it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

11 jobs found

Email me jobs like this
Refine Search
Current Search
senior technical program manager enterprise security iam
Senior Data Product Engineer, Commercial and Medical Affairs Data Products
Genmab Princeton, New Jersey
At Genmab, we are dedicated to building extra not ordinary futures, together, by developing antibody products and groundbreaking, knock-your-socks-off KYSO antibody medicines that change lives and the future of cancer treatment and serious diseases. We strive to create, champion and maintain a global workplace where individuals' unique contributions are valued and drive innovative solutions to meet the needs of our patients, care partners, families and employees. Our people are compassionate, candid, and purposeful, and our business is innovative and rooted in science. We believe that being proudly authentic and determined to be our best is essential to fulfilling our purpose. Yes, our work is incredibly serious and impactful, but we have big ambitions, bring a ton of care to pursuing them, and have a lot of fun while doing so. Does this inspire you and feel like a fit? Then we would love to have you join us! We are looking for a Senior Data Product Engineer with deep expertise in DBT, Databricks, Snowflake, Power BI/Tableau, Airflow and AWS, who can architect and implement scalable, reliable, and high-performance data products. This role will require strong technical skills across data modeling, distributed data processing, ELT pipeline development, and dashboarding, with an emphasis on automation, observability, and engineering best practices supporting our US and Global commercial data warehouse. You will be expected to design and deliver production-grade data pipelines and models, optimize query, and compute performance, and expose data to end users through well-structured semantic layers and dashboards. The ideal candidate is conceptually strong in modern data architectures and principles, capable of adapting across tools rather than being limited by them and operate as a hands-on technical lead, defining frameworks, making architectural decisions, and guiding implementation patterns across dbt, Snowflake, Databricks and BI platforms. The ideal candidate works successfully across Commercial functions to define, document, test and implement data products delivering functional requirements and impactful data products. The ideal candidate should have familiarity with commercial data sets like IQVIA One Key, Veeva Open Data, Life Science Cloud, Veeva CRM, 3PL data, Claims Data, Digital, Omnichannel and Precision lab data. Work arrangement: This role offers flexibility to work away from the office for 20%-40% of a typical schedule. Employees may use this work schedule in increments of single days or multiple consecutive days, provided it does not exceed 40% within a 60-day period, and is approved by the hiring manager. Core Responsibilities Data Engineering & Architecture Architect and implement end-to-end ELT workflows with DBT (core and Cloud), ensuring modular, testable, and reusable transformations. Build high-performance data pipelines in Snowflake and Databricks (PySpark, Delta Lake, Unity Catalog) for batch and streaming workloads. Orchestration using Apache Airflow and Amazon tools. Engineer scalable data ingestion pipelines into AWS (S3, Kinesis, Glue, Lambda, Step Functions, Airflow) with strong monitoring and fault tolerance. Ensure observability, cost efficiency & scalability in all pipeline and compute designs. Data Modeling, Governance, Security and Compliance Design normalized and star-schema models for analytical workloads, following dbt's best practices and software engineering principles. Implement data quality testing frameworks (dbt tests, Great Expectations, or custom validations) with automated CI/CD integration. Manage data versioning, lineage, and governance through tools such as Unity Catalog and AWS Lake Formation. Ensure data lineage, cataloging, and metadata management are maintained. Apply GDPR, LGPD, and other Data Privacy / Compliance rules and compliance standards. Support audits, documentation, and validation activities. Analytics Enablement & Dashboards Develop semantic data layers that support self-service analytics across BI tools (Tableau, Power BI etc.). Partner with analysts and data scientists to optimize queries and deliver production-ready datasets. Manage ingestion and harmonization of commercial datasets such as: o HCP/HCO master data (IQVIA and Veeva) o Sales and distribution data (852,867, 3PL and Country specific market or sales data) o Omnichannel engagement (email, rep-triggered, web, events) o CRM activity data (Veeva, Life Science Cloud) o Market research and syndicated data (IQVIA, etc.) o Support data pipelines used for incentive compensation, field force effectiveness, and brand performance analytics. Platform Engineering & Automation Automate deployment pipelines with CI/CD (GitHub Actions, GitLab CI, or AWS CodePipeline) for dbt and Databricks. Implement infrastructure-as-code (IaaC) for reproducibility (Terraform, CloudFormation). Ensure system reliability through observability and monitoring (Datadog, CloudWatch, Prometheus, or similar). Benchmark and optimize SQL, Python, Spark, and BI query performance at scale. Collaboration & Stakeholder Support Partner with Data Scientists, Commercial Analysts, and Business Partners to translate business needs into technical solutions. Work closely with IT, Compliance, and Data Privacy teams to ensure complaint data handling. Provide technical guidance on data availability, feasibility, and best practices. Required Qualifications 5+ years in data engineering, analytics engineering, or data platform development. Expert-level proficiency in: o DBT: advanced macros, Jinja, testing, exposures, dbt Cloud deployment. o Databricks: Spark (PySpark, SQL), Delta Lake, Unity Catalog. o Snowflake o AWS: S3, Glue, Lambda, Step Functions, Datasync, EMR, Redshift, IAM and networking/security fundamentals. o Data Visualization: Power BI or Tableau. Strong programming background in Python and SQL (including query optimization). Proven experience with distributed systems and large-scale datasets (GB-TB scale). Experience implementing CI/CD pipelines, data testing, and infrastructure as code. Solid understanding of data governance, security, and compliance in enterprise environments. Why This Role? Working as a Data Engineer in an oncology company means your work directly supports the people who need it