Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the choice for the military community and their families. Embrace a fulfilling career at USAA, where our core values - honesty, integrity, loyalty and service - define how we treat each other and our members. Be part of what truly makes us special and impactful. We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs. The Opportunity The Application Support Engineer serves as a Tier 2 (L2) technical support resource within the Association's Production Management organization. This role is responsible for monitoring, troubleshooting, incident resolution, service restoration, and operational support for critical business applications and services across the enterprise technology landscape. Working closely with the Availability Command Center (ACC), Tier 1 Operations, Application Engineering teams, Infrastructure teams, and external vendors, this position provides technical expertise for application incidents, operational issues, and service stability initiatives. The engineer investigates and resolves application performance issues, system alerts, batch processing failures, integration problems, middleware issues, and production incidents impacting business operations. We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position is based in San Antonio, TX. Relocation assistance is not available for this position. What You'll Do: Design, develop, test, and implement technical solutions that support business objectives. Write, maintain, and enhance code to deliver new features, system improvements, and ongoing product enhancements. Troubleshoot, and resolve technical issues and production incidents to ensure system reliability and performance. Analyze systems and processes to identify opportunities for improvement and drive operational efficiency. Define technical specifications, standards, and requirements that support scalable and sustainable applications Follow established Software Development Lifecycle (SDLC) practices, including requirements gathering, development, testing, deployment, and maintenance. Ensure risks associated with business activities are appropriately identified, assessed, monitored, and managed in accordance with organizational risk and compliance standards. What You Have: Bachelor's degree; OR 4 years of relevant education and/or experience. Basic Understanding of one or more of the following: Java, Swift, Objective-C, JavaScript, Kotlin, C++, HTML, CSS, SQL, Go, and Python, Mainframe technologies including COBOL, JCL, CICS, DB2, IMS, MQ, and z/OS.+ Experience with enterprise monitoring and observability tools such as Splunk, Dynatrace, Datadog, New Relic, Grafana, AppDynamics, Azure Monitor, or similar platforms. Ability to analyze logs, traces, metrics, and application performance data to identify service degradation and outage conditions. Familiarity with Kubernetes, OpenShift, Docker containers, and microservice-based applications. Understanding of API-driven architectures and integration technologies. Experience with ServiceNow, Jira, Confluence, or similar operational platforms. Understanding of Incident, Problem, Change, Event, and Knowledge Management processes. What Sets You Apart: 2+ years of experience supporting enterprise applications, infrastructure, cloud platforms, or production environments, including troubleshooting across multiple technology domains. Experience in an Enterprise Availability Command Center (ACC), Production Operations, Site Reliability Engineering (SRE), or comparable service restoration environment, with direct involvement in high-severity incident response and recovery activities. Strong analytical and problem-solving skills, with the ability to correlate monitoring, logging, and operational data to diagnose issues and restore critical business services. Working knowledge of observability, automation, service resiliency, SRE principles, and operational process improvement. Experience working within Incident Management processes and operational support procedures, with the ability to coordinate technical teams and communicate effectively during service disruptions. Experience supporting highly regulated industries such as financial services, insurance, or healthcare; ITIL Foundation certification and Azure or AWS certifications preferred. US military experience gained through military service or gained as a military spouse / domestic partner Compensation range: The salary range for this position is: $ 77,120.00 - $ 147,390.00 . USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.). Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location. Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors. The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job. Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals. For more details on our outstanding benefits, visit our benefits page on Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting. USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
09/24/2026
Full time
Why USAA? At USAA, our mission is to empower our members to achieve financial security through highly competitive products, exceptional service and trusted advice. We seek to be the choice for the military community and their families. Embrace a fulfilling career at USAA, where our core values - honesty, integrity, loyalty and service - define how we treat each other and our members. Be part of what truly makes us special and impactful. We are proud to support active-duty military spouses. USAA roles may offer remote or hybrid flexibility for active-duty military spouses consistent with applicable policy and business needs. The Opportunity The Application Support Engineer serves as a Tier 2 (L2) technical support resource within the Association's Production Management organization. This role is responsible for monitoring, troubleshooting, incident resolution, service restoration, and operational support for critical business applications and services across the enterprise technology landscape. Working closely with the Availability Command Center (ACC), Tier 1 Operations, Application Engineering teams, Infrastructure teams, and external vendors, this position provides technical expertise for application incidents, operational issues, and service stability initiatives. The engineer investigates and resolves application performance issues, system alerts, batch processing failures, integration problems, middleware issues, and production incidents impacting business operations. We offer a flexible work environment that requires an individual to be in the office 4 days per week. This position is based in San Antonio, TX. Relocation assistance is not available for this position. What You'll Do: Design, develop, test, and implement technical solutions that support business objectives. Write, maintain, and enhance code to deliver new features, system improvements, and ongoing product enhancements. Troubleshoot, and resolve technical issues and production incidents to ensure system reliability and performance. Analyze systems and processes to identify opportunities for improvement and drive operational efficiency. Define technical specifications, standards, and requirements that support scalable and sustainable applications Follow established Software Development Lifecycle (SDLC) practices, including requirements gathering, development, testing, deployment, and maintenance. Ensure risks associated with business activities are appropriately identified, assessed, monitored, and managed in accordance with organizational risk and compliance standards. What You Have: Bachelor's degree; OR 4 years of relevant education and/or experience. Basic Understanding of one or more of the following: Java, Swift, Objective-C, JavaScript, Kotlin, C++, HTML, CSS, SQL, Go, and Python, Mainframe technologies including COBOL, JCL, CICS, DB2, IMS, MQ, and z/OS.+ Experience with enterprise monitoring and observability tools such as Splunk, Dynatrace, Datadog, New Relic, Grafana, AppDynamics, Azure Monitor, or similar platforms. Ability to analyze logs, traces, metrics, and application performance data to identify service degradation and outage conditions. Familiarity with Kubernetes, OpenShift, Docker containers, and microservice-based applications. Understanding of API-driven architectures and integration technologies. Experience with ServiceNow, Jira, Confluence, or similar operational platforms. Understanding of Incident, Problem, Change, Event, and Knowledge Management processes. What Sets You Apart: 2+ years of experience supporting enterprise applications, infrastructure, cloud platforms, or production environments, including troubleshooting across multiple technology domains. Experience in an Enterprise Availability Command Center (ACC), Production Operations, Site Reliability Engineering (SRE), or comparable service restoration environment, with direct involvement in high-severity incident response and recovery activities. Strong analytical and problem-solving skills, with the ability to correlate monitoring, logging, and operational data to diagnose issues and restore critical business services. Working knowledge of observability, automation, service resiliency, SRE principles, and operational process improvement. Experience working within Incident Management processes and operational support procedures, with the ability to coordinate technical teams and communicate effectively during service disruptions. Experience supporting highly regulated industries such as financial services, insurance, or healthcare; ITIL Foundation certification and Azure or AWS certifications preferred. US military experience gained through military service or gained as a military spouse / domestic partner Compensation range: The salary range for this position is: $ 77,120.00 - $ 147,390.00 . USAA does not provide visa sponsorship for this role. Please do not apply for this role if at any time (now or in the future) you will need immigration support (i.e., H-1B, TN, STEM OPT Training Plans, etc.). Compensation: USAA has an effective process for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market data of the position. The actual salary for this role may vary by location. Employees may be eligible for pay incentives based on overall corporate and individual performance and at the discretion of the USAA Board of Directors. The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job. Benefits: At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals. For more details on our outstanding benefits, visit our benefits page on Applications for this position are accepted on an ongoing basis, this posting will remain open until the position is filled. Thus, interested candidates are encouraged to apply the same day they view this posting. USAA is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran.
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
09/24/2026
Full time
Job Description Job Description Description: Associate Network Security Engineer Cary, NC • Hybrid Our client is seeking an Associate Cybersecurity Engineer for a 12 month contract, with potential for permanent conversion, to support the Information Security organization. This role focuses on monitoring network security activities and operating and optimizing security infrastructure. The engineer will drive policy, rule, and architecture improvements to prevent and remediate incidents, perform security configuration changes, and collaborate with IT and business stakeholders on triage. The position emphasizes enterprise firewalls, SASE and ZTNA, identity and access management, Microsoft security tooling, and process development aligned to best practices and regulatory requirements. Rate : $42.00 - $48.00 per hour W2 Responsibilities: Monitor network security activities and maintain oversight of security infrastructure. Implement, monitor, and manage enterprise firewall solutions, including NGFW, to enforce network security policies. Operate and configure SASE capabilities including secure web gateways, ZTNA, and CASB. Execute security configuration changes and support incident prevention and remediation through policy, rule, and architecture optimization. Collaborate with IT and business stakeholders on security triage and operational support. Leverage Microsoft Security Suite such as Defender for Endpoint, Sentinel, and Entra/Azure AD across on premises and cloud environments. Develop and refine procedures, policies, and processes aligned with best practices and regulatory requirements. Recommend remediation measures to improve security posture and reduce risk. Communicate security concepts to cross functional teams and stakeholders. Perform other related duties as assigned. Experience Requirements: 3+ years in cloud or network security engineering, security operations, insider risk management, or security event management. Hands on experience with identity, firewall, cloud, and SIEM tools such as Microsoft Azure, Okta, Duo, Palo Alto, Fortinet, Zscaler, Windows Defender, OCI, and Sentinel. Ability to convey complex information risk and security issues in an actionable manner. Demonstrated judgment, urgency, ethical standards, regulatory awareness, customer service, and business integrity. Preferred proficiency with automation or scripting such as Ansible, Python, KQL, or PowerShell. Strong written and oral communication skills and the ability to work cross functionally with network, cloud, infrastructure, and application teams. Strong organizational skills with the ability to prioritize and deliver in a fast paced environment. Ability to accommodate approximately 5% travel. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team ( , ) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group's use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range.W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality.If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: When you work with Eliassen Group, all email communication will come from an address, never Gmail, Yahoo, etc. Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact . About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients' capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don't miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!
