS-connected assets. Other Required Skills and Abilities Understanding of federal cybersecurity policy (FISMA, NIST CSF, CDM program) and how operational cybersecurity functions support broader agency security objectives. Strong written and verbal communication skills. Ability to brief senior leadership on threat landscape and operational status. About Us : At OCH, we are more than just a government contracting firm; we are innovators and leaders in providing cutting-edge IT services and cybersecurity solutions. Driven by a set of fundamental values, we excel in creating secure, efficient, and forward-thinking solutions that empower the government agencies we work with. Our commitment to maintaining the highest standards of integrity, adapting swiftly to new challenges, and focusing on the people we serve ensures that we consistently exceed expectations and lead the industry in innovation and reliability. What Defines Us: Integrity - We act with unwavering honesty, ensuring every decision is rooted ethically. Adaptable - We swiftly adapt to changes, seizing opportunities to innovate and lead. People-Focused - We prioritize relationships, championing growth and mutual success. Accountable - We own our outcomes, striving for excellence through continuous improvement. Collaborative - We cultivate teamwork, harnessing diverse talents to forge groundbreaking solutions. Why Join Us? Step into a role at OCH where your contributions make a tangible impact. Join a team that values creativity and initiative, offering a platform to transform the landscape of government IT services. Here, your work is not just a career-it's a mission. Embrace the opportunity to grow, innovate, and excel alongside industry leaders who are as passionate about technology as they are about making a difference. Plus, we offer a comprehensive benefits package designed to support your wellbeing and work-life balance, including: Paid time off and Holidays Medical, Dental, and Vision Insurance Paid Parental Leave Short-term disability, long-term disability, and life insurance - Employer Paid! 401(k) Additional Voluntary Life Insurance Tuition Reimbursement & More! E-Verify Participation: OCH Technologies, LLC is a participant of E-Verify to verify the identity and employment eligibility of newly hired employees. Veteran's Preference and Accessibility Statement : At OCH Technologies, we deeply respect and appreciate the unique skills and experiences that veterans bring to our team. As a federal contractor, we encourage qualified veterans to apply and provide preference where permitted by law. Your service and dedication are valued here. We are committed to creating a workplace that is open, welcoming, and accessible to everyone. In accordance with the Americans with Disabilities Act (ADA) and Section 503 of the Rehabilitation Act, we provide reasonable accommodations throughout the hiring process to ensure individuals with disabilities can apply without barriers. If you need assistance or an accommodation, please contact us at . OCH Technologies, LLC is proud to be an equal opportunity employer. We are committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, disability, gender identity, or any other protected characteristic as outlined by federal, state, or local laws.
Job Description Job Description Information Systems Security Manager / Specialist Location: Arlington, VA Must have an active Top Secret Clearance Node provides HIRT remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities. Node is seeking an Information Systems Security Specialist to support this critical customer mission. Responsibilities: -Work as part of a team of Information Assurance professionals to manage the full Risk Management Framework lifecycle for Information Technology systems -Assisting technical/management leadership on major tasks or technology assignments -Establishing goals and plans that meet project objectives -Assisting in direction and control activities, having overall responsibility for security management, methods, and staffing to ensure that technical requirements are met -Participating in client negotiations and interfacing with senior management -Supporting decision making and domain knowledge that may have a critical impact on overall project implementation -Providing support to plan, coordinate, and implement a cybersecurity lab's information security -Providing support for facilitating and helping the lab identify its current security infrastructure and define future programs, design and implementation of security related to lab systems -Assisting the efforts of security staff to design, develop, engineer and implement solutions to security requirements -Implementing and development of the DHS IT security standards -Gathering and organizing technical information about the lab's mission goals and needs, existing security products, and ongoing programs -Performing risk analyses which also includes risk assessment -Planning and leading major technology assignments -Evaluating performance results and recommends major changes affecting short-term project growth and success -Functioning as a cyber technical expert across multiple project assignments -Working closely with ISSM and CISO to respond to Data Calls and satisfy requirements of ATOs Requirements Required Skills: - U.S. Citizenship - Must have an active TS/SCI clearance - Must be able to obtain DHS Suitability - 5+ years of directly