most-patients facing one of the most difficult diagnoses of their lives. Every pipeline you build, every dataset you harmonize, and every insight you enable helps accelerate how quickly life changing therapies reach the right patients at the right time. You get to solve challenging engineering problems while contributing to something bigger than technology. You're not just optimizing pipelines-you're helping ensure that a patient gets diagnosed earlier, a doctor receives better information, or a family gains access to a therapy that gives them more time together. You will work at the intersection of modern data engineering and analytics product development, solving challenges of scale, performance, and usability. This role is ideal for someone who thrives in a hands-on engineering environment and wants to build the technical foundation for data-driven decision-making across the organization. For US based candidates, the proposed salary band for this position is as follows: $132,720.00 $199,080.00 The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location. Also, certain positions are eligible for additional forms of compensation, such as discretionary bonuses and long-term incentives. When you join Genmab, you're joining a culture that supports your physical, financial, social, and emotional wellness. Within the first year, regular full-time U.S. employees are eligible for: 401(k) Plan: 100% match on the first 6% of contributions Health Benefits: Two medical plan options (including HDHP with HSA), dental, and vision insurance Voluntary Plans: Critical illness, accident, and hospital indemnity insurance Time Off: Paid vacation, sick leave, holidays, and 12 weeks of discretionary paid parental leave Support Resources: Access to child and adult backup care, family support programs, financial wellness tools, and emotional well-being support Additional Perks: Commuter benefits, tuition reimbursement, and a Lifestyle Spending Account for wellness and personal expenses Further details on eligibility for compensation and benefits based on role will be provided during the recruitment process About Genmab Genmab is an international biotechnology company with a core purpose to improve the lives of patients through innovative and differentiated antibody therapeutics. For 25 years, its hard-working, innovative and collaborative team has invented next-generation antibody technology platforms and harnessed translational, quantitative and data sciences, resulting in a proprietary pipeline including bispecific T-cell engagers, antibody-drug conjugates, next-generation immune checkpoint modulators and effector function-enhanced antibodies. By 2030, Genmab's vision is to transform the lives of people with cancer and other serious diseases with Knock-Your-Socks-Off (KYSO ) antibody medicines. Established in 1999 . click apply for full job details
09/23/2026
Full time
At Genmab, we are dedicated to building extra not ordinary futures, together, by developing antibody products and groundbreaking, knock-your-socks-off KYSO antibody medicines that change lives and the future of cancer treatment and serious diseases. We strive to create, champion and maintain a global workplace where individuals' unique contributions are valued and drive innovative solutions to meet the needs of our patients, care partners, families and employees. Our people are compassionate, candid, and purposeful, and our business is innovative and rooted in science. We believe that being proudly authentic and determined to be our best is essential to fulfilling our purpose. Yes, our work is incredibly serious and impactful, but we have big ambitions, bring a ton of care to pursuing them, and have a lot of fun while doing so. Does this inspire you and feel like a fit? Then we would love to have you join us! We are looking for a Senior Data Product Engineer with deep expertise in DBT, Databricks, Snowflake, Power BI/Tableau, Airflow and AWS, who can architect and implement scalable, reliable, and high-performance data products. This role will require strong technical skills across data modeling, distributed data processing, ELT pipeline development, and dashboarding, with an emphasis on automation, observability, and engineering best practices supporting our US and Global commercial data warehouse. You will be expected to design and deliver production-grade data pipelines and models, optimize query, and compute performance, and expose data to end users through well-structured semantic layers and dashboards. The ideal candidate is conceptually strong in modern data architectures and principles, capable of adapting across tools rather than being limited by them and operate as a hands-on technical lead, defining frameworks, making architectural decisions, and guiding implementation patterns across dbt, Snowflake, Databricks and BI platforms. The ideal candidate works successfully across Commercial functions to define, document, test and implement data products delivering functional requirements and impactful data products. The ideal candidate should have familiarity with commercial data sets like IQVIA One Key, Veeva Open Data, Life Science Cloud, Veeva CRM, 3PL data, Claims Data, Digital, Omnichannel and Precision lab data. Work arrangement: This role offers flexibility to work away from the office for 20%-40% of a typical schedule. Employees may use this work schedule in increments of single days or multiple consecutive days, provided it does not exceed 40% within a 60-day period, and is approved by the hiring manager. Core Responsibilities Data Engineering & Architecture Architect and implement end-to-end ELT workflows with DBT (core and Cloud), ensuring modular, testable, and reusable transformations. Build high-performance data pipelines in Snowflake and Databricks (PySpark, Delta Lake, Unity Catalog) for batch and streaming workloads. Orchestration using Apache Airflow and Amazon tools. Engineer scalable data ingestion pipelines into AWS (S3, Kinesis, Glue, Lambda, Step Functions, Airflow) with strong monitoring and fault tolerance. Ensure observability, cost efficiency & scalability in all pipeline and compute designs. Data Modeling, Governance, Security and Compliance Design normalized and star-schema models for analytical workloads, following dbt's best practices and software engineering principles. Implement data quality testing frameworks (dbt tests, Great Expectations, or custom validations) with automated CI/CD integration. Manage data versioning, lineage, and governance through tools such as Unity Catalog