it job board logo
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
  • Recruiting? Post a job
  • Sign in
  • Sign up
  • Home
  • Find IT Jobs
  • Register CV
  • Register as Employer
  • Contact us
  • Career Advice
Sorry, that job is no longer available. Here are some results that may be similar to the job you were looking for.

39 jobs found

Email me jobs like this
Refine Search
Current Search
iam security architect
Senior Cloud Security Engineer
BMO Financial Chicago, Illinois
BMO Financial seeks a Senior Cloud Security Engineer to secure critical banking, insurance, and investment platforms in a multi cloud environment. You will design and implement cloud security architectures, harden workloads, embed controls into CI/CD pipelines, and ensure compliance with financial regulations. Partnering with IT and Cybersecurity, you will lead threat modeling, incident response, and security automation while mentoring engineers. BMO offers an inclusive, equitable culture where diverse perspectives are valued and you can shape the future of secure digital banking. Responsibilities Design and implement secure architectures for multi cloud banking and insurance platforms. Define and enforce cloud security standards, patterns, and guardrails across AWS, Azure, and GCP. Integrate security into CI/CD pipelines and automate controls using Ia C and scripting. Lead threat modeling, risk assessments, and remediation for cloud initiatives. Configure and optimize IAM, network segmentation, encryption, and monitoring for critical workloads. Partner with IT, Cybersecurity, and lines of business to embed security in digital products. Drive incident response for cloud security events, including investigation and root cause analysis. Ensure compliance with financial services regulations and industry frameworks. Mentor engineers and champion cloud security best practices across BMO Financial. Contribute to an inclusive culture where diverse perspectives improve security outcomes. Required Skills Cloud security architecture AWS security Azure security GCP security Identity and access management (IAM) Zero Trust design Network security in cloud (VPC, security groups) Container and Kubernetes security Security automation & scripting (Python, Terraform) SIEM, logging, and monitoring Threat modeling and risk assessment Compliance (PCI-DSS, SOX, OSFI, GDPR) Incident response and forensics in cloud Dev Sec Ops and CI/CD security Encryption & key management (KMS, HSM)
09/27/2026
Full time
BMO Financial seeks a Senior Cloud Security Engineer to secure critical banking, insurance, and investment platforms in a multi cloud environment. You will design and implement cloud security architectures, harden workloads, embed controls into CI/CD pipelines, and ensure compliance with financial regulations. Partnering with IT and Cybersecurity, you will lead threat modeling, incident response, and security automation while mentoring engineers. BMO offers an inclusive, equitable culture where diverse perspectives are valued and you can shape the future of secure digital banking. Responsibilities Design and implement secure architectures for multi cloud banking and insurance platforms. Define and enforce cloud security standards, patterns, and guardrails across AWS, Azure, and GCP. Integrate security into CI/CD pipelines and automate controls using Ia C and scripting. Lead threat modeling, risk assessments, and remediation for cloud initiatives. Configure and optimize IAM, network segmentation, encryption, and monitoring for critical workloads. Partner with IT, Cybersecurity, and lines of business to embed security in digital products. Drive incident response for cloud security events, including investigation and root cause analysis. Ensure compliance with financial services regulations and industry frameworks. Mentor engineers and champion cloud security best practices across BMO Financial. Contribute to an inclusive culture where diverse perspectives improve security outcomes. Required Skills Cloud security architecture AWS security Azure security GCP security Identity and access management (IAM) Zero Trust design Network security in cloud (VPC, security groups) Container and Kubernetes security Security automation & scripting (Python, Terraform) SIEM, logging, and monitoring Threat modeling and risk assessment Compliance (PCI-DSS, SOX, OSFI, GDPR) Incident response and forensics in cloud Dev Sec Ops and CI/CD security Encryption & key management (KMS, HSM)
Software Development Engineer
Amazon Web Services, Inc. Seattle, Washington
Amazon Web Services, Inc. seeks a Software Development Engineer to build and enhance AWS IAM Identity Center services that secure access for millions of global customers. You will design, implement, and operate large-scale distributed systems, focusing on identity, authentication, and authorization. Collaborate with cross-functional teams to deliver high-quality, secure, and highly available features. You will own services end-to-end, from design and code to deployment and monitoring, using modern AWS technologies. This role suits engineers who thrive in a customer-obsessed, data-driven, and fast-paced environment. Responsibilities Design, implement, and maintain scalable, secure backend services for AWS IAM Identity Center. Develop, test, and review high-quality code for identity, authentication, and authorization workflows. Operate services in production, including monitoring, incident response, and continuous improvement. Collaborate with product, security, and other engineering teams to define requirements and deliver features. Apply secure coding practices and threat modeling to protect customer identities and data. Contribute to architectural decisions, code reviews, and technical documentation. Automate build, test, and deployment processes using CI/CD and infrastructure-as-code tools. Required Skills Java or C# or Python Distributed systems design RESTful API development AWS services (EC2, Lambda, Dynamo DB, RDS) Identity and access management (IAM, OAuth, SAML, OIDC) Microservices architecture CI/CD pipelines Monitoring and observability (Cloud Watch, X-Ray) Relational and No SQL databases Secure coding and threat modeling
09/27/2026
Full time
Amazon Web Services, Inc. seeks a Software Development Engineer to build and enhance AWS IAM Identity Center services that secure access for millions of global customers. You will design, implement, and operate large-scale distributed systems, focusing on identity, authentication, and authorization. Collaborate with cross-functional teams to deliver high-quality, secure, and highly available features. You will own services end-to-end, from design and code to deployment and monitoring, using modern AWS technologies. This role suits engineers who thrive in a customer-obsessed, data-driven, and fast-paced environment. Responsibilities Design, implement, and maintain scalable, secure backend services for AWS IAM Identity Center. Develop, test, and review high-quality code for identity, authentication, and authorization workflows. Operate services in production, including monitoring, incident response, and continuous improvement. Collaborate with product, security, and other engineering teams to define requirements and deliver features. Apply secure coding practices and threat modeling to protect customer identities and data. Contribute to architectural decisions, code reviews, and technical documentation. Automate build, test, and deployment processes using CI/CD and infrastructure-as-code tools. Required Skills Java or C# or Python Distributed systems design RESTful API development AWS services (EC2, Lambda, Dynamo DB, RDS) Identity and access management (IAM, OAuth, SAML, OIDC) Microservices architecture CI/CD pipelines Monitoring and observability (Cloud Watch, X-Ray) Relational and No SQL databases Secure coding and threat modeling
Head of Identity, Access and Authentication Services
JLL Chicago, Illinois
This job is with JLL, an inclusive employer and a member of myGwork - the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong. Whether you've got deep experience in commercial real estate, skilled trades or technology, or you're looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. We are seeking an experienced Head of Identity, Access and Authentication, reporting to the SVP of Infrastructure and Operations. As a senior member of staff in Infrastructure and Operations within IT, this individual is responsible for standardizing and scaling the Identity Access Management, Authentication, Authorization, and Active Directory functions across JLL - building a future-fit application services organization that delivers resilient, secure, and adaptable identity and access capabilities across the enterprise. The scope of this role is expected to grow over time to encompass additional products and capabilities within the broader IAM, Authentication, and Authorization ecosystem as JLL's technology landscape evolves. The Head of Identity, Access and Authentication brings experience, knowledge, and future vision for transforming the identity and access management function, including the standardization of IAM platforms, authentication protocols, authorization frameworks, Active Directory governance, and adjacent identity and access technologies across JLL's global environment. The role encompasses tier 1, 2 and 3 support of tooling and tier 3 support for identity and access infrastructure. The role holder is a senior stakeholder in all relationships with externally sourced identity and access management capabilities. Owns the direct points of contact and continuous engagement and improvement with Applications Teams. As a key member of the senior I&O leadership team, this role contributes to the development and execution of the enterprise-wide Infrastructure and Application Services strategy and is responsible for ensuring I&O strategy is fully aligned, positioning I&O to deliver compelling value to the application teams as well as the JLL Business. This individual is expected to support the SVP of I&O, the Infrastructure Leadership peer group, the Chief Architect and VPs of Application Services under the CTO by implementing identity and access solutions that align to the enterprise architecture framework and roadmap. He or she will also serve on IT planning and policymaking committees and will drive the development and adoption of enterprise technology standards, governance processes and performance metrics. As AI agents and non-human identities become first-class actors in enterprise environments, this role will be responsible for evolving JLL's IAM strategy beyond traditional human-centric models. The ideal candidate will have experience designing dynamic, context-aware access controls - including purpose-based and just-in-time authorization - for agentic and automated workloads. This individual will establish governance frameworks that ensure trust delegation, auditability, and least-privilege principles are maintained across AI-driven systems, while partnering with security and engineering teams to build behavioral baselines and enforce policy at runtime. Key Responsibilities Evolve IAM for AI agents and non-human identities: Lead the evolution of JLL's IAM strategy to address the growing presence of AI agents, service accounts, and automated workloads as first-class actors in the enterprise. Design and implement dynamic, context-aware access controls - including purpose-based and just-in-time authorization - for agentic and automated systems. Establish governance frameworks that ensure trust delegation, auditability, and least-privilege principles are maintained across AI-driven environments, partnering with security and engineering teams to build behavioral baselines and enforce policy at runtime. Standardize and expand IAM, Authentication, Authorization, and Active Directory: Define and drive the enterprise-wide standardization of Identity Access Management, Authentication, Authorization, and Active Directory functions across JLL. Establish consistent platforms, policies, and operating models that reduce fragmentation and improve security posture globally. Position the function to absorb and govern additional IAM-adjacent products and capabilities as JLL's identity landscape grows and matures. Create and execute strategy: Create and communicate a pioneering vision for Application Services within the identity and access management domain, including the value proposition in digital transformation, optimization of cloud-based identity services, and adoption of innovative technologies such as generative AI and zero-trust frameworks. Optimize, redesign, and deliver engagement models for Application Services: Streamline engagement practices, enable a compelling digital employee experience, and improve the value the enterprise receives from IAM, authentication, authorization, and Active Directory platforms and services. Champion innovation: Take advantage of breakthrough technologies by embracing and driving automation, observability, and modern identity standards such as OAuth 2.0, SAML, OpenID Connect, and passwordless authentication. Manage and optimize cloud and hybrid identity environment: Create and execute strategies for cloud, hybrid, and on-premises identity infrastructure, and maximize the value the enterprise receives from investments in identity and access platforms and services. Develop and engage talent: Create future-proofing talent strategies to develop, upskill, and retain an adaptive workforce amid the impact of generative AI and automation. Adopt leadership principles that engage teams and executives to change culture, build soft skills, and improve the employee experience. Achieve operational excellence: Modernize to a cost-optimized, on-time, and stable identity and access management environment that addresses technical debt and minimizes risks of new initiatives. Build resilient platforms to power business growth. Drive and communicate outcomes: Build relationships