Search 1,692 Remote CCSP Jobs

1,692 remote jobs

Staff Cloud Security Engineer

This position is listed on behalf of a partner company who manages all applications and next steps. Our partner is looking for a Staff Cloud Security Engineer based in United States. As a Staff Cloud Security Engineer you will help define and strengthen the security foundation of modern multi-cloud environments and next-generation applications. You will design automated security controls and embed security directly into development and deployment workflows. The role spans DevSecOps identity and access management infrastructure hardening workload security data protection and threat detection. You will partner closely with engineering DevOps product and security teams to build secure-by-default systems at scale. You will also help secure emerging AI/ML workloads protecting models data pipelines identities and sensitive information from evolving threats. Your work will directly reduce organizational risk while improving developer efficiency visibility and resilience. This is a high-impact technical leadership opportunity for a hands-on security engineer who enjoys building scalable solutions in a rapidly evolving environment. Accountabilities Design and integrate security controls directly into CI/CD pipelines using platforms such as GitHub GitLab Jenkins or Azure DevOps. Evaluate configure and manage Infrastructure as Code security scanning tools to identify meaningful risks and reduce false positives. Build automated developer feedback and remediation workflows that encourage secure-by-default development practices. Develop automation scripts using Python Bash or PowerShell to streamline security processes and improve operational efficiency. Establish and maintain IAM controls across cloud environments enforcing least-privilege access and secure identity practices. Define standards and lifecycle controls for non-human identities APIs application credentials and cloud secrets. Develop secure infrastructure baselines vulnerability management processes and hardening standards across AWS Azure and/or GCP. Use Terraform CloudFormation Bicep or comparable IaC technologies to ensure infrastructure is secure repeatable and auditable. Lead or contribute to high-impact infrastructure security initiatives including multi-cloud network isolation secure multi-tenant architectures and continuous remediation of misconfigurations. Advise engineering teams on secure cloud-native architectures spanning microservices serverless applications containers and PaaS workloads. Strengthen container and Kubernetes security through runtime controls supply-chain protections and configuration assessments. Develop security approaches for AI/ML systems addressing adversarial threats unauthorized access model protection and data pipeline security. Protect sensitive cloud and AI data through encryption anonymization secure storage tokenization and appropriate data protection controls. Partner with Security Operations to improve cloud telemetry logging observability and detection capabilities. Onboard relevant cloud log sources and develop detection rules for cloud-based threats using SIEM CSPM CWPP and related technologies. Support the triage investigation and forensic analysis of cloud and application security incidents collaborating on containment and remediation. Translate complex security requirements into practical guidance for both technical and non-technical stakeholders. Requirements 7–10+ years of hands-on experience in cloud security application security DevSecOps or closely related engineering disciplines. Deep practical expertise securing AWS and/or Azure environments including the design and maintenance of controls for multi-cloud applications. Strong knowledge of cloud identity and access management infrastructure security vulnerability management network security data protection and security monitoring. Proficiency with Python Bash PowerShell or similar scripting languages for security automation. Strong understanding of Docker Kubernetes container security and cloud-native application architectures. Hands-on experience securing Infrastructure as Code particularly with Terraform ARM CloudFormation Bicep or comparable technologies. Experience integrating security practices into CI/CD pipelines and applying DevSecOps principles across software development workflows. Familiarity with SIEM CSPM CWPP cloud logging telemetry detection engineering and incident response practices. Knowledge of AI/ML security considerations including protection of models data pipelines identities and workloads is highly valuable. Relevant industry certifications such as CCSP CISSP AWS Security Specialty Azure Security Engineer GCSA or OSCP are strongly preferred. A proactive builder mindset with a demonstrated ability to identify security gaps improve processes and develop scalable solutions. Strong cross-functional collaboration and communication skills with the ability to explain sophisticated security concepts clearly to varied audiences. Comfortable operating in a rapidly changing environment and continuously adapting to emerging cloud application and AI security threats. Benefits Competitive base salary of $168200–$252200 for eligible US locations with a higher range of $179900–$269900 applicable to CA CT DC MD MA NJ NY VA and WA. Annual bonus and equity opportunities as part of the total compensation package. Company-sponsored medical dental and vision coverage including fully employer-paid options and substantial dependent coverage. FSA and HSA options. 401(k) match. Telehealth benefits including One Medical membership options. Flexible paid time off and support for autonomous work. Learning and development opportunities comprehensive onboarding leadership training and professional growth programs. Recognition programs including peer-nominated awards and rewards. Parental leave and family support programs. Up to $20000 in fertility services including IUI and IVF plus surrogacy and adoption reimbursement. Maternity support through Maven Maternity and free breast milk shipping through Maven Milk. Pet insurance legal advisory services financial planning tools and additional wellness and family benefits. Fully remote work environment with flexibility and opportunities to work on cutting-edge cloud and AI security challenges. How Jobgether Works We use an AI-powered matching process to ensure your application is reviewed quickly objectively and fairly against the role's core requirements. Our system identifies the top-fitting candidates and this shortlist is then shared directly with the hiring company. The final decision and next steps (interviews assessments) are managed by their internal team. We appreciate your interest and wish you the best! Why Apply Through Jobgether? Data Privacy Notice By submitting your application you acknowledge that Jobgether will process your personal data to evaluate your candidacy and share relevant information with the hiring employer. This processing is based on legitimate interest and pre-contractual measures under applicable data protection laws (including GDPR). You may exercise your rights (access rectification erasure objection) at any time. We may use artificial intelligence (AI) tools to support parts of the hiring process such as reviewing applications analyzing resumes or assessing responses and identifying potential inconsistencies or verification signals in application materials based on available information. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed please contact us.