relevant experience in information security management - Hands on experience with Linux operating systems or Amazon Web Services - Experience supporting the NIST Risk Management Framework (RMF) process and contributing to a full ATO effort from initiation through authorization, including development of security documentation, control implementation statements, supporting assessment (audit) activities, and performing full POA&M management - Beginning to end Knowledge of RMF and Assessment and Authorization (A&A) documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution - Experience working on multiple complex assignments which are broad in nature, requiring originality and innovation in determining how to accomplish tasks - Ability to apply a comprehensive knowledge across key tasks and high impact assignments - Knowledge of Computer Network Defense (CND) policies, procedures & regulations - Knowledge of defense-in-depth principles and network security architecture - Knowledge of ATO requirements and strong experience with POAMs. - Knowledge and experience with full range of Microsoft Office products (Word, Excel, Powerpoint, and Visio) - Knowledge of boundary protection and network segmentation - Knowledge of authentication and access management techniques - Experience with implementing and assessing security controls for hardware, software, and network deployments - Must be able to work collaboratively with internal and external stakeholders across physical locations Desired Skills: - Experience with Risk Management Framework software (CSAM, Xacta, Archer, RegScale) - Experience with host and network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp) - Experience with Endpoint Protection tools like CrowdStrike or CarbonBlack - Working knowledge of SIEM tools like Splunk, SOAR, or ELK - Familiarity with role-based account processing operations - Familiarity with zero trust architectures - Familiarity with scripting languages (python, AWS CLI, Lambda, bash, powershell) Required Education: BS Information Management, Cybersecurity, Computer Science or related degree, or High School Diploma and 7+ years of information security management experience. Desired Certifications: - DoD 8140.01 IAT Level III, CISSP, AWS, Cisco, Microsoft Benefits Medical Dental Vision Basic Life Health Saving Account 401K Matching Three weeks of PTO/Sick 11 Paid Holidays Pre-Approved Online Training
09/26/2026
Full time
Job Description Job Description Information Systems Security Manager / Specialist Location: Arlington, VA Must have an active Top Secret Clearance Node provides HIRT remote and onsite advanced technical assistance, proactive hunting, rapid onsite incident response, and immediate investigation and resolution using host-based and network-based cybersecurity analysis capabilities. Node is seeking an Information Systems Security Specialist to support this critical customer mission. Responsibilities: -Work as part of a team of Information Assurance professionals to manage the full Risk Management Framework lifecycle for Information Technology systems -Assisting technical/management leadership on major tasks or technology assignments -Establishing goals and plans that meet project objectives -Assisting in direction and control activities, having overall responsibility for security management, methods, and staffing to ensure that technical requirements are met -Participating in client negotiations and interfacing with senior management -Supporting decision making and domain knowledge that may have a critical impact on overall project implementation -Providing support to plan, coordinate, and implement a cybersecurity lab's information security -Providing support for facilitating and helping the lab identify its current security infrastructure and define future programs, design and implementation of security related to lab systems -Assisting the efforts of security staff to design, develop, engineer and implement solutions to security requirements -Implementing and development of the DHS IT security standards -Gathering and organizing technical information about the lab's mission goals and needs, existing security products, and ongoing programs -Performing risk analyses which also includes risk assessment -Planning and leading major technology assignments -Evaluating performance results and recommends major changes affecting short-term project growth and success -Functioning as a cyber technical expert across multiple project assignments -Working closely with ISSM and CISO to respond to Data Calls and satisfy requirements of ATOs Requirements Required Skills: - U.S. Citizenship - Must have an active TS/SCI clearance - Must be able to obtain DHS Suitability - 5+ years of directly relevant experience in information security management - Hands on experience with Linux operating systems or Amazon Web Services - Experience supporting the NIST Risk Management Framework (RMF) process and contributing to a full ATO effort from initiation through authorization, including development of security documentation, control implementation statements, supporting assessment (audit) activities, and performing full POA&M management - Beginning to end Knowledge of RMF and Assessment and Authorization (A&A) documentation to include SSP, Contingency, Incident & Configuration Mgmt planning and execution - Experience working on multiple complex assignments which are broad in nature, requiring