Tlingit Haida Tribal Business Corporation
Alexandria, Virginia
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Tlingit Haida Tribal Business Corporation
Arlington, Virginia
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Tlingit Haida Tribal Business Corporation
Washington, Washington DC
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Tlingit Haida Tribal Business Corporation
Bethesda, Maryland
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/24/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
09/24/2026
Full time
Job Description Job Description About Etched Etched is building hardware for frontier intelligence. We co-design chips, racks, software, and manufacturing to deliver best-in-class throughput and latency across both prefill and decode workloads. Our first products are heavily focused on inference . Backed by hundreds of millions from top-tier investors and staffed by leading engineers, Etched is redefining the infrastructure layer for the fastest growing industry in history. Job Summary Etched's infrastructure spans some of the most sensitive compute environments in the industry: bare-metal HPC clusters running proprietary ASIC workloads, hybrid on-prem/cloud deployments, and internal toolchains that house irreplaceable chip design IP. As we scale from early silicon to production, securing these environments is foundational - not an afterthought. As our first dedicated Network Security Engineer, you will own the design and implementation of Etched's network security posture end to end. You'll work alongside the infrastructure team to harden our physical and virtual networks, enforce least-privilege access to chip design environments, and build the detection and response capabilities that keep our most sensitive assets safe. This is a high-ownership role for someone who wants to shape security architecture at a company building the compute infrastructure for the next decade of AI - not maintain someone else's stack. Key Responsibilities Design and implement a zero-trust network architecture across on-prem datacenters, multiple office locations, and multi-cloud platforms, including secure remote access that eliminates VPN sprawl without sacrificing engineer usability and speed Define and enforce network segmentation policies that isolate sensitive ASIC development workflows from general infrastructure, customer access, validation labs, and manufacturing infrastructure Balancing prevention and detection, deploy, tune, and operate NDR, IDS/IPS, and next-generation firewalls across our physical and virtual network fabric; build automation to continuously assess and enforce firewall rules, ACLs, and routing policies - treating network security configuration as code Integrate and operate EDR/XDR, MDM/MAM, SASE, and CASB tooling in partnership with end-user and IT teams, enforcing unified DLP policies and device compliance posture across endpoint, cloud, and network control planes to eliminate data exfiltration risk Own our vulnerability management process for network-layer exposure: scanning, prioritization, and remediation tracking in partnership with infrastructure engineers Lead incident response for network-layer security events: detection, containment, root-cause analysis, and post-incident hardening Partner with legal, compliance, and leadership to support regulatory requirements and customer security reviews as they arise Architect and deploy network segmentation for our HPC clusters, isolating EDA tool traffic, ASIC simulation workloads, and CI pipelines from each other and from the corporate network Architect and deploy a ZTNA-based corporate network that eliminates VPN sprawl and ensures end-user devices maintain a consistent security posture and seamless access to sensitive development environments - whether engineers are on-site, remote, or traveling - replacing location-dependent trust with continuous identity and device health verification Design and implement a scalable NDR pipeline that ingests flow data across bare-metal switches and cloud VPCs, feeds a centralized SIEM, and generates actionable alerts with low false-positive rates Develop runbooks and automated playbooks for the highest-probability incident scenarios - credential compromise, lateral movement, and exfiltration from IP-sensitive environments Integrate EDR/XDR telemetry with SASE enforcement and CASB inline controls to build a unified DLP detection and response pipeline spanning endpoints, cloud SaaS, and the corporate network Partner with end-user and IT teams to roll out MDM/MAM policies that containerize sensitive IP on engineer devices and enforce compliance-based conditional access across managed and unmanaged environments You may be a good fit if you have (Must-have qualifications) Bring deep, broad networking expertise - from low-level packet analysis and firewall log forensics to BGP configuration, multi-cloud networking, and CASB/SASE integration across a diverse SaaS landscape Have hands-on experience with the Fortinet ecosystem - firewalls, FortiSASE, FortiAPs, and switches - and are comfortable with Arista switch platforms, including configuration, EOS automation, and integration into a broader security architecture Treat security as an engineering discipline: you write code and automation rather than relying on point-and-click tooling, version-control your configurations, and develop intent-driven network automation Have experience securing high-value compute environments - datacenters, HPC clusters, semiconductor design environments, or similar settings where the cost of a breach is extremely high Have deployed and integrated EDR/XDR, MDM/MAM, SASE, and CASB tooling, and understand how to stitch them together into a unified DLP and access control framework that spans endpoints, cloud, and the network Have built or operated ZTNA-based access models and understand how to enforce consistent security posture across on-site, remote, and traveling users without degrading the experience for engineers Are comfortable owning your domain with minimal oversight: you can independently scope a project, identify the right tooling, and drive it to completion Have strong Linux fundamentals and understand how OS-level networking (iptables/nftables, network namespaces, eBPF) interacts with physical and virtual network security controls Have built or operated network security monitoring at scale - you know the difference between a good alert and noise, and you can architect a detection pipeline that surfaces real signal Can communicate risk clearly to both technical peers and non-technical leadership, and can translate security requirements into actionable infrastructure changes Strong candidates may also have experience with (Nice-to-have qualifications) Experience with EDA environments or semiconductor IP security Familiarity with cloud-native network security controls on AWS, GCP, or Azure (security groups, VPC flow logs, cloud firewalls, CSPM) Background in or exposure to NIST, SOC 2, or ISO 27001 frameworks Experience with eBPF-based network observability and security tooling Benefits Medical, dental, and vision packages with generous premium coverage $500 per month credit for waiving medical benefits Housing subsidy of $2k per month for those living within walking distance of the office Relocation support for those moving to San Jose (Santana Row) Various wellness benefits covering fitness, mental health, and more Daily lunch and dinner in our office Unlimited compute budget subject to ROI justification How we're different Etched believes in the Bitter Lesson. We are the first inference-focused frontier AI system. Our addressable market is the entirety of inference, unlike many of our competitors. We are a fully in-person team in San Jose (Santana Row), and greatly value engineering skills. We do not have boundaries between engineering and research, and we expect all of our technical staff to contribute to both and work across disciplines as needed. Compensation Range: $175K - $275K
Georgia System Operations Corporation
Tucker, Georgia
Job Description Job Description Network Security EngineerEngineer Secure, Resilient Network Services That Support Mission-Critical OperationsGeorgia System Operations Corporation (GSOC) is seeking a Network Security Engineer to design, implement, secure, and operate corporate network services and cybersecurity tools that enable reliable, protected business operations.This hands-on role combines enterprise network engineering and cybersecurity expertise across datacenter, campus, remote-site, internet-edge, and approved cloud environments. The Network Security Engineer helps safeguard availability, performance, secure access, and security visibility while advancing resilient, supportable, and automated network and security services.This opportunity is ideal for an experienced network and security professional who enjoys solving complex technical problems, strengthening controls, supporting incident response, mentoring peers, and collaborating across infrastructure, cybersecurity, application, service desk, and vendor teams. This is an onsite position and it is not eligible for visa sponsorshipWhat You'll DoAs a Network Security Engineer, you will engineer and support the network and network-focused security services that connect and protect enterprise users, systems, and sites.You will:Design, deploy, and support datacenter and campus switching, routing, VLANs, VRFs, high availability, capacity planning, and network segmentation.Administer next-generation firewalls, security zones, NAT, threat-prevention services, firewall policy lifecycle, and least-privilege access controls.Engineer WAN, internet-edge, remote-site, remote-access VPN, and site-to-site VPN connectivity, including integrations with identity, MFA, and device-trust services.Design and support corporate and guest wireless, controllers, access points, RF performance, 802.1X, network access control, device profiling, and secure authentication.Configure load balancers, virtual servers, pools, health monitors, persistence, TLS termination, and high-availability services.Manage the network-facing certificate lifecycle and PKI integrations.Engineer and operate secure web and DNS controls, network detection and response, security logging, SIEM integrations, and security-control health monitoring.Partner with the Security Operations Center on alert tuning, investigations, evidence gathering, and operational security use cases.Support secure DNS, DHCP, and IP address management and maintain telemetry, flow data, logging, alerting, packet analysis, and service dashboards.Maintain secure configuration baselines, backups, firmware and software lifecycle, and remediation of network-device and security-tool vulnerabilities.Automate repeatable work using APIs, scripting, and infrastructure-as-code practices.Develop and test network and security-platform recovery and failover capabilities.Prepare change and rollback plans and provide incident escalation, containment support, root-cause analysis, and vendor coordination. This role also:Works independently within established standards and change processes.Provides technical leadership for projects and mentors peers.Participates in technology evaluations, proof-of-concepts, cross-functional initiatives, backup support, and knowledge transfer. What You BringBachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related field. Equivalent combination of education, training, and directly related work experience may be considered.Ideally 5+ years of progressive experience supporting enterprise network and network-security infrastructure, including switching, routing, firewall administration, VPN, wireless, and troubleshooting.Strong knowledge of enterprise LAN/WAN, datacenter switching, routing, firewalls, VPN, wireless, NAC, load balancing, PKI and certificates, DNS, DHCP, IPAM, and secure configuration management.Hands-on experience operating cybersecurity tooling such as secure web and DNS services, network detection and response, vulnerability management, SIEM and logging integrations, and security monitoring.Experience with network and security automation using Python, PowerShell, Ansible, Terraform, APIs, or comparable tools.Working knowledge of NIST CSF, CIS Controls, incident-response practices, and applicable regulatory or industry requirements, including NERC CIP where relevant to the IT environment.Strong analytical, troubleshooting, documentation, communication, collaboration, and customer-service skills. Preferred QualificationsEnterprise Network EngineeringExperience engineering highly available datacenter, campus, WAN, internet-edge, remote-site, wireless, and VPN services.Experience with segmentation, least-privilege access, identity and MFA integrations, device trust, and network access control.Experience with load balancing, TLS termination, application delivery, certificate lifecycle management, and PKI integrations.Network Security & DetectionExperience operating