Cybersecurity Engineer

Senior Cybersecurity SOC Incident Response & GRC Professionals. Remote AI Project We are seeking experienced cybersecurity professionals security engineers SOC leaders incident responders security architects penetration testers and GRC specialists to help create realistic evaluation tasks for advanced AI systems. You will design real-world cybersecurity scenarios reference solutions incident reports security assessments architecture recommendations and scoring rubrics based on how senior security professionals operate in enterprise environments. What You’ll Do Create realistic cybersecurity scenarios involving security operations threat detection incident response vulnerability management security architecture and risk Develop reference incident reports forensic analyses security assessments architecture designs and compliance documentation Build scenarios involving enterprise SIEM EDR vulnerability management cloud security and GRC platforms Apply threat modeling incident response risk assessment vulnerability management and security engineering methodologies Evaluate whether AI-generated responses demonstrate authentic professional security judgment Create scoring rubrics that distinguish senior-level cybersecurity expertise from generic textbook or certification-level answers Who Can Apply Relevant backgrounds include Cybersecurity Engineers Senior Security Engineers Information Security Engineers Security Analysts Senior Security Analysts Cybersecurity Analysts Information Security Analysts Security Consultants Cybersecurity Consultants Information Security Consultants and Security Specialists. Security operations backgrounds may include SOC Analysts Senior SOC Analysts SOC Engineers SOC Leads SOC Managers Security Operations Engineers Security Operations Analysts Security Operations Managers Detection Engineers Threat Detection Engineers SIEM Engineers Security Monitoring Engineers Blue Team Engineers and Cyber Defense Analysts. Incident response and threat backgrounds may include Incident Response Analysts Incident Responders Incident Response Engineers DFIR Specialists Digital Forensics Analysts Forensic Investigators Cyber Incident Managers Threat Hunters Threat Intelligence Analysts Cyber Threat Intelligence Specialists Malware Analysts Reverse Engineers and Security Researchers. Requirements 5+ years of professional experience in cybersecurity information security security engineering incident response penetration testing GRC or a related discipline Direct ownership of significant security programs investigations architecture decisions risk assessments or compliance initiatives Strong understanding of enterprise cybersecurity operations and real-world threat response Hands-on familiarity with modern security tooling Understanding of how cybersecurity frameworks and regulatory requirements are applied in practice Ability to create clear incident reports security assessments architecture recommendations or compliance documentation Strong written communication and professional judgment Ability to distinguish practical security decisions from generic theoretical answers Preferred Background Experience at a large enterprise technology company financial institution healthcare organization security firm consulting company government organization or critical infrastructure operator Direct ownership of security incidents security architecture penetration testing or compliance programs Experience advising executives or senior leadership on cybersecurity risk Experience leading SOC incident response security engineering or GRC teams CISSP CISM GIAC OSCP CCSP CRISC CISA Security+ or equivalent professional certification Experience with NIST CSF SOC 2 ISO 27001 NIS2 or similar frameworks Experience creating security policies training programs technical documentation playbooks or evaluation rubrics Prior AI evaluation benchmark creation red teaming model testing or structured assessment experience is helpful This opportunity is ideal for senior cybersecurity professionals who can distinguish technically plausible responses from the decisions an experienced security leader would actually make during real incidents architectural reviews vulnerability programs and compliance initiatives. We are a referral partner of the client.

Senior Manager - Security Engineering

Job Posting Since 1953 Ferguson has been a source of quality supplies for a variety of industries. Together We Build Better infrastructure better homes and better businesses. We exist to make our customers’ complex projects simple successful and sustainable. We proactively solve problems adapt and grow to continuously serve our customers communities and each other. Ferguson a Fortune 500 company is proud to provide best-in-class products service and capabilities across the following industries Commercial/Mechanical Facilities Supply Fire and Fabrication HVAC Industrial Residential Trade Residential Building and Remodel Waterworks and Residential Digital Commerce. Ferguson has approximately 36000 associates across 1700 locations. Ferguson is a community of proud associates who operate with the shared purpose of building something meaningful. You will build a career that you are proud of at a company you can believe in. Senior Manager - Security Engineering Department Ferguson Information Security Reports To Director Information Security The Senior Manager Security Engineering provides vision leadership and operational accountability for Ferguson’s enterprise security engineering capabilities. This role leads the teams and services responsible for identifying reducing and reporting technology risk across applications infrastructure cloud platforms endpoints identity-integrated services email edge protections and emerging AI-enabled attack surfaces. The leader is accountable for ensuring Ferguson has the people processes tooling and partnerships required to continuously assess risk harden technology baselines validate defenses support secure delivery and drive remediation in partnership with Technology Security business and third-party participants. This position requires deep technical judgment collaborative leadership and operational rigor. It also requires the ability to translate complex security risks into actionable priorities. These priorities help Ferguson complete its business plans securely. Location This role is approved to be either Remote within the United States or Hybrid for associates in Newport News VA in accordance with company policy. Duties and Responsibilities Leadership and Strategy (40%) Build lead and develop a high-performing Security Engineering team through recruiting hiring coaching mentorship performance management and career development. Define and maintain the operating model service ownership roadmap and measurable objectives related to Security Engineering capabilities across vulnerability management DevSecOps penetration testing edge security email security endpoint security cloud and configuration posture and related engineering services. Represent Security Engineering performance risks resource needs and strategic opportunities with Information Security leadership and multi-functional Technology leadership forums. Partner with Security Architecture Security Operations GRC Identity Infrastructure Application Development Cloud and business technology teams to align engineering priorities to enterprise risk reduction and business enablement. Continuously assess team skills capacity vendor support and tooling maturity against current and emerging threats including AI-enabled attack techniques and post-quantum readiness considerations. Drive a culture of secure-by-default engineering shared accountability transparency and practical risk-based decision making across Ferguson technology teams. Establish clear metrics performance indicators reporting routines and executive-ready narratives that communicate risk posture control effectiveness remediation progress service value and investment needs. Security Engineering Management (60%) Own and mature Security Engineering service areas including vulnerability management DevSecOps penetration testing and adversarial validation edge security email security endpoint detection and response cloud security posture configuration risk application security testing and security tooling integrations. Lead Ferguson’s risk-based vulnerability management capability ensuring asset visibility authenticated scanning application and infrastructure assessment risk contextualization remediation tracking exception management and leadership reporting are operating effectively. Advance secure software delivery by integrating security testing and guidance into development workflows including static analysis software composition analysis container security secrets protection code signing secure repository practices and developer-facing remediation support. Run penetration testing AI-enabled security testing purple team support and continuous adversarial validation activities for critical applications APIs external assets cloud services identity entry points and business-critical technology platforms. Ensure public-facing applications and digital channels are protected through effective use of edge security capabilities including WAF bot management CDN security origin protection API protections and secure traffic patterns. Provide engineering ownership and oversight for email and endpoint security capabilities including migration planning policy tuning telemetry quality detection support deployment health and operational readiness. Drive enterprise configuration and posture management across cloud infrastructure endpoints applications and identity-adjacent services to identify deviations from hardened baselines and support timely remediation. Partner with Identity PAM SSO certificate and non-human identity teams where security engineering capabilities depend on identity controls privileged access machine identity key management or cryptographic services. Support pivotal initiatives such as AI resilience post-quantum readiness enterprise cryptographic visibility secrets removal cloud posture modernization and security tooling rationalization. Ensure Security Engineering platforms and service offerings are reliable monitored documented supportable and aligned with published policies standards organizational change expectations and regulatory or audit obligations. Establish and maintain runbooks customer concern paths operational handoffs service ownership documentation vendor engagement models and cross-training practices to prevent coverage gaps. Prioritize engineering work based on business risk exploitability asset criticality exposure compliance requirements operational impact and available remediation capacity. Partner with Technology teams to close visibility and deployment gaps in required security tooling so Ferguson can assess and protect operational assets consistently. Contribute technical requirements to security technology selection proof-of-value efforts vendor evaluations architecture reviews and implementation planning. Actively monitor new and emerging technologies threats attack patterns regulatory expectations and industry practices to assess their applicability to Ferguson’s security engineering program. Perform other duties or functions as requested by management. Drive and report on Service restoration activities as required. Support enterprise business and sales objectives through the effective and efficient performance of job responsibilities Qualifications and Requirements Experience leading information security engineering application security vulnerability management cloud security endpoint security or related technical security teams is required. Experience managing full-time associates contractors vendors and multi-functional delivery partners is required. Experience building or operating risk-based vulnerability management application security testing DevSecOps penetration testing security tooling or cloud posture management programs is strongly preferred. Experience partnering with infrastructure application development cloud identity security operations GRC and business technology teams to reduce enterprise technology risk is strongly preferred. Eight (8) or more years of information security technology risk security engineering or related experience is strongly preferred including demonstrated leadership accountability. Strong leadership communication organizational and internal business customer leadership skills. Ability to translate technical security findings control gaps and threat scenarios into business risk prioritized action and executive-level communication. Broad knowledge of vulnerability management exposure management application security DevSecOps penetration testing web application security API security cloud security endpoint protection email security and configuration management practices. Solid understanding of modern security tooling such as vulnerability scanners risk reporting platforms SAST SCA container security WAF bot management EDR CSPM SIEM integrations secrets management certificate management and identity-related security platforms. Ability to lead multi-functional remediation efforts where ownership technical complexity business impact and risk acceptance decisions must be coordinated across teams. Knowledge of security frameworks standards and practices such as NIST CSF ISO 27001/27002 OWASP MITRE ATT&CK CIS Benchmarks secure SDLC and IT service management. Ability to develop metrics and reporting that demonstrate security posture remediation progress control effectiveness service health and business value. Ability to operate effectively in a distributed matrixed environment with contending priorities and high demand for security engineering services. Ability to partner with architecture delivery operations infrastructure cloud identity and business teams to embed security into technology planning and delivery. Strong vendor management proof-of-value requirements development and technology evaluation skills. Fluent with Microsoft Office and collaboration tools experience with Microsoft security cloud and identity ecosystems strongly preferred. Certifications such as CISSP CISM CCSP GIAC Azure Security AWS Security or similar security and cloud certifications are preferred but not required. Solid ability to prioritize work establish timelines handle tradeoffs and deliver outcomes by deadline. At Ferguson we care for each other. We value our well-being just as much as our hard work. We are committed to a holistic approach towards benefits plans and programs that support the mental physical and financial well-being of our associates. Our competitive offering not only includes benefits like health dental vision paid time off life insurance and a 401(k) with a company match but our associates also enjoy additional meaningful and inclusive enhancements that are adaptable to their diverse situations and needs including mental health coverage gender affirming and family building benefits paid parental leave associate discounts community involvement opportunities and more! Pay Range Actual pay rate may vary depending upon location. The estimated pay range for this position is below. The specific rate will depend on a candidate’s qualifications and prior experience. $9458.97 - $16551.03 Estimated Ranges displayed are Monthly for Salaried roles OR Hourly for all other roles. This role is Bonus or Incentive Plan eligible. Ferguson complies with all wage regulations. The starting wage may be higher in certain locations based on local or state wage requirements. The Company is an equal opportunity employer as well as a government contractor that shall abide by the requirements of 41 CFR 60-300.5(a) which prohibits discrimination against qualified protected Veterans and the requirements of 41 CFR 60-741.5(A) which prohibits discrimination against qualified individuals on the basis of disability. Ferguson Enterprises LLC. is an equal employment employer F/M/Disability/Vet/Sexual Orientation/Gender Identity. Equal Employment Opportunity and Reasonable Accommodation Information