originality and innovation in determining how to accomplish tasks - Ability to apply a comprehensive knowledge across key tasks and high impact assignments - Knowledge of Computer Network Defense (CND) policies, procedures & regulations - Knowledge of defense-in-depth principles and network security architecture - Knowledge of ATO requirements and strong experience with POAMs. - Knowledge and experience with full range of Microsoft Office products (Word, Excel, Powerpoint, and Visio) - Knowledge of boundary protection and network segmentation - Knowledge of authentication and access management techniques - Experience with implementing and assessing security controls for hardware, software, and network deployments - Must be able to work collaboratively with internal and external stakeholders across physical locations Desired Skills: - Experience with Risk Management Framework software (CSAM, Xacta, Archer, RegScale) - Experience with host and network scanning software (Nessus, Security Center, Tenable Vulnerability Management, nmap, Wiz, burp) - Experience with Endpoint Protection tools like CrowdStrike or CarbonBlack - Working knowledge of SIEM tools like Splunk, SOAR, or ELK - Familiarity with role-based account processing operations - Familiarity with zero trust architectures - Familiarity with scripting languages (python, AWS CLI, Lambda, bash, powershell) Required Education: BS Information Management, Cybersecurity, Computer Science or related degree, or High School Diploma and 7+ years of information security management experience. Desired Certifications: - DoD 8140.01 IAT Level III, CISSP, AWS, Cisco, Microsoft Benefits Medical Dental Vision Basic Life Health Saving Account 401K Matching Three weeks of PTO/Sick 11 Paid Holidays Pre-Approved Online Training
Vaco is partnering with a national retail organization to hire a Manager of Cybersecurity Operations to lead and mature core security operations programs across the enterprise. This is a hands-on leadership role overseeing SOC operations, vulnerability management, endpoint security, DLP, incident response, and security automation. This role is ideal for a cybersecurity leader who can operate at both the program and technical execution level. The team needs someone who can manage internal security talent, hold external MSSP partners accountable, improve alert handling and escalation processes, and build repeatable capabilities around detection, response, reporting, and automation. The environment is collaborative, fast-moving, and highly cross-functional, requiring someone who can communicate clearly across IT, GRC, engineering, and business teams. This position is based in Tempe, Arizona and requires onsite presence Monday through Thursday, with Fridays optional remote. What You'll Be Doing Manage and mature day-to-day SOC operations, including monitoring, alert triage, escalation, and incident response workflows Partner closely with an external MSSP to drive SLA accountability, improve alert quality, and ensure critical issues are escalated quickly Lead vulnerability management efforts across tools such as Rapid7, Defender, and related platforms, including prioritization, remediation tracking, and executive reporting Oversee endpoint security and management initiatives across Intune, Jamf, Defender, and related endpoint controls Drive improvements to SIEM and SOAR capabilities, including automation opportunities for level 1 response, alert enrichment, and repeatable playbooks Build and refine incident response processes, including playbooks, simulations, post-incident reviews, and lessons learned Partner with IT, GRC, engineering, and business stakeholders to improve security posture across the organization Support DLP strategy and monitoring to protect sensitive data across SaaS, cloud, and endpoint environments Use security metrics, scorecards, and framework alignment to communicate program maturity and areas for improvement Evaluate how AI can be used responsibly in security operations, including automation of response workflows and protection of AI-enabled systems Mentor and develop security team members while remaining hands-on with technical operations when needed Help define and operationalize security programs that reduce risk while supporting business velocity Required Experience 6 or more years of experience in cybersecurity, information security operations, incident response, infrastructure, or related technical security roles Proven experience managing or leading SOC operations, either in a corporate environment or MSSP setting Strong understanding of the end-to-end incident response lifecycle, from alert intake through containment, remediation, and post-incident review Hands-on experience with cybersecurity technologies such as MDR, EDR, SIEM, SOAR, vulnerability management, and endpoint security tools Experience maturing vulnerability management programs, including risk prioritization, remediation coordination, and reporting Experience partnering with or managing MSSP relationships and holding vendors accountable to performance expectations Strong understanding of security frameworks and compliance considerations such as NIST, CIS Controls, PCI, SOX, and CCPA Ability to lead without authority and collaborate effectively across IT, engineering, GRC, and business teams Experience managing high-pressure incidents and making informed decisions under time-sensitive conditions Understanding