it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

383 jobs found

Email me jobs like this
Refine Search
Current Search
senior ai security technical architect
Network & Cybersecurity Systems Engineer
Evolv Technologies Inc. Waltham, Massachusetts
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/24/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Network Security Engineer
SMART TECH SKILLS LLC Reading, Pennsylvania
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
09/24/2026
Full time
Job Description Job Description Benefits: Competitive salary 6-Month Contract-to-Hire (CTH) Experience Level Senior Level (5 or more years of experience) Role Overview The Network Security Engineer serves as a technical Subject Matter Expert (SME) responsible for designing, deploying, administering, and optimizing enterprise network security infrastructure. This role focuses on architecting and managing Palo Alto Networks Next-Generation Firewalls (NGFWs), Cisco Firepower/ASA firewalls, Cisco ISE (Identity Services Engine), VPN infrastructure, and SD-WAN security to protect network perimeters and secure multi-site data flows across a regulated financial institution. Key Responsibilities Firewall Engineering & Perimeter Defense • Design, deploy, and manage Palo Alto Networks Next-Generation Firewalls (NGFWs) using Panorama, configuring NAT, App-ID, User-ID, Threat Prevention, URL Filtering, and WildFire. • Administer and maintain Cisco ASA and Firepower (FTD/FMC) firewalls, managing access control policies, IPS tuning, and platform lifecycle upgrades. • Lead investigations and incident responses for network-layer security alerts, policy violations, and anomalies. Network Access Control & Secure Connectivity • Administer Cisco Identity Services Engine (ISE) for Network Access Control (NAC), 802.1X authentication, RADIUS/TACACS+, device profiling, and guest access. • Manage and maintain VPN infrastructure (Cisco AnyConnect / Secure Access and site-to-site IPSec tunnels), supporting certificate-based authentication and split-tunnel configurations. • Configure and secure Cisco Catalyst SD-WAN environments, enforcing application-aware policies, traffic segmentation, and encrypted transport. • Administer Cisco Umbrella / Secure Access DNS-layer security, category-based controls, and web filtering policies. Architecture, Compliance, & Change Management • Collaborate with Cloud, Infrastructure, and Information Security teams to implement network segmentation, zero-trust controls, and security standards aligned with PCI-DSS, SOX, and NIST frameworks. • Author, review, and execute ITIL-aligned change management requests, presenting to Change Advisory Boards (CAB) and conducting post-implementation reviews. • Maintain comprehensive technical documentation, including firewall rulesets, network security architecture diagrams, runbooks, and standard operating procedures (SOPs). Required Qualifications • 5 or more years of hands-on experience in network security engineering, enterprise firewall administration, and perimeter security (CCNP Security-level expertise). • 3 or more years of hands-on experience designing, deploying, and managing Palo Alto Networks NGFWs and Panorama. • Solid hands-on experience administering Cisco ASA and Firepower (FTD/FMC) firewall environments, access control policies, and platform upgrades. • Strong working knowledge of Cisco ISE for NAC, 802.1X, RADIUS/TACACS+, and device profiling. • Experience configuring and troubleshooting enterprise VPN solutions (Cisco AnyConnect, Secure Access, IPSec site-to-site tunnels). • Solid understanding of core networking protocols, routing, and security concepts (TCP/IP, BGP, EIGRP, ACLs, NAT, SSL/TLS inspection, network micro-segmentation). • Experience working within an ITIL-based change management framework. • Must be legally authorized to work in the United States without current or future visa sponsorship. Preferred Qualifications • Industry certifications such as Palo Alto Networks Certified Network Security Engineer (PCNSE), Cisco Certified Network Professional Security (CCNP Security), or CCIE Security. • Familiarity with financial regulatory frameworks and compliance standards (e.g., FFIEC, PCI-DSS, SOX, NIST CSF). • Experience with Microsoft Azure networking and cloud security (Azure Firewall, NSGs, Virtual WAN, ExpressRoute). • Experience utilizing automation scripts (e.g., Python, Ansible) for firewall configuration and policy management. Core Skills & Attributes • Exceptional analytical, problem-solving, and root-cause diagnostic abilities for complex network security issues. • High accountability and attention to detail when executing production changes and maintaining documentation. • Excellent interpersonal and communication skills to collaborate with cross-functional IT teams, security leaders, and external auditors. • Self-driven approach to continuous learning and staying current with evolving cybersecurity threats. Flexible work from home options available.
Senior Network Security Engineer
Penumbra Alameda, California
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
09/24/2026
Full time
Job Description Job Description As a Senior Network Security Engineer at Penumbra, you will play a critical role in determining the company's long term goals. You will be a key member of the Information Security and Compliance team. This is a highly technical, hands-on role. The Sr. Network Engineer will collaborate with Security, IT, Manufacturing, and Engineering teams and be responsible for engineering solutions and supporting operational activities across a hybrid cloud environment. The role responsibilities include ensuring compliance with legal and regulatory requirements and maintaining company security policies, standards, and industry's best practices. What You'll Work On • Ensure the network security of on-premises and cloud-based systems, networks, infrastructure, and services. • Enforce secure design standards and specifications for services, systems, and products. • Responsible for network security solutions, control designs, and enforcement across our environment. • Design and perform security assessments, configuration verification, configuration reporting, and other activities to validate control effectiveness. • Engage and share results of security audits with the Information Security and business partners to promote changes vital to improve risk posture. • Collaborate with cross-functional teams to develop and implement security measures supporting on-prem and cloud systems. • Develop roadmaps, standards, and documentation for technical solutions and existing configurations. Serve as the subject matter expert across the network security environment. • Respond to and lead, as appropriate, incident response activities for security incidents. • Collaborate with IT and line of business teams to integrate security into new and existing systems, processes, and initiatives. • Manage and configure security services, e.g., firewalls, intrusion detection/prevention systems, threat prevention technologies, VPNs, and other network security appliances. • Create and maintain documentation for security procedures, designs, and protocols, conduct security training and awareness for staff as appropriate to the role. • Stay current with emerging security threats and technologies in the security landscape. Ensure compliance with regulatory requirements and industry standards in the Company's environment. What You Contribute • A Bachelor's degree in computer science or related field with 10+ years of related experience, or equivalent combination of education and experience. • Master's degree preferred in Computer Science or Engineering with an emphasis in Computer Security or a related field • Highly analytical and results and process-oriented mindset strongly desired • 10+ years of hands-on design, enforcement and testing/validation of offensive security, defensive security, systems, and solutions engineering in a large enterprise • 5+ years of hands-on security experience with cloud platforms, i.e., Azure, AWS or Google Cloud Platform services, automation, or IaC • 5+ years of hands-on experience network security experience and expert-level knowledge on security technologies such as Palo Alto Firewalls, Cisco ISE, IPS, CASB, VPN management, SAML/OIDC NAC 802.1X, SIEM, SOAR, Radius/TACACS+, directory services • Proficient with network topologies, routing protocols, i.e., OSPF, BGP, ISIS, SDN, and tunneling technologies. • Proficient with diagramming and threat models, ability and competency to design and implement controls at scale based on risks • Proficient in conducting solutions architecture, security design reviews, passionate about security and privacy research, technologies, and methods. • Possess an understanding of past and emerging security exploits, threat actor motivations, and trends • Understanding security and compliance frameworks, security engineering, software delivery, and SDLC in a hybrid environment • Outstanding ethical standards and integrity. • Excellent communicator with strong oral, written, and interpersonal communication skills • High degree of accuracy and attention to detail • Proficiency with Microsoft Word, Excel, Visio, and PowerPoint • Excellent organizational skills with the ability to prioritize assignments while handling various projects simultaneously. Working Conditions General office environment. Willingness and ability to work on site. May have business travel up to 10%. Requires some lifting and moving of up to 10 pounds Must be able to move between buildings and floors. Must be able to remain stationary and use a computer or other standard office equipment, such as a printer or copy machine, for an extensive period of time each day. Must be able to read, prepare emails, and produce documents and spreadsheets. Must be able to move within the office and access file cabinets or supplies, as needed. Must be able to communicate and exchange accurate information with employees at all levels on a daily basis. Annual Base Salary Range: $146,000 - $220,000/ year We offer a competitive compensation package plus a benefits and equity program, when applicable. Individual total compensation will vary based on factors such as qualifications, skill level, competencies, and work location. What We Offer • A collaborative teamwork environment where learning is constant, and performance is rewarded. • The opportunity to be part of the team that is revolutionizing the treatment of some of the world's most devastating diseases. • A generous benefits package for eligible employees that includes medical, dental, vision, life, AD&D, short and long-term disability insurance, 401(k) with employer match, paid parental leave, eleven paid company holidays per year, a minimum of fifteen days of accrued vacation per year, which increases with tenure, and paid sick time in compliance with applicable law(s). Penumbra, Inc., headquartered in Alameda, California, is a global healthcare company focused on innovative therapies. Penumbra designs, develops, manufactures, and markets novel products and has a broad portfolio that addresses challenging medical conditions in markets with significant unmet need. Penumbra sells its products to hospitals and healthcare providers primarily through its direct sales organization in the United States, most of Europe, Canada, and Australia, and through distributors in select international markets. The Penumbra logo is a trademark of Penumbra, Inc. Qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, age, disability, military or veteran status, or any other characteristic protected by federal, state, or local laws. If you reside in the State of California, please also refer to Penumbra's Privacy Notice for California Residents. For additional information on Penumbra's commitment to being an equal opportunity employer, please see Penumbra's AAP Policy Statement.
Principal Spacecraft Operations Engineer - Secret Clearance
Rocket Lab Corporation Long Beach, California
Job Description Job Description ABOUT ROCKET LAB Rocket Lab is the end-to-end space company building rockets, spacecraft, and critical subsystems that keep the world connected, protected, expand humanity's reach to the Moon, Mars, and beyond. We move fast, build real hardware for meaningful missions, and make the impossible routine. Come shape the future with us. SPACE SYSTEMS At Rocket Lab, we're not just launching rockets - we're building the future of space. Our Space Systems team builds everything from complete spacecraft, precision payloads to the components and subsystems that allow them to thrive in space, like solar panels, flight software, star trackers, optical systems, separation systems, radios, and more. Our Space Systems team has enabled more than 1,700 missions, ranging from interplanetary exploration, in-space manufacturing to national security and defense initiatives. The team has built spacecraft, payloads, and components for missions to the Moon and Mars, working with partners including NASA, the Space Development Agency, and the U.S. Space Force. Whether it's a single high-performance spacecraft, constellation, or the vertically integrated components that help them get to space - our world class Space Systems team is empowering some of the boldest and most ambitious space missions PRINCIPAL SPACECRAFT OPERATIONS ENGINEER II- SECRET CLEARANCE Based on site at Rocket Lab's headquarters in Long Beach, CA the PrincipalSpacecraft Operations Engineer is responsible for ensuring the health, safety, and optimal performance of a growing fleet of satellites while meeting mission objectives and SLAs for both commercial and government customers. This includes supporting diverse missions such as LEO constellations, interplanetary exploration, LEO rendezvous, and SDA-related deployments. Your expertise would be critical during commissioning, orbit raising, routine operations, and potentially re-entry phases, ensuring the health and safety of Rocket Lab's expanding fleet. The Spacecraft Operations team works closely with related teams, such as spacecraft design, AIT, flight software, propulsion, GNC, flight dynamics and ground software development to help improve both the ground and satellite-based capabilities over time. The space operations experience at Rocket Lab is unique because you will cover a multitude of roles/positions and responsibilities, with the large majority of the technical products being supplied through the vertical integration/in-house. WHAT YOU'LL GET TO DO: Serve as the program's mission operations technical lead: set the technical direction and strategy for operations, plan and prioritize the work of the mission operations staff, and act as the primary operations point of contact for program-level design decisions and trades Advocate for operability across the program: influence spacecraft and ground architecture upstream so vehicles are designed to be operated safely, efficiently, and autonomously, and push for changes to program design and execution when operational needs demand it Own mission operations requirements and lead requirements validation and verification for spacecraft missions and system-level capability and function Define the automation strategy and lead the development of robust, software-driven methods for mission operations, testing, and data analysis to ensure efficient, repeatable, and reliable spacecraft operation Design, develop, and test flight software sequences and FDIR/telemetry configurations to ensure spacecraft health and fault management through software-driven processes Architect, develop, and test ground software for long-duration operations, including scripting and automation frameworks that make operations robust, hands-off, and scalable across a growing fleet Establish and steward the integration, testing, and maintenance of mission operations tooling and codebases, including CI, version control, and release discipline. Ensure the on-call or shift schedules of operations Author and own interface specifications, CONOPS, contingency procedures, and other operational design documents Lead validation of flight products and procedures against spacecraft simulation tools, including flatsat, HITL, SIL, and digital twins Support AIT teams across multiple spacecraft integrated tests (TVAC, propulsion stack, DITL Provide program and product support to team leads and program managers, and serve as a key technical interface between the NZ and USA engineering teams Represent mission operations in program milestone reviews, design reviews, and readiness gates, and drive continuous improvement through post-mission lessons learned YOU'LL BRING THESE QUALIFICATIONS AS A PRINCIPALSPACECRAFT OPERATIONS ENGINEER: Bachelor's degree in engineering (software, computer, electrical, aerospace, mechanical, or other technical engineering discipline) 12+ years of direct experience in any of the following: space mission design, satellite subsystems, ground systems, spacecraft command control, or spacecraft operations 5+ years of experience leading teams of engineers through spacecraft missions or related aerospace projects Previous experience in roles such as Mission Lead, Mission Director, Flight Director, or Senior Spacecraft Operations Engineer Previous experience supporting mission operations activities in an on-console or operator-in-the-loop capacity Thorough understanding of key spacecraft subsystems and associated components, including attitude determination and control systems (ADCS), electrical power systems (EPS), space-to-ground communications, command and data handling (C&DH), thermal control systems (TCS), spacecraft propulsion systems, and fault detection, isolation, and recovery (FDIR) Understanding of the space environment, orbital mechanics, and rigid body dynamics 5+ years of direct software development experience (Python/Ruby/C/C++/other high-level languages), covering items such as spacecraft onboard flight scripts, ground scripting and automation, and data manipulation and analysis US citizenship is required due to program requirements Active U.S. Government Secret Security Clearance THESE QUALIFICATIONS WOULD BE NICE TO HAVE: Master's or PhD engineering in engineering (software, computer, electrical, aerospace, mechanical, or other technical engineering discipline) Prior experience in spacecraft operations Prior experience in satellite system design Prior experience in satellite ground systems Exposure to modern development practices - GIT, CI/CD, cloud infrastructure Proficiency with Agile issue-tracking tools, specifically Jira, for mission task management, status tracking, and bug reporting Software-in-the-Loop (SIL) Testing: Exposure to testing frameworks that simulate software behavior in operational environments. Hardware-in-the-Loop (HIL) Testing: Familiarity with testing frameworks that integrate software and hardware systems. Active TS/SCI U.S. Government Security Clearance This position may require prolonged periods of sitting, standing, walking, computer work, and occasional exposure to moderate levels of noise, dust, and fumes in production areas Anticipated annual equity grant value is designed around function, level, experience, and other factors; realized value depends on vesting and stock-price performance. Join one of the world's fastest-growing space companies and own a piece of it. In addition to competitive base pay, you'll receive company stock as part of your total compensation package, giving you a direct stake in our success. As we expand to new launch sites, groundbreaking missions, and global markets, your ownership has the opportunity to grow alongside the company. Our comprehensive benefits package includes our industry-leading Employee Stock Purchase Program (with a 15% discount on company stock), top-tier medical plans (HMO, PPO, and a zero cost HDHP option with a significant HSA company contribution), dental and vision coverage, paid vacation and sick time, 11 paid holidays, flexible spending and dependent care accounts, paid parental leave, disability and life insurance, and a 401(k) retirement plan with company match. Additional perks include subsidized EV charging, onsite fitness centers (where available), discounted gym memberships, complimentary snacks and beverages, 50% employee discount on our popular merch store, and a variety of other employee discounts. Level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Total Compensation (base and equity) $223,025-$339,400 USD Base Salary $173,300-$259,850 USD WHAT TO EXPECT We're on a mission to unlock the potential of space to improve life on Earth, but that's not an easy task. It takes hard work, determination, relentless innovation, teamwork, grit, and an unwavering commitment to achieving what others often deem impossible. Our people out-think, out-work, and out-pace. We pride ourselves on having each other's backs, checking our egos at the door, and rolling up our sleeves on all tasks big and small. We thrive under pressure, work to tight deadlines, and our focus is always on how we can deliver, rather than dwelling on the challenges that stand in the way. Important information: . click apply for full job details
09/24/2026
Full time