and collaborate effectively across various levels of the organization. Able to convey complex technical concepts and strategies that resonate with technical and non-technical stakeholders. Define, Measure and Drive Success: Define the value of Application Services within the IAM domain, including objectives, metrics and KPIs, and track outcomes against goals, such as reducing identity-related risk and optimizing cost. Drives the adoption of (and commitment towards) service improvements through a programmatic approach to continuous improvement which also measures impact and shares results. Continuously evaluates the business value of Application Services including the use of metrics such as Key Performance Indicators, Outcome Driven Metrics and Objectives and Key Results. Leadership Requirements Strategic Vision: Has a clear strategic vision, with the ability to develop and communicate an Application Services vision for identity and access that inspires and motivates staff and aligns with the IT and business strategy. Outstanding Communication: Exceptional communication skills and ability to effectively communicate complex concepts to various audiences, including board members, executives, technical teams, and non-technical staff; aptitude to facilitate collaboration and build relationships across business lines is critical. Able to articulate IAM and identity strategy approach to risk taking to nontechnical audiences in a way that increases sponsorship and support for ongoing endeavors. Business Acumen and Subject Matter Expertise: Strong business acumen, including industry, domain-specific knowledge of the enterprise and its business units. Deep understanding of current and emerging IAM, authentication, authorization, and Active Directory technologies and practices, and how other enterprises are employing them. Change Management: Skilled at driving cultural change; evangelizing and implementing transformational initiatives where the target state included zero-trust, cloud identity adoption at scale, and IAM standardization. Able to consolidate identity and access capabilities in large, complex enterprise organizations to deliver improved efficiency, while balancing customer preferences for agility. Team Leadership: Successful history of building and leading diverse teams; including fostering a collaborative, inclusive, and innovative work environment, as well as providing mentorship and professional development opportunities. Risk Management: Possess a deep understanding of risk management principles and methodologies; ability to assess and prioritize risks effectively, develop risk mitigation strategies, and ensure that in-place controls are aligned with governance and policy requirements, particularly in the context of identity and access security. . click apply for full job details
09/27/2026
Full time
This job is with JLL, an inclusive employer and a member of myGwork - the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly. JLL empowers you to shape a brighter way. Our people at JLL are shaping the future of real estate for a better world by combining world class services, advisory and technology for our clients. We are committed to hiring the best, most talented people and empowering them to thrive, grow meaningful careers and to find a place where they belong. Whether you've got deep experience in commercial real estate, skilled trades or technology, or you're looking to apply your relevant experience to a new industry, join our team as we help shape a brighter way forward. We are seeking an experienced Head of Identity, Access and Authentication, reporting to the SVP of Infrastructure and Operations. As a senior member of staff in Infrastructure and Operations within IT, this individual is responsible for standardizing and scaling the Identity Access Management, Authentication, Authorization, and Active Directory functions across JLL - building a future-fit application services organization that delivers resilient, secure, and adaptable identity and access capabilities across the enterprise. The scope of this role is expected to grow over time to encompass additional products and capabilities within the broader IAM, Authentication, and Authorization ecosystem as JLL's technology landscape evolves. The Head of Identity, Access and Authentication brings experience, knowledge, and future vision for transforming the identity and access management function, including the standardization of IAM platforms, authentication protocols, authorization frameworks, Active Directory governance, and adjacent identity and access technologies across JLL's global environment. The role encompasses tier 1, 2 and 3 support of tooling and tier 3 support for identity and access infrastructure. The role holder is a senior stakeholder in all relationships with externally sourced identity and access management capabilities. Owns the direct points of contact and continuous engagement and improvement with Applications Teams. As a key member of the senior I&O leadership team, this role contributes to the development and execution of the enterprise-wide Infrastructure and Application Services strategy and is responsible for ensuring I&O strategy is fully aligned, positioning I&O to deliver compelling value to the application teams as well as the JLL Business. This individual is expected to support the SVP of I&O, the Infrastructure Leadership peer group, the Chief Architect and VPs of Application Services under the CTO by implementing identity and access solutions that align to the enterprise architecture framework and roadmap. He or she will also serve on IT planning and policymaking committees and will drive the development and adoption of enterprise technology standards, governance processes and performance metrics. As AI agents and non-human identities become first-class actors in enterprise environments, this role will be responsible for evolving JLL's IAM strategy beyond traditional human-centric models. The ideal candidate will have experience designing dynamic, context-aware access controls - including purpose-based and just-in-time authorization - for agentic and automated workloads. This individual will establish governance frameworks that ensure trust delegation, auditability, and least-privilege principles are maintained across AI-driven systems, while partnering with security and engineering teams to build behavioral baselines and enforce policy at runtime. Key Responsibilities Evolve IAM for AI agents and non-human identities: Lead the evolution of JLL's IAM strategy to address the growing presence of AI agents, service accounts, and automated workloads as first-class actors in the enterprise. Design and implement dynamic, context-aware access controls - including purpose-based and just-in-time authorization - for agentic and automated systems. Establish governance frameworks that ensure trust delegation, auditability, and least-privilege principles are maintained across AI-driven environments, partnering with security and engineering teams to build behavioral baselines and enforce policy at runtime. Standardize and expand IAM, Authentication, Authorization, and Active Directory: Define and drive the enterprise-wide standardization of Identity Access Management, Authentication, Authorization, and Active Directory functions across JLL. Establish consistent platforms, policies, and operating models that reduce fragmentation and improve security posture globally. Position the function to absorb and govern additional IAM-adjacent products and capabilities as JLL's identity landscape grows and matures. Create and execute strategy: Create and communicate a pioneering vision for Application Services within the identity and access management domain, including the value proposition in digital transformation, optimization of cloud-based identity services, and adoption of innovative technologies such as generative AI and zero-trust frameworks. Optimize, redesign, and deliver engagement models for Application Services: Streamline engagement practices, enable a compelling digital employee experience, and improve the value the enterprise receives from IAM, authentication, authorization, and Active Directory platforms and services. Champion innovation: Take advantage of breakthrough technologies by embracing and driving automation, observability, and modern identity standards such as OAuth 2.0, SAML, OpenID Connect, and passwordless authentication. Manage and optimize cloud and hybrid identity environment: Create and execute strategies for cloud, hybrid, and on-premises identity infrastructure, and maximize the value the enterprise receives from investments in identity and access platforms and services. Develop and engage talent: Create future-proofing talent strategies to develop, upskill, and retain an adaptive workforce amid the impact of generative AI and automation. Adopt leadership principles that engage teams and executives to change culture, build soft skills, and improve the employee experience. Achieve operational excellence: Modernize to a cost-optimized, on-time, and stable identity and access management environment that addresses technical debt and minimizes risks of new initiatives. Build resilient platforms to power business growth. Drive and communicate outcomes: Build relationships and collaborate effectively across various levels of the organization. Able to convey complex technical concepts and strategies that resonate with technical and non-technical stakeholders. Define, Measure and Drive Success: Define the value of Application Services within the IAM domain, including objectives, metrics and KPIs, and track outcomes against goals, such as reducing identity-related risk and optimizing cost. Drives the adoption of (and commitment towards) service improvements through a programmatic approach to continuous improvement which also measures impact and shares results. Continuously evaluates the business value of Application Services including the use of metrics such as Key Performance Indicators, Outcome Driven Metrics and Objectives and Key Results. Leadership Requirements Strategic Vision: Has a clear strategic vision, with the ability to develop and communicate an Application Services vision for identity and access that inspires and motivates staff and aligns with the IT and business strategy. Outstanding Communication: Exceptional communication skills and ability to effectively communicate complex concepts to various audiences, including board members, executives, technical teams, and non-technical staff; aptitude to facilitate collaboration and build relationships across business lines is critical. Able to articulate IAM and identity strategy approach to risk taking to nontechnical audiences in a way that increases sponsorship and support for ongoing endeavors. Business Acumen and Subject Matter Expertise: Strong business acumen, including industry, domain-specific knowledge of the enterprise and its business units. Deep understanding of current and emerging IAM, authentication, authorization, and Active Directory technologies and practices, and how other enterprises are employing them. Change Management: Skilled at driving cultural change; evangelizing and implementing transformational initiatives where the target state included zero-trust, cloud identity adoption at scale, and IAM standardization. Able to consolidate identity and access capabilities in large, complex enterprise organizations to deliver improved efficiency, while balancing customer preferences for agility. Team Leadership: Successful history of building and leading diverse teams; including fostering a collaborative, inclusive, and innovative work environment, as well as providing mentorship and professional development opportunities. Risk Management: Possess a deep understanding of risk management principles and methodologies; ability to assess and prioritize risks effectively, develop risk mitigation strategies, and ensure that in-place controls are aligned with governance and policy requirements, particularly in the context of identity and access security. . click apply for full job details
Senior Cybersecurity Information Security Analyst - Federal Government
GovCIO LLC San Antonio, Texas
GovCIO LLC seeks a Senior Cyber Security Administrator to secure mission-critical federal IT systems. In this role, you will administer and harden security tools, monitor and investigate security events, and lead incident response to protect complex, multi-cloud and on-prem environments. You'll implement security baselines, support NIST/FISMA compliance, manage identity and access controls, and drive remediation of vulnerabilities. Working in a mission-driven, collaborative culture, you'll mentor others, influence security architecture, and help modernize government technology at scale. Responsibilities Administer and harden security tools, firewalls, IDS/IPS, and endpoint protection across federal environments. Monitor security events, investigate incidents, and coordinate response and remediation. Implement and maintain security baselines, configurations, and patch management processes. Support compliance with federal security standards (e.g., NIST, FISMA) and internal policies. Conduct vulnerability scans, analyze findings, and drive remediation with engineering teams. Manage identity and access controls, including privileged account management and MFA. Develop and update security documentation, runbooks, and standard operating procedures. Collaborate with Dev, Cloud, and Network teams to embed security into system designs. Support security audits, assessments, and ATO-related activities for federal systems. Mentor junior staff and contribute to continuous improvement of cybersecurity operations. Required Skills Network security administration (firewalls, IDS/IPS) Security Information and Event Management (SIEM) tools Endpoint protection and EDR platforms Vulnerability assessment and remediation Identity and Access Management (IAM) and MFANIST and FISMA compliance frameworks Incident detection, triage, and response Security hardening and configuration management Cloud security (AWS/Azure/GCP) fundamentals Scripting/automation (Power Shell, Python, or similar)