and AWS Lake Formation. Ensure data lineage, cataloging, and metadata management are maintained. Apply GDPR, LGPD, and other Data Privacy / Compliance rules and compliance standards. Support audits, documentation, and validation activities. Analytics Enablement & Dashboards Develop semantic data layers that support self-service analytics across BI tools (Tableau, Power BI etc.). Partner with analysts and data scientists to optimize queries and deliver production-ready datasets. Manage ingestion and harmonization of commercial datasets such as: o HCP/HCO master data (IQVIA and Veeva) o Sales and distribution data (852,867, 3PL and Country specific market or sales data) o Omnichannel engagement (email, rep-triggered, web, events) o CRM activity data (Veeva, Life Science Cloud) o Market research and syndicated data (IQVIA, etc.) o Support data pipelines used for incentive compensation, field force effectiveness, and brand performance analytics. Platform Engineering & Automation Automate deployment pipelines with CI/CD (GitHub Actions, GitLab CI, or AWS CodePipeline) for dbt and Databricks. Implement infrastructure-as-code (IaaC) for reproducibility (Terraform, CloudFormation). Ensure system reliability through observability and monitoring (Datadog, CloudWatch, Prometheus, or similar). Benchmark and optimize SQL, Python, Spark, and BI query performance at scale. Collaboration & Stakeholder Support Partner with Data Scientists, Commercial Analysts, and Business Partners to translate business needs into technical solutions. Work closely with IT, Compliance, and Data Privacy teams to ensure complaint data handling. Provide technical guidance on data availability, feasibility, and best practices. Required Qualifications 5+ years in data engineering, analytics engineering, or data platform development. Expert-level proficiency in: o DBT: advanced macros, Jinja, testing, exposures, dbt Cloud deployment. o Databricks: Spark (PySpark, SQL), Delta Lake, Unity Catalog. o Snowflake o AWS: S3, Glue, Lambda, Step Functions, Datasync, EMR, Redshift, IAM and networking/security fundamentals. o Data Visualization: Power BI or Tableau. Strong programming background in Python and SQL (including query optimization). Proven experience with distributed systems and large-scale datasets (GB-TB scale). Experience implementing CI/CD pipelines, data testing, and infrastructure as code. Solid understanding of data governance, security, and compliance in enterprise environments. Why This Role? Working as a Data Engineer in an oncology company means your work directly supports the people who need it most-patients facing one of the most difficult diagnoses of their lives. Every pipeline you build, every dataset you harmonize, and every insight you enable helps accelerate how quickly life changing therapies reach the right patients at the right time. You get to solve challenging engineering problems while contributing to something bigger than technology. You're not just optimizing pipelines-you're helping ensure that a patient gets diagnosed earlier, a doctor receives better information, or a family gains access to a therapy that gives them more time together. You will work at the intersection of modern data engineering and analytics product development, solving challenges of scale, performance, and usability. This role is ideal for someone who thrives in a hands-on engineering environment and wants to build the technical foundation for data-driven decision-making across the organization. For US based candidates, the proposed salary band for this position is as follows: $132,720.00 $199,080.00 The actual salary offer will carefully consider a wide range of factors, including your skills, qualifications, experience, and location. Also, certain positions are eligible for additional forms of compensation, such as discretionary bonuses and long-term incentives. When you join Genmab, you're joining a culture that supports your physical, financial, social, and emotional wellness. Within the first year, regular full-time U.S. employees are eligible for: 401(k) Plan: 100% match on the first 6% of contributions Health Benefits: Two medical plan options (including HDHP with HSA), dental, and vision insurance Voluntary Plans: Critical illness, accident, and hospital indemnity insurance Time Off: Paid vacation, sick leave, holidays, and 12 weeks of discretionary paid parental leave Support Resources: Access to child and adult backup care, family support programs, financial wellness tools, and emotional well-being support Additional Perks: Commuter benefits, tuition reimbursement, and a Lifestyle Spending Account for wellness and personal expenses Further details on eligibility for compensation and benefits based on role will be provided during the recruitment process About Genmab Genmab is an international biotechnology company with a core purpose to improve the lives of patients through innovative and differentiated antibody therapeutics. For 25 years, its hard-working, innovative and collaborative team has invented next-generation antibody technology platforms and harnessed translational, quantitative and data sciences, resulting in a proprietary pipeline including bispecific T-cell engagers, antibody-drug conjugates, next-generation immune checkpoint modulators and effector function-enhanced antibodies. By 2030, Genmab's vision is to transform the lives of people with cancer and other serious diseases with Knock-Your-Socks-Off (KYSO ) antibody medicines. Established in 1999 . click apply for full job details
Sr. Product Manager - Agentic Security
Okta Bellevue, Washington
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
09/23/2026
Full time
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
Sr. Product Manager - Agentic Security
Okta Washington, Washington DC
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
09/23/2026
Full time
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
Sr. Product Manager - Agentic Security
Okta Chicago, Illinois
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
09/23/2026
Full time
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
Sr. Product Manager - Agentic Security
Okta New York, New York
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
09/23/2026
Full time