Job Description Job Description ABOUT ROCKET LAB Rocket Lab is the end-to-end space company building rockets, spacecraft, and critical subsystems that keep the world connected, protected, expand humanity's reach to the Moon, Mars, and beyond. We move fast, build real hardware for meaningful missions, and make the impossible routine. Come shape the future with us. SPACE SYSTEMS At Rocket Lab, we're not just launching rockets - we're building the future of space. Our Space Systems team builds everything from complete spacecraft, precision payloads to the components and subsystems that allow them to thrive in space, like solar panels, flight software, star trackers, optical systems, separation systems, radios, and more. Our Space Systems team has enabled more than 1,700 missions, ranging from interplanetary exploration, in-space manufacturing to national security and defense initiatives. The team has built spacecraft, payloads, and components for missions to the Moon and Mars, working with partners including NASA, the Space Development Agency, and the U.S. Space Force. Whether it's a single high-performance spacecraft, constellation, or the vertically integrated components that help them get to space - our world class Space Systems team is empowering some of the boldest and most ambitious space missions PRINCIPAL SPACECRAFT OPERATIONS ENGINEER II- SECRET CLEARANCE Based on site at Rocket Lab's headquarters in Long Beach, CA the PrincipalSpacecraft Operations Engineer is responsible for ensuring the health, safety, and optimal performance of a growing fleet of satellites while meeting mission objectives and SLAs for both commercial and government customers. This includes supporting diverse missions such as LEO constellations, interplanetary exploration, LEO rendezvous, and SDA-related deployments. Your expertise would be critical during commissioning, orbit raising, routine operations, and potentially re-entry phases, ensuring the health and safety of Rocket Lab's expanding fleet. The Spacecraft Operations team works closely with related teams, such as spacecraft design, AIT, flight software, propulsion, GNC, flight dynamics and ground software development to help improve both the ground and satellite-based capabilities over time. The space operations experience at Rocket Lab is unique because you will cover a multitude of roles/positions and responsibilities, with the large majority of the technical products being supplied through the vertical integration/in-house. WHAT YOU'LL GET TO DO: Serve as the program's mission operations technical lead: set the technical direction and strategy for operations, plan and prioritize the work of the mission operations staff, and act as the primary operations point of contact for program-level design decisions and trades Advocate for operability across the program: influence spacecraft and ground architecture upstream so vehicles are designed to be operated safely, efficiently, and autonomously, and push for changes to program design and execution when operational needs demand it Own mission operations requirements and lead requirements validation and verification for spacecraft missions and system-level capability and function Define the automation strategy and lead the development of robust, software-driven methods for mission operations, testing, and data analysis to ensure efficient, repeatable, and reliable spacecraft operation Design, develop, and test flight software sequences and FDIR/telemetry configurations to ensure spacecraft health and fault management through software-driven processes Architect, develop, and test ground software for long-duration operations, including scripting and automation frameworks that make operations robust, hands-off, and scalable across a growing fleet Establish and steward the integration, testing, and maintenance of mission operations tooling and codebases, including CI, version control, and release discipline. Ensure the on-call or shift schedules of operations Author and own interface specifications, CONOPS, contingency procedures, and other operational design documents Lead validation of flight products and procedures against spacecraft simulation tools, including flatsat, HITL, SIL, and digital twins Support AIT teams across multiple spacecraft integrated tests (TVAC, propulsion stack, DITL Provide program and product support to team leads and program managers, and serve as a key technical interface between the NZ and USA engineering teams Represent mission operations in program milestone reviews, design reviews, and readiness gates, and drive continuous improvement through post-mission lessons learned YOU'LL BRING THESE QUALIFICATIONS AS A PRINCIPALSPACECRAFT OPERATIONS ENGINEER: Bachelor's degree in engineering (software, computer, electrical, aerospace, mechanical, or other technical engineering discipline) 12+ years of direct experience in any of the following: space mission design, satellite subsystems, ground systems, spacecraft command control, or spacecraft operations 5+ years of experience leading teams of engineers through spacecraft missions or related aerospace projects Previous experience in roles such as Mission Lead, Mission Director, Flight Director, or Senior Spacecraft Operations Engineer Previous experience supporting mission operations activities in an on-console or operator-in-the-loop capacity Thorough understanding of key spacecraft subsystems and associated components, including attitude determination and control systems (ADCS), electrical power systems (EPS), space-to-ground communications, command and data handling (C&DH), thermal control systems (TCS), spacecraft propulsion systems, and fault detection, isolation, and recovery (FDIR) Understanding of the space environment, orbital mechanics, and rigid body dynamics 5+ years of direct software development experience (Python/Ruby/C/C++/other high-level languages), covering items such as spacecraft onboard flight scripts, ground scripting and automation, and data manipulation and analysis US citizenship is required due to program requirements Active U.S. Government Secret Security Clearance THESE QUALIFICATIONS WOULD BE NICE TO HAVE: Master's or PhD engineering in engineering (software, computer, electrical, aerospace, mechanical, or other technical engineering discipline) Prior experience in spacecraft operations Prior experience in satellite system design Prior experience in satellite ground systems Exposure to modern development practices - GIT, CI/CD, cloud infrastructure Proficiency with Agile issue-tracking tools, specifically Jira, for mission task management, status tracking, and bug reporting Software-in-the-Loop (SIL) Testing: Exposure to testing frameworks that simulate software behavior in operational environments. Hardware-in-the-Loop (HIL) Testing: Familiarity with testing frameworks that integrate software and hardware systems. Active TS/SCI U.S. Government Security Clearance This position may require prolonged periods of sitting, standing, walking, computer work, and occasional exposure to moderate levels of noise, dust, and fumes in production areas Anticipated annual equity grant value is designed around function, level, experience, and other factors; realized value depends on vesting and stock-price performance. Join one of the world's fastest-growing space companies and own a piece of it. In addition to competitive base pay, you'll receive company stock as part of your total compensation package, giving you a direct stake in our success. As we expand to new launch sites, groundbreaking missions, and global markets, your ownership has the opportunity to grow alongside the company. Our comprehensive benefits package includes our industry-leading Employee Stock Purchase Program (with a 15% discount on company stock), top-tier medical plans (HMO, PPO, and a zero cost HDHP option with a significant HSA company contribution), dental and vision coverage, paid vacation and sick time, 11 paid holidays, flexible spending and dependent care accounts, paid parental leave, disability and life insurance, and a 401(k) retirement plan with company match. Additional perks include subsidized EV charging, onsite fitness centers (where available), discounted gym memberships, complimentary snacks and beverages, 50% employee discount on our popular merch store, and a variety of other employee discounts. Level and base salary will be determined on a case-by-case basis and may vary based on the following considerations: job-related knowledge and skills, education, and experience. Total Compensation (base and equity) $223,025-$339,400 USD Base Salary $173,300-$259,850 USD WHAT TO EXPECT We're on a mission to unlock the potential of space to improve life on Earth, but that's not an easy task. It takes hard work, determination, relentless innovation, teamwork, grit, and an unwavering commitment to achieving what others often deem impossible. Our people out-think, out-work, and out-pace. We pride ourselves on having each other's backs, checking our egos at the door, and rolling up our sleeves on all tasks big and small. We thrive under pressure, work to tight deadlines, and our focus is always on how we can deliver, rather than dwelling on the challenges that stand in the way. Important information: . click apply for full job details
Senior Network Security Engineer, Operational Technology
CoreWeave Livingston, New Jersey
Job Description Job Description CoreWeave is The Essential Cloud for AI . Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at . What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect critical infrastructure and continuously improve the security posture to meet the needs of our customers. With our growing reliance on connected technology, the need to keep critical systems secure, reliable, and resilient has never been more important. We are seeking an OT Security Engineer to join our team and play a pivotal role in safeguarding the operational technologies that support our datacenter networks. About the role: This position offers a unique opportunity to work at the crossroads of cyber security, operational technology (OT), engineering, and datacenter operations. As the network security engineer responsible for our operational technology networks, your responsibilities will include identifying and evaluating cybersecurity risks, designing and launching pragmatic security solutions, and embedding security controls directly into the operational systems and technologies supporting our infrastructure. You will work with suppliers and third parties in benchmarking their capabilities against expectations and industry standards. You will also lead efforts in partnering with peer security teams and partners in production engineering as you lead continuous improvement of security posture for operational technology network environments and the devices connected. This role requires both depth in understanding network security, and breadth of knowledge of the unique challenges that face the industry in securing the infrastructure that is the foundation of modern datacenters. You will act as a trusted partner who goes beyond advisory work to roll up your sleeves and deliver. Some things you will work on: Establishing standards for security expectations covering all operational technology networks and devices connected to them. This will include network segmentation, host isolation, network traversal controls, and remote connectivity. Providing solutions to complex security issues, manage multiple tasks, and prioritize effectively in a fast-paced environment. Creating an inventory and risk register that can be used as a baseline in understanding near term and long term objectives. Partnering with production engineering and business development teams evaluating priorities for risk reduction in current deployments, and risk avoidance by evolving standards for future growth. Executing and partnering with other parties in using penetration testing to evaluate effectiveness of existing controls. Coordinating with third parties and internal teams in addressing vulnerabilities via mitigation, isolation or other strategies to protect critical infrastructure in these environments. Researching industry risks and drive change in operational networks to continuously reduce risk Developing and test recovery models and response playbooks to handle compromise scenarios. Presenting technical security information to both technical and non-technical audiences, including external partners. Maintain technical documentation, reports, and security tooling with attention to detail. Who You Are: 5+ Years of experience in network infrastructure security (firewalls, ACLs, architecture, risk management) in a global network environment. Proficiency in at least one programming or scripting language (e.g., Go, Python, C/C++) for automation, code reviews, and tooling. Bachelor's degree in Computer Science or related field. Relevant certifications such as CISSP, CCNP, PCNSE are advantageous. Experience with operational technology networks (factory or industrial systems, building management systems, power, physical security systems, remote access, HVAC, etc.), factory networks or other similar environments. Strong technical knowledge of network firewalls, virtual private networks, network segmentation, and defense in depth. Able to navigate ambiguity, identify root causes, and solve complex security problems. Excellent written and verbal communication skills with strong technical documentation abilities. Capable of working independently while managing multiple priorities in a fast-paced environment. Strong desire to continuously learn and adopt new technologies and security techniques. Preferred: Prior experience with operational technology networks that span global locations Experience with the range of obscure solutions that are often deployed on operational technology networks. Deep understanding of business-wide security best practices and implementation strategies. Experience with network automation, agentic network tooling, and incident response automation. Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk. You love to solve problems that few others would tackle. You're curious about critical network infrastructure that is the foundation of modern data centers. You're an expert in network security with a passion to explore the more exotic nature of operational technology. Why CoreWeave? At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your Core Act Like an Owner Empower Employees Deliver Best-in-Class Client Experiences Achieve More Together We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $164,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We Offer The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include: Medical, dental, and vision insurance - 100% paid for by CoreWeave Company-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending Account Health Savings Account Tuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP) Mental Wellness Benefits through Spring Health Family-Forming support provided by Carrot Paid Parental Leave Flexible, full-service childcare support with Kinside 401(k) with a generous employer match Flexible PTO Catered lunch each day in our office and data center locations A casual work environment A work culture focused on innovative disruption California Applicants California Consumer Privacy Act Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA) , CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: . . click apply for full job details
09/24/2026
Full time
Job Description Job Description CoreWeave is The Essential Cloud for AI . Built for pioneers by pioneers, CoreWeave delivers a platform of technology, tools, and teams that enables innovators to build and scale AI with confidence. Trusted by leading AI labs, startups, and global enterprises, CoreWeave combines superior infrastructure performance with deep technical expertise to accelerate breakthroughs and turn compute into capability. Founded in 2017, CoreWeave became a publicly traded company (Nasdaq: CRWV) in March 2025. Learn more at . What You'll Do: CoreWeave's Network Security team ensures network infrastructure is secure, resilient and compliant. Our team partners with engineering, product teams, and partners to build secure network solutions that protect critical infrastructure and continuously improve the security posture to meet the needs of our customers. With our growing reliance on connected technology, the need to keep critical systems secure, reliable, and resilient has never been more important. We are seeking an OT Security Engineer to join our team and play a pivotal role in safeguarding the operational technologies that support our datacenter networks. About the role: This position offers a unique opportunity to work at the crossroads of cyber security, operational technology (OT), engineering, and datacenter operations. As the network security engineer responsible for our operational technology networks, your responsibilities will include identifying and evaluating cybersecurity risks, designing and launching pragmatic security solutions, and embedding security controls directly into the operational systems and technologies supporting our infrastructure. You will work with suppliers and third parties in benchmarking their capabilities against expectations and industry standards. You will also lead efforts in partnering with peer security teams and partners in production engineering as you lead continuous improvement of security posture for operational technology network environments and the devices connected. This role requires both depth in understanding network security, and breadth of knowledge of the unique challenges that face the industry in securing the infrastructure that is the foundation of modern datacenters. You will act as a trusted partner who goes beyond advisory work to roll up your sleeves and deliver. Some things you will work on: Establishing standards for security expectations covering all operational technology networks and devices connected to them. This will include network segmentation, host isolation, network traversal controls, and remote connectivity. Providing solutions to complex security issues, manage multiple tasks, and prioritize effectively in a fast-paced environment. Creating an inventory and risk register that can be used as a baseline in understanding near term and long term objectives. Partnering with production engineering and business development teams evaluating priorities for risk reduction in current deployments, and risk avoidance by evolving standards for future growth. Executing and partnering with other parties in using penetration testing to evaluate effectiveness of existing controls. Coordinating with third parties and internal teams in addressing vulnerabilities via mitigation, isolation or other strategies to protect critical infrastructure in these environments. Researching industry risks and drive change in operational networks to continuously reduce risk Developing and test recovery models and response playbooks to handle compromise scenarios. Presenting technical security information to both technical and non-technical audiences, including external partners. Maintain technical documentation, reports, and security tooling with attention to detail. Who You Are: 5+ Years of experience in network infrastructure security (firewalls, ACLs, architecture, risk management) in a global network environment. Proficiency in at least one programming or scripting language (e.g., Go, Python, C/C++) for automation, code reviews, and tooling. Bachelor's degree in Computer Science or related field. Relevant certifications such as CISSP, CCNP, PCNSE are advantageous. Experience with operational technology networks (factory or industrial systems, building management systems, power, physical security systems, remote access, HVAC, etc.), factory networks or other similar environments. Strong technical knowledge of network firewalls, virtual private networks, network segmentation, and defense in depth. Able to navigate ambiguity, identify root causes, and solve complex security problems. Excellent written and verbal communication skills with strong technical documentation abilities. Capable of working independently while managing multiple priorities in a fast-paced environment. Strong desire to continuously learn and adopt new technologies and security techniques. Preferred: Prior experience with operational technology networks that span global locations Experience with the range of obscure solutions that are often deployed on operational technology networks. Deep understanding of business-wide security best practices and implementation strategies. Experience with network automation, agentic network tooling, and incident response automation. Wondering if you're a good fit? We believe in investing in our people, and value candidates who can bring their own diversified experiences to our teams - even if you aren't a 100% skill or experience match. Here are a few qualities we've found compatible with our team. If some of this describes you, we'd love to talk. You love to solve problems that few others would tackle. You're curious about critical network infrastructure that is the foundation of modern data centers. You're an expert in network security with a passion to explore the more exotic nature of operational technology. Why CoreWeave? At CoreWeave, we work hard, have fun, and move fast! We're in an exciting stage of hyper-growth that you will not want to miss out on. We're not afraid of a little chaos, and we're constantly learning. Our team cares deeply about how we build our product and how we work together, which is represented through our core values: Be Curious at Your Core Act Like an Owner Empower Employees Deliver Best-in-Class Client Experiences Achieve More Together We support and encourage an entrepreneurial outlook and independent thinking. We foster an environment that encourages collaboration and enables the development of innovative solutions to complex problems. As we get set for takeoff, the organization's growth opportunities are constantly expanding. You will be surrounded by some of the best talent in the industry, who will want to learn from you, too. Come join us! The base salary range for this role is $164,000 to $242,000. The starting salary will be determined based on job-related knowledge, skills, experience, and market location. We strive for both market alignment and internal equity when determining compensation. In addition to base salary, our total rewards package includes a discretionary bonus, equity awards, and a comprehensive benefits program (all based on eligibility). What We Offer The range we've posted represents the typical compensation range for this role. To determine actual compensation, we review the market rate for each candidate which can include a variety of factors. These include qualifications, experience, interview performance, and location. In addition to a competitive salary, we offer a variety of benefits to support your needs. The benefits below reflect our US-based offerings for full-time employees; for roles in other locations, benefits vary and are shared during the hiring process. These include: Medical, dental, and vision insurance - 100% paid for by CoreWeave Company-paid Life Insurance Voluntary supplemental life insurance Short and long-term disability insurance Flexible Spending Account Health Savings Account Tuition Reimbursement Ability to Participate in Employee Stock Purchase Program (ESPP) Mental Wellness Benefits through Spring Health Family-Forming support provided by Carrot Paid Parental Leave Flexible, full-service childcare support with Kinside 401(k) with a generous employer match Flexible PTO Catered lunch each day in our office and data center locations A casual work environment A work culture focused on innovative disruption California Applicants California Consumer Privacy Act Equal Opportunity & Accommodations CoreWeave is an equal opportunity employer, committed to fostering an inclusive and supportive workplace. All qualified applicants and candidates will receive consideration for employment without regard to race, color, religion, sex, disability, age, sexual orientation, gender identity, national origin, veteran status, or genetic information. As part of this commitment and consistent with the Americans with Disabilities Act (ADA) , CoreWeave will ensure that qualified applicants and candidates with disabilities are provided reasonable accommodations for the hiring process, unless such accommodation would cause an undue hardship. If reasonable accommodation is needed, please contact: . . click apply for full job details