09/27/2026
Full time
GovCIO LLC seeks a Senior Cyber Security Administrator to secure mission-critical federal IT systems. In this role, you will administer and harden security tools, monitor and investigate security events, and lead incident response to protect complex, multi-cloud and on-prem environments. You'll implement security baselines, support NIST/FISMA compliance, manage identity and access controls, and drive remediation of vulnerabilities. Working in a mission-driven, collaborative culture, you'll mentor others, influence security architecture, and help modernize government technology at scale. Responsibilities Administer and harden security tools, firewalls, IDS/IPS, and endpoint protection across federal environments. Monitor security events, investigate incidents, and coordinate response and remediation. Implement and maintain security baselines, configurations, and patch management processes. Support compliance with federal security standards (e.g., NIST, FISMA) and internal policies. Conduct vulnerability scans, analyze findings, and drive remediation with engineering teams. Manage identity and access controls, including privileged account management and MFA. Develop and update security documentation, runbooks, and standard operating procedures. Collaborate with Dev, Cloud, and Network teams to embed security into system designs. Support security audits, assessments, and ATO-related activities for federal systems. Mentor junior staff and contribute to continuous improvement of cybersecurity operations. Required Skills Network security administration (firewalls, IDS/IPS) Security Information and Event Management (SIEM) tools Endpoint protection and EDR platforms Vulnerability assessment and remediation Identity and Access Management (IAM) and MFANIST and FISMA compliance frameworks Incident detection, triage, and response Security hardening and configuration management Cloud security (AWS/Azure/GCP) fundamentals Scripting/automation (Power Shell, Python, or similar)
Senior AWS Managed Services Cloud Architect
Amazon Web Services, Inc. Dallas, Texas
Amazon Web Services, Inc. seeks an AMS Cloud Architect III to design, implement, and optimize secure, highly available AWS Managed Services solutions for enterprise customers. You will lead discovery and architecture sessions, define landing zones, automation, and governance, and guide customers through migration and modernization to AMS. Partner with engineering, operations, and security teams to ensure resilient, compliant environments. Provide technical leadership, create reference architectures, perform reviews, and resolve complex incidents while mentoring engineers in a fast-paced, customer-obsessed culture. Responsibilities Design and implement secure, scalable AWS Managed Services architectures Lead customer discovery, requirements gathering, and architecture workshops Define and optimize AMS landing zones, automation, and governance patterns Guide customers through migration and modernization into AMSCollaborate with engineering, operations, and security teams on solutions Create reference architectures, standards, and best practices documentation Perform architecture and security reviews of AMS environments Troubleshoot and resolve complex cloud infrastructure issues Ensure compliance, reliability, and operational excellence for AMS workloads Mentor engineers and contribute to continuous improvement initiatives Required Skills AWS architecture and design AWS Managed Services (AMS) Infrastructure as Code (Cloud Formation, Terraform) Networking (VPC, VPN, Direct Connect) Cloud security and IAMLinux/Windows administration in cloud Monitoring and observability (Cloud Watch, X-Ray, etc.) Automation and scripting (Python, Bash, Power Shell) High availability and disaster recovery design Governance, compliance, and cost optimization on AWS
09/27/2026
Full time
Amazon Web Services, Inc. seeks an AMS Cloud Architect III to design, implement, and optimize secure, highly available AWS Managed Services solutions for enterprise customers. You will lead discovery and architecture sessions, define landing zones, automation, and governance, and guide customers through migration and modernization to AMS. Partner with engineering, operations, and security teams to ensure resilient, compliant environments. Provide technical leadership, create reference architectures, perform reviews, and resolve complex incidents while mentoring engineers in a fast-paced, customer-obsessed culture. Responsibilities Design and implement secure, scalable AWS Managed Services architectures Lead customer discovery, requirements gathering, and architecture workshops Define and optimize AMS landing zones, automation, and governance patterns Guide customers through migration and modernization into AMSCollaborate with engineering, operations, and security teams on solutions Create reference architectures, standards, and best practices documentation Perform architecture and security reviews of AMS environments Troubleshoot and resolve complex cloud infrastructure issues Ensure compliance, reliability, and operational excellence for AMS workloads Mentor engineers and contribute to continuous improvement initiatives Required Skills AWS architecture and design AWS Managed Services (AMS) Infrastructure as Code (Cloud Formation, Terraform) Networking (VPC, VPN, Direct Connect) Cloud security and IAMLinux/Windows administration in cloud Monitoring and observability (Cloud Watch, X-Ray, etc.) Automation and scripting (Python, Bash, Power Shell) High availability and disaster recovery design Governance, compliance, and cost optimization on AWS
AWS Cloud Solutions Architect II
Amazon Web Services, Inc. Herndon, Virginia
Amazon Web Services, Inc. seeks an AMS Cloud Architect II to design, implement, and optimize secure, highly available AWS Managed Services solutions. You will lead customers through cloud architecture reviews, migration planning, and modernization initiatives, leveraging services such as EC2, RDS, Lambda, CloudWatch, and CloudFormation/Terraform. Partner with cross-functional teams to automate operations, improve reliability, and ensure compliance, cost optimization, and observability. You'll mentor engineers, contribute to best practices, and thrive in AWS's customer-obsessed, data-driven, and high-ownership culture while solving complex, global-scale challenges. Responsibilities Design and implement secure, scalable architectures on AWS Managed Services Lead architecture reviews, migration strategies, and modernization roadmaps for customers Automate infrastructure and operations using Cloud Formation/Terraform and related tools Optimize reliability, performance, and cost across customer cloud environments Ensure compliance, security, and observability best practices are applied Collaborate with cross-functional AWS teams to deliver end-to-end solutions Troubleshoot complex production issues and drive root cause analysis Document architectures, runbooks, and best practices for internal and customer use Mentor engineers and share cloud architecture expertise across teams Contribute to continuous improvement of AMS offerings and technical standards Required Skills AWS architecture and design AWS Managed Services (EC2, RDS, Lambda, Cloud Watch, IAM, VPC) Infrastructure as Code (Cloud Formation, Terraform) Linux/Windows administration Networking and security in cloud environments Monitoring and observability tools Scripting (Python, Bash, or similar) CI/CD and Dev Ops practices Cost optimization on AWSIncident response and troubleshooting
09/27/2026
Full time
Amazon Web Services, Inc. seeks an AMS Cloud Architect II to design, implement, and optimize secure, highly available AWS Managed Services solutions. You will lead customers through cloud architecture reviews, migration planning, and modernization initiatives, leveraging services such as EC2, RDS, Lambda, CloudWatch, and CloudFormation/Terraform. Partner with cross-functional teams to automate operations, improve reliability, and ensure compliance, cost optimization, and observability. You'll mentor engineers, contribute to best practices, and thrive in AWS's customer-obsessed, data-driven, and high-ownership culture while solving complex, global-scale challenges. Responsibilities Design and implement secure, scalable architectures on AWS Managed Services Lead architecture reviews, migration strategies, and modernization roadmaps for customers Automate infrastructure and operations using Cloud Formation/Terraform and related tools Optimize reliability, performance, and cost across customer cloud environments Ensure compliance, security, and observability best practices are applied Collaborate with cross-functional AWS teams to deliver end-to-end solutions Troubleshoot complex production issues and drive root cause analysis Document architectures, runbooks, and best practices for internal and customer use Mentor engineers and share cloud architecture expertise across teams Contribute to continuous improvement of AMS offerings and technical standards Required Skills AWS architecture and design AWS Managed Services (EC2, RDS, Lambda, Cloud Watch, IAM, VPC) Infrastructure as Code (Cloud Formation, Terraform) Linux/Windows administration Networking and security in cloud environments Monitoring and observability tools Scripting (Python, Bash, or similar) CI/CD and Dev Ops practices Cost optimization on AWSIncident response and troubleshooting
Software Development Engineer, AWS IAM Identity Center, jamesg Team
Amazon Web Services, Inc. Seattle, Washington
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS- 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS- 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
09/27/2026
Full time
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS- 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS- 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
Software Development Engineer, AWS IAM Identity Center, jamesg Team
Amazon Web Services, Inc. Seattle, Washington
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS - 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS - 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
09/27/2026
Full time
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS - 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS - 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
L3Harris Technologies
Specialist, Software Engineering (AWS Cloud)
L3Harris Technologies Melbourne, Florida
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers' mission and quest for professional growth. L3Harris provides an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Specialist, Software Engineering (AWS Cloud) Job Code: 43381 Job Location: Melbourne, FL Job Schedule: 9/80 (Every other Friday off) Job Description: The GGSS Cloud team leverages Cloud Service Providers (AWS, Microsoft Azure, Google Cloud) in delivering modern solutions to support customer operations and information management services. We value a strong knowledge of software development best practices and experience delivering & deploying Cloud-ready applications and services. Seeking experienced Software Engineers to join our dynamic team, focusing on operating, maintaining, and sustaining an AWS cloud operational system. Essential Functions: Monitor and implement updates from AWS and third-party suppliers Maintain and enhance our Kubernetes-based cloud architecture Utilize Python, Java or C++ programming languages Support Identity and Access Management (IAM) solutions including single sign on, active directory, or Keycloak Assist in cloud migration of applications Write and maintain comprehensive documentation for developers, administrators, and operators Ensuring consistency across the baseline (version tagging, naming schemes) Leverage networking principles and security best practices in an AWS cloud environment Design and code new software or modify existing software to add new features Ability to obtain a High-Risk NOAA Public Trust clearance. Qualifications: Bachelor's Degree and minimum 4 years of prior relevant experience. Graduate Degree and a minimum of 2 years of prior related experience. In lieu of a degree, minimum of 8 years of prior related experience. Experience developing and deploying containerized applications using Docker, Podman, Kubernetes, or equivalent. Experience with Linux environments, including scripting, configuration, and software deployment. Experience with configuration management (Ansible, Chef, Puppet) and Infrastructure as Code tools (Terraform, CDK, OpenTofu, Cloud Formation). Preferred Additional Skills: Familiarity with Agile workflow tools and collaborative version control practices (Git, JIRA, Confluence, etc.) Experience with container observability tools such as Prometheus, PromQL, and Grafana Experience with Helm charts and Kubernetes package management Experience with monitoring and logging solutions (Splunk, CloudWatch, etc.) Experience with iterative software development processes (Agile, SCRUM, Kanban) AWS Certified Solutions Architect - Associate Certified Kubernetes Administrator (CKA) AWS Certified DevOps Engineer - Associate L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law. Please be aware many of our positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information. By submitting your resume for this position, you understand and agree that L3Harris Technologies may share your resume, as well as any other related personal information or documentation you provide, with its subsidiaries and affiliated companies for the purpose of considering you for other available positions. L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English or Spanish. For information regarding your Right To Work, please click here for English or Spanish.