Cyber Cloud Security Engineer - Vice President

Greenwich, Connecticut, United States New York, New York, United States

About the Role iCapital is looking for a Vice President Cyber Cloud Security Engineer to join the Security Engineering team within the Information Security organization. This role will establish and manage cloud security programs build new security architecture drive automation and continuously identify and address security gaps across iCapital technology landscape. The ideal candidate is a deeply technical individual contributor who can research design and implement security technologies and collaborate effectively across teams and functions. Responsibilities Build and manage Cloud Security Programs across AWS Azure and GCP infrastructure. Design implement and validate secure cloud infrastructure architectures ensuring new capabilities meet established security standards and requirements. Apply Zero Trust architecture principles and best practices across cloud infrastructure design and access models. Drive continuous detection remediation and resolution of cloud vulnerabilities and security misconfigurations leveraging CSPM tooling (e.g. AWS Security Hub Wiz or equivalent) and automation to continuously improve and maintain cloud security posture. Build automation capabilities for continuous monitoring and alerting across cloud infrastructure. Partner with engineering teams to drive the adoption of security standards and best practices embedding security early across the development lifecycle and supporting a shift-left security culture. Collaborate with the SOC to develop and strengthen cloud detection engineering capabilities. Assist the Risk and Governance teams with the development and implementation of cloud-related policies procedures and standards. Engage with Platform DevOps and Software Engineering teams to deliver security initiatives and provide security guidance to projects across the organization. Qualifications 6–10 years of experience in cloud environments with AWS as the primary platform including proven hands-on expertise in cloud security architecture and infrastructure design. Relevant cloud or security certifications are a plus (e.g. AWS Certified Solutions Architect AWS Certified Security – Specialty CISSP or CCSP). Proficiency with AWS-native security services including IAM Config KMS Secrets Manager CloudWatch CloudTrail and GuardDuty. Experience with cloud identity and access architecture including federation (e.g. Okta) RBAC ABAC and service-to-service authentication models. Hands-on experience with Infrastructure as Code tooling such as AWS CDK CloudFormation or Terraform. Scripting proficiency in at least one language (e.g. Python Bash) for automation and security tooling. Experience securing containerized workloads including Docker and Kubernetes with specific exposure to AWS EKS. Familiarity with how compliance frameworks such as NIST CSF CIS AWS Benchmarks ISO 27001 and SOC 2 apply to cloud security controls and infrastructure. Commitment to staying at the forefront of cloud security trends emerging threats and evolving technologies. Experience with version control CI/CD pipelines and issue tracking tools including GitLab GitLab CI and Jira. Strong verbal and written communication skills. Able to influence stakeholders and drive tasks to completion. Benefits The base salary range for this role is $170000 to $200000. iCapital offers a compensation package which includes salary equity for all full-time employees and an annual performance bonus. Employees also receive a comprehensive benefits package that includes an employer matched retirement plan generously subsidized healthcare with 100% employer paid dental vision telemedicine and virtual mental health counseling parental leave and unlimited paid time off (PTO). We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office Monday-Thursday with the flexibility to work remotely on Friday. For additional information on iCapital please visit https//www.icapitalnetwork.com/about-us Twitter @icapitalnetwork LinkedIn https//www.linkedin.com/company/icapital-network-inc Awards Disclaimer https//www.icapitalnetwork.com/about-us/recognition/ iCapital is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race religion color national origin gender sexual orientation gender identity age status as a protected veteran status as an individual with a disability or other applicable legally protected characteristics.