CSfC Sr. Network Engineer
TekSynap Aiea, Hawaii
Job Description Job Description Overview We are seeking a CSfC Senior Network Engineer to join our team supporting Network Enterprise Technology Command (NETCOM) in Honolulu, HI. TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at . Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Responsibilities RESPONSIBILITIES Assists the PM in the day-to-day management of leading Network Engineers. Must have an in-depth understanding of advanced networking O&M Commercial Solutions for Classified (CSfC) concepts and processes and experience applying these with little to no guidance. Must be able to provide guidance to others. Must be able to perform successfully in complex, unstructured situations. Must be proficient in multivendor networking environments in configuring firewalls, Intrusion Prevention/Detection systems, VPN gateways, routers, and switches (Cisco, Aruba, Juniper, Cisco ASA, etc.) Be able to develop and modify system scripts. Write standardized system documentation, including configuration guides, test procedures, test results, and training materials. Provide onsite training to technical and non-technical users on the daily use, management, and troubleshooting of the solution after installation. Support all Cross-Domain solution requirements Collaborate with other operations departments to design approved infrastructure Serve as the escalation contact during large outages for Tier 2 and 3 systems. Author network Engineering Design Packages to include detailed implementation project plans and procedures. Configures network, software, and hardware components to meet NSA CSfC, NIAP, and DoD requirements Performs network design and systems integration Designs, develops, implements, tests, and maintains complex secure communications networks Configuring/managing PKI Certificate Authorities for CSfC solutions Familiarity with Certificate Authority configuration (ISC CertAgent/MS Windows Server/Red Hat Certificate systems) Document configuration, test procedure, results, and training materials Preparing test reports and configuration documentation according to customer standards. Providing customer on-site training on solution daily use, management, and troubleshooting Provide tier 2 and 3 support as part of a technical team. Identify and recommend hardware and support solutions based on research and analysis of new technologies, interfacing with customers and vendors. Enhance department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to the company. Apply DoD STIGs and IAVAs Perform special projects and other duties as assigned. REQUIRED QUALIFICATIONS Top Secret OR Higher OR Secret Clearance level with completed T5 investigation Active Professional Network certification (CCNP-Security, CCNA, HPE Aruba Networking Certified Professional - Switching, etc.) Must have experience with one or more networking vendors: Cisco, Aruba, Juniper, etc. One of the following DoD8140 Certifications : SecurityX/CASP+ CCNA CCNP Security CCSP (Certified Cloud Security Professional) GCED (GIAC Certified Enterprise Defender) GCIA (GIAC Certified Intrusion Analyst) GCLD (GIAC Cloud Security Essentials) GDSA (GIAC Defensible Security Architecture) GFACT (GIAC Foundational Cybersecurity Technologies) 10 or more years of experience in engineering MA/MS= 10 years; BS=12 years Qualifications WORK ENVIRONMENT AND PHYSICAL DEMANDS The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: Honolulu, HI Type of environment: Office Noise level: Low Work schedule: CONUS Schedule is day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 20% PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WORK AUTHORIZATION/SECURITY CLEARANCE United States Citizenship Top Secret Clearance requirement WAGE INFORMATION Target salary range: $133,000.00 - $165,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. EQUAL EMPLOYMENT OPPORTUNITY In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
09/24/2026
Full time
Job Description Job Description Overview We are seeking a CSfC Senior Network Engineer to join our team supporting Network Enterprise Technology Command (NETCOM) in Honolulu, HI. TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. Visit us at . Apply now to explore jobs with us! The safety and health of our employees is of the utmost importance. Employees are required to comply with any vaccination requirements mandated by contract, applicable law or regulation. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. Responsibilities RESPONSIBILITIES Assists the PM in the day-to-day management of leading Network Engineers. Must have an in-depth understanding of advanced networking O&M Commercial Solutions for Classified (CSfC) concepts and processes and experience applying these with little to no guidance. Must be able to provide guidance to others. Must be able to perform successfully in complex, unstructured situations. Must be proficient in multivendor networking environments in configuring firewalls, Intrusion Prevention/Detection systems, VPN gateways, routers, and switches (Cisco, Aruba, Juniper, Cisco ASA, etc.) Be able to develop and modify system scripts. Write standardized system documentation, including configuration guides, test procedures, test results, and training materials. Provide onsite training to technical and non-technical users on the daily use, management, and troubleshooting of the solution after installation. Support all Cross-Domain solution requirements Collaborate with other operations departments to design approved infrastructure Serve as the escalation contact during large outages for Tier 2 and 3 systems. Author network Engineering Design Packages to include detailed implementation project plans and procedures. Configures network, software, and hardware components to meet NSA CSfC, NIAP, and DoD requirements Performs network design and systems integration Designs, develops, implements, tests, and maintains complex secure communications networks Configuring/managing PKI Certificate Authorities for CSfC solutions Familiarity with Certificate Authority configuration (ISC CertAgent/MS Windows Server/Red Hat Certificate systems) Document configuration, test procedure, results, and training materials Preparing test reports and configuration documentation according to customer standards. Providing customer on-site training on solution daily use, management, and troubleshooting Provide tier 2 and 3 support as part of a technical team. Identify and recommend hardware and support solutions based on research and analysis of new technologies, interfacing with customers and vendors. Enhance department and organization reputation by accepting ownership for accomplishing new and different requests; exploring opportunities to add value to the company. Apply DoD STIGs and IAVAs Perform special projects and other duties as assigned. REQUIRED QUALIFICATIONS Top Secret OR Higher OR Secret Clearance level with completed T5 investigation Active Professional Network certification (CCNP-Security, CCNA, HPE Aruba Networking Certified Professional - Switching, etc.) Must have experience with one or more networking vendors: Cisco, Aruba, Juniper, etc. One of the following DoD8140 Certifications : SecurityX/CASP+ CCNA CCNP Security CCSP (Certified Cloud Security Professional) GCED (GIAC Certified Enterprise Defender) GCIA (GIAC Certified Intrusion Analyst) GCLD (GIAC Cloud Security Essentials) GDSA (GIAC Defensible Security Architecture) GFACT (GIAC Foundational Cybersecurity Technologies) 10 or more years of experience in engineering MA/MS= 10 years; BS=12 years Qualifications WORK ENVIRONMENT AND PHYSICAL DEMANDS The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: Honolulu, HI Type of environment: Office Noise level: Low Work schedule: CONUS Schedule is day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 20% PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WORK AUTHORIZATION/SECURITY CLEARANCE United States Citizenship Top Secret Clearance requirement WAGE INFORMATION Target salary range: $133,000.00 - $165,000.00. The salary range displayed is an estimate only and is not a guarantee of compensation or salary, and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. EQUAL EMPLOYMENT OPPORTUNITY In order to provide equal employment and advancement opportunities to all individuals, employment decisions will be based on merit, qualifications, and abilities. TekSynap does not discriminate against any person because of race, color, creed, religion, sex, national origin, disability, age, genetic information or any other characteristic protected by law (referred to as "protected status"). This nondiscrimination policy extends to all terms, conditions, and privileges of employment as well as the use of all company facilities, participation in all company-sponsored activities, and all employment actions such as promotions, compensation, benefits, and termination of employment.
Senior Network Exploitation Engineer
Nyla Technology Solutions Annapolis Junction, Maryland
Job Description Job Description Job Description ACTIVE SECURITY CLEARANCE AT THE TS/SCI POLYGRAPH LEVEL IS REQUIRED We are seeking an aggressive, hands-on Red Team / Cyber Assessment Engineer to join our technical assessment team in Annapolis Junction, MD, with periodic OCONUS travel requirements. In this role, you will execute adversarial assessments, emulate real-world threat actors, and evaluate complex network architectures to identify vulnerabilities before adversaries can exploit them. You won't just run automated scanners-you will conduct full-scope Red Team engagements, perform deep network anomaly analysis, leverage the MITRE ATTCK framework, and author comprehensive mitigation reports to harden critical infrastructure. If you thrive on offensive cyber operations, analyzing raw telemetry for Indicators of Compromise (IOCs), and delivering high-impact security assessments, you'll fit right in with Team Nyla. The annual base salary range for this role is $176,000-$208,000 (USD) , which does not include discretionary bonus compensation or our comprehensive benefits package. Actual compensation offered to the successful candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level, among other things. , Required Skills Red Team Assessment Experience: Proven track record conducting offensive security assessments, adversarial emulations, and technical vulnerability evaluations. Assessment Mitigation Reporting: Demonstrated capability to author detailed assessment findings, technical threat reports, and actionable remediation plans. Network Threat Analysis: Strong expertise in network traffic analysis, anomaly detection, IOC identification, and multi-source telemetry evaluation. Security Frameworks: Deep working knowledge of the MITRE ATTCK framework, NIST cybersecurity controls, and ISO 27001 standards. Operational Mobility: Willingness and ability to undertake periodic OCONUS travel for on-site assessment operations. Education: Bachelor's Degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline, PLUS 7+ years of professional cybersecurity and Red Team assessment experience OR Master's Degree in a related technical field, PLUS 5+ years of specialized offensive security and threat assessment experience OR High School Diploma / GED, PLUS 11+ years of hands-on technical experience in cybersecurity operations, network assessment, and Red Teaming in lieu of a degree. , Desired Skills Offensive Certifications: Industry certifications such as OSCP, CRTP, CRTE, CRTO, or equivalent penetration testing credentials. Penetration Testing Exploitation: Practical experience with ethical hacking, exploit development, post-exploitation techniques, and manual penetration testing. Zero Trust Concepts: Understanding of Zero Trust architecture and modern network infrastructure hardening. Blue/Purple Team Collaboration: Experience supporting defensive monitoring, detection engineering, or joint Purple Team exercises. Python Scripting: Basic proficiency in Python for automated parsing, custom payload delivery, or quick assessment scripting. , About Nyla Technology Solutions Nyla Technology Solutions delivers exceptional Artificial Intelligence (AI), Data Science, and Software Engineering services for the U.S. Government. Nyla embraces a forward-thinking and bold approach at every turn, earning us a solid reputation of technical trendsetters within the industry. We have a passion for developing solutions that have a quick and immediate impact on mission. Headquartered in Columbia, Maryland, our customers love how we tackle their most challenging problems and get things done. If you have the unique experience and expertise we are seeking, along with the desire and determination to invest your time and energy as a part of Nyla's team, Taking Care of All of You Nyla provides a top-of-market compensation and benefits package. And through our unique Nyla FLEX program, we custom tailor these benefits to best fit your lifestyle. The Nyla FLEX benefit program is designed to offer you flexibility in the 3 biggest areas of your life: your pay, your leave, and your schedule. PAY - Nyla starts with 4 weeks of Annual Leave plus 11 holidays and an additional day of Annual Leave for each year you're at the company. You have the flexibility to cash out your annual leave hours, opt out of other Nyla benefits, and/or arrange for additional hours on contract (over 40 hrs/week). There's even an option to earn 1.3 times your hourly rate once you work over 1880 hours on contract! LEAVE - Want to spend more time with the family? Want more time to travel the world? You can BUY additional annual leave for a total of 6 weeks of annual leave. That's up to 240 hours of leave plus 11 holidays! That's not even including paid anniversary leave! SCHEDULE - Does the traditional 40-hour workweek no longer fit your lifestyle? With Nyla FLEX, you have the freedom to scale down to 30-32 hours while still enjoying the top-notch Nyla benefits you know and love. It's flexibility that works for you without compromising the perks! WHAT ABOUT OTHER BENEFITS? Nyla's health care (medical, dental, and vision) is 100% covered by the company. We provide 10% 401k matching - with full vesting day 1! Our Professional Development offers $5,000 per year to be used towards fees, tuition, or time off for your continued growth. We even have a student loan repayment program and we provide 8 hours of volunteering annually so you can support your community, making your world a better place. To learn more about Nyla's culture and our exceptional benefit packages click here. Nyla is an equal opportunity employer.
09/24/2026
Full time
Job Description Job Description Job Description ACTIVE SECURITY CLEARANCE AT THE TS/SCI POLYGRAPH LEVEL IS REQUIRED We are seeking an aggressive, hands-on Red Team / Cyber Assessment Engineer to join our technical assessment team in Annapolis Junction, MD, with periodic OCONUS travel requirements. In this role, you will execute adversarial assessments, emulate real-world threat actors, and evaluate complex network architectures to identify vulnerabilities before adversaries can exploit them. You won't just run automated scanners-you will conduct full-scope Red Team engagements, perform deep network anomaly analysis, leverage the MITRE ATTCK framework, and author comprehensive mitigation reports to harden critical infrastructure. If you thrive on offensive cyber operations, analyzing raw telemetry for Indicators of Compromise (IOCs), and delivering high-impact security assessments, you'll fit right in with Team Nyla. The annual base salary range for this role is $176,000-$208,000 (USD) , which does not include discretionary bonus compensation or our comprehensive benefits package. Actual compensation offered to the successful candidate may vary from posted hiring range based upon geographic location, work experience, education, and/or skill level, among other things. , Required Skills Red Team Assessment Experience: Proven track record conducting offensive security assessments, adversarial emulations, and technical vulnerability evaluations. Assessment Mitigation Reporting: Demonstrated capability to author detailed assessment findings, technical threat reports, and actionable remediation plans. Network Threat Analysis: Strong expertise in network traffic analysis, anomaly detection, IOC identification, and multi-source telemetry evaluation. Security Frameworks: Deep working knowledge of the MITRE ATTCK framework, NIST cybersecurity controls, and ISO 27001 standards. Operational Mobility: Willingness and ability to undertake periodic OCONUS travel for on-site assessment operations. Education: Bachelor's Degree in Cybersecurity, Computer Science, Computer Engineering, or a related technical discipline, PLUS 7+ years of professional cybersecurity and Red Team assessment experience OR Master's Degree in a related technical field, PLUS 5+ years of specialized offensive security and threat assessment experience OR High School Diploma / GED, PLUS 11+ years of hands-on technical experience in cybersecurity operations, network assessment, and Red Teaming in lieu of a degree. , Desired Skills Offensive Certifications: Industry certifications such as OSCP, CRTP, CRTE, CRTO, or equivalent penetration testing credentials. Penetration Testing Exploitation: Practical experience with ethical hacking, exploit development, post-exploitation techniques, and manual penetration testing. Zero Trust Concepts: Understanding of Zero Trust architecture and modern network infrastructure hardening. Blue/Purple Team Collaboration: Experience supporting defensive monitoring, detection engineering, or joint Purple Team exercises. Python Scripting: Basic proficiency in Python for automated parsing, custom payload delivery, or quick assessment scripting. , About Nyla Technology Solutions Nyla Technology Solutions delivers exceptional Artificial Intelligence (AI), Data Science, and Software Engineering services for the U.S. Government. Nyla embraces a forward-thinking and bold approach at every turn, earning us a solid reputation of technical trendsetters within the industry. We have a passion for developing solutions that have a quick and immediate impact on mission. Headquartered in Columbia, Maryland, our customers love how we tackle their most challenging problems and get things done. If you have the unique experience and expertise we are seeking, along with the desire and determination to invest your time and energy as a part of Nyla's team, Taking Care of All of You Nyla provides a top-of-market compensation and benefits package. And through our unique Nyla FLEX program, we custom tailor these benefits to best fit your lifestyle. The Nyla FLEX benefit program is designed to offer you flexibility in the 3 biggest areas of your life: your pay, your leave, and your schedule. PAY - Nyla starts with 4 weeks of Annual Leave plus 11 holidays and an additional day of Annual Leave for each year you're at the company. You have the flexibility to cash out your annual leave hours, opt out of other Nyla benefits, and/or arrange for additional hours on contract (over 40 hrs/week). There's even an option to earn 1.3 times your hourly rate once you work over 1880 hours on contract! LEAVE - Want to spend more time with the family? Want more time to travel the world? You can BUY additional annual leave for a total of 6 weeks of annual leave. That's up to 240 hours of leave plus 11 holidays! That's not even including paid anniversary leave! SCHEDULE - Does the traditional 40-hour workweek no longer fit your lifestyle? With Nyla FLEX, you have the freedom to scale down to 30-32 hours while still enjoying the top-notch Nyla benefits you know and love. It's flexibility that works for you without compromising the perks! WHAT ABOUT OTHER BENEFITS? Nyla's health care (medical, dental, and vision) is 100% covered by the company. We provide 10% 401k matching - with full vesting day 1! Our Professional Development offers $5,000 per year to be used towards fees, tuition, or time off for your continued growth. We even have a student loan repayment program and we provide 8 hours of volunteering annually so you can support your community, making your world a better place. To learn more about Nyla's culture and our exceptional benefit packages click here. Nyla is an equal opportunity employer.