09/27/2026
Full time
L3Harris is dedicated to recruiting and developing high-performing talent who are passionate about what they do. Our employees are unified in a shared dedication to our customers' mission and quest for professional growth. L3Harris provides an inclusive, engaging environment designed to empower employees and promote work-life success. Fundamental to our culture is an unwavering focus on values, dedication to our communities, and commitment to excellence in everything we do. L3Harris is the Trusted Disruptor in defense tech. With customers' mission-critical needs always in mind, our employees deliver end-to-end technology solutions connecting the space, air, land, sea and cyber domains in the interest of national security. Job Title: Specialist, Software Engineering (AWS Cloud) Job Code: 43381 Job Location: Melbourne, FL Job Schedule: 9/80 (Every other Friday off) Job Description: The GGSS Cloud team leverages Cloud Service Providers (AWS, Microsoft Azure, Google Cloud) in delivering modern solutions to support customer operations and information management services. We value a strong knowledge of software development best practices and experience delivering & deploying Cloud-ready applications and services. Seeking experienced Software Engineers to join our dynamic team, focusing on operating, maintaining, and sustaining an AWS cloud operational system. Essential Functions: Monitor and implement updates from AWS and third-party suppliers Maintain and enhance our Kubernetes-based cloud architecture Utilize Python, Java or C++ programming languages Support Identity and Access Management (IAM) solutions including single sign on, active directory, or Keycloak Assist in cloud migration of applications Write and maintain comprehensive documentation for developers, administrators, and operators Ensuring consistency across the baseline (version tagging, naming schemes) Leverage networking principles and security best practices in an AWS cloud environment Design and code new software or modify existing software to add new features Ability to obtain a High-Risk NOAA Public Trust clearance. Qualifications: Bachelor's Degree and minimum 4 years of prior relevant experience. Graduate Degree and a minimum of 2 years of prior related experience. In lieu of a degree, minimum of 8 years of prior related experience. Experience developing and deploying containerized applications using Docker, Podman, Kubernetes, or equivalent. Experience with Linux environments, including scripting, configuration, and software deployment. Experience with configuration management (Ansible, Chef, Puppet) and Infrastructure as Code tools (Terraform, CDK, OpenTofu, Cloud Formation). Preferred Additional Skills: Familiarity with Agile workflow tools and collaborative version control practices (Git, JIRA, Confluence, etc.) Experience with container observability tools such as Prometheus, PromQL, and Grafana Experience with Helm charts and Kubernetes package management Experience with monitoring and logging solutions (Splunk, CloudWatch, etc.) Experience with iterative software development processes (Agile, SCRUM, Kanban) AWS Certified Solutions Architect - Associate Certified Kubernetes Administrator (CKA) AWS Certified DevOps Engineer - Associate L3Harris Technologies is proud to be an Equal Opportunity Employer. L3Harris is committed to treating all employees and applicants for employment with respect and dignity and maintaining a workplace that is free from unlawful discrimination. All applicants will be considered for employment without regard to race, color, religion, age, national origin, ancestry, ethnicity, gender (including pregnancy, childbirth, breastfeeding or other related medical conditions), gender identity, gender expression, sexual orientation, marital status, veteran status, disability, genetic information, citizenship status, characteristic or membership in any other group protected by federal, state or local laws. L3Harris maintains a drug-free workplace and performs pre-employment substance abuse testing and background checks, where permitted by law. Please be aware many of our positions require the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. In addition, applicants who accept a conditional offer of employment may be subject to government security investigation(s) and must meet eligibility requirements for access to classified information. By submitting your resume for this position, you understand and agree that L3Harris Technologies may share your resume, as well as any other related personal information or documentation you provide, with its subsidiaries and affiliated companies for the purpose of considering you for other available positions. L3Harris Technologies is an E-Verify Employer. Please click here for the E-Verify Poster in English or Spanish. For information regarding your Right To Work, please click here for English or Spanish.
Software Development Engineer, AWS IAM Identity Center, jamesg Team
Amazon Web Services, Inc. Seattle, Washington
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS - 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS - 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
09/27/2026
Full time
AWS Identity platform provides the bedrock for secure and continuous access to all AWS services. By quickly connecting millions of users, across the world we empower organizations and enterprises to accelerate their cloud and digital transformation. Engineers within AWS Identity need to be creative, responsible, and curious while working with others to move quickly in turning code into customer solutions. You're excited about rolling up your sleeves, implementing ideas, and learning from those around you. You relish the opportunity to dig into challenging operational issues, fix them permanently while taking the learning back as you design the next iteration. This specific position within AWS IAM Identity Center where you design and build services that enables customers manage their workforce and individual identities and manage their access to AWS applications and SaaS offerings. Key job responsibilities In this role, you will collaborate with talented engineers to build innovative services used by millions of users worldwide. Our team operates at the intersection of security and user experience, enhancing both for AWS customers. You will work on core platforms that power AWS IAM Identity Center, leveraging the latest technologies to solve complex problems. About the team AWS IAM Identity Center (IdC) helps customers securely create or connect workforce identities and manage their access centrally across AWS accounts and applications. IdC simplifies the administrative complexity of federating and managing permissions separately for each AWS account, allows customers to set up AWS applications from a single interface, and to assign access to their cloud applications from a single place. IdC offers additional identity federation functionality to provide a uniform identity platform for a large set of internal AWS Data, ML & Business applications such as QuickSight, Sagemaker, RedShift and IoT. BASIC QUALIFICATIONS - 3+ years of non-internship professional software development experience - 2+ years of non-internship design or architecture (design patterns, reliability and scaling) of new and existing systems experience - Experience programming with at least one software programming language PREFERRED QUALIFICATIONS - 3+ years of full software development life cycle, including coding standards, code reviews, source control management, build processes, testing, and operations experience - Bachelor's degree in computer science or equivalent Amazon is an equal opportunity employer and does not discriminate on the basis of protected veteran status, disability, or other legally protected status. Our inclusive culture empowers Amazonians to deliver the best results for our customers. If you have a disability and need a workplace accommodation or adjustment during the application and hiring process, including support for the interview or onboarding process, please visit for more information. If the country/region you're applying in isn't listed, please contact your Recruiting Partner. The base salary range for this position is listed below. Your Amazon package will include sign-on payments and restricted stock units (RSUs). Final compensation will be determined based on factors including experience, qualifications, and location. Amazon also offers comprehensive benefits including health insurance (medical, dental, vision, prescription, Basic Life & AD&D insurance and option for Supplemental life plans, EAP, Mental Health Support, Medical Advice Line, Flexible Spending Accounts, Adoption and Surrogacy Reimbursement coverage), 401(k) matching, paid time off, and parental leave. Learn more about our benefits at . USA, WA, Seattle - 143 400.00 USD annually
Security Control Assessor/Representatives
Dark Wolf Solutions Arlington, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Partner directly with cybersecurity engineering and DevSecOps prototyping teams to integrate security controls early in the development lifecycle. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 3-5+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $150,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Assessor
Omniscius Consulting Arlington, Virginia
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
09/26/2026
Full time
Job Description Job Description Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Clearance: Top Secret clearance with the ability to obtain SCI with CI Polygraph Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active Top Secret clearance with the ability to obtain SCI with CI Polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Powered by JazzHR I48iVzr4Ds
Offensive Security Control Assessor Security Control Assessor Representative
Dark Wolf Solutions Herndon, Virginia
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
09/26/2026
Full time
Job Description Job Description Dark Wolf Solutions is seeking Security Control Assessor/Representatives (SCA/Rs) to lead security control assessments across high-priority projects. Working at the intersection of cybersecurity engineering, cloud architecture, and DevSecOps prototyping, you will evaluate security controls for cutting-edge AI/LLM technologies across multiple classification levels. This position is ideal for a pragmatic cloud assessor or SCAR who excels in fast-paced DevSecOps environments, understands AWS cloud security, and is eager to shape the cybersecurity posture of next-generation DoD AI capabilities.This position will be based out of Arlington, VA with hybrid/remote opportunities. Additional responsibilities include: Key Responsibilities Execute formal SCA/R duties. Lead security assessment efforts, establishing reusable security playbooks and assessment frameworks for rapid AI deployment into enterprise workflows. Evaluate technical control effectiveness across AWS cloud infrastructure, DevSecOps pipelines, microservices, containerized workloads, and GenAI/LLM application stacks. Bridge the gap between OffSec and development by applying software design best practices. Lead technical exchange meetings (TEMs), participate in Discovery & Framing workshops, and maintain effective communication with cross-functional teams and stakeholders. Act as the primary subject matter expert and lead developer for custom offensive tooling, integrating disparate capabilities into a cohesive, mission-ready platform. Review, author, and maintain assessment packages-including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), and POA&Ms-tailored to rapid prototyping and AI systems. Assess technical security risks specific to AI/LLM implementations, such as API exposure, vector database access controls, model integration surface area, and software supply chain dependencies. Support continuous monitoring (ConMon), technical risk evaluations, and cloud architecture reviews across multi-tenant, multi-classification environments. Coordinate with Authorizing Officials (AOs), program managers, and engineering leads to deliver decision-ready risk briefings and ATO recommendations. Provide technical input and oversight for cybersecurity engineering and penetration testing activities across prototype projects. Required Qualifications Active Top Secret security clearance Current DoD 8570/8140 IAM Level II or Level III certification (e.g., Security+, CySA+, CISM, CISSP, CCISO, CAP/CISC) 5-7+ years of experience conducting security control assessments, compliance testing, or A&A/RMF activities for DoD or federal information systems Solid operational understanding of core AWS cloud services (EC2, S3, IAM, VPCs, Security Groups, Security Hub) and how security controls function within cloud-native and CI/CD pipeline environments. Experience with GitLab CI/CD (pipeline design, runners, artifact management) and AWS Cloud services (EC2, VPC, IAM, S3). Strong working knowledge of NIST SP 800-53 (Rev. 4/5), NIST SP 800-37 (RMF), DoD Cloud Computing SRG, and FedRAMP baselines. Demonstrated experience writing and evaluating core RMF artifacts (SSPs, SAPs, SARs, POA&Ms) Exceptional written and verbal communication skills, with the ability to articulate technical risk clearly to executive stakeholders, Authorizing Officials, and engineering teams. Hands-on experience navigating government GRC repositories, such as eMASS or XACTA. Desired Qualifications Hands-on experience mapping security controls to the NIST AI Risk Management Framework (AI RMF), the OWASP Top 10 for LLM Applications, or the DoD Responsible AI (RAI) Guidelines. Familiarity evaluating secure design patterns for autonomous AI Agents (e.g., tool-calling permissions, sandboxing agent execution environments, prompt boundaries, and ReAct/LangGraph architectures). Experience assessing cloud-managed AI ecosystems and foundation model platforms (e.g., AWS Bedrock, AWS SageMaker, Hugging Face Enterprise, or self-hosted open-source models). Understanding of data protection, access controls, and boundary security for RAG pipelines and vector databases (e.g., OpenSearch Vector Engine, Pinecone, Milvus, or PostgreSQL pgvector). Familiarity evaluating risks unique to LLMs-including prompt injection, data poisoning, model inversion, insecure output handling, and open-source supply chain vulnerabilities in AI libraries (PyTorch, LangChain, LlamaIndex). Exposure to LLM guardrail platforms, evaluation frameworks, or AI security tools (e.g., Promptfoo, Garak, Giskard, NeMo Guardrails) used to test model robustness and output safety. Experience with cATO methodologies, Infrastructure as Code (IaC) templates (Terraform, CloudFormation), and container security (AWS EKS/ECS, Docker). Active AWS Certifications (e.g., AWS Certified Security - Specialty or AWS Certified Solutions Architect). Background or familiarity with offensive security, penetration testing The salary range for this position is estimated to be between $135,000.00 - $160,000.00, commensurate on experience and technical skillset. We are proud to be an EEO/AA employer Minorities/Women/Veterans/Disabled and other protected categories. In compliance with federal law, all persons hired will be required to verify identity, confirm US Citizenship, and complete the required employment eligibility verification upon hire. We are strictly looking for direct, full-time W2 employees. We do not engage with third-party staffing agencies, C2C, or 1099 independent contractors for this role.