next-generation firewalls, threat-prevention services, secure web or DNS controls, network detection and response, and vulnerability-management processes.Experience integrating network-security telemetry with SIEM, logging, alerting, dashboards, and incident-response workflows.Experience partnering with a SOC on investigation, tuning, containment, evidence, or root-cause activities.Automation, Resilience & OperationsExperience automating network or security operations through scripting, APIs, Ansible, Terraform, or infrastructure as code.Experience developing recovery, failover, configuration-backup, firmware-lifecycle, and vulnerability-remediation practices.Experience preparing changes, rollback plans, technical documentation, performance measures, and vendor-supported resolutions.CertificationsRelevant credentials such as CCNA, CCNP, ACP, PCNSE or equivalent firewall-vendor certification, CWNA, Security+, CISSP, AZ-700, or similar certifications are preferred. Advantages of Working at GSOCWorking at GSOC means more than just a job it's an opportunity to contribute to work that truly matters. Mission-Driven ImpactYour work supports secure, reliable corporate network services and cybersecurity capabilities used across GSOC's enterprise environment. Network Engineering & Cybersecurity DepthApply both network engineering and hands-on security expertise across switching, routing, wireless, firewalls, VPN, application delivery, monitoring, automation, and incident support. Technical Leadership & Continuous ImprovementLead technical projects, mentor peers, evaluate new technologies, automate repeatable work, and strengthen resilience, visibility, and operational supportability. Strong Values and Professional StandardsWork in an environment grounded in accountability, collaboration, integrity, security, compliance, and continuous improvement. Work Environment & BenefitsGSOC offers a professional, collaborative work environment with competitive compensation, comprehensive benefits, and a commitment to creating a respectful and inclusive workplace.Participation in an on-call rotation, emergency support, and scheduled maintenance outside normal business hours is required. Why Join GSOCAt GSOC, you will help engineer the network and security services that enable dependable business operations, secure access, security visibility, and resilient enterprise technology.You'll collaborate across infrastructure, cybersecurity, applications, service desk, and vendor teams while expanding your technical leadership and automation capabilities. Apply TodayIf you're ready to combine enterprise network engineering and cybersecurity expertise in a hands-on role supporting reliable, protected operations, we encourage you to apply. GSOC does not accept unsolicited resumes or candidate submissions from staffing agencies, search firms, or third-party recruiters. Any unsolicited resumes submitted without a valid, executed agreement will become the property of GSOC, and no placement fee will be paid. Job Posted by ApplicantPro
09/24/2026
Full time
Job Description Job Description Network Security EngineerEngineer Secure, Resilient Network Services That Support Mission-Critical OperationsGeorgia System Operations Corporation (GSOC) is seeking a Network Security Engineer to design, implement, secure, and operate corporate network services and cybersecurity tools that enable reliable, protected business operations.This hands-on role combines enterprise network engineering and cybersecurity expertise across datacenter, campus, remote-site, internet-edge, and approved cloud environments. The Network Security Engineer helps safeguard availability, performance, secure access, and security visibility while advancing resilient, supportable, and automated network and security services.This opportunity is ideal for an experienced network and security professional who enjoys solving complex technical problems, strengthening controls, supporting incident response, mentoring peers, and collaborating across infrastructure, cybersecurity, application, service desk, and vendor teams. This is an onsite position and it is not eligible for visa sponsorshipWhat You'll DoAs a Network Security Engineer, you will engineer and support the network and network-focused security services that connect and protect enterprise users, systems, and sites.You will:Design, deploy, and support datacenter and campus switching, routing, VLANs, VRFs, high availability, capacity planning, and network segmentation.Administer next-generation firewalls, security zones, NAT, threat-prevention services, firewall policy lifecycle, and least-privilege access controls.Engineer WAN, internet-edge, remote-site, remote-access VPN, and site-to-site VPN connectivity, including integrations with identity, MFA, and device-trust services.Design and support corporate and guest wireless, controllers, access points, RF performance, 802.1X, network access control, device profiling, and secure authentication.Configure load balancers, virtual servers, pools, health monitors, persistence, TLS termination, and high-availability services.Manage the network-facing certificate lifecycle and PKI integrations.Engineer and operate secure web and DNS controls, network detection and response, security logging, SIEM integrations, and security-control health monitoring.Partner with the Security Operations Center on alert tuning, investigations, evidence gathering, and operational security use cases.Support secure DNS, DHCP, and IP address management and maintain telemetry, flow data, logging, alerting, packet analysis, and service dashboards.Maintain secure configuration baselines, backups, firmware and software lifecycle, and remediation of network-device and security-tool vulnerabilities.Automate repeatable work using APIs, scripting, and infrastructure-as-code practices.Develop and test network and security-platform recovery and failover capabilities.Prepare change and rollback plans and provide incident escalation, containment support, root-cause analysis, and vendor coordination. This role also:Works independently within established standards and change processes.Provides technical leadership for projects and mentors peers.Participates in technology evaluations, proof-of-concepts, cross-functional initiatives, backup support, and knowledge transfer. What You BringBachelor's degree in Information Technology, Computer Science, Engineering, Cybersecurity, or a related field. Equivalent combination of education, training, and directly related work experience may be considered.Ideally 5+ years of progressive experience supporting enterprise network and network-security infrastructure, including switching, routing, firewall administration, VPN, wireless, and troubleshooting.Strong knowledge of enterprise LAN/WAN, datacenter switching, routing, firewalls, VPN, wireless, NAC, load balancing, PKI and certificates, DNS, DHCP, IPAM, and secure configuration management.Hands-on experience operating cybersecurity tooling such as secure web and DNS services, network detection and response, vulnerability management, SIEM and logging integrations, and security monitoring.Experience with network and security automation using Python, PowerShell, Ansible, Terraform, APIs, or comparable tools.Working knowledge of NIST CSF, CIS Controls, incident-response practices, and applicable regulatory or industry requirements, including NERC CIP where relevant to the IT environment.Strong analytical, troubleshooting, documentation, communication, collaboration, and customer-service skills. Preferred QualificationsEnterprise Network EngineeringExperience engineering highly available datacenter, campus, WAN, internet-edge, remote-site, wireless, and VPN services.Experience with segmentation, least-privilege access, identity and MFA integrations, device trust, and network access control.Experience with load balancing, TLS termination, application delivery, certificate lifecycle management, and PKI integrations.Network Security & DetectionExperience operating next-generation firewalls, threat-prevention services, secure web or DNS controls, network detection and response, and vulnerability-management processes.Experience integrating network-security telemetry with SIEM, logging, alerting, dashboards, and incident-response workflows.Experience partnering with a SOC on investigation, tuning, containment, evidence, or root-cause activities.Automation, Resilience & OperationsExperience automating network or security operations through scripting, APIs, Ansible, Terraform, or infrastructure as code.Experience developing recovery, failover, configuration-backup, firmware-lifecycle, and vulnerability-remediation practices.Experience preparing changes, rollback plans, technical documentation, performance measures, and vendor-supported resolutions.CertificationsRelevant credentials such as CCNA, CCNP, ACP, PCNSE or equivalent firewall-vendor certification, CWNA, Security+, CISSP, AZ-700, or similar certifications are preferred. Advantages of Working at GSOCWorking at GSOC means more than just a job it's an opportunity to contribute to work that truly matters. Mission-Driven ImpactYour work supports secure, reliable corporate network services and cybersecurity capabilities used across GSOC's enterprise environment. Network Engineering & Cybersecurity DepthApply both network engineering and hands-on security expertise across switching, routing, wireless, firewalls, VPN, application delivery, monitoring, automation, and incident support. Technical Leadership & Continuous ImprovementLead technical projects, mentor peers, evaluate new technologies, automate repeatable work, and strengthen resilience, visibility, and operational supportability. Strong Values and Professional StandardsWork in an environment grounded in accountability, collaboration, integrity, security, compliance, and continuous improvement. Work Environment & BenefitsGSOC offers a professional, collaborative work environment with competitive compensation, comprehensive benefits, and a commitment to creating a respectful and inclusive workplace.Participation in an on-call rotation, emergency support, and scheduled maintenance outside normal business hours is required. Why Join GSOCAt GSOC, you will help engineer the network and security services that enable dependable business operations, secure access, security visibility, and resilient enterprise technology.You'll collaborate across infrastructure, cybersecurity, applications, service desk, and vendor teams while expanding your technical leadership and automation capabilities. Apply TodayIf you're ready to combine enterprise network engineering and cybersecurity expertise in a hands-on role supporting reliable, protected operations, we encourage you to apply. GSOC does not accept unsolicited resumes or candidate submissions from staffing agencies, search firms, or third-party recruiters. Any unsolicited resumes submitted without a valid, executed agreement will become the property of GSOC, and no placement fee will be paid. Job Posted by ApplicantPro
Tlingit Haida Tribal Business Corporation
Falls Church, Virginia
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
09/24/2026
Full time