Senior Security Engineer, Infrastructure & Network Security
Metropolis Acton, California
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
09/24/2026
Full time
Job Description Job Description Who we are The real world is the next frontier, and at Metropolis, we are creating the artificial intelligence to make it responsive. We are pioneering the Recognition Economy - a future where mundane repetition disappears and being known unlocks access, comfort and belonging everywhere you go. From transforming parking into a seamless drive-in, drive-out experience for millions of Members to expanding our intelligence layer across retail and hospitality, we are building a world that feels instinctive and magical. The future isn't coming; it's here, and we need builders, innovators and problem solvers to help us create it. Who you are Metropolis is seeking a Senior Security Engineer to establish and lead a dedicated infrastructure and network security engineering function within our Corporate IT and Information Security organization. In this senior technical role, you will design, build, and manage a dedicated AWS environment to power our security tooling, automation, and operational infrastructure, while also supporting our expanding Oracle Cloud Infrastructure footprint. You will drive enterprise network security initiatives-including firewalls, segmentation, WAF technologies, and zero-trust architectures-to protect our corporate office networks and remote access environments. Collaborating closely with Corporate IT, Network Engineering, Central Cloud Infrastructure, and platform engineering teams, you will deliver resilient security infrastructure that safeguards our expanding technology ecosystem. What you'll do Design, build, and manage a dedicated AWS environment owned by Corporate IT and Information Security to support security tooling, automation, and operational workloads Support Oracle Cloud Infrastructure environments as part of broader enterprise transformation initiatives Lead enterprise network engineering and network security initiatives across corporate office networks, firewalls, segmentation, and wireless environments Implement and manage VPN, remote access, WAF technologies, and secure connectivity architectures Drive zero-trust initiatives and enhance enterprise network visibility and monitoring Manage identity, access, endpoint, and server security platforms across the enterprise Develop infrastructure-as-code and cloud automation to scale security operations infrastructure Execute vulnerability management programs and establish enterprise infrastructure hardening and operational resiliency Provide detection engineering and incident response support across security platforms Partner closely across Corporate IT, Network Engineering, Central Cloud Infrastructure, Enterprise Systems, and platform engineering teams What we're looking for Demonstrate strong AWS and cloud security experience Exhibit strong networking and network security experience Show experience with enterprise identity systems and access management Display experience with security engineering infrastructure and automation Support hybrid enterprise and cloud-native environments Utilize modern infrastructure and security tooling Maintain familiarity with regulated environments such as PCI and SOC Possess experience with scripting and programming Experience leveraging AI tools to transform static workflows into responsive, high-output processes While not required, these are a plus: Use Python as the preferred language for scripting and programming 4 Days in Office: Metropolis values in-person collaboration to drive innovation, strengthen culture, and enhance the Member experience. Our corporate team members hold to our office-first model, which requires employees to be on-site at least four days a week, fostering organic interactions that spark creativity and connection When you join Metropolis, you'll join a team of world-class product leaders and engineers, building an ecosystem of technologies at the intersection of parking, mobility, and real estate. Our goal is to build an inclusive culture where everyone has a voice and the best idea wins. You will play a key role in building and maintaining this culture as our organization grows. The anticipated base salary for this position is $160,000.00 USD to $215,000.00 USD annually. The actual base salary offered is determined by a number of variables, including, as appropriate, the applicant's qualifications for the position, years of relevant experience, distinctive skills, level of education attained, certifications or other professional licenses held, and the location of residence and/or place of employment. Base salary is one component of Metropolis's total compensation package, which may also include access to or eligibility for healthcare benefits, a 401(k) plan, short-term and long-term disability coverage, basic life insurance, a lucrative stock option plan, bonus plans and more. Metropolis may utilize an automated employment decision tool (AEDT) to assess or evaluate your candidacy for employment or promotion. AEDTs are used to assist in assessing a candidate's application relative to the required job qualifications and responsibilities listed in the job posting. As part of this process, Metropolis retains data relevant to your candidacy, including personal information, for a period that is reasonably necessary for the use of the tool. If you are hired for the position, your data may become part of your employee records. Metropolis Technologies is an equal opportunity employer. We make all hiring decisions based on merit, qualifications, and business needs, without regard to race, color, religion, sex (including gender identity, sexual orientation, or pregnancy), national origin, disability, veteran status, or any other protected characteristic under federal, state, or local law.
PKI Subject Matter Expert w/Secret Clearance
TekSynap
Job Description Job Description Overview WORK ENVIRONMENT The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: On-site, DISA Headquarters, 6914 Cooper Ave, Fort Meade, MD 20755 Type of environment: Office - on-site at a Government facility (classified environment) Noise level: Low to Medium Work schedule: Day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 10%. Occasional travel within the National Capital Region and to up to four (4) conferences per year. WORK AUTHORIZATION/SECURITY CLEARANCE U.S. Citizen Secret Clearance PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WAGE INFORMATION Target salary range: $100,000 - $16,000.00/yr. The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. Responsibilities We are seeking a PKI Subject Matter Expert - Cryptographic Modernization (PQC, Algorithm Evolution & NPE) - Key Personnel to join our team supporting the DISA PKI Public Key Enablement (PKE) Engineering Support Task Order (SETI Small Business) in Fort Meade, Maryland. REQUIRED QUALIFICATIONS Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments. Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations. Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography. Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states. Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST). Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities. Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains. Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process. Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred. Certifications Certification: DoD 8140 Cyber Workforce Qualification Program, IAT Level II, IAT Level III, IAM III or equivalent, required at time of assignment Education Education: Bachelor's degree in Computer Science, Cybersecurity, Mathematics, Engineering, or a related field. Master's degree preferred; equivalent demonstrated technical experience may be considered. Clearance Clearance: Active Secret clearance required. Must be onboard at the start of the Period of Performance. RESPONSIBILITIES Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio. Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations. Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes. Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states. Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture. Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs. Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team. Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs. Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME. Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day. Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy. Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released. Qualifications TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at . We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. EQUAL EMPLOYMENT OPPORTUNITY . click apply for full job details
09/24/2026
Full time
Job Description Job Description Overview WORK ENVIRONMENT The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: On-site, DISA Headquarters, 6914 Cooper Ave, Fort Meade, MD 20755 Type of environment: Office - on-site at a Government facility (classified environment) Noise level: Low to Medium Work schedule: Day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 10%. Occasional travel within the National Capital Region and to up to four (4) conferences per year. WORK AUTHORIZATION/SECURITY CLEARANCE U.S. Citizen Secret Clearance PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WAGE INFORMATION Target salary range: $100,000 - $16,000.00/yr. The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. Responsibilities We are seeking a PKI Subject Matter Expert - Cryptographic Modernization (PQC, Algorithm Evolution & NPE) - Key Personnel to join our team supporting the DISA PKI Public Key Enablement (PKE) Engineering Support Task Order (SETI Small Business) in Fort Meade, Maryland. REQUIRED QUALIFICATIONS Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments. Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations. Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography. Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states. Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST). Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities. Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains. Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process. Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred. Certifications Certification: DoD 8140 Cyber Workforce Qualification Program, IAT Level II, IAT Level III, IAM III or equivalent, required at time of assignment Education Education: Bachelor's degree in Computer Science, Cybersecurity, Mathematics, Engineering, or a related field. Master's degree preferred; equivalent demonstrated technical experience may be considered. Clearance Clearance: Active Secret clearance required. Must be onboard at the start of the Period of Performance. RESPONSIBILITIES Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio. Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations. Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes. Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states. Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture. Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs. Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team. Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs. Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME. Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day. Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy. Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released. Qualifications TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at . We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. EQUAL EMPLOYMENT OPPORTUNITY . click apply for full job details
Network Security Engineer
Oneida Technical Solutions West Point, New York
Job Description Job Description Network Security EngineerOneida Technical Solutions (OTS), headquartered in Oneida, New York, is a tribally-owned, dynamic, and growth-oriented firm focused on serving the Information Technology (IT) and Cybersecurity needs of the U.S. Department of Defense (DoD). We are seeking qualified Network Engineers to join our team serving the United States Military Academy (USMA) at West Point, NY. The role is onsite at USMA.The selected candidate will support the USMA Networking Service Branch's mission and strategic direction by providing knowledge, techniques, and expertise in configuring and administering a Cisco Networking environment across the USMA campus.Target Salary Range: $105,000 - $120,000Job Description:Overview: Under general supervision, the Network Security Engineer will be responsible for the acquisition, installation, maintenance, and operation of USMA's local area network (LAN). This is a critical role tasked with managing network performance and ensuring the security of network infrastructure.Primary Duties & Responsibilities:Acquire, install, and maintain all network hardware and software components, ensuring optimal performance and security.Manage network performance by monitoring and analyzing traffic, identifying issues, and implementing solutions.Ensure that security procedures are implemented, enforced, and regularly updated to align with industry standards.Evaluate, develop, and maintain telecommunications systems to support organizational operations.Troubleshoot and resolve network problems, ensuring minimal disruption to services.Establish and implement network policies, procedures, and standards that conform to information systems and organizational objectives.Train users on network operations and security best practices to enhance overall network security awareness.Report frequently to the assigned Support Manager and/or Senior Network Administrator on network performance and security status.Evaluate DoD and NIST security controls, determining their applicability to the environment while assessing potential impacts.Implement security controls as directed by the customer's Cybersecurity branch to enhance the security posture of the organization.Investigate and recommend new and emerging security paradigms to continuously improve network security.Collaboration with other USMA and OTS functions (Cyber, IT support, Enterprise Services, etc.) to resolve network related issues. The nature of the position involves actively participating in multiple working groups and disseminating information across all levels of the organization.Additional duties may include:Installation/Replacement/Management of Uninterruptible Power Supply (UPS) devices.Minimum Qualifications:Cisco Certified Network Associate (CCNA) certification.Expertise in Internet Protocol version 6 (IPv6) design, implementation, management, and monitoring.Strong understanding of Zero Trust Architectures (ZTA) including enterprise implementation, configuration, management, monitoring, troubleshooting, and technology integration.Must meet minimum standards for DoD8140 certification for advanced-level work roles.Must be fluent in the principles and requirements of the CCIE Security and Cisco Certified Design Expert (CCDE) material, however certifications to CCIE and CCDE are not required.Proficient in network security concepts and technologies.Excellent problem-solving skills and attention to detail.Strong communication skills for effective user training and reporting.Ability to work collaboratively in a team-oriented environment.Preferred Qualifications:Advanced Certifications: Possession of advanced networking and security certifications such as Cisco Certified Network Professional (CCNP) or Cisco Certified Internetwork Expert (CCIE) is highly preferred, demonstrating a deeper level of expertise in network security and infrastructure.Experience with Network Security Frameworks: Proven experience with security frameworks and standards such as NIST Cybersecurity Framework, ISO 27001, and DoD RMF (Risk Management Framework) to ensure compliance and best practices in network security management.Proficiency in Network Management Tools: Familiarity with advanced network monitoring and management tools (e.g., SolarWinds, Wireshark, Nagios) for traffic analysis and performance optimization.Hands-on Experience with Firewall and IDS/IPS Technologies: Demonstrated experience in configuring and managing firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) to enhance network security.Knowledge of Cloud Security: Understanding of security protocols and practices related to cloud services and architectures (e.g., AWS, Azure) that support organizational operations.Scripting and Automation Skills: Proficiency in scripting languages (e.g., Python, PowerShell) to automate network tasks and enhance operational efficiency.Strong Analytical Skills: Ability to analyze complex network issues and provide clear, actionable recommendations to improve network performance and security.Oneida Technical Solutions is an equal opportunity employer. Qualified candidates will be considered without regard to legally protected characteristics. Job Posted by ApplicantPro
09/24/2026
Full time
Job Description Job Description Network Security EngineerOneida Technical Solutions (OTS), headquartered in Oneida, New York, is a tribally-owned, dynamic, and growth-oriented firm focused on serving the Information Technology (IT) and Cybersecurity needs of the U.S. Department of Defense (DoD). We are seeking qualified Network Engineers to join our team serving the United States Military Academy (USMA) at West Point, NY. The role is onsite at USMA.The selected candidate will support the USMA Networking Service Branch's mission and strategic direction by providing knowledge, techniques, and expertise in configuring and administering a Cisco Networking environment across the USMA campus.Target Salary Range: $105,000 - $120,000Job Description:Overview: Under general supervision, the Network Security Engineer will be responsible for the acquisition, installation, maintenance, and operation of USMA's local area network (LAN). This is a critical role tasked with managing network performance and ensuring the security of network infrastructure.Primary Duties & Responsibilities:Acquire, install, and maintain all network hardware and software components, ensuring optimal performance and security.Manage network performance by monitoring and analyzing traffic, identifying issues, and implementing solutions.Ensure that security procedures are implemented, enforced, and regularly updated to align with industry standards.Evaluate, develop, and maintain telecommunications systems to support organizational operations.Troubleshoot and resolve network problems, ensuring minimal disruption to services.Establish and implement network policies, procedures, and standards that conform to information systems and organizational objectives.Train users on network operations and security best practices to enhance overall network security awareness.Report frequently to the assigned Support Manager and/or Senior Network Administrator on network performance and security status.Evaluate DoD and NIST security controls, determining their applicability to the environment while assessing potential impacts.Implement security controls as directed by the customer's Cybersecurity branch to enhance the security posture of the organization.Investigate and recommend new and emerging security paradigms to continuously improve network security.Collaboration with other USMA and OTS functions (Cyber, IT support, Enterprise Services, etc.) to resolve network related issues. The nature of the position involves actively participating in multiple working groups and disseminating information across all levels of the organization.Additional duties may include:Installation/Replacement/Management of Uninterruptible Power Supply (UPS) devices.Minimum Qualifications:Cisco Certified Network Associate (CCNA) certification.Expertise in Internet Protocol version 6 (IPv6) design, implementation, management, and monitoring.Strong understanding of Zero Trust Architectures (ZTA) including enterprise implementation, configuration, management, monitoring, troubleshooting, and technology integration.Must meet minimum standards for DoD8140 certification for advanced-level work roles.Must be fluent in the principles and requirements of the CCIE Security and Cisco Certified Design Expert (CCDE) material, however certifications to CCIE and CCDE are not required.Proficient in network security concepts and technologies.Excellent problem-solving skills and attention to detail.Strong communication skills for effective user training and reporting.Ability to work collaboratively in a team-oriented environment.Preferred Qualifications:Advanced Certifications: Possession of advanced networking and security certifications such as Cisco Certified Network Professional (CCNP) or Cisco Certified Internetwork Expert (CCIE) is highly preferred, demonstrating a deeper level of expertise in network security and infrastructure.Experience with Network Security Frameworks: Proven experience with security frameworks and standards such as NIST Cybersecurity Framework, ISO 27001, and DoD RMF (Risk Management Framework) to ensure compliance and best practices in network security management.Proficiency in Network Management Tools: Familiarity with advanced network monitoring and management tools (e.g., SolarWinds, Wireshark, Nagios) for traffic analysis and performance optimization.Hands-on Experience with Firewall and IDS/IPS Technologies: Demonstrated experience in configuring and managing firewalls, intrusion detection systems (IDS), and intrusion prevention systems (IPS) to enhance network security.Knowledge of Cloud Security: Understanding of security protocols and practices related to cloud services and architectures (e.g., AWS, Azure) that support organizational operations.Scripting and Automation Skills: Proficiency in scripting languages (e.g., Python, PowerShell) to automate network tasks and enhance operational efficiency.Strong Analytical Skills: Ability to analyze complex network issues and provide clear, actionable recommendations to improve network performance and security.Oneida Technical Solutions is an equal opportunity employer. Qualified candidates will be considered without regard to legally protected characteristics. Job Posted by ApplicantPro
Staff/Principal, Hardware Engineer
Aurelius Systems San Francisco, California
Job Description Job Description Who We Are: Aurelius Systems is a VC backed defense tech startup building autonomous, edge deployed directed energy systems for counter-UAS. We build laser weapons to shoot down drones. We're a small team of 10 engineers, former US military operators, and subject matter experts scaling America's directed energy dominance. The first cost effective, reliable and robust laser weapon system. Our namesake isn't an accident. Marcus Aurelius wrote about doing the work in front of you, every day, without excuses. Henry Ford didn't wait for permission to reinvent manufacturing. That's how we operate - small team, unreasonable output, no hiding behind the unachievable. In addition to our San Francisco lab, we opened our Detroit manufacturing hub and field test weekly on our own 400-acre private range. The Role and Your Impact: We need a Principal Hardware Engineer to bring senior technical judgment across Archimedes hardware. You are a highly experienced builder who has seen systems go the full way. From a working prototype to hardware that ships and survives in the field. You've done it more than once. You know where systems break, where teams get stuck, and how to keep both moving. This is a technical leadership seat, not a people management seat. Your role is to raise the level of the hardware org through experience, architectural judgment, and hands-on execution. You lead by example, you unblock hard problems, and you set the technical bar for how hardware gets designed and shipped at Aurelius. You'll partner with the founders and the Director of Engineering on architecture and roadmap. You'll work directly alongside mechanical, electrical, power, embedded, and optics engineers on the hardest problems the team is facing. What You'll Own: Architectural direction across the hardware stack from mechanical, electrical, power, to embedded integration Technical decisions on the hardest problems, from concept through production readiness Pattern recognition and technical review like surfacing risk early, and catching what junior engineers miss Handson execution when the problem needs your specific experience to solve fast Design and manufacturing trades across cost, mass, reliability, schedule, and field performance Cross-team judgment when hardware, controls, optics, and software collide Setting the technical bar for design reviews, documentation quality, and release standards Mentorship by example. Engineers should learn from watching you work, not from being managed by you What We're Looking For: 10+ years designing and shipping complex hardware systems Track record taking systems the full development cycle from prototype through manufacturing and deployment Senior IC or technical leadership background at hardware companies that actually shipped Deep technical judgment across at least two of: mechanical, electrical, power electronics, embedded systems Pattern recognition from having built real systems before, especially systems that had to survive real-world conditions Comfort operating as the technical anchor on a small team, not the manager of a large one Nice to Haves: Directed energy, laser, or high-power systems experience Defense or aerospace program experience with MIL-STD or equivalent qualification Founder or founding engineer background at a hardware company Manufacturing depth as-in you've stood up production lines or worked closely with the manufacturers who do Active security clearance or ability to obtain one How You Operate: Extreme bias for action. You'd rather build a prototype tomorrow than model it for a month You characterize your own systems before the field does Comfortable with ambiguity and fast iteration in a startup environment You debug from first principles, not intuition alone Clear communicator across mechanical, electrical, optical, and software teams Self directed. You identify what needs to happen next and do it without being told Why Join Aurelius Systems: Build more in 1 month than most engineers build in 1 year. We field test weekly. Your work goes downrange, not into a filing cabinet. Career velocity is real. At 10 engineers, there are no layers between you and impact. Work on a problem that actually matters. Small cheap drones are changing warfare. Our laser systems are the asymmetric answer - infinite magazine, near zero cost per shot, scalable to every base, border, facility, and truck. Join the densest defense startup ecosystem in the country. California is where the next generation of defense companies are being built. How We Work: Core hours are Monday through Friday, 9 to 6. When we're sprinting toward a demo or field test, the team ramps up - nights, weekends, whatever it takes to ship. When the sprint lands, we ramp down. We don't manufacture intensity for show. Benefits: Competitive salary and equity United Health Care medical, dental, and vision coverage Flexible 18 days PTO plus 5 sick days Travel to field test events and range days Covered daily lunches and office snacks and drinks E-bike and scooter stipend up to $500 Direct access to leadership and real ownership over your work Export Control Notice: This role requires access to export-controlled information or items that require U.S. Person status. As defined by U.S. law, individuals who are any one of the following are considered to be a U.S. Person: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3). Compensation Range: $255K - $305K