Security Control Assessor
Apavo Corporation Arlington, Virginia
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
09/26/2026
Full time
Job Description Job Description Description: Job Title: Security Control Assessor Location: On Site in Arlington, VA Department: Cyber Security Services Reports To: Management FLSA Status: Full Time/Non-exempt Job Purpose: The security control assessor (SCAs) supports a critical, objective role to evaluate the effectiveness of implemented controls in mitigating security risks. The SCA will support a critical mission within the intelligence community. In the role as a SCA, you are expected to use automated scanning tools, manual techniques, and specialized testing methodologies to identify weaknesses and vulnerabilities. The SCA is expected to be a collaborative member of the RMF program of the organization, to provide intelligent input to system security architectures in order to align with RMF principles and guidelines. This includes ensuring to guide the RMF process so that security controls are integrated seamlessly into system designs to provide comprehensive protection against threats and vulnerabilities. Duties & Responsibilities: The SCA's specific duties include: Advise the Information System Owner (ISO) concerning the impact levels for Confidentiality, Integrity, and Availability for the information on systems. Ensure security assessments are completed for each IS. Initiate a POA&M with identified weaknesses and suspense dates for each IS based on findings and recommendations from the SAR. Evaluate security assessment documentation and provide written recommendations for security authorization to the CISO and AO. Assess proposed changes to Information Systems, their environment of operation, and mission needs that could affect system authorization. Serve as a cybersecurity technical advisor to the CISO and AO under their purview. Be integral to the development of the monitoring strategy. The system-level continuous monitoring strategy must conform to all applicable published DoD enterprise-level or DoD Component-level continuous monitoring strategies. Determine and document in the SAR a risk level for every noncompliant security control in the system baseline. Determine and document in the SAR an aggregate level of risk to the system and identify the key drivers for the assessment. The SCA's risk assessment considers threats, vulnerabilities, and potential impacts as well as existing and planned risk mitigation. Develop the continuous monitoring plan specific to the information system. The SCA is responsible for the RMF deliverables associated with Step 4 of DOD and IC RMF Policies for assigned systems. This includes, but is not limited to: Security Assessment Plans tailored to specific systems control requirements Security control assessment input, which includes narratives for the review of controls and artifacts Security Assessment Reports ATO recommendations or ATO with Condition Memorandums Conduct initial remediation actions once a security assessment has been completed to ensure proper hand off to the ISSM and ISSOs. Assessment of selected controls IAW continuous monitoring strategy The SCA is expected to have additional duties as assigned in support of corporate cyber security services. Additional details are reviewed in accordance with company policies. Requirements: Required Skills & Experience: Strong knowledge of Risk Management Framework (RMF) 800-37 and continuous monitoring 800-137 Expert knowledge and hands-on experience with FISMA Systems, NIST 800-series guidelines, FIPS, Security Assessment & Authorization (SA&A) requirements and processes, Continuous Monitoring Framework experience and its tools, Plan of Action & Milestones (POA&M) policies, and vulnerability/patch management, risk management, project management, proficient with Microsoft products - Word, Excel, PowerPoint. Proficient with vulnerability and scanning tools and well-versed in interpreting risk posture resulting from assessment reports. Experience in project management and tracking, and the Microsoft suite of office products Experience of assessing cloud-based security authorizations (FedRamp, AWS & Azure) as well as the NIST control responsibilities Experience with SAP/JSIG Expert with documenting and or reviewing of security materials such as; system security plans (SSP), Security Assessment Report (SAR), and Security Assessment Plan (SAP), and other documents per NIST 800 guidelines. Experience supporting cloud-based security authorizations (FedRamp, AWS, & Azure) Experience creating Security Assessment Plans, Security Assessment Reports, and Executive-level briefings Qualifications: Bachelor's Degree in Computer Science or a related technical discipline Master's Degree preferred. Minimum 6-10 years of experience. Must currently possess an active TS/SCI with the ability to obtain and maintain a CI polygraph. DOD 8140 IAM Level II (CAP, CASP, CISM, CISSP, GSLC, CCISO) is required Systems Security Engineering background preferred. Effective communication skills to collaborate with cross-functional teams and stakeholders on implementing security measures organization-wide. Strong analytical skills for identifying system vulnerabilities and documenting control remediation recommendations through collaboration on System Impact Analysis and Documented Risk Acceptance. Detail-oriented with the ability to manage multiple tasks and prioritize effectively. Comprehensive knowledge of RMF activities at a senior level (ability to articulate to Executive audiences preferred). Familiarity with federal regulatory requirements, contractual obligations, and industry standards related to information security. Evaluate adherence to standards such as Privacy, GDPR, and HIPAA Other: This is typical office or administrative work, and there is no exposure to adverse environmental conditions. This position requires sedentary work. Sedentary work is defined as: Exerting up to 10 pounds of force occasionally and/or a negligible amount of force frequently or constantly to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Jobs are sedentary if walking and standing are required only occasionally, and all other sedentary criteria are met.
Senior Cloud Security Assessor
Spry Methods Washington, Washington DC
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
09/26/2026
Full time
Job Description Job Description Experienced assessor sought to lead rigorous, evidence-based security assessments of cloud and hybrid systems supporting federal missions. Who we are looking for: Spry Methods is seeking an experienced Senior Cloud Security Assessor to join our team in the Washington, DC area. The successful candidate will bring extensive hands-on experience conducting independent security control assessments of cloud and hybrid systems, with particular depth in federal cloud environments. This role requires sound professional judgment, strong analytical skills, and a practical, common-sense approach to applying security requirements to system data, technical evidence, mission context, and actual risk. Key Responsibilities: • Lead full-cycle Security Assessment and Authorization (SA&A) activities for cloud, hybrid, and enterprise systems as an independent assessor. • Assess Microsoft Azure and Amazon Web Services (AWS) environments, including the implementation and operating effectiveness of administrative, operational, and technical security controls. • Retrieve and review FedRAMP authorization packages and supporting documentation, then analyze the package for applicability, control inheritance, residual risk, gaps, and customer responsibilities. • Conduct detailed analysis of assessment artifacts, including system security plans, policies, procedures, architecture and data-flow diagrams, inventories, configurations, logs, scan results, test outputs, and other supporting evidence. • Develop Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Risk Assessment Reports (RARs), Required Evidence Lists, and Plans of Action and Milestones (POA&Ms). • Perform network, system, application, and NIST security control testing from administrative, operational, and technical perspectives. • Analyze vulnerability scan results, interpret risk, and use manual validation and corroborating evidence to distinguish actionable findings from false positives or unsupported conclusions. • Apply security requirements using practical judgment and data context rather than relying solely on checklist compliance. Evaluate whether evidence is relevant, reliable, sufficient, and representative of the assessed environment. • Clearly communicate findings, risk, root cause, and feasible mitigation options to technical teams, system owners, executives, and other assessment stakeholders. • Coordinate evidence requests, interviews, test activities, and assessment schedules with customer personnel and Information Systems Security Analysts. • Support security assessment program operations and contribute to consistent assessment methods, quality reviews, and defensible reporting. Minimum Qualifications • Active Certified Information Systems Security Professional (CISSP) certification is required. • At least eight years of demonstrated, hands-on experience conducting security control assessments, including substantial experience serving as an independent assessor for cloud and hybrid systems. • Extensive experience conducting independent security assessments of federal systems hosted in Microsoft Azure and AWS environments, including evaluation of security controls, architecture, inherited controls, customer-configured controls, and cloud-specific risks. • Demonstrated experience retrieving, navigating, and analyzing FedRAMP authorization packages and associated security artifacts. • Strong knowledge of federal Risk Management Framework (RMF) processes and NIST security control assessment practices. • Ability to analyze large volumes of technical and governance evidence, connect information across artifacts, identify inconsistencies, and reach clear, supportable conclusions. • Strong understanding of IT security requirements, technical countermeasures, vulnerability management, risk management, contingency planning, secure data communications, and system security architecture. • Excellent technical writing and stakeholder communication skills, with the ability to explain risk and recommended mitigation in clear, decision-oriented language. • Bachelor's degree in cybersecurity, information technology, computer science, or a related field, or eight additional years of relevant specialized experience. • Experience using CSAM or a comparable governance, risk, and compliance platform. Preferred Qualifications • Certificate of Cloud Security Knowledge (CCSK), Certified Cloud Security Professional (CCSP), Certified Governance, Risk and Compliance (CGRC), or comparable cloud or assessment certification. • Experience supporting federal cybersecurity programs and conducting assessments, audits, or control implementation reviews in accordance with NIST Special Publications. • Experience assessing cloud service offerings that rely on FedRAMP-authorized services and documenting control inheritance and customer responsibility requirements. • DoD 8570/8140 IAM Level II eligibility or an equivalent qualification, when required by the customer environment. • Experience evaluating privacy and data protection considerations as part of security assessments. Success in this role: The successful assessor is technically credible, independent, and evidence-driven. They know when the data supports a finding, when additional validation is needed, and when a requirement must be interpreted in light of architecture, mission use, and actual exposure. They produce assessment results that are clear, consistent, defensible, and actionable. We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.