Job Description Job Description About Zedcor Inc. Zedcor Inc. (TSX-V:ZDC) is disrupting the traditional physical security industry through its proprietary MobileyeZ security towers by providing turnkey and customized mobile surveillance and live monitoring solutions to blue-chip customers across North America. The Company continues to expand its established platform of over 1,200 MobileyeZ towers in Canada and the United States, with emphasis on industry leading service levels, data-supported efficiency outcomes, and continued innovation. Zedcor services the Canadian market through equipment and service centers currently located in British Columbia, Alberta, Manitoba, and Ontario. The Company continues to advance its U.S. expansion which now has the capacity to service markets throughout the Midwest with locations throughout Texas Colorado, Arizona, Nevada and Florida. For more information, check out . Position Overview The Senior Network / Firewall Engineer to design, build, secure, and maintain a large-scale hybrid network environment. This is not an entry-level role. The successful candidate must be able to solve complex technical problems under pressure and operate with cybersecurity, uptime, encryption, monitoring, and compliance in mind. The environment includes Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint routers, switches, Wi-Fi, F5 BIG-IP, Azure WAF, Azure Application Gateway, Azure Front Door, centralized logging, centralized monitoring, and internal PKI. Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Qualifications & Requirements Key Responsibilities Design, build, maintain, and troubleshoot IPsec and SSL VPN networks. Manage and support a Cradlepoint environment of 20,000+ devices. Manage Sophos firewalls or become proficient with Sophos within the first 30 days if experienced with another major firewall platform. Ensure DNS and DHCP are centrally managed, monitored, logged, secured, and not hosted directly on firewalls. Patch, monitor, log, audit, and secure network infrastructure. Ensure network links, management access, VPNs, and sensitive data flows are encrypted. Document network designs, firewall rules, routing policies, VPN configurations, standards, and runbooks. Support incident response, change management, vulnerability remediation, disaster recovery, SOC 2, FedRAMP, and StateRAMP readiness. Use Zedcor's internal PKI solution for device identity, certificates, authentication, encryption, and secure management. Maintain centralized logging, centralized audit logging, centralized authentication, centralized monitoring, and alerting. Ensure firewalls are used as security enforcement points, not as core infrastructure service providers. Support F5 BIG-IP, Azure WAF, Azure Application Gateway, and Azure Front Door. Configure and troubleshoot dynamic routing, including internal BGP. Support Azure VPN Gateway, Azure Networking, Sophos firewalls, Cradlepoint, switches, Wi-Fi, WAF, and load-balancing platforms. Minimum Qualifications 5+ years of hands-on network engineering, firewall engineering, or network security engineering experience. Strong Azure Networking experience, including Azure VPN Gateway, virtual networks, routing, NSGs, private connectivity, and hybrid networking. Strong knowledge of IPsec VPNs, SSL VPNs, routing, switching, segmentation, firewall policies, NAT, high availability, and secure remote access. Solid understanding of DNS and DHCP design, troubleshooting, and security best practices. Strong understanding of encryption, PKI, certificate-based authentication, secure management access, and network security best practices. Ability to work full-time on-site in Houston, Texas. Ability to troubleshoot complex production issues under pressure. Understanding of why DNS and DHCP should not be hosted directly on firewalls, including separation of duties, availability, scalability, logging, auditability, and change-control risks. Hands-on experience with BGP and dynamic routing. Strong experience with Sophos or another major enterprise firewall platform such as Fortinet, Palo Alto, Cisco, or Check Point. Local Houston-area candidate able to work in office 5 days per week. Preferred Qualifications Sophos firewall experience. F5 BIG-IP, WAF, load-balancing, Azure WAF, Azure Application Gateway, or Azure Front Door experience. Enterprise PKI and certificate lifecycle experience. Certifications such as CCNP, CCNA, NSE, PCNSE, Sophos, Azure Network Engineer Associate, Security+, CISSP, or equivalent practical experience. Azure Monitor, Microsoft Sentinel, Defender for Cloud, Intune, or similar monitoring/security tooling experience. Cradlepoint or large-scale cellular router experience. Why Join Zedcor? At Zedcor, you won't just maintain systems, you'll help build and shape the future of security technology. We provide the tools, mentorship, and the environment to help you thrive and grow in your career. If you're looking to take your skills to the next level, Zedcor offers a dynamic and rewarding opportunity. Zedcor Inc. is an Equal Opportunity Employer and maintains the policy of recruiting and retaining the best-qualified personnel who demonstrate the ability to perform competently and work well with others. It is the policy of Zedcor to provide equal employment opportunity regardless of race (including traits historically or culturally associated with race, such as hair texture and protective hairstyles), religion (including religious dress and religious grooming), color, age (40 and over), genetic information, disability (mental and physical), medical condition (as defined under state law), national origin (including language use restrictions and possession of a driver's license issued under section 12801.9 of the California Vehicle Code), ancestry, sex (including gender, gender identity, gender expression), sexual orientation, marital status, familial status, parental status, domestic partner status, citizenship status, pregnancy (including perceived pregnancy, childbirth, lactation, or pregnancy-related conditions), military caregiver status, military status, veteran status, or any other status protected by federal, state, or local law. This policy of nondiscrimination is applied to all aspects of the employment relationship. The Company complies with the Americans with Disabilities Act (ADA) and applicable state and local laws in ensuring equal opportunity and employment for qualified persons with disabilities. We also consider qualified applicants with criminal histories, consistent with legal requirements. The following link provides more information regarding the Federal laws prohibiting discrimination in employment: EEO is the Law - Notice of Applicant Rights Under the Law.
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
09/24/2026
Full time
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
Tlingit Haida Tribal Business Corporation
Silver Spring, Maryland
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
09/24/2026
Full time
Job Description Job Description At Tlingit Haida Tribal Business Corporation (THTBC), your work goes beyond the job description-it becomes part of a purpose-driven legacy. Our continuous commitment to growth directly contributes to the strength, resilience, and future of the communities we serve. Every milestone we achieve helps fund programs, expand services, and create lasting value for the Tribe, making each success a shared one. For more than 35 years THTBC and its subsidiaries have delivered mission-critical services to federal clients globally. From logistics and information technology to cybersecurity and facilities operations, we are united by a single purpose: to generate meaningful economic opportunity and sustainable growth for the Tlingit & Haida Tribes of Alaska. Together We Grow - One Mission, One Team - With a Commitment to Serve Subsidiary: T&H Services Job Title: FRCS Network Security Engineer Work Location: Washington Navy Yard, Washington D.C. Labor Category: Full-Time Exempt Travel Requirement: Up to 25% Annual Salary: $130,000 - $140,000 About the Role The FRCS Network Security Engineer provides technical support for Government-owned Facility-Related Control Systems (FRCS), Operational Technology (OT), and associated IT infrastructure. The position is responsible for maintaining the security, reliability, configuration, and operation of networked, isolated, and standalone control systems. What You'll Be Doing Establish and maintain the FRCS Cybersecurity Program in accordance with UFC 4-010-06, applicable DoD requirements, and Government cybersecurity standards. Manage, maintain, program, monitor, troubleshoot, repair, and support Government-owned FRCS, OT, and associated IT systems, including BCS, DDC, EMCS, UCS, SCADA, plant controls, advanced metering, and related platforms. Troubleshoot, repair, replace, maintain, and calibrate control system equipment and components, including pneumatic devices, control cabling, wiring, relays, transformers, switches, fuses, and related equipment. Research, coordinate, test, and implement approved software, firmware, hardware, programming, and configuration changes in accordance with Government configuration management requirements. Implement cybersecurity requirements, conduct vulnerability assessments, support remediation, and perform activities necessary to maintain system accreditation and operational readiness. Monitor system logs, network traffic, alarms, events, and other security data; immediately report suspected access violations, cybersecurity events, or network intrusions to appropriate Government personnel. Configure and maintain cybersecurity technologies, including antivirus, HIPS, IDS/IPS, SIEM, and related security tools, and develop detection signatures using YARA, Snort, Suricata, or similar technologies. Identify and document FRCS operating in override, bypass, manual mode, or other conditions that prevent normal automatic operation and provide required daily status reporting. Perform root-cause analysis for repetitive or critical FRCS failures and document findings and recommended corrective actions. Support applicable control systems, including Automatic Transfer of Standby Power Programs (ATSPP), Master Load-Shed Controls (MLSC), Automated Demand Response (ADR), Fire Alarm Systems (FAS), and Mass Notification Systems (MNS). Coordinate with Government personnel, vendors, OEMs, and contractors on system integration, testing, certification, maintenance, repairs, upgrades, and operational validation. Maintain FRCS inventory, asset accountability, system configuration, and required technical documentation. What We're Looking For Bachelor's degree in Computer Science, Information Systems, or a related field, or equivalent combination of education and relevant experience. Minimum of four (4) years of relevant experience in network engineering, cybersecurity, control systems integration, or a related field. Experience with FRCS, OT, and IT environments, including BCS, DDC, EMCS, UCS, SCADA, or similar control systems. Working knowledge of TCP/IP, network protocols, traffic analysis, system administration, network security, and defense-in-depth principles. Experience with vulnerability management, IDS/IPS, SIEM, network or host-based forensics, and cybersecurity incident response. Experience with Windows and Unix/Linux environments and virtualization technologies such as VMware. ISA Certified Control Systems Technician (CCST) certification and applicable OEM control system certification, as required by the contract. Must possess a DoD 8570/8140-compliant IAT Level II certification, such as Security+ CE or an approved equivalent. Advanced cybersecurity certification such as CISSP, CASP+, GIAC/GCIA/GCIH, or applicable SIEM certification preferred. Must maintain eligibility and authorization to access the Government worksite. Must possess and maintain a valid state driver's license and a safe driving record, in accordance with company policy, to operate vehicles or equipment as required for the position. Physical Demands & Work Environment: Ability to sit or stand for extended periods and regularly work at a computer or technical workstation. Ability to lift and carry up to 50 pounds and perform occasional bending, stooping, reaching, pushing, and pulling associated with equipment installation and maintenance. Must be able to work on-call, alternate, or extended schedules when necessary to meet mission requirements, including weekends and holidays. Work may be performed indoors or outdoors and may require access to mechanical spaces, confined spaces, elevated areas, or other operational environments while using appropriate PPE. US Pay Range $130,000-$140,000 USD Why Us? At Tlingit Haida Tribal Business Corporation (THTBC), our work goes beyond delivering exceptional services-we are driven by a mission to create meaningful impact. When you join our team, you become part of an organization that values purpose, performance, and people. We offer the opportunity to work in dynamic, fast-paced environments where your contributions directly impact mission success. Our teams are built on collaboration, accountability, and a commitment to excellence, ensuring you are supported while being challenged to grow. Join us and be part of a team where your work matters. Benefits We offer a comprehensive and flexible benefits package designed to support your health, well-being, and financial security. Benefits include: Medical, Dental, and Vision coverage TRICARE Supplemental Critical Illness insurance Company-Paid Life and Short-Term Disability insurance Optional Long-Term Disability Paid Leave 401(k) Retirement Plan Identity Theft Protection Employee Discounts Wellness Seminars For union represented positions, benefits and leave are provided in accordance with the applicable Collective Bargaining Agreement. Pre-Employment Screening: All candidates must successfully complete pre-employment screening, which may include a criminal background check, motor vehicle record review, and 5-panel drug screening, in accordance with company policy and applicable laws. Equal Employment Opportunity: We are proud to be an equal opportunity employer and are committed to full compliance with all applicable federal, state, and local employment laws. We consider all qualified applicants for employment without regard to race, color, religion, creed, national origin, sex, gender identity or expression, age, marital status, sexual orientation, veteran status, disability, pregnancy, parental status, or any other status protected by applicable law. Reasonable Accommodation: If you have a disability or medical condition and require a reasonable accommodation at any stage of the hiring process, please notify the designated recruiter so we can provide appropriate assistance.