Secure Every Identity, from AI to Human Identity is the key to unlocking the potential of AI. Okta secures AI by building the trusted, neutral infrastructure that enables organizations to safely embrace this new era. This work requires a relentless drive to solve complex challenges with real-world stakes. We are looking for builders and owners who operate with speed and urgency and execute with excellence. This is an opportunity to do career-defining work. We're all in on this mission. If you are too, let's talk. About the Role We are seeking a Senior Product Manager to drive the vision, strategy, and execution for a key product area within the Auth0 Identity Security product line, with a focused mandate on the rapidly evolving domain of Agentic Security. This role sits at the intersection of product strategy, cross-functional leadership, and agile execution - requiring someone who can both shape long-term direction and deliver with precision. We are the team that builds solutions that protect our customer's Auth0 environments. Our group delivers features such as attack protection, bot detection, adaptive MFA, identity security for AI Agents and related analytics / insights on the effectiveness of our solutions in thwarting attacks from bad actors. The ideal candidate brings direct, hands-on experience in agentic security product management, with a deep understanding of how AI agents are built, orchestrated, and secured. This includes practical knowledge of agentic workflows, MCP servers, agentic tooling, and their use through productivity applications such as Claude Code. A core focus of this role is runtime security & AI agent classification: building real-time detection, behavioral analysis, and protection capabilities for agentic systems. The successful candidate will have command of the OWASP Top 10 for Agentic AI attack vectors and mitigations, and will bring experience in identifying and responding to threats such as prompt injection, agent intent anomalies, and rogue agent detection - including scenarios where an agent may have been compromised or infiltrated. Beyond agentic-native threats, this role demands strong fluency in fraud and risk mitigation, spanning both traditional and emerging attack surfaces. This includes a depth of knowledge across classic vectors - Account Takeover (ATO), resource draining, and fraudulent account creation - as well as their evolving equivalents in multi-agent and autonomous system environments. Key Responsibilities Product Strategy & Roadmap: Define and champion a clear product strategyand roadmap, utilizing data-driven prioritization methods to maximize customer value and business impact. Manage inputs from diverse cross-functional stakeholders. Customer Experience: Drive customer research (surveys, interviews, data analysis) to identify top opportunities, optimize the end-to-end customer journey, and ensure product value realization. Experience Design: Partner with Product Design on prototypes, wireframes, and concepts, continuously improving the usability of both the UI and APIs for technical and business audiences. Agile Execution & Delivery: Maintain active, daily collaboration with engineering teams. Write clear user stories, scope work for sprints, and actively participate in Agile cadences. Proactively solve problems and manage ambiguity to ensure on-time delivery. Performance Optimization: Drive continuous data analysis and insights into customer adoption. Establish clear hypotheses and baselines for feature launches, then track progress toward strategic targets and drive continuous product iteration based on learnings. Commercial Growth & Value: Partner closely with Product Marketing to run targeted customer campaigns. These efforts will drive trial conversions, accelerate Product-Led Growth (PLG) motions, boost retention, and increase high-value usage and adoption. Go-to-Market: Proactively monitor the competitive landscape to identify gaps and differentiators. Partner with Product Marketing and pre-sales engineering to refine product positioning, develop engaging customer value messaging, and craft supporting content (blogs, webinars). Field & Customer Engagement: Actively engage with the field organization (Sales, Solutions Engineering, Technical Account Managers) to build deep knowledge of the voice of the customer. Drive customer conversations during pre-sales, renewals, and at key events to gather feedback and support adoption. AI-Powered Productivity: Drive efficiency and strategic insight by leveraging AI tools for high-value activities, including prototyping, synthesizing customer insights, accelerating competitive and market analysis, and rapidly generating high-quality product documentation. Required Qualifications AI Agent Experience: Significant product experience with AI Agent creation, orchestration and the use of MCP (Model Context Protocol) servers for exposing context, tools, and resources to agents. Ability to use this experience to define how Auth0's should securely authenticate, authorize, and monitor non-human AI principals at runtime. Agentic Threat Remediation: You have a strong command of the OWASP Top 10 for Agentic AI, and can articulate how each attack class manifests in real-world agentic deployments. You bring direct experience identifying, triaging, and driving remediation of agentic threats, with particular depth in: prompt injection attacks, agent intent anomalies, and rogue agent detection. Product Management Experience: 5-8 years of experience in Product Management, whether from startup or high-growth company environments. Education: An Undergraduate and/or Masters Degree in Computer Science, Engineering, Information Systems or a related technical field. General Security Industry Experience: Prior working experience in the security, fraud or compliance industries with foundational knowledge of Identity and Access Management (IAM/CIAM) concepts (e.g., OAuth 2.0, OpenID Connect, SSO, MFA, RBAC) and/or familiarity with compliance frameworks relevant to identity security (e.g., GDPR, CCPA, SOC 2). Communication: Excellent communication skills (presentation, verbal, and written) and a highly collaborative approach, working with cross-functional stakeholders across the organization. Enterprise Software: Demonstrated experience in delivery of global, enterprise software across all aspects of the product lifecycle. Results Driven: A clear history of being outcome-driven and achieving tangible business results through the successful delivery of products, features, or capabilities that you have owned. Problem Solving: Keen analytical, problem-solving, and decision-making abilities, with a proven capacity to formulate effective action plans even when faced with incomplete, conflicting, or ambiguous inputs. Entrepreneurial: Bring an entrepreneurial mindset and a strong