Security Control Assessor - Intermediate
RIVIDIUM Springfield, Virginia
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
09/26/2026
Full time
Job Description Job Description RiVidium Inc. is seeking a Security Control Assessor who conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST 800-37). TASKS: Manage and approve Accreditation Packages (e.g., ISO/IEC 15026-2). Plan and conduct security authorization reviews and assurance case development for initial installation of systems and networks. Review authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. Verify that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. Develop security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). Establish acceptable limits for the software application, network, or system. Manage Accreditation Packages (e.g., ISO/IEC 15026-2). Perform security reviews, identify gaps in security architecture, and develop a security risk management plan. Perform security reviews and identify security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. Perform risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Verify and update security documentation reflecting the application/system security design features. Participate in Risk Governance process to provide security risks, mitigations, and input on other technical risk. Ensure that plans of actions and milestones or remediation plans are in place for vulnerabilities identified during risk assessments, audits, inspections, etc. Assure successful implementation and functionality of security requirements and appropriate information technology (IT) policies and procedures that are consistent with the organization's mission and goals. Define and document how the implementation of a new system or new interfaces between systems impacts the security posture of the current environment. Ensure that security design and cybersecurity development activities are properly documented (providing a functional description of security implementation) and updated as necessary. Support necessary compliance activities (e.g., ensure that system security configuration guidelines are followed, compliance monitoring occurs). Ensure that all acquisitions, procurements, and outsourcing efforts address information security requirements consistent with organization goals. Assess the effectiveness of security controls. Assess all the configuration management (change configuration/release management) processes. ABILITIES: Ability to identify systemic security issues based on the analysis of vulnerability and configuration data. Ability to answer questions in a clear and concise manner. Ability to ask clarifying questions. Ability to communicate complex information, concepts, or ideas in a confident and well-organized manner through verbal, written, and/or visual means. Ability to communicate effectively when writing.A0015: Ability to conduct vulnerability scans and recognize vulnerabilities in security systems.A0016: Ability to facilitate small group discussions.A0018: Ability to prepare and present briefings. Ability to produce technical documentation. Ability to design valid and reliable assessments. Ability to analyze test data. Ability to collect, verify, and validate test data. Ability to dissect a problem and examine the interrelationships between data that may appear unrelated. Ability to identify basic common coding flaws at a high level. Ability to translate data and test results into evaluative conclusions. Ability to ensure security practices are followed throughout the acquisition process. Ability to apply collaborative skills and strategies. Ability to apply critical reading/thinking skills. Ability to effectively collaborate via virtual teams. Ability to evaluate information for reliability, validity, and relevance. Ability to evaluate, analyze, and synthesize large quantities of data (which may be fragmented and contradictory) into high quality, fused targeting/intelligence products. Requirements: Bachelor degree or higher from an accredited college or university. Prefer an accredited Computer Science, Cyber Security, Information Technology, Software Engineering, Information Systems, or Computer Engineering degree; or a degree in a Mathematics or Engineering field. IAT/IAM Level 2 certification The annual salary range for this position is $135,000-$140,000. The listed salary range represents a general guideline; however, RiVidium Inc. considers a number of factors when determining base salary offers such as the scope and responsibilities of the position and the candidate's experience, education, skills, and current market conditions. At RiVidium Inc. it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case.
Network & Cybersecurity Systems Engineer
Evolv Technologies Inc. Waltham, Massachusetts
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
09/26/2026
Full time
Job Description Job Description The Elevator Pitch Are you ready to own the network and cybersecurity backbone of a company that's redefining security technology? Do you thrive at the intersection of network engineering, cybersecurity operations, and compliance-where your work directly reduces risk and keeps the business resilient against an ever-changing threat landscape? Evolv is seeking a Network & Cybersecurity Engineer to design, implement, and defend our network infrastructure and security tooling. You'll be the technical owner of Evolv's network and security posture-from firewalls and access control to identity governance and threat detection-reporting to the Senior Director of Cybersecurity & Technology. This is a pivotal role in maturing Evolv's security program to meet the evolving demands of the business and our growing compliance obligations. You'll partner closely with the Systems Engineer and the rest of the IT team, and serve as the subject matter expert on networking, enterprise cybersecurity, and compliance tooling. If you're energized by staying ahead of emerging threats and building durable, well-governed security controls, this role is for you. Success in the Role: What are performance outcomes over the first 6-12 months you will work toward completing? In the first 30 days, you will: Get to know the IT and security team and the tools/platforms currently in use Start building relationships with key stakeholders across the company, especially R&D and Legal/Compliance Learn Evolv's compliance commitments and ongoing authorization efforts, and how best to support them Gain familiarity with the current network/security toolstack: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, VPN/ZTNA, identity platforms (Okta, Entra ID), SIEM/EDR/DLP tooling, and the MDR relationship Within 3 months, you will: Begin implementing or improving network and security controls that measurably reduce risk Build trust-based relationships with peers in IT and stakeholders across business units Become the established subject matter expert on network security and compliance tooling at Evolv Take ownership of the MDR relationship and escalated detection response By the end of the first year, you will: Be recognized as the trusted subject matter expert across network infrastructure, and security operations Have driven measurable improvements to Evolv's security posture and compliance readiness Successfully supported compliance requirements and audit readiness, partnering closely with Legal/Compliance and R&D Documented network and security architecture, processes, and runbooks that reduce single points of failure Be seen as the go-to resource for network security questions, escalations, and best-practice guidance The Work: What type of work will you be doing? What assignments, requirements, or skills will you be performing on a regular basis? Infrastructure, Security & Compliance: Design, implement, and maintain network infrastructure: firewalls (Palo Alto), switching (Cisco/Meraki), NAC, and VPN/ZTNA solutions Administer identity and access: Okta/Entra ID, Conditional Access policies, MFA enforcement, identity lifecycle management, and IGA Own security tooling and controls: SIEM, EDR, DLP, and vulnerability management, aligned to CIS Controls, NIST CSF, and other relevant compliance frameworks Manage the MDR relationship and respond to escalated detections Drive the IT process and policy redesign required to meet current compliance requirements, and to support additional frameworks as those efforts come online, in partnership with Legal/Compliance Harden AWS/Azure environments from a security perspective: IAM least-privilege, VPC/network security, Azure Policy Provide front-line escalation support and mentoring to IT teammates; maintain runbooks and documentation Assess technology and network risk across the company and recommend remediations Leadership, Team Structure & Culture You will join the IT organization as a direct report to the Senior Director of Cybersecurity & Technology, working alongside a Systems Engineer peer who owns day-to-day systems and endpoint operations. This is a hands-on, collaborative team that takes security and operational excellence seriously. This is a senior individual contributor role focused on deep technical impact-your job is to own and mature Evolv's network security and cybersecurity posture through the systems, controls, and automation you build. You'll have meaningful autonomy over how you approach problems and are actively encouraged to bring creative solutions, identify improvement opportunities, and advocate for better ways of working. You'll work alongside teammates who share your drive for continuous improvement, and you'll have a manager who values initiative, trusts the team to execute, and wants to hear your ideas. Where is the role located? This role is based out of Evolv HQ in Waltham, Massachusetts. This is a hybrid role with an expectation of 3 days per week on-site. Fully remote candidates will not be considered. Compensation and Transparency Statement The base salary range for this full-time position is $102,000-$166,000. In addition to base salary, this role offers a competitive target bonus, equity, and a comprehensive benefits package. This range reflects our commitment to pay transparency and equity, in alignment with applicable state laws. Our compensation ranges are determined based on factors such as role, level, location, market benchmarks, and internal equity. The posted range represents the good-faith estimate of what we expect to pay for this role across U.S. locations. Actual compensation within the range will be based on the candidate's skills, experience, education, and geographic location. In accordance with state and local pay transparency laws-including those in California, Colorado, Massachusetts, New York, New Jersey, and others-we disclose salary ranges in all job postings and provide additional information upon request. During the hiring process, your recruiter will share: •The specific salary range for your preferred location •A general overview of our benefits and equity offerings •Insights into how compensation decisions are made, including factors that influence starting pay We are committed to fair pay practices, and we regularly review our compensation programs to ensure they are competitive, equitable, and aligned with our values. Benefits At Evolv, we're on a mission to help make public spaces safer through innovative security technology. So, we're looking for future teammates who embody our values, people who: Do the right thing, always; Put people first' Own it; Win together; and continue to Be bold, stay curious. Our Benefits Include : Equity as part of your total compensation package Medical, dental, and vision insurance Health Savings Account (HSA) A 401(k) plan (and 2% company match) Flexible Paid Time Off (PTO)- take the time you need to recharge, with manager approval and business needs in mind Quarterly stipend for perks and benefits that matter most to you Tuition reimbursement to support your ongoing learning and development Subscription to Calm Evolv Technology ("Evolv") is an Equal Opportunity Employer and prohibits discrimination and harassment of any kind. We welcome and encourage diversity in the workplace, and all employment decisions are made without regard to race, color, religion, national, social or ethnic origin, sex (including pregnancy), age, disability, HIV Status, sexual orientation, gender identity and/or expression, veteran status, or any other status protected by law in the locations where we operate. Evolv will not tolerate discrimination or harassment based on any of these characteristics. Evolv is committed to offering an inclusive and accessible experience for all job seekers, including individuals with disabilities. If you need a reasonable accommodation as part of the job application process, please connect with us at . Evolv participates in E-verify for all employees after the completion of Form I-9.
Principal Platform Engineer
RxSense Boston, Massachusetts
Job Description Job Description We are a healthcare technology company that provides platforms and solutions to improve the management and access of cost-effective pharmacy benefits. Our technology helps enterprise and partnership clients simplify their businesses and helps consumers save on prescriptions. As a leader in SaaS technology for healthcare, we offer innovative solutions with integrated intelligence on a single enterprise platform that connects the pharmacy ecosystem. With our expertise and modern, modular platform, our partners use real-time data to transform their business performance and optimize their innovative models in the marketplace. Position Summary The Principal Platform Engineer owns the core engineering platform that every product team at RxSense builds on. As a direct report to the VP, Infrastructure Engineering, this role is accountable for the cloud infrastructure, CI/CD systems, developer tooling, and reliability practices that determine how confidently and how fast RxSense engineering can ship. This is a hands-on-keyboard, architect-level role, partnering with software engineers, AI engineers, security, and finance to build a platform that teams choose to build on rather than one they are required to use. Essential Duties and Responsibilities Design, build, and operate the core cloud infrastructure that supports RxSense engineering, including compute, networking, identity and access management, and container orchestration on AWS. Own the CI/CD platform used across engineering teams, including build pipelines, artifact management, environment promotion, progressive rollout, and rollback. Build and maintain the observability stack across the organization, including logging, metrics, distributed tracing, alerting, and the SLIs and SLOs that define reliable service. Drive infrastructure as code practices across the organization and manage the Kubernetes clusters, custom controllers, and operators that back production workloads. Partner with security and compliance to manage secrets, network policy, and access controls appropriate to a regulated healthcare and pharmacy benefits environment. Design self-service developer tooling and platform APIs and set the abstractions that let product and AI engineering teams' provision, deploy, and operate services without handholding. Own incident response tooling, on-call practices, and reliability engineering standards, and lead or support major incident response across the platform. Partner with engineering leadership and finance on infrastructure cost visibility, capacity planning, and cost optimization. Write documentation, runbooks, and clear interfaces so the platform is adoptable by other engineering teams without handholding. Participate in code review and promote collaboration and best practices, including simplicity, automation, sound design patterns, test coverage, and reusability. Work normal day business hours in the Eastern US time zone Education, Experience, and Competencies BS (or higher, e.g., MS or Ph.D.) in Computer Science or a related technical field involving coding, or equivalent technical experience. 8+ years of platform, infrastructure, or site reliability engineering experience, with demonstrated Staff, Principal, or Architect-level scope, such as owning platform architecture end to end or being accountable for critical production systems. We evaluate candidates on the scope and impact of their work rather than years of experience alone. Deep, hands-on experience designing and operating CI/CD pipelines for high-velocity engineering organizations, including artifact management, environment promotion, and progressive rollout. Strong AWS background, comfortable down to the IAM, networking, and container orchestration layers, including production Kubernetes experience. Experience with GitHub and GitHub actions. Proven track record building internal developer platforms or tools that other engineering teams adopted by choice, not by mandate. Hands-on coding fluency in Python, Go, or TypeScript. This is a keyboard role, not an architecture-only role. Comfortable operating in a polyglot environment. The RxSense engineering stack spans Python, .NET, and TypeScript, and you will support services across all three. Practical experience with infrastructure as code (such as Terraform, CloudFormation, or Pulumi) and modern observability tooling (such as Prometheus, New Relic, Grafana, Datadog, or Open Telemetry). Comfortable owning the cost and reliability conversation with both engineering leadership and finance partners. Strong written communication and a bias toward documentation, runbooks, and clear interfaces. Proven analytical thinking and problem-solving skills. Excellent communication skills, both verbal and written. Bonus Qualifications Experience supporting infrastructure for AI or LLM-powered workloads, including GPU provisioning, model serving, or agent runtime infrastructure. Background in healthcare, PBM, pharmacy, or another regulated data environment. Kubernetes operator experience or comfort building custom controllers. FinOps experience, particularly attributing infrastructure spend to features, teams, or business units. Familiarity with distributed systems tooling such as Kafka, gRPC, or Dragonfly and Redis. Experience with Agile development methodologies, preferably both Scrum and Kanban. Experience with code scanning, security, and quality checks as part of the CICD. Salary Range: $190,000 - $235,000 RxSense believes that a diverse workforce is a more talented and productive workforce. As such, we are an Equal Opportunity and Affirmative Action employer. Our recruitment process is free from discriminatory hiring practices and all qualified applicants are considered for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity, ancestry, age, or national origin. Neither will qualified applicants be discriminated against on the basis of disability or protected veteran status. We believe in the strength of the collaboration, creativity and sense of community a diverse workforce brings.