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/24/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
09/24/2026
Full time
Job Description Job Description Job Title: Network Security Engineer Department: Information Technology Location: Rochester, NY Classification: Exempt Reports To: Director of Information Technology Please note: Candidates must be authorized to work in the United States and able to work onsite in the Rochester, NY office. Sponsorship is not available for this position. Company Overview: Woods Oviatt Gilman, LLP is a leading and reputable full-service law firm dedicated to providing exceptional legal services to our clients. With a team of highly skilled and experienced attorneys, we strive to deliver comprehensive and effective solutions to meet the diverse needs of our clients. Our headquarters is in Rochester, NY with additional offices in Albany and Buffalo, NY. We foster a collaborative and inclusive work environment where every team member is valued and respected. We encourage open communication, teamwork, and professional growth. Our firm promotes a healthy work-life balance and supports the well-being of our employees. Position Summary: The Network Security Engineer is a hands-on technical role responsible for implementing, configuring, and maintaining the firm's security controls across a hybrid environment, including FortiGate firewalls, endpoint protection, cloud email and Microsoft 365, Intune-managed devices, and a co-managed monitoring and detection service. The Engineer works under the direction of the Director of Information Technology, who sets security policy and priorities for the department, and provides the technical assessment, recommendations, and documentation that support those decisions. Because the firm safeguards confidential and privileged client information, this position calls for strong technical skill, sound judgment, discretion, and clear communication with both the IT team and firm personnel. Duties and Responsibilities: Network and Perimeter Security Administer, tune, and monitor FortiGate firewalls, including security policies, VPN configuration, intrusion prevention, web and content filtering, and logging Implement and maintain network segmentation, secure remote access, and wireless security across firm locations, in line with the department's standards Maintain secure connectivity for remote and hybrid users, including VPN and conditional access Conduct scheduled reviews of firewall rules and network configurations, recommend changes to the Director of Information Technology, and maintain accurate network security documentation Endpoint, Identity, and Email Security Administer the firm's endpoint protection platforms, including CrowdStrike and Microsoft endpoint protection, covering policy configuration, detection review, containment actions, and agent coverage Configure and maintain device compliance, configuration, and application deployment through Microsoft Intune in a hybrid environment, including full-disk encryption and recovery key handling Configure and maintain identity and access controls across Microsoft Entra ID and on-premises Active Directory, including multifactor authentication, conditional access, and privileged account settings, and perform periodic access reviews Configure and maintain security settings for cloud email and collaboration, including mail flow and filtering rules, phishing and malware defenses, email authentication records, and Microsoft 365 security configuration Perform vulnerability and patch management across servers, endpoints, and network devices, including scanning, prioritizing findings, tracking remediation, and reporting status to the Director of Information Technology Monitoring, Detection, and Incident Response Serve as the day-to-day technical contact for the firm's managed monitoring service, triaging alerts, validating findings, and carrying issues through to resolution Investigate security events and perform containment, eradication, and recovery steps in accordance with the firm's incident response procedures, escalating promptly to the Director of Information Technology Contribute to the development, maintenance, and testing of the firm's incident response plan, including participation in tabletop exercises Verify that backup, recovery, and business continuity controls are functioning and tested, and support the department's disaster recovery planning Security Program Support, Privacy, and Compliance Provide technical evaluation and recommendations to support the department's selection and adoption of a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001 Implement and maintain the technical controls that support the framework, and assist in assessing and reporting the firm's posture against it Assist the Director of Information Technology in drafting and maintaining information security policies, standards, and procedures, and implement the technical measures that carry them out Maintain security documentation, control evidence, and a working risk log, and recommend remediation priorities to the Director of Information Technology Support compliance with applicable privacy and data protection obligations, including the New York SHIELD Act and other state privacy requirements, and requirements applicable to regulated client data such as protected health information Prepare technical responses and supporting documentation for client security requirements, including outside counsel guidelines, security questionnaires, and client and third-party audits, and complete remediation items assigned by the Director of Information Technology Support obligations arising from clients in regulated industries, including financial services requirements such as NYDFS Part 500 as applied to the firm through client agreements Perform technical security reviews of vendors, applications, and services under consideration, and provide findings and recommendations to the Director of Information Technology Assist with independent assessments, including penetration testing and external audits, and complete assigned remediation work Awareness and Collaboration Administer the firm's security awareness program, including training delivery, phishing simulations, and user communication developed with the Director of Information Technology Partner with the IT team on secure configuration, change management, and project work, and provide technical guidance to service desk staff on security escalations Report on control status, vulnerabilities, incidents, and open remediation items to the Director of Information Technology Maintain current knowledge of emerging threats, vulnerabilities, and security technologies relevant to the legal industry, and share findings with the department Technical Skills: Required Hands-on administration of FortiGate firewalls, including policy management, VPN, intrusion prevention, and content filtering Endpoint detection and response administration, ideally CrowdStrike Falcon, and familiarity with Microsoft endpoint protection Microsoft 365 security administration, including cloud email protection, mail flow and filtering, phishing defense, and email authentication using SPF, DKIM, and DMARC Identity and access administration across Microsoft Entra ID and on-premises Active Directory in a hybrid configuration, including multifactor authentication and conditional access Microsoft Intune administration, including device compliance and configuration, application deployment, and device encryption in a hybrid environment Solid networking fundamentals, including TCP/IP, routing and switching, VLANs, DNS, DHCP, segmentation, and wireless security Vulnerability management and patch management practice, including scanning, prioritization, and remediation tracking Security monitoring and log analysis, and experience working with a managed detection and response or co-managed SOC provider Working familiarity with a recognized security framework such as the NIST Cybersecurity Framework, CIS Controls, or ISO 27001, and experience implementing controls in support of one Familiarity with privacy and data protection requirements, including state breach notification obligations and handling of regulated data Ability to produce clear technical documentation, control evidence, risk write-ups, and status reporting for both technical and non-technical readers Preferred Prior experience in a law firm or other professional services environment, including familiarity with outside counsel guidelines and client security audits Experience preparing responses to client security questionnaires and third-party risk assessments Azure or other cloud security administration PowerShell or comparable scripting for automation and reporting Experience with data loss prevention, email encryption, or information rights management Experience with security awareness platforms and phishing simulation tools Familiarity with SD-WAN, zero trust, or secure access service edge architectures Relevant certifications such as Fortinet NSE, CompTIA Security+, GIAC credentials, Microsoft SC-200 or SC-300, CISSP, or CISM Qualifications and Competencies: Strong analytical and problem-solving skills, with sound technical judgment in assessing and prioritizing risk . click apply for full job details
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/24/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $165,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
Job Description Job Description Company Overview: Arctiq is a global, intelligence-driven technology services company delivering professional and managed services across Hybrid Cloud Infrastructure, Networking & Connected Experiences, Cybersecurity, Data & AI, Autonomous Operations & Intelligence, and Enterprise Service Management. We help organizations operate, secure, and modernize complex environments by unifying infrastructure, networking, data, security, automation, and observability under a single, integrated operating model. Our work focuses on helping customers reduce operational friction, improve resilience, and make better, faster decisions as their environments evolve. Arctiq builds on decades of industry expertise and a customer-centric ethos to deliver exceptional value to clients across diverse industries. This is a 3-month contract-to-hire position with one of Arctiq's clients. It is on-site in Alpharetta, GA. Position Overview: We are seeking a highly skilled Network Security Engineer to support and manage global physical security and infrastructure operations. This role is responsible for deploying, maintaining, and supporting enterprise security systems, access control platforms, surveillance technologies, and supporting infrastructure across a distributed global environment. The ideal candidate will have extensive hands-on experience with cloud-based security platforms, smart-hands support, access control systems, video surveillance solutions, and infrastructure hardware. This position is security-focused, with networking knowledge serving as a supporting competency. This is an onsite role (5 days/week) with participation in an on-call support rotation required, supporting global operations across multiple time zones (8am-5pm core hours). Occasional travel to support installations and operational initiatives may be required. Responsibilities: Physical Security Operations Administer and support global physical security systems and operations Deploy, configure, and maintain enterprise access control platforms including Verkada, Avigilon, and Openpath Manage and troubleshoot camera systems, access control hardware, and monitoring solutions Configure and support wired access control panels and associated infrastructure Monitor security events and ensure operational health of physical security platforms globally Perform firmware updates, patching, and lifecycle management of security devices Global Infrastructure & Security Operations Monitor the health, availability, and performance of global physical security and infrastructure systems Proactively monitor enterprise security platforms, servers, storage systems, network connectivity, and associated cloud services Investigate and resolve alerts, outages, and performance degradation across global environments Perform firmware upgrades, software updates, and security patching for cameras, access control systems, servers, and supporting infrastructure Maintain operational dashboards and monitoring tools to ensure continuous visibility of security and infrastructure assets worldwide Coordinate incident response activities related to security systems, storage platforms, server infrastructure, and connectivity disruptions Infrastructure & Smart Hands Support Provide smart-hands support for servers, network equipment, access control systems, surveillance devices, PCs/desktop hardware, and infrastructure management tools Deploy new hardware and perform rack-and-stack activities Configure, install, and commission security and infrastructure equipment using standardized deployment procedures Coordinate hardware replacements, upgrades, and equipment refresh activities Support remote sites and assist local teams with physical installations and troubleshooting Security Technology Administration Manage cloud-based security platforms and associated integrations Support hardware and software components of security ecosystems Ensure security systems maintain operational availability and compliance requirements Develop and maintain documentation, standard operating procedures, and asset inventories Incident Response & Support Participate in an on-call rotation providing after-hours support Respond to outages involving security systems, camera platforms, access control services, and connectivity-related incidents Troubleshoot loss-of-connectivity events and coordinate restoration efforts Escalate and coordinate with vendors and internal infrastructure teams as required Qualifications: Required: 8+ years of experience in physical security technology, infrastructure operations, or network/security engineering Hands-on experience supporting Verkada, Avigilon, Openpath, enterprise camera systems, and access control platforms Experience deploying and maintaining cloud-based security solutions Strong troubleshooting skills across hardware, software, and connectivity issues Experience with cabling, wiring, access panels, surveillance equipment, and supporting infrastructure Understanding of networking fundamentals including TCP/IP, switching, routing, VLANs, and remote connectivity Experience supporting servers, storage systems, and enterprise infrastructure environments Ability to travel occasionally to support installations and operational initiatives Preferred: Experience supporting global security operations centers (SOC) or enterprise security programs Familiarity with enterprise monitoring and infrastructure management tools Experience managing firmware, software upgrades, and device lifecycle planning Security industry certifications or vendor certifications related to access control or video surveillance systems Knowledge of physical security best practices and operational risk management Arctiq is an equal opportunity employer. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know. We celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply. We thank you for your interest in joining the Arctiq team! While we welcome all applicants, only those who are selected for an interview will be contacted.