of AI concepts and their impact on cybersecurity operations, including AI-enabled threats and secure use of AI tools Bachelor's degree in a related field, or equivalent additional experience Nice to Have CISM, CISSP, or similar security certification Experience with Rapid7, Microsoft Defender, Intune, Jamf, Workato, or comparable security and automation tools Experience building SOAR workflows or security automation playbooks Familiarity with cloud security controls across AWS, Azure, or GCP Experience in SaaS-heavy environments Experience with DLP program ownership or data protection initiatives Background supporting retail, consumer-facing, or high-growth business environments Compensation & Benefits Salary range: $150,000 to $160,000 base, depending on experience Bonus potential and other financial incentives Comprehensive benefits package available If you are a hands-on cybersecurity operations leader who can mature SOC processes, improve vulnerability and endpoint programs, and build practical automation across a growing security environment, we would welcome the opportunity to connect. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets . click apply for full job details
09/25/2026
Full time
Vaco is partnering with a national retail organization to hire a Manager of Cybersecurity Operations to lead and mature core security operations programs across the enterprise. This is a hands-on leadership role overseeing SOC operations, vulnerability management, endpoint security, DLP, incident response, and security automation. This role is ideal for a cybersecurity leader who can operate at both the program and technical execution level. The team needs someone who can manage internal security talent, hold external MSSP partners accountable, improve alert handling and escalation processes, and build repeatable capabilities around detection, response, reporting, and automation. The environment is collaborative, fast-moving, and highly cross-functional, requiring someone who can communicate clearly across IT, GRC, engineering, and business teams. This position is based in Tempe, Arizona and requires onsite presence Monday through Thursday, with Fridays optional remote. What You'll Be Doing Manage and mature day-to-day SOC operations, including monitoring, alert triage, escalation, and incident response workflows Partner closely with an external MSSP to drive SLA accountability, improve alert quality, and ensure critical issues are escalated quickly Lead vulnerability management efforts across tools such as Rapid7, Defender, and related platforms, including prioritization, remediation tracking, and executive reporting Oversee endpoint security and management initiatives across Intune, Jamf, Defender, and related endpoint controls Drive improvements to SIEM and SOAR capabilities, including automation opportunities for level 1 response, alert enrichment, and repeatable playbooks Build and refine incident response processes, including playbooks, simulations, post-incident reviews, and lessons learned Partner with IT, GRC, engineering, and business stakeholders to improve security posture across the organization Support DLP strategy and monitoring to protect sensitive data across SaaS, cloud, and endpoint environments Use security metrics, scorecards, and framework alignment to communicate program maturity and areas for improvement Evaluate how AI can be used responsibly in security operations, including automation of response workflows and protection of AI-enabled systems Mentor and develop security team members while remaining hands-on with technical operations when needed Help define and operationalize security programs that reduce risk while supporting business velocity Required Experience 6 or more years of experience in cybersecurity, information security operations, incident response, infrastructure, or related technical security roles Proven experience managing or leading SOC operations, either in a corporate environment or MSSP setting Strong understanding of the end-to-end incident response lifecycle, from alert intake through containment, remediation, and post-incident review Hands-on experience with cybersecurity technologies such as MDR, EDR, SIEM, SOAR, vulnerability management, and endpoint security tools Experience maturing vulnerability management programs, including risk prioritization, remediation coordination, and reporting Experience partnering with or managing MSSP relationships and holding vendors accountable to performance expectations Strong understanding of security frameworks and compliance considerations such as NIST, CIS Controls, PCI, SOX, and CCPA Ability to lead without authority and collaborate effectively across IT, engineering, GRC, and business teams Experience managing high-pressure incidents and making informed decisions under time-sensitive conditions Understanding of AI concepts and their impact on cybersecurity operations, including AI-enabled threats and secure use of AI tools Bachelor's degree in a related field, or equivalent additional experience Nice to Have CISM, CISSP, or similar security certification Experience with Rapid7, Microsoft Defender, Intune, Jamf, Workato, or comparable security and automation tools Experience building SOAR workflows or security automation playbooks Familiarity with cloud security controls across AWS, Azure, or GCP Experience in SaaS-heavy environments Experience with DLP program ownership