Cloud Security Engineer - Assistant Vice President

Lisbon, Portugal

About the Role iCapital is looking for a Assistant Vice President Cyber Cloud Security Engineer to join the Security Engineering team within the Information Security organization. This role will establish and manage cloud security programs build new security architecture drive automation and continuously identify and address security gaps across iCapital's technology landscape. The ideal candidate is a deeply technical individual contributor who can research design and implement security technologies and collaborate effectively across teams and functions. Responsibilities Build and manage Cloud Security Programs across AWS Azure and GCP infrastructure Design implement and validate secure cloud infrastructure architectures ensuring new capabilities meet established security standards and requirements. Apply Zero Trust architecture principles and best practices across cloud infrastructure design and access models. Drive continuous detection remediation and resolution of cloud vulnerabilities and security misconfigurations leveraging CSPM tooling (e.g. AWS Security Hub Wiz or equivalent) and automation to continuously improve and maintain cloud security posture. Build automation capabilities for continuous monitoring and alerting across cloud infrastructure. Partner with engineering teams to drive the adoption of security standards and best practices embedding security early across the development lifecycle and supporting a shift-left security culture. Collaborate with the SOC to develop and strengthen cloud detection engineering capabilities. Assist the Risk and Governance teams with the development and implementation of cloud-related policies procedures and standards. Engage with Platform DevOps and Software Engineering teams to deliver security initiatives and provide security guidance to projects across the organization. Qualifications 6–9 years of experience in cloud environments with AWS as the primary platform including proven hands-on expertise in cloud security architecture and infrastructure design. Relevant cloud or security certifications are a plus (e.g. AWS Certified Solutions Architect AWS Certified Security – Specialty CISSP or CCSP). Proficiency with AWS-native security services including IAM Config KMS Secrets Manager CloudWatch CloudTrail and GuardDuty. Experience with cloud identity and access architecture including federation (e.g. Okta) RBAC ABAC and service-to-service authentication models. Hands-on experience with Infrastructure as Code tooling such as AWS CDK CloudFormation or Terraform. We believe the best ideas and innovation happen when we are together. Employees in this role will work in the office four days with the flexibility to work remotely one day (Friday). Benefits iCapital offers a comprehensive benefits package that includes a total compensation program consisting of competitive salary annual performance bonus and equity for all full-time employees healthcare with 100% employer-paid health and dental insurance and generous paid time off (PTO). For additional information on iCapital Network please visit https//www.icapitalnetwork.com/about-us Twitter @icapitalnetwork LinkedIn https//www.linkedin.com/company/icapital-network-inc

(715) Cybersecurity Analyst (Part-Time)

Arlington, VA

Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality value-added solutions. Our solutions are designed and managed to not only reduce costs but to improve business processes accelerate response time improve services to end-users and give our customers a competitive edge now and into the future. Position Description Arlo Solutions is seeking an experienced Part-time Cybersecurity Analyst to support the Defense Support of Civil Authorities (DSCA) cybersecurity mission. The Cybersecurity Analyst serves as a trusted cybersecurity advisor responsible for supporting Risk Management Framework (RMF) activities cybersecurity engineering security assessments continuous monitoring vulnerability management compliance validation and enterprise cyber risk management across multiple Department of Defense information systems. The successful candidate will work closely with Government Authorizing Officials (AOs) Security Control Assessors (SCAs) Information System Security Managers (ISSMs) Information System Security Officers (ISSOs) Program Managers engineers and mission owners to ensure systems remain compliant with DoD cybersecurity policies while enabling mission execution. This position requires strong analytical skills technical cybersecurity knowledge excellent communication abilities and experience supporting DoD Assessment & Authorization (A&A) activities. Location Remote or (Hybrid - Arlington VA) Clearance Active Secret Clearance Responsibilities and/or Success Factors Cybersecurity Governance Support implementation of the DoD Risk Management Framework (RMF) lifecycle Assist Government ISSMs with maintaining cybersecurity authorization packages. Review and analyze cybersecurity documentation for completeness and compliance. Perform cybersecurity policy research and interpretation. Develop recommendations to reduce organizational cyber risk. Assist with cybersecurity governance boards and risk review meetings. Support cybersecurity strategy development. Assist leadership with enterprise cybersecurity initiatives. Risk Management Framework (RMF) Support all six RMF Steps Prepare Categorize Select Implement Assess Authorize Monitor Responsibilities include Security Plans (SSPs) Security Assessment Plans (SAPs) Security Assessment Reports (SARs) Risk Assessment Reports (RARs) POA&M development Security Categorization Control inheritance analysis Reciprocity reviews Continuous Authorization activities Authorization package quality reviews Cybersecurity Assessments Conduct or support Security Control Assessments (SCA) Cybersecurity Readiness Assessments Gap Assessments Compliance Reviews Risk Assessments Technical Control Validation Architecture Reviews Cloud Security Reviews Zero Trust Assessments Assist in validating implementation of NIST SP 800-53 Rev. 5 security controls. Continuous Monitoring Support Enterprise Continuous Monitoring (ConMon) activities including POA&M tracking Vulnerability trend analysis Configuration management reviews Security control effectiveness reviews Monthly cybersecurity status reporting Audit log reviews Incident trend analysis Compliance metrics Risk dashboards Vulnerability Management Review ACAS/Nessus scan results. Analyze STIG compliance. Validate vulnerability remediation. Track critical findings. Perform risk prioritization. Coordinate remediation activities. Develop mitigation recommendations. Support cybersecurity inspections. Documentation Develop and maintain SSPs SAPs SARs RARs POA&Ms Configuration Management Plans Continuous Monitoring Strategies Security Engineering documentation Architecture Diagrams Data Flow Diagrams Standard Operating Procedures Cybersecurity Briefings Executive Reports Minimum Qualifications Including Certificates Active DoD Secret Clearance. Bachelor's degree in Cybersecurity Computer Science Information Assurance Information Systems Engineering or related discipline. (5) Five or more years supporting DoD cybersecurity programs. Experience implementing DoD RMF. Experience with NIST SP 800-53 Rev. 5. Experience supporting ATO/IATT/ATO-C activities. Experience writing RMF artifacts. Experience conducting security control validation. Experience supporting vulnerability management. Experience with STIG implementation. Experience with ACAS/Nessus. Strong written and verbal communication skills. Ability to brief senior Government leadership. Desired Qualifications CISSP CASP+ Security+ CISM CCSP CGRC (formerly CAP) CEH GIAC certifications Cloud security certifications (AWS Azure Google Cloud) Experience with Xacta eMASS or other Governance Risk and Compliance (GRC) platforms. Experience with Agile Authorization and Continuous Authorization. Experience supporting Cloud Service Providers (CSPs). Knowledge of Zero Trust Architecture. Experience supporting DevSecOps pipelines. Experience with AI-enabled systems and emerging technologies. AAP Statement We are proud to be an Affirmative Action and Equal Opportunity Employer and as such we evaluate qualified candidates in full consideration without regard to race color religion sex sexual orientation gender identity marital status national origin age disability status protected veteran status and any other protected status.