09/24/2026
Full time
Job Description Job Description Company Overview: Arctiq is a global, intelligence-driven technology services company delivering professional and managed services across Hybrid Cloud Infrastructure, Networking & Connected Experiences, Cybersecurity, Data & AI, Autonomous Operations & Intelligence, and Enterprise Service Management. We help organizations operate, secure, and modernize complex environments by unifying infrastructure, networking, data, security, automation, and observability under a single, integrated operating model. Our work focuses on helping customers reduce operational friction, improve resilience, and make better, faster decisions as their environments evolve. Arctiq builds on decades of industry expertise and a customer-centric ethos to deliver exceptional value to clients across diverse industries. This is a 3-month contract-to-hire position with one of Arctiq's clients. It is on-site in Alpharetta, GA. Position Overview: We are seeking a highly skilled Network Security Engineer to support and manage global physical security and infrastructure operations. This role is responsible for deploying, maintaining, and supporting enterprise security systems, access control platforms, surveillance technologies, and supporting infrastructure across a distributed global environment. The ideal candidate will have extensive hands-on experience with cloud-based security platforms, smart-hands support, access control systems, video surveillance solutions, and infrastructure hardware. This position is security-focused, with networking knowledge serving as a supporting competency. This is an onsite role (5 days/week) with participation in an on-call support rotation required, supporting global operations across multiple time zones (8am-5pm core hours). Occasional travel to support installations and operational initiatives may be required. Responsibilities: Physical Security Operations Administer and support global physical security systems and operations Deploy, configure, and maintain enterprise access control platforms including Verkada, Avigilon, and Openpath Manage and troubleshoot camera systems, access control hardware, and monitoring solutions Configure and support wired access control panels and associated infrastructure Monitor security events and ensure operational health of physical security platforms globally Perform firmware updates, patching, and lifecycle management of security devices Global Infrastructure & Security Operations Monitor the health, availability, and performance of global physical security and infrastructure systems Proactively monitor enterprise security platforms, servers, storage systems, network connectivity, and associated cloud services Investigate and resolve alerts, outages, and performance degradation across global environments Perform firmware upgrades, software updates, and security patching for cameras, access control systems, servers, and supporting infrastructure Maintain operational dashboards and monitoring tools to ensure continuous visibility of security and infrastructure assets worldwide Coordinate incident response activities related to security systems, storage platforms, server infrastructure, and connectivity disruptions Infrastructure & Smart Hands Support Provide smart-hands support for servers, network equipment, access control systems, surveillance devices, PCs/desktop hardware, and infrastructure management tools Deploy new hardware and perform rack-and-stack activities Configure, install, and commission security and infrastructure equipment using standardized deployment procedures Coordinate hardware replacements, upgrades, and equipment refresh activities Support remote sites and assist local teams with physical installations and troubleshooting Security Technology Administration Manage cloud-based security platforms and associated integrations Support hardware and software components of security ecosystems Ensure security systems maintain operational availability and compliance requirements Develop and maintain documentation, standard operating procedures, and asset inventories Incident Response & Support Participate in an on-call rotation providing after-hours support Respond to outages involving security systems, camera platforms, access control services, and connectivity-related incidents Troubleshoot loss-of-connectivity events and coordinate restoration efforts Escalate and coordinate with vendors and internal infrastructure teams as required Qualifications: Required: 8+ years of experience in physical security technology, infrastructure operations, or network/security engineering Hands-on experience supporting Verkada, Avigilon, Openpath, enterprise camera systems, and access control platforms Experience deploying and maintaining cloud-based security solutions Strong troubleshooting skills across hardware, software, and connectivity issues Experience with cabling, wiring, access panels, surveillance equipment, and supporting infrastructure Understanding of networking fundamentals including TCP/IP, switching, routing, VLANs, and remote connectivity Experience supporting servers, storage systems, and enterprise infrastructure environments Ability to travel occasionally to support installations and operational initiatives Preferred: Experience supporting global security operations centers (SOC) or enterprise security programs Familiarity with enterprise monitoring and infrastructure management tools Experience managing firmware, software upgrades, and device lifecycle planning Security industry certifications or vendor certifications related to access control or video surveillance systems Knowledge of physical security best practices and operational risk management Arctiq is an equal opportunity employer. If you need any accommodations or adjustments throughout the interview process and beyond, please let us know. We celebrate our inclusive work environment and welcome members of all backgrounds and perspectives to apply. We thank you for your interest in joining the Arctiq team! While we welcome all applicants, only those who are selected for an interview will be contacted.
Job Description Job Description About the Company : Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service. Security Engineer - Network & Identity: The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response. Essential Duties and Responsibilities: Network Security Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments. Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions. Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments. Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls. Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity. Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication. Assess network security posture, develop remediation plans, and drive continuous security improvements. Cryptography, PKI & Certificate Management Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program. Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments. Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms. Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise. Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities. Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements. Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications. Identity & Access Define authentication and authorization standards for workforce, partner, application, service, and machine identities. Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls. Develop, test, and enforce Conditional Access policies and Zero Trust access controls. Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities. Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM. Implement least-privilege and risk-based access models across enterprise platforms. Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls. Govern application registrations, service principals, enterprise applications, API permissions, and managed identities. Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations. Design and implement security controls across Microsoft Azure and AWS environments. Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources. Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations. Create reusable secure-by-default templates and reduce manual administration through automation and orchestration Conduct access reviews, entitlement certifications, and identity governance activities. Education or Desired License and Certificates: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience. Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred. Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred. CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred Preferred Experience & Qualifications: 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline. Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM). Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments. Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls. Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions. Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring. Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies. Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms. Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies. Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services. Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP. Competencies: Mandarin fluency preferred but not required. Strong analytical, troubleshooting, and problem-solving skills. Ability to work independently and collaboratively in a fast-paced environment. Excellent communication, stakeholder management, and technical documentation skills. Strong organization, attention to detail, initiative, and ownership. Ability to balance security, reliability, usability, scalability, and business requirements. Proactive approach to automation, standardization, and continuous improvement. Travel 5%-20% Work Location and Status: Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston No visa sponsorship Compensation: Compensation commensurate with experience Competitive salary and annual bonus eligibility Comprehensive benefits package including health, dental, vision, and retirement plans Strong personal and company growth opportunities Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.
09/24/2026
Full time
Job Description Job Description About the Company : Sungrow North America is a leading provider of renewable energy solutions, specializing in the development and manufacturing of photovoltaic inverters and energy storage systems. The company offers a comprehensive range of products and services designed to optimize the performance and efficiency of solar power installations. Sungrow North America aims to provide sustainable and reliable energy solutions to meet the growing demand for clean power and is known for its commitment to innovation, high-quality standards, and exceptional customer service. Security Engineer - Network & Identity: The Security Engineer (Network & Identity) is a hands-on engineering role within the IT team responsible for designing, implementing, securing, and automating Sungrow USA's network security, PKI and certificate management, and identity & access infrastructure across on-premises, cloud, and SaaS environments. This role serves as the technical owner for network security architecture, cryptographic services, certificate lifecycle management, authentication, and access controls. The position focuses on Zero Trust security, network segmentation, certificate-based authentication, and identity protection to reduce organizational risk and enable secure business operations and platform ownership rather than SOC operations, threat monitoring, or incident response. Essential Duties and Responsibilities: Network Security Design, implement, and maintain secure enterprise network architectures across corporate offices, data centers, cloud platforms, and remote workforce environments. Architect network segmentation, Zero Trust access controls, and secure connectivity standards using Fortinet and Zscaler security solutions. Develop and maintain Zero Trust architectures across network, identity, endpoint, application, and cloud environments. Design and administer secure remote access using Zscaler Private Access, VPN technologies, and identity-aware access controls. Manage firewall policies, network security controls, routing security, DNS security, and hybrid-cloud connectivity. Design and support Network Access Control architectures using IEEE 802.1X, RADIUS, and certificate-based authentication. Assess network security posture, develop remediation plans, and drive continuous security improvements. Cryptography, PKI & Certificate Management Own the enterprise PKI, cryptography, and certificate lifecycle management architecture, standards, and governance program. Design and manage certificate-based authentication and machine identity solutions for users, devices, servers, applications, cloud workloads, and network infrastructure across Azure, AWS, and hybrid environments. Implement and maintain certificate lifecycle automation using Microsoft Cloud PKI, Keyfactor, CyberArk Certificate Manager, EJBCA, DigiCert, AppViewX, or comparable platforms. Manage certificate issuance, enrollment, discovery, deployment, monitoring, renewal, revocation, auditing, and compliance across the enterprise. Design and support cryptographic services and certificate-based security controls, including TLS/mTLS, code signing, PKI trust hierarchies, certificate-based authentication, SCEP, PKCS, and machine identities. Establish PKI and cryptographic standards, key