or data protection initiatives Background supporting retail, consumer-facing, or high-growth business environments Compensation & Benefits Salary range: $150,000 to $160,000 base, depending on experience Bonus potential and other financial incentives Comprehensive benefits package available If you are a hands-on cybersecurity operations leader who can mature SOC processes, improve vulnerability and endpoint programs, and build practical automation across a growing security environment, we would welcome the opportunity to connect. Determining compensation for this role (and others) at Vaco/Highspring depends upon a wide array of factors including but not limited to the individual's skill sets, experience and training, licensure and certifications, office location and other geographic considerations, as well as other business and organizational needs. With that said, as required by local law in geographies that require salary range disclosure, Vaco/Highspring notes the salary range for the role is noted in this job posting. The individual may also be eligible for discretionary bonuses, and can participate in medical, dental, and vision benefits as well as the company's 401(k) retirement plan. Additional disclaimer: Unless otherwise noted in the job description, the position Vaco/Highspring is filing for is occupied. Please note, however, that Vaco/Highspring is regularly asked to provide talent to other organizations. By submitting to this position, you are agreeing to be included in our talent pool for future hiring for similarly qualified positions. Submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. Further assessment of candidates beyond this initial phase within Vaco/Highspring will be otherwise assessed by recruiters and hiring managers. Vaco/Highspring does not have knowledge of the tools used by its clients in making final hiring decisions and cannot opine on their use of AI products. EEO Notice Vaco by Highspring is an Equal Opportunity Employer and does not discriminate against any employee or applicant for employment because of race (including but not limited to traits historically associated with race such as hair texture and hair style), color, sex (includes pregnancy or related conditions), religion or creed, national origin, citizenship, age, disability, status as a veteran, union membership, ethnicity, gender, gender identity, gender expression, sexual orientation, marital status, political affiliation, or any other protected characteristics as required by federal, state or local law. Vaco by Highspring and its parents, affiliates, and subsidiaries are committed to the full inclusion of all qualified individuals. As part of this commitment, Vaco by Highspring and its parents, affiliates, and subsidiaries will ensure that persons with disabilities are provided reasonable accommodations. If reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to receive other benefits and privileges of employment, please contact . Vaco by Highspring also wants all applicants to know their rights that workplace discrimination is illegal. Representation Notice By submitting to this position, you agree that you will be giving Vaco by Highspring the exclusive right to present your as a candidate for the foregoing employment opportunity. You further agree that you have represented information about yourself accurately and have not affirmatively misrepresented your qualifications. You also agree to maintain as confidential, to the fullest extent permitted by law, any information you learn from Vaco by Highspring about the position and you will limit disclosure of information about the position only to the extent necessary to perform any obligations in furtherance of your application. In exchange, Vaco by Highspring agrees to exercise reasonable efforts to represent you through all solicitation, job screening and resume dispersal. For residents of Ontario, Canada: Based on Highspring's discussions with its Client, Highspring's understanding is that this position for employment is a current vacancy (either through Highspring as a contractor or with the client directly). Privacy Notice Vaco by Highspring and its parents, affiliates, and subsidiaries ("we," "our," or "Vaco by Highspring") respects your privacy and are committed to providing transparent notice of our policies. California residents may access Vaco by Highspring HR Notice at Collection for California Applicants and Employees here. Virginia residents may access our state specific policies here. Residents of all other states may access our policies here. Canadian residents may access our policies in English here and in French here. Residents of countries governed by GDPR may access our policies here. Additionally, submissions to this position are subject to the use of AI to perform preliminary candidate screenings, focused on ensuring minimum job requirements noted in the position are satisfied. More details about Vaco by Highspring's use of AI can be found here (). Further assessment of candidates beyond this initial phase will be conducted by recruiters and hiring managers. Vaco by Highspring does not know and cannot opine on if its client's use of AI products in hiring. Pay Transparency Notice Determining compensation for this role (and others) at Vaco by Highspring depends upon a wide array of factors including but not limited to: the individual's skill sets . click apply for full job details