09/24/2026
Full time
Job Description Job Description Who We Are: Aurelius Systems is a VC backed defense tech startup building autonomous, edge deployed directed energy systems for counter-UAS. We build laser weapons to shoot down drones. We're a small team of 10 engineers, former US military operators, and subject matter experts scaling America's directed energy dominance. The first cost effective, reliable and robust laser weapon system. Our namesake isn't an accident. Marcus Aurelius wrote about doing the work in front of you, every day, without excuses. Henry Ford didn't wait for permission to reinvent manufacturing. That's how we operate - small team, unreasonable output, no hiding behind the unachievable. In addition to our San Francisco lab, we opened our Detroit manufacturing hub and field test weekly on our own 400-acre private range. The Role and Your Impact: We need a Principal Hardware Engineer to bring senior technical judgment across Archimedes hardware. You are a highly experienced builder who has seen systems go the full way. From a working prototype to hardware that ships and survives in the field. You've done it more than once. You know where systems break, where teams get stuck, and how to keep both moving. This is a technical leadership seat, not a people management seat. Your role is to raise the level of the hardware org through experience, architectural judgment, and hands-on execution. You lead by example, you unblock hard problems, and you set the technical bar for how hardware gets designed and shipped at Aurelius. You'll partner with the founders and the Director of Engineering on architecture and roadmap. You'll work directly alongside mechanical, electrical, power, embedded, and optics engineers on the hardest problems the team is facing. What You'll Own: Architectural direction across the hardware stack from mechanical, electrical, power, to embedded integration Technical decisions on the hardest problems, from concept through production readiness Pattern recognition and technical review like surfacing risk early, and catching what junior engineers miss Handson execution when the problem needs your specific experience to solve fast Design and manufacturing trades across cost, mass, reliability, schedule, and field performance Cross-team judgment when hardware, controls, optics, and software collide Setting the technical bar for design reviews, documentation quality, and release standards Mentorship by example. Engineers should learn from watching you work, not from being managed by you What We're Looking For: 10+ years designing and shipping complex hardware systems Track record taking systems the full development cycle from prototype through manufacturing and deployment Senior IC or technical leadership background at hardware companies that actually shipped Deep technical judgment across at least two of: mechanical, electrical, power electronics, embedded systems Pattern recognition from having built real systems before, especially systems that had to survive real-world conditions Comfort operating as the technical anchor on a small team, not the manager of a large one Nice to Haves: Directed energy, laser, or high-power systems experience Defense or aerospace program experience with MIL-STD or equivalent qualification Founder or founding engineer background at a hardware company Manufacturing depth as-in you've stood up production lines or worked closely with the manufacturers who do Active security clearance or ability to obtain one How You Operate: Extreme bias for action. You'd rather build a prototype tomorrow than model it for a month You characterize your own systems before the field does Comfortable with ambiguity and fast iteration in a startup environment You debug from first principles, not intuition alone Clear communicator across mechanical, electrical, optical, and software teams Self directed. You identify what needs to happen next and do it without being told Why Join Aurelius Systems: Build more in 1 month than most engineers build in 1 year. We field test weekly. Your work goes downrange, not into a filing cabinet. Career velocity is real. At 10 engineers, there are no layers between you and impact. Work on a problem that actually matters. Small cheap drones are changing warfare. Our laser systems are the asymmetric answer - infinite magazine, near zero cost per shot, scalable to every base, border, facility, and truck. Join the densest defense startup ecosystem in the country. California is where the next generation of defense companies are being built. How We Work: Core hours are Monday through Friday, 9 to 6. When we're sprinting toward a demo or field test, the team ramps up - nights, weekends, whatever it takes to ship. When the sprint lands, we ramp down. We don't manufacture intensity for show. Benefits: Competitive salary and equity United Health Care medical, dental, and vision coverage Flexible 18 days PTO plus 5 sick days Travel to field test events and range days Covered daily lunches and office snacks and drinks E-bike and scooter stipend up to $500 Direct access to leadership and real ownership over your work Export Control Notice: This role requires access to export-controlled information or items that require U.S. Person status. As defined by U.S. law, individuals who are any one of the following are considered to be a U.S. Person: (1) U.S. citizens, (2) legal permanent residents (a.k.a. green card holders), and (3) certain protected classes of asylees and refugees, as defined in 8 U.S.C. 1324b(a)(3). Compensation Range: $255K - $305K
Senior Security Network Engineer (Security Clearance Required)
EHS TECHNOLOGIES CORPORATION Philadelphia, Pennsylvania
Job Description Job Description Description: US CITIZENSHIP, DoD SECRET SECURITY CLEARANCE IS REQUIRED. If your resume does not clearly state that you have an active DoD Secret security clearance, auto-filtering tools will reject/remove your application. EXPERIENCE for Senior Security Network Engineer position: Eight (8) years' experience in network security, demonstrating strong experience with Cisco Prime Infrastructure, understanding of IEEE 802.11 protocols, familiarity with TCP/IP (specifically Layers 3/4), and switching and routing protocols (internet standards and general architecture) and associated hardware. ReadSeal Experience Cisco ASA Cisco Firepower Switching and Troubleshooting Cisco Wireless LAN Controller Cisco DNA Center Bluecoat Proxy RSA Server Cisco ISE This is a Cyber Security Workforce IAT II position- Must hold one of the following active certifications: IAT Level III CISSP/CCNP-Routing or CCNP Security Requirements: EDUCATION for Senior Security Network Engineer: Minimum Education: Bachelor's degree in Information Technology, Computer Science, or an equivalent technical degree from an accredited college or university. Benefits for a Senior Security Network Engineer: As a team member of EHS Technologies, you'll have available benefits including Bonus Eligibility, No Cost Full Coverage Health Insurance, available Pet Insurance, industry high 401k matching among many other excellent benefits and up to 26 days of holiday and PTO EHS Technologies is an Equal Opportunity Employer.
09/24/2026
Full time
Job Description Job Description Description: US CITIZENSHIP, DoD SECRET SECURITY CLEARANCE IS REQUIRED. If your resume does not clearly state that you have an active DoD Secret security clearance, auto-filtering tools will reject/remove your application. EXPERIENCE for Senior Security Network Engineer position: Eight (8) years' experience in network security, demonstrating strong experience with Cisco Prime Infrastructure, understanding of IEEE 802.11 protocols, familiarity with TCP/IP (specifically Layers 3/4), and switching and routing protocols (internet standards and general architecture) and associated hardware. ReadSeal Experience Cisco ASA Cisco Firepower Switching and Troubleshooting Cisco Wireless LAN Controller Cisco DNA Center Bluecoat Proxy RSA Server Cisco ISE This is a Cyber Security Workforce IAT II position- Must hold one of the following active certifications: IAT Level III CISSP/CCNP-Routing or CCNP Security Requirements: EDUCATION for Senior Security Network Engineer: Minimum Education: Bachelor's degree in Information Technology, Computer Science, or an equivalent technical degree from an accredited college or university. Benefits for a Senior Security Network Engineer: As a team member of EHS Technologies, you'll have available benefits including Bonus Eligibility, No Cost Full Coverage Health Insurance, available Pet Insurance, industry high 401k matching among many other excellent benefits and up to 26 days of holiday and PTO EHS Technologies is an Equal Opportunity Employer.
Principal AI Engineer
eSimplicity Columbia, Maryland
Job Description Job Description Description: About Us: eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow. Responsibilities: The Agentic AI & MCP Specialist will architect, develop, and operationalize next-generation agentic systems powered by advanced LLMs and Model Context Protocol (MCP) frameworks. This role focuses on building intelligent, multi-step, tool-using agents that can autonomously reason, plan, and execute complex workflows across a cloud-based analytics ecosystem. The specialist will design and implement agent orchestration frameworks, integrate model-driven decision logic, and build robust, production-grade agent capabilities that safely leverage emerging AI techniques. This position requires a deeply skilled software developer who combines strong engineering fundamentals with hands-on experience creating agentic systems, working with MCP-based integrations, designing LLM-driven tools, and building secure, scalable AI applications. The role provides technical leadership, explores cutting-edge agentic patterns, drives proof-of-concept innovation, and partners with engineering and product teams to translate experimental architectures into real-world impact. Requirements: Required Qualifications: All candidates must pass public trust clearance through the U.S. Federal Government. This requires candidates to either be U.S. citizens or pass clearance through the Foreign National Government System which will require that candidates have lived within the United States for at least 3 out of the previous 5 years, have a valid and non-expired passport from their country of birth and appropriate VISA/work permit documentation. Bachelor's Degree and 10+ years of software engineering experience Experience designing, developing, and supporting production applications, platforms, or services. Experience developing agentic AI solutions, including planning, tool utilization, workflow orchestration, multi-step reasoning, or autonomous task execution. Experience designing and implementing Model Context Protocol (MCP) integrations, tool interfaces, or model-driven service architectures. Ability to analyze business, customer, or mission requirements and develop scalable AI-driven solutions that align with technical and operational objectives. Experience with large language model (LLM) development practices, including fine-tuning, retrieval-augmented generation (RAG), prompt engineering, and agent interaction patterns. Proficiency in Python and experience working with APIs, microservices, distributed computing environments, and cloud-native architectures. Experience deploying and integrating AI agents or LLM-enabled applications within cloud environments such as Azure, AWS, or Google Cloud Platform (GCP). Knowledge of MLOps and LLMOps practices, including model versioning, automated testing, deployment automation, monitoring, performance evaluation, and governance. Ability to contribute to solution design discussions, provide technical guidance to team members, and communicate AI-related concepts to technical and non-technical audiences. Experience using version control systems and CI/CD practices, including source code management, automated testing, deployment pipelines, and release management for production environments. Desired Qualifications: Experience building multi-agent systems, agent swarms, or coordinated reasoning frameworks. Familiarity with advanced tool-calling strategies, including dynamic tool selection, function-call planning, or graph-structured task planners. Experience with structured LLM evaluation methods, agent benchmarking, or test harnesses for autonomous systems. Knowledge of performance optimization techniques for LLMs and agents, including caching, model distillation, model routing, or accelerated inference. Background integrating agentic components with large-scale data or analytics platforms (e.g., Databricks, Snowflake, Spark). Hands-on experience developing innovative POCs or experimental agentic architectures in fast-paced R&D environments. Familiarity with emerging agentic frameworks such as Strands Agents, LangGraph, CrewAI, etc. Exposure to safety-oriented design patterns for autonomous systems, including guardrails, validation layers, or constrained-action frameworks. Experience designing and building secure, compliance-aware systems that handle sensitive data in accordance with HIPAA and federal security standards, including implementation of encryption, access controls, auditability, and governance for protected health information (PHI) within AI/LLM workflows. Working Environment : eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by manager. Occasional travel for training and project meetings. It is estimated to be less than 5% per year. Benefits: eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms. Reasonable Accommodation: eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources. Equal Employment Opportunity: eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any othe
09/24/2026
Full time
Job Description Job Description Description: About Us: eSimplicity is a modern digital services company that partners with government agencies to improve the lives and protect the well-being of all Americans, from veterans and service members to children, families, and seniors. Our engineers, designers, and strategists cut through complexity to create intuitive products and services that equip federal agencies with solutions to courageously transform today for a better tomorrow. Responsibilities: The Agentic AI & MCP Specialist will architect, develop, and operationalize next-generation agentic systems powered by advanced LLMs and Model Context Protocol (MCP) frameworks. This role focuses on building intelligent, multi-step, tool-using agents that can autonomously reason, plan, and execute complex workflows across a cloud-based analytics ecosystem. The specialist will design and implement agent orchestration frameworks, integrate model-driven decision logic, and build robust, production-grade agent capabilities that safely leverage emerging AI techniques. This position requires a deeply skilled software developer who combines strong engineering fundamentals with hands-on experience creating agentic systems, working with MCP-based integrations, designing LLM-driven tools, and building secure, scalable AI applications. The role provides technical leadership, explores cutting-edge agentic patterns, drives proof-of-concept innovation, and partners with engineering and product teams to translate experimental architectures into real-world impact. Requirements: Required Qualifications: All candidates must pass public trust clearance through the U.S. Federal Government. This requires candidates to either be U.S. citizens or pass clearance through the Foreign National Government System which will require that candidates have lived within the United States for at least 3 out of the previous 5 years, have a valid and non-expired passport from their country of birth and appropriate VISA/work permit documentation. Bachelor's Degree and 10+ years of software engineering experience Experience designing, developing, and supporting production applications, platforms, or services. Experience developing agentic AI solutions, including planning, tool utilization, workflow orchestration, multi-step reasoning, or autonomous task execution. Experience designing and implementing Model Context Protocol (MCP) integrations, tool interfaces, or model-driven service architectures. Ability to analyze business, customer, or mission requirements and develop scalable AI-driven solutions that align with technical and operational objectives. Experience with large language model (LLM) development practices, including fine-tuning, retrieval-augmented generation (RAG), prompt engineering, and agent interaction patterns. Proficiency in Python and experience working with APIs, microservices, distributed computing environments, and cloud-native architectures. Experience deploying and integrating AI agents or LLM-enabled applications within cloud environments such as Azure, AWS, or Google Cloud Platform (GCP). Knowledge of MLOps and LLMOps practices, including model versioning, automated testing, deployment automation, monitoring, performance evaluation, and governance. Ability to contribute to solution design discussions, provide technical guidance to team members, and communicate AI-related concepts to technical and non-technical audiences. Experience using version control systems and CI/CD practices, including source code management, automated testing, deployment pipelines, and release management for production environments. Desired Qualifications: Experience building multi-agent systems, agent swarms, or coordinated reasoning frameworks. Familiarity with advanced tool-calling strategies, including dynamic tool selection, function-call planning, or graph-structured task planners. Experience with structured LLM evaluation methods, agent benchmarking, or test harnesses for autonomous systems. Knowledge of performance optimization techniques for LLMs and agents, including caching, model distillation, model routing, or accelerated inference. Background integrating agentic components with large-scale data or analytics platforms (e.g., Databricks, Snowflake, Spark). Hands-on experience developing innovative POCs or experimental agentic architectures in fast-paced R&D environments. Familiarity with emerging agentic frameworks such as Strands Agents, LangGraph, CrewAI, etc. Exposure to safety-oriented design patterns for autonomous systems, including guardrails, validation layers, or constrained-action frameworks. Experience designing and building secure, compliance-aware systems that handle sensitive data in accordance with HIPAA and federal security standards, including implementation of encryption, access controls, auditability, and governance for protected health information (PHI) within AI/LLM workflows. Working Environment : eSimplicity supports a remote work environment operating within the Eastern time zone so we can work with and respond to our government clients. Expected hours are 9:00 AM to 5:00 PM Eastern unless otherwise directed by manager. Occasional travel for training and project meetings. It is estimated to be less than 5% per year. Benefits: eSimplicity offers a comprehensive benefits package, including medical, dental, and vision coverage, 401(k) retirement benefits, paid time off, paid holidays, life and disability insurance, and additional wellness and employee support programs. Eligibility may vary based on employment status and applicable plan terms. Reasonable Accommodation: eSimplicity is committed to providing reasonable accommodations to qualified individuals with disabilities during the application and hiring process. Applicants who need assistance or an accommodation should contact Human Resources. Equal Employment Opportunity: eSimplicity is an Equal Opportunity Employer, including disability and protected veteran status. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran status, disability, or any othe
Senior Network Security Engineer
NPO USA Chicago, Illinois
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
09/24/2026
Full time
Job Description Job Description About Us: NPO Torino is a specialized Digital Transformation company, recently acquired by the Fondo Italiano d'Investimento (Italian Investment Fund). With our headquarters in Turin and an operational presence in the United States and Brazil, we support companies in their technological evolution journey by combining consulting expertise with advanced IT solutions. We offer services in cloud computing, cybersecurity, AI for business, FinOps, system integration, and IT governance, featuring a customized and results-driven approach. Our mission is to simplify digital complexity and transform it into strategic value for enterprises. Backed by the Fondo Italiano d'Investimento , NPO Torino is accelerating its growth as a partner of choice for companies looking to tackle innovation challenges with vision, pragmatism, and sustainability. Salary range $80K to $92K. Work is partially remote with occasional travel to USA, and in Canada. Role Description: We are looking for a highly qualified Senior Network Security Engineer to join our Network & Security Business Unit. The professional will be responsible for the design, implementation, maintenance, and troubleshooting of complex network security infrastructures. The ideal candidate has deep, vertical expertise with leading security vendors (Fortinet, Palo Alto Networks, Cisco, F5) and a proven track record of managing modern architectures, including SASE solutions. Key Responsibilities: Design and manage security architectures based on Next-Generation Firewalls (NGFW). Implement and manage SASE (Secure Access Service Edge) solutions for distributed environments. Perform configuration , policy management, and advanced troubleshooting on multi-vendor equipment. Manage perimeter and internal security within Enterprise environments. Conduct log analysis, incident management, and system hardening. Provide technical mentoring for junior team members (optional, if required). Fundamental Technical Requirements (Must-Have) The candidate must demonstrate practical, in-depth, hands-on experience with the following technologies: Palo Alto Networks: Advanced configuration and management of NGFW (PA Series). Solid experience with Panorama for centralized management. Proven experience with SASE solutions (Prisma Access) and GlobalProtect. Fortinet: Advanced management of FortiGate (including VDOM, SD-WAN, SSL Inspection). Experience with the wider Fortinet ecosystem (FortiManager, FortiAnalyzer). Cisco Security: Experience with Cisco Security solutions (Firepower/FTD, ASA). Knowledge of Cisco ISE (Identity Services Engine) and TrustSec architectures is a strong plus. F5 Networks: Implementation and management of F5 BIG-IP solutions. Strong configuration and troubleshooting skills on LTM (Local Traffic Manager) and/or APM (Access Policy Manager) / AWAF modules. Soft Skills & Additional Requirements: Minimum of 5+ years of experience in Network Security Engineering roles. Excellent troubleshooting and problem-solving skills under pressure. Preferred Certifications (Nice-to-Have): Palo Alto: PCNSE (Palo Alto Networks Certified Network Security Engineer). Fortinet: NSE 4 / NSE 7. Cisco: CCNP Security or CCIE Security. F5: F5 Certified Administrator (F5-CA) or Technology Specialist (F5-CTS). Introduce Yourself (Screening Questions): "Do you have direct implementation experience with Prisma Access? Can you briefly describe a SASE architecture you have managed?" "Have you ever managed migrations between these vendors (e.g., from Cisco to Fortinet or vice versa)?" What We Offer: Salary commensurate with experience. Structured training and certification plans. Corporate benefits: Welfare Plan, Smart Working.