management practices, and security controls to support Zero Trust, regulatory compliance, and enterprise security requirements. Troubleshoot and resolve complex certificate, cryptographic, trust chain, authentication, and secure communications issues across enterprise systems and applications. Identity & Access Define authentication and authorization standards for workforce, partner, application, service, and machine identities. Design, implement, and maintain Microsoft Entra ID architecture, tenant governance, and identity security controls. Develop, test, and enforce Conditional Access policies and Zero Trust access controls. Implement and maintain MFA, passwordless authentication, phishing-resistant authentication, and Microsoft Entra ID Protection capabilities. Design and support enterprise SSO and federation integrations using SAML, OAuth 2.0, OpenID Connect, and SCIM. Implement least-privilege and risk-based access models across enterprise platforms. Administer RBAC, administrative separation, Microsoft Entra Privileged Identity Management, and least-privilege access controls. Govern application registrations, service principals, enterprise applications, API permissions, and managed identities. Support B2B collaboration, guest-user governance, external workforce access, and third-party identity integrations. Design and implement security controls across Microsoft Azure and AWS environments. Apply least privilege, RBAC, encryption, secrets management, and secure configuration standards to on-prem and cloud resources. Automate identity provisioning and deprovisioning, access governance, certificate management, configuration validation, and security operations. Create reusable secure-by-default templates and reduce manual administration through automation and orchestration Conduct access reviews, entitlement certifications, and identity governance activities. Education or Desired License and Certificates: Bachelor's degree in Computer Science, Information Technology, Cybersecurity, Engineering, or a related field, or equivalent professional experience. Microsoft Certified: Identity and Access Administrator Associate (SC-300) preferred. Microsoft Certified: Azure Security Engineer Associate (AZ-500) preferred. CCNA, Fortinet, Zscaler, AWS Security, CISSP, CISM, Terraform, or relevant PKI certification preferred Preferred Experience & Qualifications: 5+ years of experience in security engineering, identity & access management (IAM), network security, cloud security, or a related enterprise IT discipline. Hands-on experience with Microsoft Entra ID, including Conditional Access, MFA, SSO, Identity Protection, PIM, RBAC, identity governance, and modern authentication protocols (SAML, OAuth, OpenID Connect, SCIM). Experience designing, implementing, and securing enterprise identity, privileged access, and machine identity solutions across hybrid and multi-cloud environments. Hands-on experience with Fortinet, Zscaler (ZIA/ZPA), Zero Trust architectures, least-privilege access models, and network security controls. Experience designing and operating enterprise PKI, certificate lifecycle management, certificate-based authentication, and machine identity platforms such as Keyfactor, DigiCert, EJBCA, AppViewX, CyberArk Certificate Manager, or similar solutions. Experience securing Azure and AWS environments, including identity, networking, encryption, secrets management, logging, and security monitoring. Experience with PAM and IGA platforms such as CyberArk, Delinea, BeyondTrust, SailPoint, Saviynt, or similar technologies. Experience integrating identity, network, cloud, and security telemetry with SIEM and security operations platforms. Strong automation and Infrastructure as Code skills using PowerShell, Python, Microsoft Graph API, REST APIs, Terraform, or similar technologies. Strong troubleshooting skills across authentication, federation, certificates, PKI, network security, cloud access, application integrations, and enterprise identity services. Knowledge of cybersecurity and compliance frameworks including SOC 2, ISO/IEC 27001, NIST CSF, NIST 800-63, CIS Controls, Zero Trust, and NERC CIP. Competencies: Mandarin fluency preferred but not required. Strong analytical, troubleshooting, and problem-solving skills. Ability to work independently and collaboratively in a fast-paced environment. Excellent communication, stakeholder management, and technical documentation skills. Strong organization, attention to detail, initiative, and ownership. Ability to balance security, reliability, usability, scalability, and business requirements. Proactive approach to automation, standardization, and continuous improvement. Travel 5%-20% Work Location and Status: Full time, Hybrid at any Sungrow USA office in Phoenix, Costa Mesa, or Houston No visa sponsorship Compensation: Compensation commensurate with experience Competitive salary and annual bonus eligibility Comprehensive benefits package including health, dental, vision, and retirement plans Strong personal and company growth opportunities Sungrow is an equal opportunity employer. Due to strong interest in this position, Sungrow will only reach out to those candidates who best meet the requirements. Thank you for your interest in Sungrow.
Machine Learning Engineer 5 (IC) Do you love building and pioneering in the AI and technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors who love to solve real problems and meet real customer needs. We are seeking Machine Learning Engineers who are passionate about leveraging cutting-edge open source frameworks, advanced algorithms, and emerging technologies to join our team. As a Machine Learning Engineer, you'll have the opportunity to be on the forefront of driving major AI transformations and scaling production models across Capital One. What You'll Do: The MLE role overlaps with many disciplines, such as Ops, Modeling, and Data Engineering. In this role, you'll be expected to perform many ML engineering activities, including one or more of the following: Design, build, and/or deliver ML models and components that solve real-world business problems, while working in collaboration with the Product and Data Science teams Build and scale massive multi-tenant platforms that enable running large footprint ML model training and/or serving at scale Inform your ML infrastructure decisions using your understanding of ML modeling techniques and issues, including choice of model, data, and feature selection, model training, hyperparameter tuning, dimensionality, bias/variance, and validation) Solve complex problems by writing and testing application code, developing and validating ML models, and automating tests and deployment Collaborate as part of a cross-functional Agile team to create and enhance software that enables state-of-the-art big data and ML applications Retrain, maintain, and monitor models in production Leverage or build cloud-based architectures, technologies, and/or platforms to deliver optimized ML models at scale. Construct optimized data pipelines to feed ML models Leverage continuous integration and continuous deployment best practices, including test automation and monitoring, to ensure successful deployment of ML models and application code Ensure all code is well-managed to reduce vulnerabilities, models are well-governed from a risk perspective, and the ML follows best practices in Responsible and Explainable AI Use programming languages like Python, Scala, or Java Basic Qualifications: Bachelor's Degree or higher in Computer Science, Machine Learning or a related quantitative field (Statistics, Economics, Operations Research, Analytics, Mathematics, Engineering) At least 6 years of experience programming with Python, Java, Golang, or C++ At least 6 years of Machine Learning experience using industry standard frameworks PyTorch or Tensorflow and libraries (Pandas, NumPy, Scikit-learn) At least 6 years of experience using and operating large scale distributed systems (Spark, Ray) to prepare AI/ML data At least 4 years of experience deploying and operating Machine Learning solutions in production and operating production services in the cloud (AWS, GCP, Azure) and using Kubernetes to manage large scale containerized ML software systems Preferred Qualifications: Master's or Doctoral Degree in Computer Science, Electrical Engineering, Mathematics, or related field 5+ years of experience optimizing ML algorithms, configurations, and infrastructure 5+ years of experience following software development best practices including source control, testing, code reviews, CI/CD, etc. 5+ years of experience building resilient software solutions with pre-production testing, advanced deployment techniques (one-box, blue/green, gradual dial-up), monitoring, alarms, and preparing incident response plans 5+ years of experience working with Machine Learning techniques (Supervised, semi-supervised, and unsupervised, reinforcement learning, etc.) model types (Regression, Classification, Clustering, etc.), model Architectures (RNNs, CNNs, LSTMs, Transformers), training concepts (loss function, hyperparameters, regularization), and how to evaluate model accuracy and diagnose and address common issues (underfitting, overfitting) 5+ years of experience designing, implementing, and scaling production-ready data pipelines for training and evaluating ML models ML industry impact through conference presentations, papers, blog posts, open source contributions, or patents Ability to communicate complex technical and machine learning concepts clearly to a variety of audiences Capital One will consider sponsoring a new qualified applicant for employment authorization for this position. The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $229,900 - $262,400 for Machine Learning Engineer 5 New York, NY: $250,800 - $286,200 for Machine Learning Engineer 5 Richmond, VA: $209,000 - $238,500 for Machine Learning Engineer 5 San Francisco, CA: $250,800 - $286,200 for Machine Learning Engineer 5 San Jose, CA: $250,800 - $286,200 for Machine Learning Engineer 5 Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
09/23/2026
Full time
Machine Learning Engineer 5 (IC) Do you love building and pioneering in the AI and technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors who love to solve real problems and meet real customer needs. We are seeking Machine Learning Engineers who are passionate about leveraging cutting-edge open source frameworks, advanced algorithms, and emerging technologies to join our team. As a Machine Learning Engineer, you'll have the opportunity to be on the forefront of driving major AI transformations and scaling production models across Capital One. What You'll Do: The MLE role overlaps with many disciplines, such as Ops, Modeling, and Data Engineering. In this role, you'll be expected to perform many ML engineering activities, including one or more of the following: Design, build, and/or deliver ML models and components that solve real-world business problems, while working in collaboration with the Product and Data Science teams Build and scale massive multi-tenant platforms that enable running large footprint ML model training and/or serving at scale Inform your ML infrastructure decisions using your understanding of ML modeling techniques and issues, including choice of model, data, and feature selection, model training, hyperparameter tuning, dimensionality, bias/variance, and validation) Solve complex problems by writing and testing application code, developing and validating ML models, and automating tests and deployment Collaborate as part of a cross-functional Agile team to create and enhance software that enables state-of-the-art big data and ML applications Retrain, maintain, and monitor models in production Leverage or build cloud-based architectures, technologies, and/or platforms to deliver optimized ML models at scale. Construct optimized data pipelines to feed ML models Leverage continuous integration and continuous deployment best practices, including test automation and monitoring, to ensure successful deployment of ML models and application code Ensure all code is well-managed to reduce vulnerabilities, models are well-governed from a risk perspective, and the ML follows best practices in Responsible and Explainable AI Use programming languages like Python, Scala, or Java Basic Qualifications: Bachelor's Degree or higher in Computer Science, Machine Learning or a related quantitative field (Statistics, Economics, Operations Research, Analytics, Mathematics, Engineering) At least 6 years of experience programming with Python, Java, Golang, or C++ At least 6 years of Machine Learning experience using industry standard frameworks PyTorch or Tensorflow and libraries (Pandas, NumPy, Scikit-learn) At least 6 years of experience using and operating large scale distributed systems (Spark, Ray) to prepare AI/ML data At least 4 years of experience deploying and operating Machine Learning solutions in production and operating production services in the cloud (AWS, GCP, Azure) and using Kubernetes to manage large scale containerized ML software systems Preferred Qualifications: Master's or Doctoral Degree in Computer Science, Electrical Engineering, Mathematics, or related field 5+ years of experience optimizing ML algorithms, configurations, and infrastructure 5+ years of experience following software development best practices including source control, testing, code reviews, CI/CD, etc. 5+ years of experience building resilient software solutions with pre-production testing, advanced deployment techniques (one-box, blue/green, gradual dial-up), monitoring, alarms, and preparing incident response plans 5+ years of experience working with Machine Learning techniques (Supervised, semi-supervised, and unsupervised, reinforcement learning, etc.) model types (Regression, Classification, Clustering, etc.), model Architectures (RNNs, CNNs, LSTMs, Transformers), training concepts (loss function, hyperparameters, regularization), and how to evaluate model accuracy and diagnose and address common issues (underfitting, overfitting) 5+ years of experience designing, implementing, and scaling production-ready data pipelines for training and evaluating ML models ML industry impact through conference presentations, papers, blog posts, open source contributions, or patents Ability to communicate complex technical and machine learning concepts clearly to a variety of audiences Capital One will consider sponsoring a new qualified applicant for employment authorization for this position. The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $229,900 - $262,400 for Machine Learning Engineer 5 New York, NY: $250,800 - $286,200 for Machine Learning Engineer 5 Richmond, VA: $209,000 - $238,500 for Machine Learning Engineer 5 San Francisco, CA: $250,800 - $286,200 for Machine Learning Engineer 5 San Jose, CA: $250,800 - $286,200 for Machine Learning Engineer 5 Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