(224) Security Control Accessor

Hybrid

Company Summary Arlo Solutions (Arlo) is an information technology consulting services company that specializes in delivering technology solutions. Our reputation reflects the high quality of the talented Arlo Solutions team and the consultants working in partnership with our customers. Our mission is to understand and meet the needs of both our customers and consultants by delivering quality value-added solutions. Our solutions are designed and managed to not only reduce costs but to improve business processes accelerate response time improve services to end-users and give our customers a competitive edge now and into the future. Position Overview The Department of Defense’s (DoD) Chief Digital and Artificial Intelligence Office (CDAO) is at the forefront of supporting the DoD with the adoption of innovative technologies such as data analytics and artificial intelligence to help accelerate predictions forecasts and interpretations for both strategic and tactical decisions across the enterprise. These ground-breaking endeavors bring new challenges to the assessment of DoD IT systems that previously did not exist. The Security Control Assessor (SCA) plays a pivotal role in comprehensively understanding the cybersecurity posture of a given capability within CDAO. SCAs must go beyond a mere compliance focus on controls to articulate the inherent risks of systems. Success in this position requires expertise in statutory guidance such as the NIST 800 series DoDI 8500.01 DoD 8140.03 ISO 27001 COBIT DoD RMF and Operation Vulcan Logic (OVL) along with current cybersecurity best practices The SCA provides authoritative risk determinations and recommendations critical for the Authorizing Official (AO) to grant an Authority to Operate (ATO). Their assessments integrate technical rigor with regulatory compliance ensuring a robust security posture and informing strategic decision-making. Work Location Full time remote. Candidates in the Washington DC Metropolitan preferred. Travel requirements will vary with location however expect approximately 10% to 25%. Job Responsibilities Provide the AO with an independent risk assessment of assigned systems and an authorization. Advise Program Managers on AO determination utilizing OVL documentation. Provide senior advisory support to CDAO AO regarding authorizations of CDAO capabilities. Utilize expert knowledge and experience regarding risk management strategies in support of a major DoD program. Providing support regarding the agile authorization and OVL processes. Provide independent risk analysis and recommendation. Collaborate between the AO and the program as well as Program leadership. Identify the security baseline based on the mission and security impacts to the system. Determine assessment criteria develop review and create a plan to assess the security requirements. Assess the security requirements in accordance with the assessment procedures defined in the Security Assessment Plan (SAP). Prepare the Security Assessment Report (SAR). Monitor POAM actions based on findings and reassess remediated risk(s) as appropriate. Develop the Risk Recommendation and AO Determination Brief. Develop a system-level continuous monitoring strategy. Author and present briefs regarding status of authorizations to AO and other senior Government officials. Provides security architecture and DoD compliance advisory support. Success Factors Have a strong background in risk management and governance risk and compliance (GRC). Strong clients focus and commitment to continuous improvement ability to proactively network and establish relationships. Manage multiple priorities in a high-paced and fast-changing environment. Perform other duties as assigned or required. Education and Minimum Qualifications Must have at least a Public Trust – Secret level clearance preferred. Bachelor’s degree in computer science/information technology or other related degree fields (master’s degree is preferred or at least 5 years of related experience) At least 5+ years of cybersecurity experience including a senior technical or management role Project or Program Management experience a plus. At least one IAT/IAM or equivalent security certifications ex. Sec+ CISSP CCSP CISM CISA or CASP Experience working with OSD leadership or Military component or branch. Understanding of NIST 800 series guidelines DoDI 8500.01 DoD 8140.03 rISO 27001 COBIT DoD RMF OVL and current cybersecurity best practices. Excellent communication/presentation skills briefing senior military and government civilian leadership. Experienced with writing standard operating procedures. Experience in hands on with eMASS Xacta and/or other GRC tools. Experience with Federal and FedRamp A&A Processes. AAP Statement We are proud to be an Affirmative Action and Equal Opportunity Employer and as such we evaluate qualified candidates in full consideration without regard to race color religion sex sexual orientation gender identity marital status national origin age disability status protected veteran status and any other protected status.