Principal Staff Engineer - Web Platform
PlanetArt Agoura Hills, California
Job Description Job Description Company and Vision PlanetArt's vision is to be the leading seller of personalized and make-on-demand products worldwide. We provide consumers with unmatched tools and content and an unparalleled end-to-end customer experience that result in high-quality, meaningful finished products and memorable celebrations of live events. The company's brands include the popular FreePrints and FreePrints Photobooks apps and the industry leading SimplytoImpress card and stationery site, as well as Personal Creations, CafePress and ISeeMe! Visit to learn more about our brands. We have more than 500 team members across multiple offices, primarily in Calabasas CA, San Diego CA, Woodridge IL, Minneapolis, MN and Pleasanton, CA. We also have team members in two company-owned offices in China, as well as in Europe. Job Overview PlanetArt is seeking a Principal Staff Engineer-Web Platform to serve as a senior technical leader within our engineering organization and a key partner to the VP of Engineering. This is a highly hands-on role focused on building, operating, and scaling high-traffic ecommerce web platforms in a fast-moving production environment. Reporting directly to the VP of Engineering, this engineer will play a critical role in architecting, developing, troubleshooting, and maintaining our LAMP-based web applications and AWS infrastructure. The ideal candidate is equally comfortable writing production code, diagnosing complex site reliability issues, managing cloud infrastructure, and leading technical problem-solving during high-severity incidents. This role requires strong operational judgment and the ability to independently own production challenges across application, database, infrastructure, and deployment layers. The engineer will collaborate closely with our China-based development organization, serving as a senior US-based technical lead responsible for cross-team coordination, code quality, architectural guidance, and production stability. This is an ideal opportunity for an experienced engineer who thrives in high-scale ecommerce environments and enjoys combining deep application engineering with modern cloud operations and production ownership. PLEASE NOTE: Candidates much be local to or willing to relocate to the Calabasas area as we operate on a hybrid work model (3 days onsite, 2 remote) What You'll Do Key Responsibilities Full-Stack Platform Engineering: Design, develop, and maintain scalable features and services across our LAMP-based ecommerce platform, with a strong focus on reliability, performance, maintainability, and operational excellence. Production Operations & Incident Response : Act as a senior technical escalation point for complex production incidents, troubleshooting issues across application, infrastructure, networking, database, CDN, and deployment layers. Lead root cause analysis and drive long-term stability improvements. AWS Infrastructure Ownership : Manage and optimize AWS infrastructure, including deployment architecture, scaling strategies, observability, security, disaster recovery, and cost efficiency. Partner closely with DevOps and engineering leadership on operational best practices. High-Scale Performance Optimization : Monitor and improve application, database, and infrastructure performance for high-traffic consumer web applications. Identify bottlenecks and implement scalable solutions to improve uptime, latency, and system resilience. Cross-Functional Technical Leadership: Partner with Product, Design, Operations, and Customer Experience teams to translate business requirements into scalable technical solutions and ensure successful project execution. Global Engineering Collaboration : Work closely with the China-based engineering team to coordinate development efforts, conduct code reviews, align on architectural direction, manage releases, and maintain strong engineering communication across time zones. Code Quality & Engineering Standards : Champion high engineering standards through code reviews, testing strategies, documentation, observability, and operational best practices. Drive continuous improvement in system reliability and development processes. Technical Mentorship & Leadership : Provide technical mentorship and architectural guidance across the engineering organization. Influence technical direction through hands-on leadership, strong execution, and collaborative problem-solving. Requirements What You Should Have Skills, Qualifications, and Requirements Senior-Level Full-Stack Engineering Experience: 5+ years of professional experience building and operating large-scale web applications, including substantial hands-on experience with the LAMP stack (Linux, Apache, MySQL, PHP). Strong AWS & Cloud Operations Expertise : Deep hands-on experience with AWS services and production cloud environments, including EC2, RDS, S3, Lambda, CloudWatch, networking, scaling, monitoring, and infrastructure troubleshooting. Ecommerce & High-Traffic Website Experience : Experience supporting high-volume consumer-facing websites or ecommerce platforms, with a strong understanding of scalability, uptime, performance optimization, and operational reliability. Production Troubleshooting Expertise : Demonstrated ability to diagnose and resolve complex production issues under pressure, including database replication issues, performance degradation, infrastructure failures, deployment issues, and site outages. Distributed Systems & Database Knowledge : Strong understanding of distributed web architectures, database performance tuning, replication strategies, caching, queuing systems, and fault-tolerant system design. Global Team Collaboration: Experience working effectively with offshore or globally distributed engineering teams, with strong communication, coordination, and cross-cultural collaboration skills. Chinese Language Skills: Ability to communicate in Mandarin (spoken or written) is highly desirable to facilitate collaboration with our China-based engineering team. Engineering Best Practices: Strong understanding of software engineering fundamentals including Git workflows, CI/CD pipelines, automated testing, observability, code review practices, and secure development standards. Ownership Mentality: Self-directed engineer with strong operational instincts, excellent judgment, and the ability to independently own critical technical initiatives from design through production support. Technical Leadership: Demonstrated ability to influence engineering direction, mentor developers, and drive technical excellence through hands-on leadership rather than direct people management. What You Can Expect Working Conditions Work is performed in an office environment with low to moderate noise levels. Position requires regular, continuous use of computer. Position requires regular sitting and standing. Position requires regular interaction with team members through the following methods: in-person, phone, Zoom, Slack, or email. May require occasional travel. This is a hybrid position; employees are expected to be in the office three days per week (Monday, Tuesday, and Thursday) with the option of working remotely two days (Wednesday and Friday). Benefits The compensation range for this position is $130,000-$220,000 annual salary. PlanetArt offers a comprehensive benefits package, including: Health, Dental, and Vision Insurance Life Insurance Pet Insurance Mental Health Insurance 401(k) with matching Comprehensive Time Off Program including Paid Time Off, Sick Days, Paid Holidays, and Floating Holidays Employee Product Discounts
09/24/2026
Full time
Job Description Job Description Company and Vision PlanetArt's vision is to be the leading seller of personalized and make-on-demand products worldwide. We provide consumers with unmatched tools and content and an unparalleled end-to-end customer experience that result in high-quality, meaningful finished products and memorable celebrations of live events. The company's brands include the popular FreePrints and FreePrints Photobooks apps and the industry leading SimplytoImpress card and stationery site, as well as Personal Creations, CafePress and ISeeMe! Visit to learn more about our brands. We have more than 500 team members across multiple offices, primarily in Calabasas CA, San Diego CA, Woodridge IL, Minneapolis, MN and Pleasanton, CA. We also have team members in two company-owned offices in China, as well as in Europe. Job Overview PlanetArt is seeking a Principal Staff Engineer-Web Platform to serve as a senior technical leader within our engineering organization and a key partner to the VP of Engineering. This is a highly hands-on role focused on building, operating, and scaling high-traffic ecommerce web platforms in a fast-moving production environment. Reporting directly to the VP of Engineering, this engineer will play a critical role in architecting, developing, troubleshooting, and maintaining our LAMP-based web applications and AWS infrastructure. The ideal candidate is equally comfortable writing production code, diagnosing complex site reliability issues, managing cloud infrastructure, and leading technical problem-solving during high-severity incidents. This role requires strong operational judgment and the ability to independently own production challenges across application, database, infrastructure, and deployment layers. The engineer will collaborate closely with our China-based development organization, serving as a senior US-based technical lead responsible for cross-team coordination, code quality, architectural guidance, and production stability. This is an ideal opportunity for an experienced engineer who thrives in high-scale ecommerce environments and enjoys combining deep application engineering with modern cloud operations and production ownership. PLEASE NOTE: Candidates much be local to or willing to relocate to the Calabasas area as we operate on a hybrid work model (3 days onsite, 2 remote) What You'll Do Key Responsibilities Full-Stack Platform Engineering: Design, develop, and maintain scalable features and services across our LAMP-based ecommerce platform, with a strong focus on reliability, performance, maintainability, and operational excellence. Production Operations & Incident Response : Act as a senior technical escalation point for complex production incidents, troubleshooting issues across application, infrastructure, networking, database, CDN, and deployment layers. Lead root cause analysis and drive long-term stability improvements. AWS Infrastructure Ownership : Manage and optimize AWS infrastructure, including deployment architecture, scaling strategies, observability, security, disaster recovery, and cost efficiency. Partner closely with DevOps and engineering leadership on operational best practices. High-Scale Performance Optimization : Monitor and improve application, database, and infrastructure performance for high-traffic consumer web applications. Identify bottlenecks and implement scalable solutions to improve uptime, latency, and system resilience. Cross-Functional Technical Leadership: Partner with Product, Design, Operations, and Customer Experience teams to translate business requirements into scalable technical solutions and ensure successful project execution. Global Engineering Collaboration : Work closely with the China-based engineering team to coordinate development efforts, conduct code reviews, align on architectural direction, manage releases, and maintain strong engineering communication across time zones. Code Quality & Engineering Standards : Champion high engineering standards through code reviews, testing strategies, documentation, observability, and operational best practices. Drive continuous improvement in system reliability and development processes. Technical Mentorship & Leadership : Provide technical mentorship and architectural guidance across the engineering organization. Influence technical direction through hands-on leadership, strong execution, and collaborative problem-solving. Requirements What You Should Have Skills, Qualifications, and Requirements Senior-Level Full-Stack Engineering Experience: 5+ years of professional experience building and operating large-scale web applications, including substantial hands-on experience with the LAMP stack (Linux, Apache, MySQL, PHP). Strong AWS & Cloud Operations Expertise : Deep hands-on experience with AWS services and production cloud environments, including EC2, RDS, S3, Lambda, CloudWatch, networking, scaling, monitoring, and infrastructure troubleshooting. Ecommerce & High-Traffic Website Experience : Experience supporting high-volume consumer-facing websites or ecommerce platforms, with a strong understanding of scalability, uptime, performance optimization, and operational reliability. Production Troubleshooting Expertise : Demonstrated ability to diagnose and resolve complex production issues under pressure, including database replication issues, performance degradation, infrastructure failures, deployment issues, and site outages. Distributed Systems & Database Knowledge : Strong understanding of distributed web architectures, database performance tuning, replication strategies, caching, queuing systems, and fault-tolerant system design. Global Team Collaboration: Experience working effectively with offshore or globally distributed engineering teams, with strong communication, coordination, and cross-cultural collaboration skills. Chinese Language Skills: Ability to communicate in Mandarin (spoken or written) is highly desirable to facilitate collaboration with our China-based engineering team. Engineering Best Practices: Strong understanding of software engineering fundamentals including Git workflows, CI/CD pipelines, automated testing, observability, code review practices, and secure development standards. Ownership Mentality: Self-directed engineer with strong operational instincts, excellent judgment, and the ability to independently own critical technical initiatives from design through production support. Technical Leadership: Demonstrated ability to influence engineering direction, mentor developers, and drive technical excellence through hands-on leadership rather than direct people management. What You Can Expect Working Conditions Work is performed in an office environment with low to moderate noise levels. Position requires regular, continuous use of computer. Position requires regular sitting and standing. Position requires regular interaction with team members through the following methods: in-person, phone, Zoom, Slack, or email. May require occasional travel. This is a hybrid position; employees are expected to be in the office three days per week (Monday, Tuesday, and Thursday) with the option of working remotely two days (Wednesday and Friday). Benefits The compensation range for this position is $130,000-$220,000 annual salary. PlanetArt offers a comprehensive benefits package, including: Health, Dental, and Vision Insurance Life Insurance Pet Insurance Mental Health Insurance 401(k) with matching Comprehensive Time Off Program including Paid Time Off, Sick Days, Paid Holidays, and Floating Holidays Employee Product Discounts
Principal Agentic AI Security Engineer
AbbVie North Chicago, Illinois
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
09/24/2026
Full time
Job Description Job Description Company Description About AbbVie AbbVie's mission is to discover and deliver innovative medicines and solutions that solve serious health issues today and address the medical challenges of tomorrow. We strive to have a remarkable impact on people's lives across several key therapeutic areas including immunology, oncology and neuroscience - and products and services in our Allergan Aesthetics portfolio. For more information about AbbVie, please visit us at . on LinkedIn, Facebook, Instagram, X and YouTube. Job Description We are building a team that develops AI agents to solve hard security problems and you will be tackling the hardest ones. This is a hands-on, senior IC role. You will architect, build, and ship agentic AI systems that operate autonomously within security environments, while also driving the technical direction and standards for how these systems are built, tested, and secured. This is not a management role and not a pure research role. You will write code, ship systems, and get your hands dirty but you will be working on problems where there is no playbook yet. You will define the approach, build the proof of concept, harden it for production, and write the technical guidance others follow. Responsibilities: Architect and build AI agent systems for security operations autonomous detection, investigation, response, threat hunting, vulnerability analysis, and risk assessment Tackle the novel, high-complexity problems: adversarial robustness of agent systems, secure agent-to-agent communication, guardrails for autonomous decision-making in high-stakes security contexts Develop frameworks, tooling, and patterns for building secure and reliable agentic AI systems then use them yourself Conduct original research and experimentation on agentic AI applied to offensive and defensive security, translating findings into working code Build proof-of-concept exploits and adversarial tests against agentic AI systems to identify failure modes and inform defensive design Develop and publish technical guidance and policy for agentic AI security grounded in systems you have built and broken Independently author security position papers on emerging technologies strategic, high-level documents that frame organizational thinking on new threat domains and drive downstream policy and technical guidance Serve as a subject matter expert and key driver of the AI Cybersecurity Maturity program, spanning application security, training, AI controls and infrastructure, AI discovery and inventory, operations and incident response, and policy and procedure development Integrate LLMs, custom models, and security tooling (SIEM, EDR, SOAR, cloud platforms, vulnerability scanners) into agent architectures Evaluate and adopt emerging AI capabilities (new models, frameworks, techniques) and determine their applicability to security problems Set technical direction for agent development practices, including evaluation frameworks, testing methodologies, and deployment patterns Mentor and elevate other engineers on the team through code review, design guidance, and technical leadership Qualifications Required: Bachelor's Degree with 9 years' experience; Master's Degree with 8 years' experience; PhD with 4 years' experience. Respective years of experience in cybersecurity, security engineering, or security research with substantial hands-on technical depth Strong software engineering skills you ship production systems, not just prototypes. Python required; additional languages a plus Deep expertise in at least two of: security operations, application security, threat intelligence, vulnerability research, detection engineering, offensive security, cloud security Demonstrated experience building AI agents and AI/ML-powered security tools or automation that operated at scale Hands-on experience with agentic coding tools (e.g., Claude Code, Cursor, GitHub Copilot, Aider, or similar) as part of your daily development workflow you build with agents, not just build agents Track record of original technical work published research, open-source tooling, conference presentations, or equivalent evidence of independent technical contribution Ability to work at the intersection of security and AI: you understand both the security implications of AI systems and how to apply AI to security problems Experience developing technical standards, frameworks, or guidance that others adopted Strong written and verbal communication you can explain complex technical concepts to both engineers and senior leadership, and you can write strategically about emerging technology risks at a level that shapes organizational direction Preferred: Experience with agent orchestration and autonomous systems (custom frameworks, LangChain, AutoGen, MCP, or similar) Background in adversarial ML, AI red teaming, or AI safety Familiarity with security compliance frameworks (NIST, ISO 27001, SOX) and how they apply to AI systems Published work (Black Hat, DEF CON, OWASP, academic journals, or equivalent venues) Experience in regulated industries (financial services, healthcare, critical infrastructure, government/defense) Contributions to open-source security projects OWASP, MITRE ATT&CK, or similar framework expertise applied in production environments Security clearance eligibility (not required) Additional Information Applicable only to applicants applying to a position in any location with pay disclosure requirements under state or local law: The compensation range described below is the range of possible base pay compensation that the Company believes in good faith it will pay for this role at the time of this posting based on the job grade for this position. Individual compensation paid within this range will depend on many factors including geographic location, and we may ultimately pay more or less than the posted range. This range may be modified in the future. We offer a comprehensive package of benefits including paid time off (vacation, holidays, sick), medical/dental/vision insurance and 401(k) to eligible employees. This job is eligible to participate in our long-term incentive programs. Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, incentive, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole and absolute discretion unless and until paid and may be modified at the Company's sole and absolute discretion, consistent with applicable law. AbbVie is an equal opportunity employer and is committed to operating with integrity, driving innovation, transforming lives and serving our community. Equal Opportunity Employer/Veterans/Disabled. US & Puerto Rico only - to learn more, visit -us/equal-employment-opportunity-employer.html US & Puerto Rico applicants seeking a reasonable accommodation, click here to learn more: -us/reasonable- accommodations.html