Machine Learning Engineer 3 Do you love building and pioneering in the AI and technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors who love to solve real problems and meet real customer needs. We are seeking Machine Learning Engineers who are passionate about leveraging cutting-edge open source frameworks, advanced algorithms, and emerging technologies to join our team. As a Machine Learning Engineer, you'll have the opportunity to be on the forefront of driving major AI transformations and scaling production models across Capital One. What You'll Do: The MLE role overlaps with many disciplines, such as Ops, Modeling, and Data Engineering. In this role, you'll be expected to perform many ML engineering activities, including one or more of the following: Design, build, and/or deliver ML models and components that solve real-world business problems, while working in collaboration with the Product and Data Science teams Inform your ML infrastructure decisions using your understanding of ML modeling techniques and issues, including choice of model, data, and feature selection, model training, hyperparameter tuning, dimensionality, bias/variance, and validation) Solve complex problems by writing and testing application code, developing and validating ML models, and automating tests and deployment Collaborate as part of a cross-functional Agile team to create and enhance software that enables state-of-the-art big data and ML applications Retrain, maintain, and monitor models in production Leverage or build cloud-based architectures, technologies, and/or platforms to deliver optimized ML models at scale. Construct optimized data pipelines to feed ML models Leverage continuous integration and continuous deployment best practices, including test automation and monitoring, to ensure successful deployment of ML models and application code Ensure all code is well-managed to reduce vulnerabilities, models are well-governed from a risk perspective, and the ML follows best practices in Responsible and Explainable AI Use programming languages like Python, Scala, or Java Basic Qualifications: Bachelor's Degree or higher in Computer Science, Machine Learning or a related quantitative field (Statistics, Economics, Operations Research, Analytics, Mathematics, Engineering) At least 3 years of experience programming with Python, Java, Golang, or C++ At least 2 years of Machine Learning experience using industry standard frameworks PyTorch or Tensorflow and libraries (Pandas, NumPy, Scikit-learn) At least 3 years of experience using and operating large scale distributed systems (Spark, Ray) to prepare AI/ML data At least 1 year of experience deploying and operating Machine Learning solutions in production and operating production services in the cloud (AWS, GCP, Azure) and using Kubernetes to manage large scale containerized ML software systems Preferred Qualifications: Master's or Doctoral Degree in Computer Science, Electrical Engineering, Mathematics, or related field 1+ years of experience optimizing ML algorithms, configurations, and infrastructure 1+ years of experience following software development best practices including source control, testing, code reviews, CI/CD, etc. 1+ years of experience building resilient software solutions with pre-production testing, advanced deployment techniques (one-box, blue/green, gradual dial-up), monitoring, alarms, and preparing incident response plans 1+ years of experience working with Machine Learning techniques (Supervised, semi-supervised, and unsupervised, reinforcement learning, etc.) model types (Regression, Classification, Clustering, etc.), model Architectures (RNNs, CNNs, LSTMs, Transformers), training concepts (loss function, hyperparameters, regularization), and how to evaluate model accuracy and diagnose and address common issues (underfitting, overfitting) Authored/co-authored a paper on a ML technique, model, or proof of concept 1+ years of experience designing, implementing, and scaling production-ready data pipelines for training and evaluating ML models At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (e.g. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-3, and O-1, or any other forms of work authorization that require immigration support from an employer ). The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $161,800 - $184,600 for Machine Learning Engineer 3 New York, NY: $176,500 - $201,400 for Machine Learning Engineer 3 Plano, TX: $147,100 - $167,900 for Machine Learning Engineer 3 Richmond, VA: $147,100 - $167,900 for Machine Learning Engineer 3 Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).
09/23/2026
Full time
Machine Learning Engineer 3 Do you love building and pioneering in the AI and technology space? Do you enjoy solving complex business problems in a fast-paced, collaborative, inclusive, and iterative delivery environment? At Capital One, you'll be part of a big group of makers, breakers, doers and disruptors who love to solve real problems and meet real customer needs. We are seeking Machine Learning Engineers who are passionate about leveraging cutting-edge open source frameworks, advanced algorithms, and emerging technologies to join our team. As a Machine Learning Engineer, you'll have the opportunity to be on the forefront of driving major AI transformations and scaling production models across Capital One. What You'll Do: The MLE role overlaps with many disciplines, such as Ops, Modeling, and Data Engineering. In this role, you'll be expected to perform many ML engineering activities, including one or more of the following: Design, build, and/or deliver ML models and components that solve real-world business problems, while working in collaboration with the Product and Data Science teams Inform your ML infrastructure decisions using your understanding of ML modeling techniques and issues, including choice of model, data, and feature selection, model training, hyperparameter tuning, dimensionality, bias/variance, and validation) Solve complex problems by writing and testing application code, developing and validating ML models, and automating tests and deployment Collaborate as part of a cross-functional Agile team to create and enhance software that enables state-of-the-art big data and ML applications Retrain, maintain, and monitor models in production Leverage or build cloud-based architectures, technologies, and/or platforms to deliver optimized ML models at scale. Construct optimized data pipelines to feed ML models Leverage continuous integration and continuous deployment best practices, including test automation and monitoring, to ensure successful deployment of ML models and application code Ensure all code is well-managed to reduce vulnerabilities, models are well-governed from a risk perspective, and the ML follows best practices in Responsible and Explainable AI Use programming languages like Python, Scala, or Java Basic Qualifications: Bachelor's Degree or higher in Computer Science, Machine Learning or a related quantitative field (Statistics, Economics, Operations Research, Analytics, Mathematics, Engineering) At least 3 years of experience programming with Python, Java, Golang, or C++ At least 2 years of Machine Learning experience using industry standard frameworks PyTorch or Tensorflow and libraries (Pandas, NumPy, Scikit-learn) At least 3 years of experience using and operating large scale distributed systems (Spark, Ray) to prepare AI/ML data At least 1 year of experience deploying and operating Machine Learning solutions in production and operating production services in the cloud (AWS, GCP, Azure) and using Kubernetes to manage large scale containerized ML software systems Preferred Qualifications: Master's or Doctoral Degree in Computer Science, Electrical Engineering, Mathematics, or related field 1+ years of experience optimizing ML algorithms, configurations, and infrastructure 1+ years of experience following software development best practices including source control, testing, code reviews, CI/CD, etc. 1+ years of experience building resilient software solutions with pre-production testing, advanced deployment techniques (one-box, blue/green, gradual dial-up), monitoring, alarms, and preparing incident response plans 1+ years of experience working with Machine Learning techniques (Supervised, semi-supervised, and unsupervised, reinforcement learning, etc.) model types (Regression, Classification, Clustering, etc.), model Architectures (RNNs, CNNs, LSTMs, Transformers), training concepts (loss function, hyperparameters, regularization), and how to evaluate model accuracy and diagnose and address common issues (underfitting, overfitting) Authored/co-authored a paper on a ML technique, model, or proof of concept 1+ years of experience designing, implementing, and scaling production-ready data pipelines for training and evaluating ML models At this time, Capital One will not sponsor a new applicant for employment authorization, or offer any immigration related support for this position (e.g. H1B, F-1 OPT, F-1 STEM OPT, F-1 CPT, J-1, TN, E-3, and O-1, or any other forms of work authorization that require immigration support from an employer ). The minimum and maximum full-time annual salaries for this role are listed below, by location. Please note that this salary information is solely for candidates hired to perform work within one of these locations, and refers to the amount Capital One is willing to pay at the time of this posting. Salaries for part-time roles will be prorated based upon the agreed upon number of hours to be regularly worked. McLean, VA: $161,800 - $184,600 for Machine Learning Engineer 3 New York, NY: $176,500 - $201,400 for Machine Learning Engineer 3 Plano, TX: $147,100 - $167,900 for Machine Learning Engineer 3 Richmond, VA: $147,100 - $167,900 for Machine Learning Engineer 3 Candidates hired to work in other locations will be subject to the pay range associated with that location, and the actual annualized salary amount offered to any candidate at the time of hire will be reflected solely in the candidate's offer letter. This role is also eligible to earn performance based incentive compensation, which may include cash bonus(es) and/or long term incentives (LTI). Incentives could be discretionary or non discretionary depending on the plan. Capital One offers a comprehensive, competitive, and inclusive set of health, financial and other benefits that support your total well-being. Learn more at the Capital One Careers website . Eligibility varies based on full or part-time status, exempt or non-exempt status, and management level. This role is expected to accept applications for a minimum of 5 business days.No agencies please. Capital One is an equal opportunity employer (EOE, including disability/vet) committed to non-discrimination in compliance with applicable federal, state, and local laws. Capital One promotes a drug-free workplace. Capital One will consider for employment qualified applicants with a criminal history in a manner consistent with the requirements of applicable laws regarding criminal background inquiries, including, to the extent applicable, Article 23-A of the New York Correction Law; San Francisco, California Police Code Article 49, Sections ; New York City's Fair Chance Act; Philadelphia's Fair Criminal Records Screening Act; and other applicable federal, state, and local laws and regulations regarding criminal background inquiries. If you have visited our website in search of information on employment opportunities or to apply for a position, and you require an accommodation, please contact Capital One Recruiting at 1- or via email at . All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. For technical support or questions about Capital One's recruiting process, please send an email to Capital One does not provide, endorse nor guarantee and is not liable for third-party products, services, educational tools or other information available through this site. Capital One Financial is made up of several different entities. Please note that any position posted in Canada is for Capital One Canada, any position posted in the United Kingdom is for Capital One Europe and any position posted in the Philippines is for Capital One Philippines Service Corp. (COPSSC).