Senior Solutions Architect, Identity Security

Remote United States

Description Keeper Security is hiring a Senior Solution Architect Identity Security to join our Sales Engineering organization. This is a 100% remote position with an opportunity to work a hybrid schedule for candidates based in the Chicago IL or El Dorado Hills CA metro areas. Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations globally. Keeper is published in 23 languages and sold in over 150 countries. Join one of the fastest-growing cybersecurity companies and help shape the technical strategy behind Keeper’s most important enterprise opportunities. About Keeper Keeper Security is one of the fastest-growing cybersecurity software companies that protects thousands of organizations and millions of people in over 150 countries. Keeper is a pioneer of zero-knowledge and zero-trust security built for any IT environment. Its core offering KeeperPAM® is an AI-enabled cloud-native platform that protects all users devices and infrastructure from cyber attacks. Recognized for its innovation in the Gartner Magic Quadrant for Privileged Access Management (PAM) Keeper secures passwords and passkeys infrastructure secrets remote connections and endpoints with role-based enforcement policies least privilege and just-in-time access. Learn why Keeper is trusted by leading organizations to defend against modern adversaries at KeeperSecurity.com About the Role This is a senior customer-facing solution architecture role focused on strategic enterprise opportunities in identity security and privileged access management. The ideal candidate has deep experience leading complex technical engagements shaping solution direction and serving as a trusted advisor across executive and technical audiences. This role partners closely with Sales Engineering Sales Leadership Product and other cross-functional teams to establish technical vision drive architectural alignment and support success across a portfolio of strategic accounts. The Solution Architect engages early in enterprise sales cycles leads complex discovery and solution design guides proof-of-concept strategy and execution and helps elevate the quality of technical engagements across the field organization. Responsibilities Engage early in strategic enterprise opportunities to establish technical direction align on customer outcomes and position Keeper’s identity security platform effectively Lead discovery sessions that uncover privileged access challenges architectural constraints business drivers and technical requirements across complex customer environments Design and articulate reference architectures that map Keeper’s platform capabilities to hybrid cloud on-premises and SaaS environments Support and guide proof-of-concept and proof-of-value engagements for high-priority enterprise opportunities Deliver executive presentations technical briefings and architecture discussions tailored to CISOs CIOs security architects infrastructure teams and other stakeholders Partner with field Sales Engineers to strengthen technical strategy improve execution and elevate engagement quality across a portfolio of enterprise accounts Collaborate with Product Management to share market intelligence competitive insight and customer requirements that inform product direction Partner with Sales leadership to prioritize strategic opportunities and align solution architecture resources to the highest-impact engagements Represent Keeper at executive briefings marquee customer engagements webinars conferences and other market-facing events Maintain strong awareness of the privileged access management and broader identity security landscape including legacy platforms emerging competitors and adjacent identity technologies Travel required based on customer and business needs Requirements 10+ years of experience in enterprise technology including at least 5 years in a senior customer-facing pre-sales solutions architecture or technical advisory role Deep domain expertise in identity security identity and access management or privileged access management Strong working knowledge of enterprise PAM concepts including least privilege zero standing privilege secrets management session management and privileged account governance Demonstrated experience leading complex technical engagements with enterprise customers including discovery architecture design executive presentations and competitive positioning Proven ability to operate across a broad portfolio of strategic accounts while applying strong judgment about where direct engagement is most valuable Excellent communication and presentation skills with the ability to translate complex security architecture into both business and technical value Familiarity with the broader enterprise identity ecosystem including Active Directory Microsoft Entra ID Okta cloud IAM SIEM integrations IGA platforms and DevOps or CI/CD environments Ability to work cross-functionally with Sales Engineering Product Sales Leadership and other internal stakeholders in a fast-paced enterprise environment Preferred Qualifications Prior experience at a leading identity security PAM or IAM vendor in a pre-sales or solutions architecture role Experience supporting enterprise customers in regulated industries such as federal financial services energy or healthcare Familiarity with compliance and regulatory frameworks such as FedRAMP NIST SOC 2 PCI-DSS or NERC CIP Experience presenting to executive and security leadership at Fortune 500 or Global 2000 organizations Background in competitive displacement strategies within the identity security or privileged access market Relevant certifications such as CISSP CCSP AWS Certified Solutions Architect or Azure Solutions Architect Expert Benefits Medical Dental & Vision (inclusive of domestic partnerships) Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life Voluntary Short/Long Term Disability Insurance 401K (Roth/Traditional) A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty etc) Above market annual bonuses Keeper Security Inc. is an equal opportunity employer and participant in the U.S. Federal E-Verify program. We celebrate diversity and are committed to creating an inclusive environment for all employees. Classification Exempt Keeper Candidate Privacy Notice This notice explains how Keeper Security processes your personal data during recruitment. Depending on the role and location the Controller of personal data (the organization responsible for determining why and how personal data is processed) will be Keeper Security Inc. (US) Keeper Security EMEA Ltd. (Ireland) or Keeper Security APAC K.K (Japan). Data We Collect Information You provide Contact details CV/resume cover letter Employment history qualifications work eligibility Application responses and uploaded documents Information We generate Interview notes assessments communications Scheduling information Information From Others Recruiter/referral information who submit your profile References (with your consent before final offer) Public professional profiles Background verification (post offer) Voluntary Diversity and Equal Opportunity Information We may ask you to voluntarily provide diversity information including race/ethnicity gender disability status and veteran status (US). Providing this information is optional and Keeper collects this data in order to comply with EEOC and similar requirements How We Use Your Data Assess your application and suitability Manage interviews and recruitment workflow Consider you for other/future roles (we may seek your consent to keep your information on our systems beyond the retention period specified) Comply with employment law obligations Legal Basis Legitimate Interests (recruitment management security and integrity of the hiring process) Contracting steps (for progressed candidates) Legal and regulatory compliance obligations explicit consent where required Who We Share Information With Internal HR hiring managers interviewers IT support for system administration Note - diversity and equal opportunity data is not shared with hiring managers. Third Parties Service providers who assist with Applicant tracking recruitment systems and assessment providers Background verification vendors (post offer) Recruitment agencies (where applicable) Tools to support communication collaboration and to securely store your data Keeper ensures that all our third parties are contractually bound to protect your personal data with adequate safeguards in place. International Transfers Your data may be accessed by Keeper entities globally as needed for the purposes of hiring and decision making. We protect any such data transfer between Keeper entities using appropriate safeguards under applicable data protection laws. Security We implement appropriate technical and organizational measures to protect your data consistent with our industry leading security standards. Retention We keep your data for 24 months from your last application activity then delete or anonymize it. Exceptions You opt into our talent database for further retention by providing consent (extended retention) You're hired (transfers to employee records) Your Rights You have the following rights and can contact us at the email below to exercise them Access correct or delete your data subject to applicable law and retention requirements Object to or restrict processing Withdraw consent (where applicable) Request data portability Lodge a complaint with your data protection authority If you become an employee your rights regarding your employee record are governed by our internal Employee Privacy Notice and certain data will be retained as required under relevant laws such as employment or tax law. When you request access to your personal data some information may be redacted if it includes the personal data of other individuals or information that we must protect in order to preserve their privacy rights. Automated Decisions Keeper does not make hiring decisions using solely automated processing. 10. Contact - Candidates can send privacy questions to privacy@keepersecurity.com

Senior Information Systems Security Officer (ISSO)