09/26/2026
Full time
Job Description Job Description We are a healthcare technology company that provides platforms and solutions to improve the management and access of cost-effective pharmacy benefits. Our technology helps enterprise and partnership clients simplify their businesses and helps consumers save on prescriptions. As a leader in SaaS technology for healthcare, we offer innovative solutions with integrated intelligence on a single enterprise platform that connects the pharmacy ecosystem. With our expertise and modern, modular platform, our partners use real-time data to transform their business performance and optimize their innovative models in the marketplace. Position Summary The Principal Platform Engineer owns the core engineering platform that every product team at RxSense builds on. As a direct report to the VP, Infrastructure Engineering, this role is accountable for the cloud infrastructure, CI/CD systems, developer tooling, and reliability practices that determine how confidently and how fast RxSense engineering can ship. This is a hands-on-keyboard, architect-level role, partnering with software engineers, AI engineers, security, and finance to build a platform that teams choose to build on rather than one they are required to use. Essential Duties and Responsibilities Design, build, and operate the core cloud infrastructure that supports RxSense engineering, including compute, networking, identity and access management, and container orchestration on AWS. Own the CI/CD platform used across engineering teams, including build pipelines, artifact management, environment promotion, progressive rollout, and rollback. Build and maintain the observability stack across the organization, including logging, metrics, distributed tracing, alerting, and the SLIs and SLOs that define reliable service. Drive infrastructure as code practices across the organization and manage the Kubernetes clusters, custom controllers, and operators that back production workloads. Partner with security and compliance to manage secrets, network policy, and access controls appropriate to a regulated healthcare and pharmacy benefits environment. Design self-service developer tooling and platform APIs and set the abstractions that let product and AI engineering teams' provision, deploy, and operate services without handholding. Own incident response tooling, on-call practices, and reliability engineering standards, and lead or support major incident response across the platform. Partner with engineering leadership and finance on infrastructure cost visibility, capacity planning, and cost optimization. Write documentation, runbooks, and clear interfaces so the platform is adoptable by other engineering teams without handholding. Participate in code review and promote collaboration and best practices, including simplicity, automation, sound design patterns, test coverage, and reusability. Work normal day business hours in the Eastern US time zone Education, Experience, and Competencies BS (or higher, e.g., MS or Ph.D.) in Computer Science or a related technical field involving coding, or equivalent technical experience. 8+ years of platform, infrastructure, or site reliability engineering experience, with demonstrated Staff, Principal, or Architect-level scope, such as owning platform architecture end to end or being accountable for critical production systems. We evaluate candidates on the scope and impact of their work rather than years of experience alone. Deep, hands-on experience designing and operating CI/CD pipelines for high-velocity engineering organizations, including artifact management, environment promotion, and progressive rollout. Strong AWS background, comfortable down to the IAM, networking, and container orchestration layers, including production Kubernetes experience. Experience with GitHub and GitHub actions. Proven track record building internal developer platforms or tools that other engineering teams adopted by choice, not by mandate. Hands-on coding fluency in Python, Go, or TypeScript. This is a keyboard role, not an architecture-only role. Comfortable operating in a polyglot environment. The RxSense engineering stack spans Python, .NET, and TypeScript, and you will support services across all three. Practical experience with infrastructure as code (such as Terraform, CloudFormation, or Pulumi) and modern observability tooling (such as Prometheus, New Relic, Grafana, Datadog, or Open Telemetry). Comfortable owning the cost and reliability conversation with both engineering leadership and finance partners. Strong written communication and a bias toward documentation, runbooks, and clear interfaces. Proven analytical thinking and problem-solving skills. Excellent communication skills, both verbal and written. Bonus Qualifications Experience supporting infrastructure for AI or LLM-powered workloads, including GPU provisioning, model serving, or agent runtime infrastructure. Background in healthcare, PBM, pharmacy, or another regulated data environment. Kubernetes operator experience or comfort building custom controllers. FinOps experience, particularly attributing infrastructure spend to features, teams, or business units. Familiarity with distributed systems tooling such as Kafka, gRPC, or Dragonfly and Redis. Experience with Agile development methodologies, preferably both Scrum and Kanban. Experience with code scanning, security, and quality checks as part of the CICD. Salary Range: $190,000 - $235,000 RxSense believes that a diverse workforce is a more talented and productive workforce. As such, we are an Equal Opportunity and Affirmative Action employer. Our recruitment process is free from discriminatory hiring practices and all qualified applicants are considered for employment without regard to race, color, religion, sex, gender, sexual orientation, gender identity, ancestry, age, or national origin. Neither will qualified applicants be discriminated against on the basis of disability or protected veteran status. We believe in the strength of the collaboration, creativity and sense of community a diverse workforce brings.
PKI Subject Matter Expert w/Secret Clearance
TekSynap
Job Description Job Description Overview WORK ENVIRONMENT The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: On-site, DISA Headquarters, 6914 Cooper Ave, Fort Meade, MD 20755 Type of environment: Office - on-site at a Government facility (classified environment) Noise level: Low to Medium Work schedule: Day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 10%. Occasional travel within the National Capital Region and to up to four (4) conferences per year. WORK AUTHORIZATION/SECURITY CLEARANCE U.S. Citizen Secret Clearance PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WAGE INFORMATION Target salary range: $100,000 - $16,000.00/yr. The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. Responsibilities We are seeking a PKI Subject Matter Expert - Cryptographic Modernization (PQC, Algorithm Evolution & NPE) - Key Personnel to join our team supporting the DISA PKI Public Key Enablement (PKE) Engineering Support Task Order (SETI Small Business) in Fort Meade, Maryland. REQUIRED QUALIFICATIONS Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments. Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations. Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography. Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states. Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST). Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities. Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains. Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process. Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred. Certifications Certification: DoD 8140 Cyber Workforce Qualification Program, IAT Level II, IAT Level III, IAM III or equivalent, required at time of assignment Education Education: Bachelor's degree in Computer Science, Cybersecurity, Mathematics, Engineering, or a related field. Master's degree preferred; equivalent demonstrated technical experience may be considered. Clearance Clearance: Active Secret clearance required. Must be onboard at the start of the Period of Performance. RESPONSIBILITIES Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio. Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations. Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes. Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states. Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture. Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs. Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team. Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs. Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME. Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day. Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy. Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released. Qualifications TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at . We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. EQUAL EMPLOYMENT OPPORTUNITY . click apply for full job details
09/26/2026
Full time
Job Description Job Description Overview WORK ENVIRONMENT The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of the job. Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions. Location: On-site, DISA Headquarters, 6914 Cooper Ave, Fort Meade, MD 20755 Type of environment: Office - on-site at a Government facility (classified environment) Noise level: Low to Medium Work schedule: Day shift Monday - Friday. May be requested to work evenings and weekends to meet program and contract needs. Amount of Travel: Less than 10%. Occasional travel within the National Capital Region and to up to four (4) conferences per year. WORK AUTHORIZATION/SECURITY CLEARANCE U.S. Citizen Secret Clearance PHYSICAL DEMANDS The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions. While performing the duties of this job, the employee is regularly required to use hands to handle, feel, touch; reach with hands and arms; talk and hear. The employee is regularly required to stand; walk; sit; climb or balance; and stoop, kneel, crouch, or crawl. The employee is regularly required to lift up to 10 pounds. The employee is frequently required to lift up to 25 pounds; and up to 50 pounds. The vision requirements include close vision, distance vision, peripheral vision, depth perception, and ability to adjust focus. WAGE INFORMATION Target salary range: $100,000 - $16,000.00/yr. The salary range displayed is an estimate only and is not a guarantee of compensation or salary and will be determined on several factors regarding the individual's particular combination of education, knowledge, skills, competencies and experience, as well as contract parameters and organizational requirements. The displayed salary is one component of the total compensation package for employees. OTHER INFORMATION Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities and activities may change at any time with or without notice. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. Many positions require specific certifications and/or the ability to obtain a security clearance. Security clearances may only be granted to U.S. citizens. Applicants who accept an offer of employment may be subject to investigations performed by TekSynap and/or the Government to verify the candidate meets the required qualifications and other eligibility requirements. Responsibilities We are seeking a PKI Subject Matter Expert - Cryptographic Modernization (PQC, Algorithm Evolution & NPE) - Key Personnel to join our team supporting the DISA PKI Public Key Enablement (PKE) Engineering Support Task Order (SETI Small Business) in Fort Meade, Maryland. REQUIRED QUALIFICATIONS Ten (10) or more years of hands-on PKI, cryptographic engineering, or cryptographic infrastructure experience, including at least five (5) years in DoD or federal high-security environments. Hands-on, low-level technical proficiency in cryptographic infrastructure and system integration within high-security environments, with demonstrated capability to engineer solutions for complex hardware and legacy software integrations. Demonstrated understanding of the mathematics, protocols, and hardware that drive public key cryptography. Practical, demonstrable knowledge of NIST post-quantum standards (FIPS 203 ML-KEM, FIPS 204 ML-DSA, FIPS 205 SLH-DSA) and the engineering steps to migrate production systems to quantum-safe states. Expertise automating certificate lifecycles for Non-Person Entities (routers, firewalls, microservices, Kubernetes) using automated certificate management protocols (ACME, EST). Hands-on experience with Hardware Security Modules (Entrust, Thales, SafeNet), key ceremonies, and HSM lifecycle or refresh activities. Experience with Certificate Authority platforms, preferably Red Hat Certificate System, including CA stand-up, configuration, and certificate profile management across classified and unclassified domains. Working knowledge of DoD PKI policy, DoDI 8520.02, STIG application, and the DoD PKI Authority to Operate (ATO) accreditation process. Familiarity with the DoD PKE custom tool suite (e.g., InstallRoot, FileSigner, CRL Auto Cache, PITT) and software development in C++, C#, Java, Python, or Rust is strongly preferred. Certifications Certification: DoD 8140 Cyber Workforce Qualification Program, IAT Level II, IAT Level III, IAM III or equivalent, required at time of assignment Education Education: Bachelor's degree in Computer Science, Cybersecurity, Mathematics, Engineering, or a related field. Master's degree preferred; equivalent demonstrated technical experience may be considered. Clearance Clearance: Active Secret clearance required. Must be onboard at the start of the Period of Performance. RESPONSIBILITIES Serve as the senior technical and cryptographic authority, the technical trust anchor for implementation, for algorithm evolution and Post-Quantum Cryptography across the DoD PKI Portfolio. Recommend approaches that steer the PKI program away from legacy, vulnerable cryptographic implementations. Develop and execute the plan to migrate DoD PKI to stronger cryptographic algorithms in accordance with NIST SP 800-131A Rev3 and the CNSA 2.0 PQC timeline, addressing encryption, digital signing, key agreement, key derivation, key wrapping, key transport, hash functions, and message authentication codes. Apply practical knowledge of NIST-standardized quantum-resistant algorithms, including ML-KEM and ML-DSA, and define the engineering steps required to transition existing systems to quantum-safe states. Maintain cryptographic agility across the portfolio in response to evolving NIST standards and Executive Order 14412, so algorithm changes are absorbed by configuration and re-test rather than re-architecture. Coordinate with COTS vendors (approximately 15 in the current ecosystem) to test feasibility and assess the timeliness of product transition plans; maintain the vendor tracking report and raise capability gaps to the coordination cell and Component CIOs. Develop and deploy PKE lab environments supporting Algorithm Evolution and PQC integration testing; document and report results to DoD working groups including the Certificate Validation Tiger Team. Evaluate HSM platforms for PQC readiness; HSM hardware refresh is within contract scope and the current environment uses Entrust HSMs. Provide Non-Person Entity (NPE) certificate management expertise, automating certificate lifecycles for routers, firewalls, microservices, and Kubernetes clusters using automated certificate management protocols such as EST and ACME. Support Certificate Authority Development, including CA architecture analysis, deficiency identification, Analysis of Alternatives development, and CA deployment across 42 NIPRNet and 31 SIPRNet Red Hat Certificate Authorities supporting approximately 10,000 certificate issuances per day. Provide input to CA deployment plans and develop and document Change Requests to modify software and hardware configurations, submitted through the PKI Configuration Management process and Remedy. Provide Tier III technical support for the most complex cryptographic and infrastructure issues, and review and update PKE enablement documentation as cryptographic changes are released. Qualifications TekSynap is a fast growing high-tech company that understands both the pace of technology today and the need to have a comprehensive well planned information management environment. "Technology moving at the speed of thought" embodies these principles - the need to nimbly utilize the best that information technology offers to meet the business needs of our Federal Government customers. Apply now to explore jobs with us at . We offer our full-time employees a competitive benefits package to include health, dental, vision, 401K, life insurance, short-term and long-term disability plans, vacation time and holidays. TekSynap is a drug-free workplace. We reserve the right to conduct drug testing in accordance with federal, state, and local laws. All employees and candidates may be subject to drug screening if deemed necessary to ensure a safe and compliant working environment. By applying to a role at TekSynap you are providing consent to receive text messages regarding your interview and employment status. If at any time you would like to opt out of text messaging, respond "STOP". As part of the application process, you agree that TekSynap Corporation may retain and use your name, e-mail, and contact information for purposes related to employment consideration. EQUAL EMPLOYMENT OPPORTUNITY . click apply for full job details
Network Security Engineer
EF Johnson Technologies Inc. Irving, Texas
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.
09/26/2026
Full time
Job Description Job Description Network Security Engineer About Us EFJohnson Technologies is a subsidiary of JVCKENWOOD Corporation, a leading provider of P25 communications solutions for first responders in public safety and public service, the federal government, and industrial organizations. Our products are marketed under the EFJohnson and KENWOOD brands. EFJohnson provides wireless communications products and systems for public safety, commercial, and government customers. We design, manufacture, and market conventional and trunked radio systems, land mobile radio repeaters, and mobile and portable radios, including Project 25 digital radio products. As a Network Security Engineer you'll design, implement, and enforce comprehensive network and security architectures for mission-critical radio, data, and monitoring systems. This position will develop and maintain security standards and technical controls directly aligned with NIST SP 800-171 and CMMC Level 2 requirements to ensure protection of Controlled Unclassified Information (CUI). As a Network Security Engineer, you'll collaborate with network and system architects to embed security throughout the full system lifecycle, from design and segmentation to identity management, remote access, and incident response. This role is hybrid, based out of Irving, TX. Key Responsibilities Security Architecture & Compliance Define, document, and maintain comprehensive network security standards mapped to NIST SP 800-171 and CMMC Level 2 controls. Collaborate with architects to incorporate security in every design, emphasizing segmentation and isolation of CUI assets. Design, test, and maintain network-level controls supporting Identification & Authentication (IA) and System & Communications Protection (SC) families. Contribute technical content to the System Security Plan (SSP), Plan of Action and Milestones (POA&M), and compliance evidence packages. Enforce configuration management and formal change-control processes to maintain baseline compliance. Perform security impact assessments on proposed design changes, ensuring traceability to CMMC requirements. Identity & Access Management (IAM) Design and deploy centralized LDAP for directory services and user authentication. Design, implement, and administer TACACS+ for AAA control across routers, switches, and radio controllers. Configure and manage Multi-Factor Authentication (MFA) for privileged and remote accounts (CMMC IA.L2-3.5.3). Ensure unique identification and authentication of all users and devices (CMMC IA.L2-3.5.1). Integrate IAM systems with centralized logging and SIEM tools to support audit and traceability requirements. Network Security Services Implementation Design, configure, and deploy Remote Access VPNs and IPSec site-to-site tunnels for secure connectivity, ensuring encryption of CUI in transit. Configure, deploy, and manage Next-Generation Firewalls (NGFWs) to enforce zone-based policies and control traffic between segmented network zones. Implement and tune Intrusion Prevention Systems (IPS) to detect and block malicious traffic in real time. Run regular vulnerability assessments and penetration tests; prioritize remediation actions that impact CMMC compliance. Integrate firewall, VPN, and IPS logs with centralized SIEM systems; conduct Root Cause Analysis (RCA) for network or IAM-related security incidents. Act as Tier 2/Tier 3 escalation for the Security Operations Center (SOC). CUI Data Handling & Protection Ensure CUI is encrypted in transit and at rest using approved algorithms and key management standards. Implement network segmentation, VLAN isolation, and access-controlled zones to separate CUI from non-CUI traffic. Configure syslog, NTP, SNMPv3, and TLS securely for audit traceability and time-correlated event tracking. Enforce least-privilege access for CUI repositories and verify logging for all privileged actions. Conduct quarterly configuration audits and evidence collection in support of the corporate CMMC compliance program. Operational Security & Monitoring Maintain configuration baselines and perform periodic compliance checks on all network-security devices. Automate log collection and configuration integrity validation using secure scripting methods. Maintain network documentation, change-management records, and segmentation diagrams. Provide support for field deployments, system upgrades, and on-site network hardening activities. Assist with tabletop exercises, incident response drills, and after-action reviews. Collaboration & Continuous Improvement Partner with network and system engineering teams to embed secure-by-design principles into radio network infrastructure and analyzer platforms. Mentor junior engineers through scheduled security and compliance training sessions. Coordinate with software and system teams to ensure servers, databases, and applications meet hardened configuration baselines. Contribute to EF Johnson's internal Security Program Initiative, ensuring continuous improvement and measurable compliance progress. Recommend new tools, automation frameworks, and monitoring solutions to improve efficiency and visibility. Complete additional duties as required. Agree to abide by the established Approval Matrix. Qualifications Bachelor's Degree in Cybersecurity, Computer Science, Engineering Technology, or a related discipline; Master's preferred. Cisco CCNP Security or equivalent required. CISSP, CompTIA CySA+, or CISM preferred. Experience implementing security controls aligned to NIST SP 800-171 and CMMC Level 2. Hands-on experience with firewalls, VPNs, IPS, AAA, and logging systems. Familiarity with Linux security hardening, log analysis, and automation scripting (Python, Bash, Ansible). Experience conducting packet analysis and forensics (Wireshark, Zeek, Suricata). Knowledge of public-safety radio networks, LMR systems, and secure field deployments preferred. What We're Looking For Advanced technical capacity in network and security engineering. Strong written and verbal communication skills. Demonstrated analytical, diagnostic, and problem-solving ability. Experience with Windows and Linux administration. Rapid learning aptitude for new tools and methods. Proficiency with scripting, configuration management, and SIEM integration. In-depth understanding of TCP/IP, UDP, SNMPv3, SSL/TLS, IPSec, and 802.1X. P25, DFSI+, and SIP preferred. Travel Requirements Up to 30% What We Offer Competitive salary Health, dental, and vision benefits Additional supplemental benefits 401K + employer match Tuition reimbursement 12 paid holidays + additional PTO Supportive- team-driven environment Opportunities to work on mission-critical projects that make a real impact Equal Opportunity Statement EF Johnson Technologies is an Equal Opportunity/AFFIRMATIVE ACTION Employer who values diversity and inclusion in the workplace. It is the policy of this company to provide equal opportunity with regard to all terms and conditions of employment. The company complies with federal and state laws prohibiting discrimination on the basis of sex, race, color, religion, creed, national origin, disability, veteran status, age, sexual orientation, gender identity, genetic information, pregnancy, or any other protected characteristic.

Modal Window

  • Home
  • Contact
  • About Us
  • FAQs
  • Terms & Conditions
  • Privacy
  • Employer
  • Post a Job
  • Search Resumes
  • Sign in
  • Job Seeker
  • Find Jobs
  • Create Resume
  • Sign in
  • IT blog
  • Facebook
  • Twitter
  • LinkedIn
  • Youtube
© 2008-2026 IT Job Board