Network Security Engineer
Agile Defense Suitland, Maryland
Job Description Job Description About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests. Requisition #: 1853 Job Title: Network Security Engineer Location: Suitland, MD Clearance Level: Public Trust Job Description Agile Defense is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new access control platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices. This role also supports the agency's modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE. Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication. Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS 3715 appliances, ensuring high availability and consistent policy enforcement. Support the agency's migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets. Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams. Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policy driven access control. Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based authorization, and directory based authentication workflows. Deploy, configure, and maintain Cisco ISE components, including: o Policy Sets, Authorization Profiles, and Authentication Rules o TACACS+ device administration o 802.1X for wired and wireless networks o Profiling, posture, and compliance policies o Certificate based authentication and PKI integrations Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues. Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience. Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures. Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts. Education and Background Bachelor's degree in Information Technology, Cybersecurity, or a related field. Years of Experience Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE. Four (4) years of experience supporting identity centric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls. Required Skills Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication. Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in: o Authentication and authorization policies (RADIUS/TACACS+) o 802.1X/EAP methods for wireless and wired access o Device profiling, posture checks, and endpoint compliance o Certificate based authentication (EAP TLS) and PKI integration o AAA integrations for switches, appliances, firewalls, and wireless controllers Experience working with Cisco ISE deployed on Cisco SNS 3715 appliances, preferably in a two node clustered, high availability setup. Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows. Hands on experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based policy decisions, and directory based authentication. Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding. Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles. Solid understanding of telecommunications, network security, and Zero Trust best practices. Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and non technical audiences. Preferred Skills Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications. Working Conditions On-site 5 days a week in Suitland, Maryland In addition, Agile Defense invests in its employees beyond just compensation. Agile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections. Our Core Values Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are. Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do. Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated. Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support. Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task. Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges. Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/24/2026
Full time
Job Description Job Description About Agile Defense At Agile Defense we know that action defines the outcome and new challenges require new solutions. That's why we always look to the future and embrace change with an unmovable spirit and the courage to build for what comes next. Our vision is to bring adaptive innovation to support our nation's most important missions through the seamless integration of advanced technologies, elite minds, and unparalleled agility-leveraging a foundation of speed, flexibility, and ingenuity to strengthen and protect our nation's vital interests. Requisition #: 1853 Job Title: Network Security Engineer Location: Suitland, MD Clearance Level: Public Trust Job Description Agile Defense is seeking a Senior Network Security Engineer to support the agency as it moves away from its legacy ForeScout CounterACT NAC/NAM system and adopts Cisco Identity Services Engine (ISE) as the new access control platform. The engineer will help configure and manage Cisco ISE across the environment, handling AAA services, wired and wireless 802.1X authentication, device administration, and posture checks for users and devices. This role also supports the agency's modernization work by improving authentication processes, updating ISE policies, and strengthening identity-based access controls. The engineer will troubleshoot access issues, refine policy designs, and help ensure users and devices can connect securely and reliably as the organization completes its transition from ForeScout to Cisco ISE. Troubleshoot and resolve Cisco ISE issues across RADIUS, TACACS+, 802.1X, device administration, and endpoint authentication. Deploy, configure, and maintain Cisco ISE running on two clustered Cisco SNS 3715 appliances, ensuring high availability and consistent policy enforcement. Support the agency's migration from ForeScout CounterACT to Cisco ISE, including reviewing legacy ForeScout policies, device groups, and access rules and mapping them into ISE policy sets. Provide general wireless support, including basic troubleshooting, wireless access workflows, and coordination with wireless infrastructure teams. Configure and support Cisco ISE integrations with Cisco 9800 WLCs, including guest/registration portals, wireless onboarding, and policy driven access control. Integrate and maintain Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based authorization, and directory based authentication workflows. Deploy, configure, and maintain Cisco ISE components, including: o Policy Sets, Authorization Profiles, and Authentication Rules o TACACS+ device administration o 802.1X for wired and wireless networks o Profiling, posture, and compliance policies o Certificate based authentication and PKI integrations Monitor security events using ISE logs, syslog, and performing root cause analysis for authentication and access issues. Manage identity integrations, enforce security policies, and tune configurations to support Zero Trust and improve user experience. Perform routine health checks, upgrades, migrations, and document changes through SOPs, engineering designs, and implementation procedures. Work closely with engineering, operations, and compliance teams while mentoring junior staff and contributing to knowledge sharing efforts. Education and Background Bachelor's degree in Information Technology, Cybersecurity, or a related field. Years of Experience Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE. Four (4) years of experience supporting identity centric or Zero Trust architectures with strong knowledge of segmentation, certificate management, and endpoint posture controls. Required Skills Senior Network Security Engineer responsible for designing, configuring, monitoring, and troubleshooting Cisco ISE as a NAC/NAM platform, including TACACS+/RADIUS services, device administration policies, and wired/wireless 802.1X authentication. Eight (8) years of experience in a large government organization with five (5) years in technical leadership, including four (4) years implementing and troubleshooting Cisco ISE with expertise in: o Authentication and authorization policies (RADIUS/TACACS+) o 802.1X/EAP methods for wireless and wired access o Device profiling, posture checks, and endpoint compliance o Certificate based authentication (EAP TLS) and PKI integration o AAA integrations for switches, appliances, firewalls, and wireless controllers Experience working with Cisco ISE deployed on Cisco SNS 3715 appliances, preferably in a two node clustered, high availability setup. Understanding of ForeScout CounterACT, including legacy NAC/NAM policies, device classification, and access workflows, to support the migration to Cisco ISE Experience providing general wireless network support, including basic troubleshooting, controller interactions, and wireless access workflows. Hands on experience integrating Cisco ISE with Active Directory (AD) and LDAP, including identity lookups, group based policy decisions, and directory based authentication. Experience supporting Cisco ISE integrations with Cisco 9800 Wireless LAN Controllers, including guest/registration page redirection and wireless onboarding. Experience migrating legacy NAC, RADIUS, or device authentication systems into Cisco ISE while aligning with Zero Trust principles. Solid understanding of telecommunications, network security, and Zero Trust best practices. Strong communication skills with the ability to explain Cisco ISE, NAC/NAM, and AAA concepts to both technical and non technical audiences. Preferred Skills Preferred certifications: Cisco CCNP Security, Cisco ISE Specialist, or similar identity/security certifications. Working Conditions On-site 5 days a week in Suitland, Maryland In addition, Agile Defense invests in its employees beyond just compensation. Agile's benefits offerings include, dependent upon position, Health Insurance, Life Insurance, Paid Time Off, Holiday Pay, short-term and long-term Disability, Retirement and Learning and Development opportunities as well as other optional benefit elections. Our Core Values Employees of Agile Defense are our number one priority, and the importance we place on our culture here is fundamental. Our culture is alive and evolving, but it always stays true to its roots. Here, you are valued as a family member, and we believe that we can accomplish great things together. Agile Defense has been highly successful in the past few years due to our employees and the culture we create together. What makes us Agile? We call it the 6Hs, the values that define our culture and guide everything we do. Together, these values infuse vibrancy, integrity, and a tireless work ethic into advancing the most important national security and critical civilian missions. It's how we show up every day. It's who we are. Happy - Be Infectious. Happiness multiplies and creates a positive and connected environment where motivation and satisfaction have an outsized effect on everything we do. Helpful - Be Supportive. Being helpful is the foundation of teamwork, resulting in a supportive atmosphere where collaboration flourishes, and collective success is celebrated. Honest - Be Trustworthy. Honesty serves as our compass, ensuring transparent communication and ethical conduct, essential to who we are and the complex domains we support. Humble - Be Grounded. Success is not achieved alone, humility ensures a culture of mutual respect, encouraging open communication, and a willingness to learn from one another and take on any task. Hungry - Be Eager. Our hunger for excellence drives an insatiable appetite for innovation and continuous improvement, propelling us forward in the face of new and unprecedented challenges. Hustle - Be Driven. Hustle is reflected in our relentless work ethic, where we are each committed to going above and beyond to advance the mission and achieve success. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Principal AI Engineer
Phizenix New York, New York
Job Description Job Description Job description At , we solve the most complex and critical challenges by moving quickly from analysis to action when it really matters; creating value that has a lasting impact on companies, their people, and the communities they serve. We hold ourselves accountable by providing space for authenticity, growth, and equity for everyone. has embraced a hybrid work model to provide flexibility and support work-life integration. Travel is part of this position, but frequency may vary based on client, team, and individual circumstances. Relocation assistance is not available for this position. About the Role The Principal AI Engineer sits at the intersection of software engineering, data science, platform architecture, and AI governance. You will be the technical owner of how AI/ML engineering is designed, built, governed, and shipped across a portfolio of products serving all of domains. This is a hands-on engineering and technical leadership position. You will move fluidly between writing production code, architecting multi-tenant AI services, building internal developer tooling, leading security and governance design, and mentoring engineering teams. Your success is measured by team-level outcomes - scalable patterns that outlast your direct involvement. What You'll Do AI Productization & Platform Engineering Design and own the firm's AI productization & governance playbook, covering service patterns, security/compliance standards, model evaluation rubrics, and production-readiness criteria. Build and maintain reusable internal tooling, including AI service scaffolding, evaluation and monitoring tooling, and data infrastructure - designed for team adoption without ongoing hand-holding. Establish AI agent governance policies covering agent permissions, code execution controls, access to internal systems, and human-in-the-loop enforcement. Partner with Security, Legal, and Compliance to define SOC2/ISO-aligned AI controls, vendor DPA requirements, and prompt data classification policies. Establish standardized deployment patterns using containerization, infrastructure-as-code, and CI/CD pipeline templates reusable across teams. Developer Experience & Engineering Excellence Champion AI-assisted development practices across the engineering org, including LLM-integrated development workflows, test-driven development patterns, and reusable tooling standards that scale across teams. Codify modern software development standards (CI/CD, DevOps, testing, delivery quality) referenced by multiple teams as a baseline for new or re-platformed products. Mentor engineers and tech leads with observable improvement in delivery consistency, design quality, and production readiness rigor. Cross-Functional Leadership & Stakeholder Influence Serve as the go-to technical authority on AI/ML, platform architecture, and engineering practices - regularly consulted by senior stakeholders at the design and strategy stages. Bridge technical and non-technical stakeholders, translating complex architectural decisions, AI risk topics, and platform tradeoffs into clear, actionable guidance. What You'll Need Required 15+ years in software engineering, data science, or a closely related technical field. Bachelor's degree or higher in Computer Science, Engineering, or a related field. Deep expertise in AI/ML frameworks and the Python ecosystem, with hands-on experience deploying models to public cloud infrastructure. Demonstrated experience designing and operating multi-tenant AI services and LLM integrations in production. Proven track record leading microservices architecture - decomposing monoliths, defining service contracts, and operationalizing CI/CD for distributed systems. Strong hands-on command of containerization (Docker), infrastructure-as-code (Terraform), and modern DevOps practices. Substantive experience with AI/LLM security - including prompt injection, data boundary enforcement, model supply chain risk, and AI-specific threat modeling. Strong problem-solving skills, especially in building governance frameworks, evaluation rubrics, and reusable platform patterns at scale. Excellent written and verbal communication skills in English; ability to translate complex technical topics to diverse audiences, including executive stakeholders. Experience with Agile methodologies and cross-functional product team collaboration. Preferred / Additional Qualifications Experience applying AI/ML in business consulting, advisory, or professional services contexts. Familiarity with AI service interface and gateway design patterns, including emerging AI integration protocols. Contributions to open-source AI/ML projects, publications, or active involvement in technical communities. Advanced certifications in AI, deep learning, cloud architecture, or security (e.g., AWS/GCP/Azure ML, CISSP). Experience defining AI compliance controls for SOC2, ISO 27001, or TISAX frameworks. Demonstrated enthusiasm for developer education - writing internal guides, running workshops, or building internal tooling communities. Proficiency in additional languages is a plus (Go, Typescript) Demonstrated ability and enthusiasm to mentor and uplift junior team members or peers Willingness to work outside of normal business hours, and in particular as unique projects/needs arise. Ability to work full time in an office and remote environment; physically able to sit/stand at a computer and work in front of a computer screen for significant portions of the workday Must become familiar with, and promote and abide by, our Core Values as defined by the and foster an inclusive environment with people at all levels of an organization
09/24/2026
Full time
Job Description Job Description Job description At , we solve the most complex and critical challenges by moving quickly from analysis to action when it really matters; creating value that has a lasting impact on companies, their people, and the communities they serve. We hold ourselves accountable by providing space for authenticity, growth, and equity for everyone. has embraced a hybrid work model to provide flexibility and support work-life integration. Travel is part of this position, but frequency may vary based on client, team, and individual circumstances. Relocation assistance is not available for this position. About the Role The Principal AI Engineer sits at the intersection of software engineering, data science, platform architecture, and AI governance. You will be the technical owner of how AI/ML engineering is designed, built, governed, and shipped across a portfolio of products serving all of domains. This is a hands-on engineering and technical leadership position. You will move fluidly between writing production code, architecting multi-tenant AI services, building internal developer tooling, leading security and governance design, and mentoring engineering teams. Your success is measured by team-level outcomes - scalable patterns that outlast your direct involvement. What You'll Do AI Productization & Platform Engineering Design and own the firm's AI productization & governance playbook, covering service patterns, security/compliance standards, model evaluation rubrics, and production-readiness criteria. Build and maintain reusable internal tooling, including AI service scaffolding, evaluation and monitoring tooling, and data infrastructure - designed for team adoption without ongoing hand-holding. Establish AI agent governance policies covering agent permissions, code execution controls, access to internal systems, and human-in-the-loop enforcement. Partner with Security, Legal, and Compliance to define SOC2/ISO-aligned AI controls, vendor DPA requirements, and prompt data classification policies. Establish standardized deployment patterns using containerization, infrastructure-as-code, and CI/CD pipeline templates reusable across teams. Developer Experience & Engineering Excellence Champion AI-assisted development practices across the engineering org, including LLM-integrated development workflows, test-driven development patterns, and reusable tooling standards that scale across teams. Codify modern software development standards (CI/CD, DevOps, testing, delivery quality) referenced by multiple teams as a baseline for new or re-platformed products. Mentor engineers and tech leads with observable improvement in delivery consistency, design quality, and production readiness rigor. Cross-Functional Leadership & Stakeholder Influence Serve as the go-to technical authority on AI/ML, platform architecture, and engineering practices - regularly consulted by senior stakeholders at the design and strategy stages. Bridge technical and non-technical stakeholders, translating complex architectural decisions, AI risk topics, and platform tradeoffs into clear, actionable guidance. What You'll Need Required 15+ years in software engineering, data science, or a closely related technical field. Bachelor's degree or higher in Computer Science, Engineering, or a related field. Deep expertise in AI/ML frameworks and the Python ecosystem, with hands-on experience deploying models to public cloud infrastructure. Demonstrated experience designing and operating multi-tenant AI services and LLM integrations in production. Proven track record leading microservices architecture - decomposing monoliths, defining service contracts, and operationalizing CI/CD for distributed systems. Strong hands-on command of containerization (Docker), infrastructure-as-code (Terraform), and modern DevOps practices. Substantive experience with AI/LLM security - including prompt injection, data boundary enforcement, model supply chain risk, and AI-specific threat modeling. Strong problem-solving skills, especially in building governance frameworks, evaluation rubrics, and reusable platform patterns at scale. Excellent written and verbal communication skills in English; ability to translate complex technical topics to diverse audiences, including executive stakeholders. Experience with Agile methodologies and cross-functional product team collaboration. Preferred / Additional Qualifications Experience applying AI/ML in business consulting, advisory, or professional services contexts. Familiarity with AI service interface and gateway design patterns, including emerging AI integration protocols. Contributions to open-source AI/ML projects, publications, or active involvement in technical communities. Advanced certifications in AI, deep learning, cloud architecture, or security (e.g., AWS/GCP/Azure ML, CISSP). Experience defining AI compliance controls for SOC2, ISO 27001, or TISAX frameworks. Demonstrated enthusiasm for developer education - writing internal guides, running workshops, or building internal tooling communities. Proficiency in additional languages is a plus (Go, Typescript) Demonstrated ability and enthusiasm to mentor and uplift junior team members or peers Willingness to work outside of normal business hours, and in particular as unique projects/needs arise. Ability to work full time in an office and remote environment; physically able to sit/stand at a computer and work in front of a computer screen for significant portions of the workday Must become familiar with, and promote and abide by, our Core Values as defined by the and foster an inclusive environment with people at all levels of an organization