Remote United States

Keeper Security is hiring an Information Systems Security Officer to join our Governance Risk and Compliance team. This is a 100% remote position from select locations with an opportunity to work a hybrid schedule for candidates based in the Chicago IL metro area. Keeper’s cybersecurity software is trusted by millions of people and thousands of organizations globally. Keeper is published in 23 languages and is sold in over 150 countries. Join one of the fastest-growing cybersecurity companies and help maintain the security compliance and authorization readiness of systems supporting highly regulated government environments. About Keeper Keeper Security is a leading cybersecurity software company that protects thousands of organizations and millions of people in more than 150 countries. Keeper delivers a powerful zero-trust and zero-knowledge solution built to meet the stringent requirements of federal IT environments. Its flagship offering KeeperPAM® is an AI-enabled cloud-native platform that protects users devices and critical infrastructure from cyber attacks. Recognized in the Gartner® Magic QuadrantTM for Privileged Access Management (PAM) Keeper combines robust compliance with unmatched visibility and control. With industry-leading certifications including FedRAMP High and GovRAMP High Authorization Keeper provides the security assurance public sector organizations require. Learn why federal agencies including NASA and the DOJ trust Keeper to defend against today’s sophisticated adversaries at KeeperSecurity.com About the Role Reporting to the Senior Director of Governance Risk and Compliance the Information Systems Security Officer will oversee the security posture and compliance readiness of assigned information systems. This role will work closely with Engineering DevOps IT Security and Compliance teams to ensure security controls are implemented documented monitored and maintained in alignment with federal and industry requirements. The ideal candidate has hands-on experience supporting system authorization activities maintaining security documentation and coordinating remediation across technical teams. This role will serve as a primary security and compliance point of contact for assigned systems and help ensure continuous readiness for audits assessments and authorization reviews. Responsibilities Serve as the Information Systems Security Officer for assigned systems and environments Maintain a comprehensive understanding of system architecture data flows boundaries dependencies and security controls Develop review and maintain system security documentation including System Security Plans control implementation statements policies procedures and supporting evidence Support initial and ongoing authorization activities including FedRAMP High GovRAMP High DoD Impact Level 5 and related government security requirements Coordinate security control implementation and validation with Engineering DevOps IT Security and other system owners Manage Plans of Action and Milestones including documenting findings assigning ownership tracking remediation and validating closure evidence Support continuous monitoring activities including vulnerability findings configuration compliance control evidence system changes and risk exceptions Review proposed system infrastructure and application changes to identify security and compliance impacts Coordinate responses to third-party assessors auditors government stakeholders and internal compliance reviews Evaluate security findings and help determine risk impact corrective actions and required escalation Support incident response contingency planning disaster recovery and tabletop exercises for assigned systems Maintain accurate audit evidence and ensure documentation remains current complete and assessment-ready Track security metrics risks findings and remediation progress and communicate status to GRC and technical leadership Help ensure systems comply with data classification access control logging encryption configuration and vulnerability management requirements Use AI-enabled tools such as Claude ChatGPT or similar platforms where appropriate and permitted to support control analysis documentation evidence review research and workflow efficiency Requirements 5+ years of experience in information security information assurance cybersecurity compliance system security or a related role Experience serving as an ISSO system security analyst compliance engineer or similar role for regulated information systems Strong knowledge of NIST SP 800-53 security controls and the Risk Management Framework Experience supporting FedRAMP GovRAMP DoD Impact Level requirements or similar government authorization programs Hands-on experience developing and maintaining System Security Plans control narratives Plans of Action and Milestones and assessment evidence Experience supporting Authorization to Operate activities continuous monitoring and recurring security assessments Ability to understand cloud and application architectures and translate technical implementations into clear security control documentation Strong understanding of vulnerability management configuration management access control logging encryption incident response and system change management Experience working with technical teams to implement and validate security requirements Working knowledge of AWS cloud environments and cloud security concepts Strong project management documentation and organizational skills Excellent written and verbal communication skills with the ability to communicate effectively with engineers auditors executives and government stakeholders Ability and willingness to use AI-enabled tools effectively and responsibly to support research control analysis documentation and operational efficiency Due to this role’s involvement in GovCloud and FedRAMP environments qualified candidates must be a U.S. Citizen Ability to pass an enhanced security background check including a financial vulnerability assessment Preferred Qualifications Experience supporting FedRAMP High GovRAMP High or DoD Impact Level 5 environments Experience with cloud-native SaaS products and AWS-based system architectures Familiarity with automated compliance evidence collection and continuous monitoring tools Experience with NIST SP 800-37 NIST SP 800-53A FIPS 199 FIPS 200 and related federal security guidance Experience supporting SOC 2 ISO 27001 or other commercial compliance frameworks Experience participating in third-party assessments or working directly with 3PAOs Relevant certifications such as CISSP CISM CAP/CGRC Security+ or CCSP Experience working in cybersecurity identity security privileged access management or another security-sensitive software environment Benefits Medical Dental & Vision (inclusive of domestic partnerships) Employer Paid Life Insurance & Employee/Spouse/Child Supplemental life Voluntary Short/Long Term Disability Insurance 401K (Roth/Traditional) A generous PTO plan that celebrates your commitment and seniority (including paid Bereavement/Jury Duty etc) Above market annual bonuses Keeper Security Inc. is an equal opportunity employer and participant in the U.S. Federal E-Verify program. We celebrate diversity and are committed to creating an inclusive environment for all employees. Classification Exempt Keeper Candidate Privacy Notice This notice explains how Keeper Security processes your personal data during recruitment. Depending on the role and location the Controller of personal data (the organization responsible for determining why and how personal data is processed) will be Keeper Security Inc. (US) Keeper Security EMEA Ltd. (Ireland) or Keeper Security APAC K.K (Japan). Data We Collect Information You provide Contact details CV/resume cover letter Employment history qualifications work eligibility Application responses and uploaded documents Information We generate Interview notes assessments communications Scheduling information Information From Others Recruiter/referral information who submit your profile References (with your consent before final offer) Public professional profiles Background verification (post offer) Voluntary Diversity and Equal Opportunity Information We may ask you to voluntarily provide diversity information including race/ethnicity gender disability status and veteran status (US). Providing this information is optional and Keeper collects this data in order to comply with EEOC and similar requirements How We Use Your Data Assess your application and suitability Manage interviews and recruitment workflow Consider you for other/future roles (we may seek your consent to keep your information on our systems beyond the retention period specified) Comply with employment law obligations Legal Basis Legitimate Interests (recruitment management security and integrity of the hiring process) Contracting steps (for progressed candidates) Legal and regulatory compliance obligations explicit consent where required Who We Share Information With Internal HR hiring managers interviewers IT support for system administration Note - diversity and equal opportunity data is not shared with hiring managers. Third Parties Service providers who assist with Applicant tracking recruitment systems and assessment providers Background verification vendors (post offer) Recruitment agencies (where applicable) Tools to support communication collaboration and to securely store your data Keeper ensures that all our third parties are contractually bound to protect your personal data with adequate safeguards in place. International Transfers Your data may be accessed by Keeper entities globally as needed for the purposes of hiring and decision making. We protect any such data transfer between Keeper entities using appropriate safeguards under applicable data protection laws. Security We implement appropriate technical and organizational measures to protect your data consistent with our industry leading security standards. Retention We keep your data for 24 months from your last application activity then delete or anonymize it. Exceptions You opt into our talent database for further retention by providing consent (extended retention) You're hired (transfers to employee records) Your Rights You have the following rights and can contact us at the email below to exercise them Access correct or delete your data subject to applicable law and retention requirements Object to or restrict processing Withdraw consent (where applicable) Request data portability Lodge a complaint with your data protection authority If you become an employee your rights regarding your employee record are governed by our internal Employee Privacy Notice and certain data will be retained as required under relevant laws such as employment or tax law. When you request access to your personal data some information may be redacted if it includes the personal data of other individuals or information that we must protect in order to preserve their privacy rights. Automated Decisions Keeper does not make hiring decisions using solely automated processing. 10. Contact - Candidates can send privacy questions to privacy@keepersecurity.com