intellectual curiosity that drives you to learn and delve deeply into both business and technical aspects of this role. Agile Development: Deep experience working successfully with engineering teams in an Agile development environment, including scoping, sprint planning, and backlog management and prioritization. .1 Below is the annual On Target Compensation (OTE) range for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York and Washington. Your actual OTE, which is inclusive of base salary and incentive compensation, will depend on factors such as your skills, qualifications, experience, and work location. In addition, Okta offers equity (where applicable) and benefits, including health, dental and vision insurance, 401(k), flexible spending account, and paid leave (including PTO and parental leave) in accordance with our applicable plans and policies. To learn more about our Total Rewards program please visit: The annual OTE range for this position for candidates located in California (excluding San Francisco Bay Area), Colorado, Illinois, New York, and Washington is between: $169,000-$253,000 USD The Okta Experience Supporting Your Well-Being Driving Social Impact Developing Talent and Fostering Connection + Community We are intentional about connection. Our global community, spanning over 20 offices worldwide, is united by a drive to innovate. Your journey begins with an immersive, in-person onboarding experience designed to accelerate your impact and connect you to our mission and team from day one. Okta is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, ancestry, marital status, age, physical or mental disability, or status as a protected veteran. We also consider for employment qualified applicants with arrest and convictions records, consistent with applicable laws. If reasonable accommodation is needed to complete any part of the job application, interview process, or onboarding please use this Form to request an accommodation. Notice for New York City Applicants & Employees: Okta may use Automated Employment Decision Tools (AEDT), as defined by New York City Local Law 144, that use artificial intelligence, machine learning, or other automated processes to assist in our recruitment and hiring process . click apply for full job details
Security Specialist Senior - WIAM Policy and Controls
PNC
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
09/23/2026
Full time
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
Security Specialist Senior - WIAM Policy and Controls
PNC
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
09/23/2026
Full time
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
Security Specialist Senior - WIAM Policy and Controls
PNC Remote, Oregon
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
09/23/2026
Full time
Position Overview At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success. As a Security Specialist Sr within PNC's Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Lakewood, CO Role Summary Senior leadership role responsible for defining, scaling, and sustaining the enterprise WIAM governance function, ensuring strong alignment across policy, risk, controls, and operations. Drives proactive risk management, strengthens control effectiveness, and positions the organization for consistent audit readiness. Key Responsibilities • Define and evolve the WIAM governance framework, including policy alignment, control design standards, and operating model • Establish and lead a centralized governance capability to ensure consistency across IAM domains and processes • Drive alignment of issues risk controls policy, ensuring traceability, defensibility, and regulatory compliance • Lead enterprise-wide efforts to identify systemic risks, prioritize remediation, and improve control sustainability • Define and monitor governance KPIs, scorecards, and maturity metrics, driving continuous improvement • Provide strategic direction for audit readiness, regulatory alignment, and external/internal assessments • Partner with senior leaders across IAM engineering, operations, and business units to drive adoption of governance standards • Influence decision-making by translating complex risk and control concepts into clear, actionable insights for leadership • Establish scalable processes that reduce reliance on reactive issue management and enable proactive risk mitigation • Mentor and develop junior team members, promoting governance best practices and consistency Required Experience 8+ years in IAM, cybersecurity governance, risk, controls, audit, or related security leadership roles. Preferred Certifications: CISSP, CISM, CRISC, CGRC (or equivalent governance / risk credentials). • Deep expertise in IAM governance, risk management, controls, and regulatory expectations • Proven experience designing and scaling enterprise governance frameworks • Strong understanding of control design, effectiveness testing, and audit defense • Ability to connect policy, risk, and control execution across complex environments • Advanced analytical skills, including trend analysis and risk-based decisioning • Strong leadership, influencing, and stakeholder engagement capabilities across all levels • Experience working in highly regulated environments (e.g., financial services preferred)PNC is an in-office company that fosters a supportive culture where employees can thrive and achieve balance. We encourage candidates to connect with their recruiter and hiring manager to understand workplace expectations and ensure the role aligns with their goals.PNC will not provide sponsorship for employment visas or participate in STEM OPT for this position. Job Description Provides technical evaluation and analysis in a specific Security area. Supports activities, process, and tools needed to improve overall security posture of the organization. Primary responsibilities do not include Architect or Engineering responsibilities. Provides subject matter expertise. Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, creates documentation. Performs investigation and data loss prevention, data manipulation, coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls. Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff. Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines. Develops policies and procedures to standardize security functions and eliminate potential vulnerabilities and threats. Oversees that business needs are being met during development. Shares knowledge, leads and mentors are the discretion of management. Aligns the controls of a specific Security area to the enterprise framework. Devises control implementation strategy. PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be: Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions. Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework. Qualifications Successful candidates must demonstrate appropriate knowledge, skills, and abilities for a role. Listed below are skills, competencies, work experience, education, and required certifications/licensures needed to be successful in this position. Preferred Skills Access Control (AC), Building Architecture, Customer Solutions, Disaster Recovery Planning, Identity Access Management (IAM), Information Security, Network Security, Physical Security, Risk Assessments, Security Technologies Competencies Analytical Thinking, Effective Communications, Information Assurance, Information Security Management, Information Security Technologies, IT Environment, IT Standards, Procedures & Policies, IT Systems Management, Knowledge of Organization, Problem Solving, Software Security Assurance Work Experience Roles at this level typically require a university / college degree. Higher level education such as a Masters degree, PhD, or certifications is desirable. Industry relevant experience is typically 8+ years. Specific certifications are often required. In lieu of a degree, a comparable combination of education, job specific certification(s), and experience (including military service) may be considered. Education Bachelors Certifications No Required Certification(s) Licenses No Required License(s) Language Assessments No Required or Preferred Language Assessments Pay Transparency Base Salary: $112,000.00 - $228,800.00Salaries may vary based on geographic location, market data and on individual skills, experience, and education. This role is incentive eligible with the payment based upon company, business and/or individual performance. Application Window Generally, this opening is expected to be posted for two business days from 07/22/2026, although it may be longer with business discretion. Benefits PNC offers a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include: medical/prescription drug coverage (with a Health Savings Account feature), dental and vision options; employee and spouse/child life insurance; short and long-term disability protection; 401(k) with PNC match, pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption, surrogacy, and doula reimbursement; educational assistance, including select programs fully paid; a robust wellness program with financial incentives.In addition, PNC generally provides the following paid time off, depending on your eligibility: maternity and/or parental leave; up to 11 paid holidays each year; 9 occasional absence days each year, unless otherwise required by law; between 15 to 25 vacation days each year, depending on career level; and years of service. To learn more about these and other programs, including benefits for full time and part-time employees, visit . Disability Accommodations Statement If an accommodation is required to participate in the application process, please contact us via email at . Please include "accommodation request" in the subject line title and be sure to include your name, the job ID, and your preferred method of contact in the body of the email. Emails not related to accommodation requests will not receive responses. Applicants may also call and say "Workday" for accommodation assistance. All information provided will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations. At PNC we foster an inclusive and accessible workplace. We provide reasonable accommodations to employment applicants and qualified individuals with a disability who need an accommodation to perform the essential functions of their positions. Equal Employment Opportunity (EEO) PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law. This position is subject to the requirements of Section 19 of the Federal Deposit Insurance Act (FDIA) and, for any registered role . click apply for full job details
Security Control Assessor (SCA)
Chenega Corporation Arlington, Virginia
Job Description Job Description Overview Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interests of our nation. SecuriGence is seeking a talented Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years relevant experience 5+ years relevant experience DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience in assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Strong knowledge of CSAM Expert with documenting and or reviewing security materials such as; system security plans (SSP), Security Assessment Report (SAR), Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings. How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
09/22/2026
Full time
Job Description Job Description Overview Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interests of our nation. SecuriGence is seeking a talented Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years relevant experience 5+ years relevant experience DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience in assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Strong knowledge of CSAM Expert with documenting and or reviewing security materials such as; system security plans (SSP), Security Assessment Report (SAR), Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings. How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
Lead Senior Security Control Assessor (SCA)
Chenega Corporation Arlington, Virginia
Job Description Job Description Overview Lead Senior Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation. SecuriGence is seeking a talented Lead Senior Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability of the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline for all IS. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years of relevant experience 5+ years relevant experience required DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
09/22/2026
Full time