Senior Network Security Engineer
Ignite IT
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
09/24/2026
Full time
Job Description Job Description We are seeking a Senior Network Security Engineer for an operations-first role supporting enterprise network security infrastructure across on-premises, remote-access, hybrid-cloud, and cloud-connected environments. This is not primarily an architecture/design role. The priority is a hands-on engineer who can administer, configure, maintain, troubleshoot, patch, upgrade, back up, validate, document, and operate production security platforms with minimal ramp-up. Firewall operations: hands-on Cisco and Palo Alto firewall administration, rule changes, NAT, troubleshooting, policy cleanup, upgrades, backups, logging, and production support. VPN / remote access: support for remote-access VPN, site-to-site VPN, user connectivity issues, certificates, authentication flows, and after-hours troubleshooting. RSA / MFA administration: RSA SecurID or equivalent MFA operations, token support, server administration, user troubleshooting, VPN integration, certificates, patching, backups, logs, and monitoring. Day-to-day operations: ticket resolution, monitoring alerts, health checks, change requests, incident support, maintenance windows, operational reporting, and customer support. Configuration and administration: installing, configuring, maintaining, patching, upgrading, backing up, validating, and troubleshooting assigned security platforms. Production troubleshooting: strong TCP/IP, DNS, routing, firewall logs, packet captures, VPN authentication, certificate, and connectivity troubleshooting. Documentation and process discipline: SOPs, runbooks, diagrams, change records, rollback plans, evidence collection, knowledge transfer, and formal change management. Federal/customer environment maturity: Public Trust eligibility, regulated-environment documentation, customer support, cross-team coordination, and comfort working with government stakeholders. The best candidate can credibly say: "I have operated enterprise Cisco and Palo Alto firewalls in production, handled firewall rule changes and troubleshooting, supported VPN users and site-to-site tunnels, administered or supported RSA/MFA tied to VPN access, followed formal change-management processes, maintained documentation and backups, and can step into daily operational support with minimal ramp-up." Scope and Role Boundaries Primary platforms include Cisco ASA/Firepower/FTD/FMC, Palo Alto NGFW/Panorama/GlobalProtect, remote-access and site-to-site VPN, RSA SecurID Authentication Manager or comparable MFA, monitoring/logging/SIEM integrations, and related network security controls. Coordinate with SOC/NOC, cloud, identity/directory, wireless/LAN, server, endpoint, system owner, application, governance, and vendor teams during changes, incidents, troubleshooting, compliance, and audit support. Cloudflare, Cisco ISE/NAC, secure web/email gateways, packet visibility tools, SD-WAN/SASE/ZTNA, AWS/Azure security, and F5/application-delivery awareness are useful where they intersect with assigned operational support, but the core need is firewall, VPN, RSA/MFA, and production operations. Key Responsibilities Provide daily, weekly, monthly, and annual operational support for assigned security systems, including tickets, alerts, health checks, email/phone support, metrics, status reporting, and operational validation. Administer and troubleshoot enterprise firewalls, including rule bases, NAT, segmentation, high availability, threat prevention, VPN integration, logging, secure baselines, rule reviews, recertification, cleanup, and decommissioning. Install, configure, maintain, patch, upgrade, back up, and validate firewall, VPN, MFA, and related network security systems in production environments. Support remote-access VPN, site-to-site VPN, partner connectivity, cloud connectivity, mobile/remote users, certificates, authentication policies, availability, utilization, and user access issues. Maintain and troubleshoot RSA SecurID Authentication Manager or equivalent MFA services, including servers/appliances, agents, certificates, HA, backups, logs, monitoring, directory integration, VPN authentication, and token lifecycle support. Respond to incidents, vulnerability notices, urgent requests, vendor advisories, PSIRT notices, system alerts, and emergency troubleshooting while minimizing service disruption. Use firewall logs, VPN logs, packet captures, SIEM data, monitoring tools, DNS/routing checks, and standard diagnostics to resolve complex connectivity, authentication, TLS/certificate, and application-flow issues. Create and maintain topology diagrams, equipment inventories, configurations, SOPs, runbooks, implementation plans, rollback plans, build/upgrade procedures, troubleshooting notes, and knowledge articles. Follow approved change, release, incident, problem, and configuration-management processes; prepare change records, peer-review materials, validation evidence, root-cause analysis, metrics, and audit artifacts. Support vulnerability remediation, POA&M tracking, continuous monitoring, compliance reviews, audit evidence collection, and coordination with ISSO, system owner, and security governance teams. Requirements 7+ years of experience in network security engineering, network infrastructure, cybersecurity infrastructure, or a closely related role. 5+ years of hands-on experience administering, maintaining, and troubleshooting enterprise firewall platforms in production environments. Hands-on experience with Cisco security technologies such as Cisco ASA, Firepower, FTD, FMC, AnyConnect/Secure Client, or equivalent Cisco firewall/VPN platforms. Hands-on experience with Palo Alto Networks technologies such as NGFW, Panorama, GlobalProtect, security profiles, App-ID/User-ID, logging, and policy optimization. Experience administering or supporting RSA SecurID Authentication Manager or comparable enterprise MFA/two-factor authentication platforms, including token support, server operations, patching/upgrades, backups, certificates, monitoring, and directory/VPN integration. Strong knowledge of firewall policy, NAT, VPNs, routing, DNS, DHCP, BGP, TLS/certificates, packet captures, log analysis, segmentation, high availability, and common network diagnostic tools. Experience with enterprise monitoring, logging, SIEM, alerting, vulnerability management, incident response, formal change management, and regulated-environment documentation. Ability to create clear technical documentation, support customers and stakeholders, prioritize operational work, communicate clearly, and coordinate across technical teams. Ability to obtain and maintain a Public Trust background investigation. Desired Certifications Relevant certifications are helpful but should not replace demonstrated hands-on experience. Examples include CCNP Security, CCIE Security, PCNSE, PCCSE, CISSP, CCSP, AWS Certified Security - Specialty, AWS Advanced Networking - Specialty, Microsoft Certified: Azure Security Engineer Associate, Microsoft Certified: Azure Network Engineer Associate, CompTIA Security+, CompTIA CySA+, GIAC certifications, or equivalent vendor/cloud certifications. Core Competencies Enterprise firewall engineering and policy lifecycle management VPN, remote access, RSA/MFA, and token lifecycle operations Cloudflare, edge security, secure access, and Zero Trust support Content filtering, secure web/email gateway, and NAC operations Hybrid-cloud network security and secure connectivity Monitoring, logging, SIEM integration, and incident response support Security visibility, packet analysis, and advanced troubleshooting Vulnerability remediation, compliance evidence, and POA&M support Change management, documentation, reporting, and operational metrics Technical leadership, customer support, and cross-team collaboration Benefits 401(k) 401(k) matching Dental insurance Flexible schedule Flexible spending account Health insurance Health savings account Life insurance Paid time off Professional development assistance Referral program Retirement plan Tuition reimbursement Vision insurance
Staff / Principal Platform Engineer
AppGate Cybersecurity, Inc. New York, New York
Job Description Job Description Staff / Principal Platform Engineer Location: New York City Hybrid Department: AI Platform & Infrastructure Team Reports to: Vangie Shue - Principal Engineering Manager About AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution and Cyber Advisory Services. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate Cyber Advisory Services harden your security posture and ensure business continuity. AppGate safeguards Fortune 500 enterprises and government agencies worldwide. Learn more at About the Role As we expand our platform, we are standing up a new AI Platform & Infrastructure team: the engine room of AppGate's AI strategy. This team owns the infrastructure layer that every next-generation security capability is built on, from network observability to AI-driven threat detection and the secure operation of emerging Agentic AI systems. We're looking for a Staff or Principal Platform Engineer to build and operate the foundational platform behind AppGate's AI products. You combine deep DevOps and cloud infrastructure expertise with hands-on experience operationalizing AI/ML systems, and you treat observability as a first-class engineering discipline. This is a rare opportunity to join a small, private, high-impact company where your work directly shapes the architecture, reliability and core platform that defines the future of security. You'll own the platform spanning APIs, cloud and self-managed solutions and AI/ML infrastructure, and you'll make it fast, reliable and observable at scale. This is a high-leverage, hands-on role for a senior engineer who sets technical direction and still ships. Key Responsibilities Build the Platform: design, build and operate the cloud infrastructure, services and pipelines that AppGate's AI and cloud products run on. Strong experience with self-managed technologies (kafka, elasticsearch) and Kubernetes are a must. Infrastructure as Code & Deployment Orchestration: Terraform and Helm for cloud provisioning, service deployment and configuration management. Implement Observability: instrument APIs, cloud services and AI/ML infrastructure with metrics, logging, tracing and alerting, and define SLOs and operational health metrics that teams trust. Data Platform: real-time and batch data ingestion pipelines, feature stores and data quality. Integrations: third-party connectors, APIs and platform integrations. Operationalize AI/ML: build model serving and inference pipelines, experiment tracking and the MLOps tooling for deployment, versioning, drift monitoring and lifecycle management. Engineer for reliability & automation: apply SRE practices to reduce toil, improve resilience and keep latency and uptime within target across the platform. Automate everything - deliver infrastructure-as-code, CI/CD and self-service tooling so product teams ship safely and quickly. Set technical direction: define platform standards, architecture and best practices, and raise the engineering bar through design reviews and mentorship. Collaborate cross-functionally: partner with data scientists, product teams and leadership to align platform investment with AppGate's strategic vision. Required Qualifications Experience: extensive platform, infrastructure or SRE engineering experience, with a track record of operating production systems at scale. Staff-level candidates typically bring 8+ years and Principal-level candidates 12+ years, though we hire on demonstrated impact. DevOps depth: strong command of infrastructure-as-code (Terraform or equivalent), CI/CD, containers and orchestration (Docker, Kubernetes), and cloud platforms (AWS). Observability expertise: hands-on experience implementing observability across APIs, cloud services and distributed systems using tools such as Prometheus, Grafana, OpenTelemetry, the ELK stack or comparable, including SLO and error-budget practice. Data platform skills: familiarity with real-time and batch ingestion pipelines, feature stores and data quality at production scale. Engineering craft: fluency in a primary backend language (Python, Go or similar) and a strong bias toward automation, testing and reliable, maintainable systems. Leadership: a record of setting technical direction, leading complex initiatives across teams, mentoring senior engineers, while still being very hands-on. Mindset: pragmatic, rigorous and ownership-driven. You thrive in a small, fast-moving environment and enjoy building foundations others depend on. Preferred Qualifications AI/ML infrastructure: experience building or operating model serving, inference pipelines and MLOps tooling such as MLflow, Kubeflow, SageMaker or equivalent, including model deployment, versioning and drift monitoring. Networking & Zero Trust fundamentals: working knowledge of the network and routing layer beneath modern access solutions - TCP/IP, TLS, tunneling/overlay networks, packet routing and filtering, DNS and firewalling - and familiarity with Zero Trust Network Access (ZTNA) or adjacent domains (VPN, SDP, SASE, software-defined networking). You can reason about traffic paths, latency and throughput end-to-end, and instrument the network as a first-class observability signal. Compensation Staff: 185k-225k base Principal: 215k-270k base We offer performance bonuses and considerable equity. AppGate is An Equal Opportunity/Affirmative Action Employer and a federal contractor subject to the Rehabilitation Act of 1973 and the Vietnam Era Veterans Readjustment Assistance Act of 1974 as amended, and their corresponding regulations. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. Further, AppGate is an affirmative action employer committed to taking positive steps to employ, advance in employment and otherwise afford equal employment opportunity to protected veterans and individuals with disabilities. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.
09/24/2026
Full time
Job Description Job Description Staff / Principal Platform Engineer Location: New York City Hybrid Department: AI Platform & Infrastructure Team Reports to: Vangie Shue - Principal Engineering Manager About AppGate AppGate secures and protects an organization's most valuable assets with its high performance Zero Trust Network Access (ZTNA) solution and Cyber Advisory Services. AppGate ZTNA is the only direct-routed Zero Trust solution built for peak performance, superior protection and seamless interoperability. AppGate Cyber Advisory Services harden your security posture and ensure business continuity. AppGate safeguards Fortune 500 enterprises and government agencies worldwide. Learn more at About the Role As we expand our platform, we are standing up a new AI Platform & Infrastructure team: the engine room of AppGate's AI strategy. This team owns the infrastructure layer that every next-generation security capability is built on, from network observability to AI-driven threat detection and the secure operation of emerging Agentic AI systems. We're looking for a Staff or Principal Platform Engineer to build and operate the foundational platform behind AppGate's AI products. You combine deep DevOps and cloud infrastructure expertise with hands-on experience operationalizing AI/ML systems, and you treat observability as a first-class engineering discipline. This is a rare opportunity to join a small, private, high-impact company where your work directly shapes the architecture, reliability and core platform that defines the future of security. You'll own the platform spanning APIs, cloud and self-managed solutions and AI/ML infrastructure, and you'll make it fast, reliable and observable at scale. This is a high-leverage, hands-on role for a senior engineer who sets technical direction and still ships. Key Responsibilities Build the Platform: design, build and operate the cloud infrastructure, services and pipelines that AppGate's AI and cloud products run on. Strong experience with self-managed technologies (kafka, elasticsearch) and Kubernetes are a must. Infrastructure as Code & Deployment Orchestration: Terraform and Helm for cloud provisioning, service deployment and configuration management. Implement Observability: instrument APIs, cloud services and AI/ML infrastructure with metrics, logging, tracing and alerting, and define SLOs and operational health metrics that teams trust. Data Platform: real-time and batch data ingestion pipelines, feature stores and data quality. Integrations: third-party connectors, APIs and platform integrations. Operationalize AI/ML: build model serving and inference pipelines, experiment tracking and the MLOps tooling for deployment, versioning, drift monitoring and lifecycle management. Engineer for reliability & automation: apply SRE practices to reduce toil, improve resilience and keep latency and uptime within target across the platform. Automate everything - deliver infrastructure-as-code, CI/CD and self-service tooling so product teams ship safely and quickly. Set technical direction: define platform standards, architecture and best practices, and raise the engineering bar through design reviews and mentorship. Collaborate cross-functionally: partner with data scientists, product teams and leadership to align platform investment with AppGate's strategic vision. Required Qualifications Experience: extensive platform, infrastructure or SRE engineering experience, with a track record of operating production systems at scale. Staff-level candidates typically bring 8+ years and Principal-level candidates 12+ years, though we hire on demonstrated impact. DevOps depth: strong command of infrastructure-as-code (Terraform or equivalent), CI/CD, containers and orchestration (Docker, Kubernetes), and cloud platforms (AWS). Observability expertise: hands-on experience implementing observability across APIs, cloud services and distributed systems using tools such as Prometheus, Grafana, OpenTelemetry, the ELK stack or comparable, including SLO and error-budget practice. Data platform skills: familiarity with real-time and batch ingestion pipelines, feature stores and data quality at production scale. Engineering craft: fluency in a primary backend language (Python, Go or similar) and a strong bias toward automation, testing and reliable, maintainable systems. Leadership: a record of setting technical direction, leading complex initiatives across teams, mentoring senior engineers, while still being very hands-on. Mindset: pragmatic, rigorous and ownership-driven. You thrive in a small, fast-moving environment and enjoy building foundations others depend on. Preferred Qualifications AI/ML infrastructure: experience building or operating model serving, inference pipelines and MLOps tooling such as MLflow, Kubeflow, SageMaker or equivalent, including model deployment, versioning and drift monitoring. Networking & Zero Trust fundamentals: working knowledge of the network and routing layer beneath modern access solutions - TCP/IP, TLS, tunneling/overlay networks, packet routing and filtering, DNS and firewalling - and familiarity with Zero Trust Network Access (ZTNA) or adjacent domains (VPN, SDP, SASE, software-defined networking). You can reason about traffic paths, latency and throughput end-to-end, and instrument the network as a first-class observability signal. Compensation Staff: 185k-225k base Principal: 215k-270k base We offer performance bonuses and considerable equity. AppGate is An Equal Opportunity/Affirmative Action Employer and a federal contractor subject to the Rehabilitation Act of 1973 and the Vietnam Era Veterans Readjustment Assistance Act of 1974 as amended, and their corresponding regulations. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age or any other federally protected class. Further, AppGate is an affirmative action employer committed to taking positive steps to employ, advance in employment and otherwise afford equal employment opportunity to protected veterans and individuals with disabilities. In furtherance of AppGate's policy regarding affirmative action and equal employment opportunity, AppGate has developed a written affirmative action program. This program is available for review upon request by any applicant or employee during normal business hours by contacting the company's EEO Coordinator.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board