Security Engineer — Application Security & Identity

Boston Massachusetts Carmel Indiana Chicago Illinois Lambertville New Jersey Remote United States

At Real Chemistry making the world a healthier place isn’t just an aspiration—it’s our everyday reality. Our drive to transform healthcare is informed by our blend of deep scientific expertise human-centred creativity and AI-driven insights fostering a unique environment where innovation thrives and our people are impact-obsessed. As a global agency we provide a full suite of services across healthcare communications and marketing to our clients including top players in the pharmaceutical and biotech industries. Our LifeatRealChem culture is rooted in our people—we believe we are best together and are committed to excellence for both our clients and colleagues. Whether you're a seasoned professional or just starting your career if you share our passion for healthcare and connection we invite you to explore our opportunities. Discover your purpose. Embrace innovation. Experience LifeatRealChem. Security Engineer — Application Security & Identity Function Information Security Reports to Head of Security Role Summary Owns application security across multiple environments each with increasing control and compliance requirements. Acts as reviewer for the least complex environments and co-reviewer for higher complexity and controlled environments. Defines and enforces security controls across AWS hosted workloads and GitHub based development pipelines while maintaining independent review authority. Applications originate as AI-assisted prototypes and require structured security validation before enterprise production deployment. This is a hybrid role based in any of our US offices—including New York City Boston Chicago Carmel or San Francisco—or remotely within the US depending on team and business needs. Key Responsibilities Conduct security reviews of Internally developed applications including Data flow validation Security control design and implementation Secrets handling AI/LLM Data Loss Prevention (DLP) Co-lead production readiness reviews for strictly governed environments Threat modeling Hardening validation Compliance mapping (SOC 2and contractual and regulatory requirements) Define and enforce identity architecture Corporate identity Entra ID Workload identity AWS IAM and GitHub OIDC Define and manage GitHub native security controls GitHub Advanced Security (CodeQL / SAST) Dependabot (dependency scanning) Secret scanning Branch protection and environment controls Establish standards for security tooling SAST (CodeQL Semgrep) SCA (Dependabot Snyk) Container scanning (Trivy ECR scanning) Infrastructure as Code (IaC) policy (OPA Sentinel tfsec) Define AWS security standards IAM design and least-privilege access Logging and audit requirements Secrets management and rotation Scope and coordinate third-party penetration testing Maintain audit logging maturity per environment requirements Baseline logging User-level activity tracking Tamper-evident audit trails with SIEM integration Perform initial triage and risk classification within time requirements for critical issues identified in intake (data exposure credentials regulatory risk). Partner with DevOps Engineering to ensure security policies are implemented in pipelines and infrastructure AI Security & Usage Governance Define approved AI providers and usage boundaries Establish prompt data classification and handling policies Enforce human-in-the-loop requirements where appropriate Define cost/spend guardrails for AI services Required Qualifications 5+ years (or 3–5+ in high-growth environments) in cloud security 2 of which should be be focused application security Hands-on security experience with AWS IAM SAML / OIDC federation GitHub security tooling Experience with threat modeling and coordinating penetration testing Familiarity with SOC 2 GDPR and HIPAA-adjacent controls In-depth understanding of the risk lifecycle Preferred Qualifications Experience securing GitHub-based CI/CD pipelines Experience in AWS native environments Exposure to regulated industries (GxP 21 CFR Part 11) Security certifications (CISSP CCSP OSCP GIAC etc.) Associates degree or higher Experience bringing low-code or AI-generated applications under enterprise security controls Pay Range $100000-120000 This is the pay range the Company believes it will pay for this position at the time of this posting. Consistent with applicable law compensation will be determined based on job-related non-discriminatory factors including but not limited to work experience skills certifications and geographical location. The Company reserves the right to modify this pay range at any time Real Chemistry is proud to be Great Place to Work® certified check out what our people shared about our culture and workplace on our Great Places to Work Profile here We believe we can do our best when feeling our best which is why we’ve put together a benefits program designed to give you the support you and your family need at every stage of life. Real Chemistry offers a comprehensive benefit program and perks tailored to your region. Globally this includes offices in our key markets with free snacks to keep you running all day long generous holiday and paid time off options for private medical dental and vison plans and support in saving for the future. Other perks include mental wellness coaching and support and access to more than 13000 online classes with LinkedIn Learning. Learn more about our great benefits and perks and search specific offerings in your region at www.realchemistrybenefits.com At Real Chemistry we believe we're at our best when we're connected. Our Real Hybrid and Regional Teams (Real HART) approach is designed to foster collaboration learning innovation and meaningful relationships while providing flexibility where appropriate. Because our workforce spans multiple countries regions and client needs work arrangements may vary by role and location. Some positions offer hybrid or remote flexibility while others require regular in-office presence. For example certain teams and regions including some of our UK operations have office-based requirements. Your recruiter will discuss the specific expectations for the role you're pursuing during the interview process and keep you informed throughout the hiring journey. For employees located within a one-hour commute of a Real Chemistry office we require in-person attendance two days per week either from a Real Chemistry office or when working onsite with clients. Employees in regions without a nearby office may work remotely and come together throughout the year for collaboration culture-building learning and team connection opportunities. While these guidelines reflect our current workplace model we understand that everyone’s circumstances are unique. If you require additional flexibility we welcome an open conversation with your recruiter and our HR team to discuss your needs and determine what may be possible. Real Chemistry is an Equal Opportunity employer. We continually strive to build and sustain an inclusive and equitable work environment where our employees feel empowered to leverage all they bring from their personal lived experience and professional expertise to make our team the best in the industry. We encourage motivated and qualified applicants to apply without regard to race color religion sex (including pregnancy) sexual orientation gender identity/expression ethnic or national origin age physical or mental disability genetic information marital information or any other characteristic protected by federal state or local employment discrimination laws where Real Chemistry operates. Should you require accommodations throughout the interview process please let your recruiter know. Notice Real Chemistry and its affiliates' names are being misused by scammers through messaging services fake websites and apps. Do not share personal or financial information or make payments to any unverified sources claiming to be connected to Real Chemistry. We are working to stop these unauthorized activities and protect our community. Read more here

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time


For the 10 positions listed above we've analyzed the salary ranges, where available, and the resulting overall salary range is: 168.2K - 252.2K USD.

For 18 similar CCSP position(s) we've listed yesterday we've checked the salary ranges, as posted, and the resulting overall range is: 69K - 230K USD.

For 662 similar CCSP position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 60K - 350K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.