Job Description Job Description Overview Lead Senior Security Control Assessor (SCA) Arlington, VA Are you ready to enhance your skills and build your career in a rapidly evolving business climate? Are you looking for a career where professional development is embedded in your employer's core culture? If so, Chenega Military, Intelligence & Operations Support (MIOS) could be the place for you! Join our team of professionals who support large-scale government operations by leveraging cutting-edge technology and take your career to the next level! SecuriGence delivers essential technology services to our customers in support of their missions to sustain the national security and economic interest of our nation. SecuriGence is seeking a talented Lead Senior Security Control Assessor to help contribute to our success. Come help us solve problems with Innovation Through Intelligence. Responsibilities Advise the A&A Manager concerning the impact levels for Confidentiality, Integrity, and Availability of the information on systems. Conduct a Security Assessment Plan (SAP) for each package assessment. Ensure security assessments are completed for each IS and package is submitted before or on target date. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the A&A Manager, CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the A&A Manager under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline for all IS. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop a continuous monitoring plan specific to the information system. Other duties as assigned. Qualifications Bachelor's degree required OR Associate's degree with 2+ years of relevant experience OR High school diploma or GED equivalent with 4+ years of relevant experience 5+ years relevant experience required DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) required Top Secret clearance with SCI eligibility is required Knowledge, Skills and Abilities: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings How you'll grow At Chenega MIOS, our professional development plan focuses on helping our team members at every level of their careers to identify and use their strengths to do their best work every day. From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to help sharpen skills in addition to hands-on experience in the global, fast-changing business world. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their careers. Benefits At Chenega MIOS, we know that great people make a great organization. We value our team members and offer them a broad range of benefits. Learn more about what working at Chenega MIOS can mean for you. Chenega MIOS's culture Our positive and supportive culture encourages our team members to do their best work every day. We celebrate individuals by recognizing their uniqueness and offering them the flexibility to make daily choices that can help them be healthy, centered, confident, and aware. We offer well-being programs and continuously look for new ways to maintain a culture where we excel and lead healthy, happy lives. Corporate citizenship Chenega MIOS is led by a purpose to make an impact that matters. This purpose defines who we are and extends to relationships with our clients, our team members, and our communities. We believe that business has the power to inspire and transform. We focus on education, giving, skill-based volunteerism, and leadership to help drive positive social impact in our communities. Learn more about Chenega's impact on the world. Chenega MIOS News- Tips from your Talent Acquisition Team We want job seekers exploring opportunities at Chenega MIOS to feel prepared and confident. To help you with your research, we suggest you review the following links: Chenega MIOS web site - Glassdoor at-Chenega-MIOS- EI_IE369514.11,23.htm LinkedIn - Facebook -
Security Control Assessor (SME), Level III
OneZero Solutions Curtis Bay, Maryland
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details
09/15/2026
Full time
Job Description Job Description We are an employee-centric company that truly values our team members and the contributions they make to our customers and the missions they support. We pride ourselves on being forward-leaning thinkers and on building teams that are, and continue to be, technically proficient across a broad range of cyber mission areas. OneZero full-time employees receive a highly competitive benefits package, including health, dental, vision, and life insurance, a 401(k) with company matching, paid time off and holidays, an employee referral program, and educational assistance. Additional details are available on our website: Position Title : Security Control Assessor (SME), Level IIILocation: USCG Surface Forces Logistics Center, 2401 Hawkins Point Road, Baltimore, MD 21226. Work may also be performed at the SFLC satellite offices at 707 East Ordnance Road, approximately one mile from the primary site, and at other sites as determined necessary by the Contracting Officer's Representative (COR).Clearance:No security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.Position SummaryThe Security Control Assessor (SCA) provides independent security control assessment and authorization support to the USCG SFLC Business Operations Division in support of Surface Domain Operational Technology (OT) and Platform IT systems. The role is the assessment authority on the team: it evaluates whether security and privacy controls are implemented correctly, operating as intended, and producing the intended outcome, and it provides the evidence the Authorizing Official relies on to make risk decisions.This is the senior assessment position on the task order and is distinct from the ISSO roles, which own and maintain the authorization packages. The SCA assesses; the ISSOs prepare and sustain. The position is expected to operate with a high degree of independence and to advise the OT Security Manager (ISSM) directly.Key ResponsibilitiesSupport the OT Security Manager (ISSM) and staff in establishing and maintaining the programs, procedures, and policies that protect Government Sensitive But Unclassified (SBU) information.Perform independent assessments of SFLC Operational Technology to verify that applicable security and privacy controls are implemented correctly, operating as intended, and producing the desired outcome.Provide security assessment and authorization consultation services to the ISSM, on site.Review existing policies, procedures, and guidelines for compliance with DHS, USCG, and DoD cybersecurity policy; draft or revise SFLC policy documentation for ISSM review, approval, and organizational implementation.Assist in preparing RMF security authorization documentation for submission to the Authorizing Official (AO).Maintain security assessment information and supporting documentation within Government-designated systems and repositories.Create and validate SFLC security assessment and authorization accounts within Government-designated systems and tools.Update and maintain assessment and authorization status within Government-designated tracking systems and databases.Upload, track, and update Plans of Action and Milestones (POA recommend POA&M updates based on assessment results and maintain traceability from identified vulnerabilities through to the applicable POA&M.Conduct vulnerability scans of SFLC OT, networks, devices, and associated components using Government-approved tools.Provide assistance to system administrators in remediating vulnerabilities identified through scanning.Provide vulnerability and risk management support in conjunction with assessment and authorization activities.Maintain the enterprise tracking log for electronic spillage activities in accordance with Government policy.Support the destruction of removable media generated during assessment activities in accordance with Government procedures.Support cybersecurity strategic planning and continuous monitoring activities, evaluating enterprise services through assessment of priorities and risk.Provide bi-weekly status reports to the SFLC OT Security Manager (ISSM).Conduct a monthly project status update briefing to the ISSM at SFLC Baltimore.Required QualificationsExperienceTen (10) or more years of progressive cybersecurity experience, including at least five (5) years performing security control assessments or independent A&A validation in a federal environment.Demonstrated experience executing NIST SP 800-37 RMF end to end, including control assessment against NIST SP 800-53A.Experience assessing systems to a formal authorization decision and producing assessment artifacts relied upon by an Authorizing Official.Experience conducting and interpreting vulnerability scans and translating findings into risk-based recommendations and POA&M entries.Experience drafting and revising organizational cybersecurity policy for Government review and adoption.CertificationMust hold and maintain at least one active certification approved for Information Assurance Management (IAM) Level II or Level III. Any one of the following satisfies the requirement:CISSP - Certified Information Systems Security Professional (or CISSP Associate)CISM - Certified Information Security ManagerCGRC - Governance, Risk and Compliance Certification (formerly CAP)CASP+ - CompTIA Advanced Security PractitionerGSLC - GIAC Security Leadership CertificationCCISO - EC-Council Certified Chief Information Security Officer (Level III only)Certification requirements are subject to confirmation against COMDTINST M2620.2 (series) Appendix D, the controlling USCG certification matrix. Verify the accepted certification list with the Program Manager before extending an offer.Evidence of active certification in good standing is required prior to onboarding. Waivers and exceptions to certification requirements will not be granted.Certifications must remain current, active, and in good standing throughout performance. Loss, lapse, or revocation of a required certification is grounds for removal from the contract. Continuing education required to maintain certification is at the employee's and company's expense.Ability to work independently and advise a Government security manager at the senior level.Strong written communication: the role produces bi-weekly written reporting and briefs the ISSM monthly.Ability to read, write, speak, and understand English fluently.Preferred QualificationsPrior USCG, DHS, or DoD assessment experience, particularly with Surface Domain OT or Platform IT systems.Familiarity with COMDTINST M2620.2 (series) and COMDTINST 5500.13 (series).Experience assessing OT/ICS or PIT systems where conventional endpoint tooling cannot be deployed.CGRC (formerly CAP), CISA, or GSNA in addition to the required baseline certification.Experience supporting DHS SELC-aligned programs.Master's degree in cybersecurity, information systems, or a related field.Technical SkillsNIST SP 800-37 (RMF), 800-53 / 53A / 53B, 800-137 (ISCM), FIPS 199 and FIPS 200DHS 4300A Sensitive Systems Handbook and the DHS Systems Engineering Life Cycle (SELC)Government-designated A&A repositories and tracking tools (e.g., eMASS or successor)DISA Security Technical Implementation Guides (STIGs) and Security Requirements Guides (SRGs)Government-approved vulnerability scanning and compliance tooling (e.g., ACAS/Nessus, SCAP-validated scanners)POA&M development, tracking, and closure, including waiver and risk acceptance packagesOperational Technology (OT), Platform IT (PIT), and industrial control system environments, including constraints on agent-based toolingNIST SP 800-30 risk assessment methodology and NIST SP 800-115 technical assessment techniquesElectronic spillage handling and removable media sanitization proceduresSecurity ClearanceNo security clearance required. This position does not involve access to classified information or classified IT systems.S. citizenship is required in accordance with HSAR 3052.204-71 Alternate I.A favorably adjudicated Tier 1 background investigation (or higher) is required. Candidates without an existing investigation on file must complete an Electronic Application (eApp) for investigation processing.Note to recruiting: per the task order, the position is not billable until the selected candidate is fully cleared, has a CAC in hand, and has reported to the work site. Fill timelines should assume 30-90 days for investigation and CAC issuance.EducationBachelor 's degree in cybersecurity, computer science, information systems, engineering, or a related field.Work EnvironmentPrimarily on-site at SFLC Baltimore. On-site presence is required for the monthly status briefing to the ISSM and for participation in change management boards, technical exchange meetings, and Government working groups.The Government furnishes workspace, telephone, a Standard Workstation, and copy/fax access.Remote work may be authorized at the sole discretion of the Government. If authorized, compliant hardware, software, and internet service are contractor- furnished.Occasional travel outside the local commuting area may be required for training and associated off-site meetings, subject to advance COR approval and reimbursed per the Federal Travel Regulations. The 707 East Ordnance Road satellite office is within the local commuting area.OneZero Solutions, LLC is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, pregnancy, genetic information, disability, status as a protected veteran, or any other protected category under applicable federal, state, and local laws.To request an accommodation . click apply for full job details

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board