What Jobs are available for Threat Modeling in the United States?

Showing 195 Threat Modeling jobs in the United States

Information Security Manager

Maryland, Maryland ValidaTek, Inc.

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

Company Overview At ValidaTek, we modernize and optimize IT services to solve some of the most critical challenges facing federal civilian and defense agencies. From customers to partners to top-talent employees, ValidaTek puts people first, empowering them to exceed expectations and transform government organizations. Our success starts and ends with our people, so we built a company where great people can do great things, with the resources and autonomy to make decisions that transform organizations. We operate as one team of diverse people, united by a passion for continuous growth and optimization. Our commitment to quality and performance optimization is the reason why our IT Service Projects and New Development Projects have been appraised at CMMI Maturity Level 5, positioning us as one of a handful of elite companies to receive the highest form of third-party validation.

We are seeking an experienced Information Security Manager to support a Defense Information Systems Agency (DISA) Cyber Program. The ideal candidate will oversee security operations, compliance, risk management, and cyber defense initiatives to protect DoD networks and information systems. This role requires strong leadership, technical expertise, and a understanding of DISA policies and cybersecurity frameworks. Primary place of performance will be Pensacola, FL where an on-site presence is required.

Responsibilities
  • Lead and manage cybersecurity efforts for the DISA Cyber Program, ensuring compliance with DoD and DISA security requirements.
  • Develop, implement, maintain, and ensure compliance with information security policies, standards, and procedures in accordance with NIST, RMF, and other relevant frameworks.
  • Oversee risk management and vulnerability assessment processes to identify, assess, and mitigate security threats.
  • Conduct security audits, assessments, and incident response activities to protect sensitive information.
  • Coordinate with internal and external stakeholders, including government officials, contractors, and cybersecurity teams, to enhance security posture
  • Serve as the primary liaison between the organization and external security assessors or auditors.
  • Oversee system risk management, vulnerability assessments, and mitigation strategies.
  • Monitor emerging cyber threats and recommend proactive defense strategies.
  • Provide leadership and mentorship to security personnel, fostering a culture of continuous improvement and security awareness.
  • Monitor emerging cyber threats and recommend proactive defense strategies.
  • Manage security tools, technologies, and processes, ensuring alignment with mission requirements.
  • Develop and deliver reports, briefings, and security recommendations to senior leadership.
Qualifications
  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field
  • Minimum of 8+ years of experience in information security, with at least 3 years in a managerial role.
  • Active DoD Secret clearance – required.
  • ITIL certification – preferred.
  • Strong knowledge of DoD cybersecurity policies, including DISA STIGs, RMF, NIST 800-53, and Zero Trust Architecture.
  • Experience with security tools such as SIEMs, IDS/IPS, vulnerability scanners, and endpoint protection solutions.
  • Experience with categorization and assignment of security controls and creation and maintenance of A&A packages in DISA’s Enterprise Mission Assurance Support Service (eMass) system.
  • Proven ability to manage cyber incidents, security assessments, and compliance efforts.
  • Exceptional communication skills and the ability to engage with technical and non-technical stakeholders.
  • Active CISSP, CISM, or equivalent DoD 8570 IAM Level III certification.

Preferred Qualifications:

  • Experience working with DISA, DoD Cyber Operations, or similar environments.
  • Familiarity with cloud security (AWS, Azure, DoD Cloud environments).
  • Hands-on experience with automation and orchestration tools for security operations.
  • Knowledge of Zero Trust and AI-driven cybersecurity solutions.
Posted Min Pay Rate USD $130,000.00/Yr.Posted Max Pay Rate USD $160,000.00/Yr.Salary Disclosure Actual salary will be based on a variety of factors including but not limited to experience, geographic location, contract affordability, internal equity, education, and certifications. The upper end of the salary range may be reserved for individuals who have demonstrated tenure with the company, seniority, and proven excellent performance. This includes factors such as education, certifications, and extensive/unique experience beyond what is required.EEO Statement ValidaTek is an Equal Opportunity Employer. All qualified applicants will be considered without regard to disability, protected veteran status, or any other status protected by federal, state, or local laws. Applicants who are selected for employment will be required to verify authorization to work in the United States. Offers of employment will be contingent upon passing a post-offer background check. #J-18808-Ljbffr
View Now

Information Security Engineer

75215 Texas, Texas ISNetworld

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

Overview

The Position: The Information Security Engineer position will be responsible for providing technical and business assistance for a wide variety of information security related matters. It requires monitoring of computer networks for security issues, install security software and document all security issues or breaches found.

Who should apply?
  • Bachelor’s Degree in Cyber Security, or equivalent/related field or equivalent years of experience
  • 8+ years in an information security technical role
  • Experience in securing cloud environments, specifically Azure, and auditing its services and resources against best practices and identify misconfigurations
  • Hands-on experience with mitigating security controls (next gen anti-virus, EDR, IPS/IDS, DLP, web and network proxies, URL content filtering, log collection (SIEM), vulnerability management, multi-factor authentication, identity management and conditional access polices, VPN's) and how they work in an overall defense in depth risk assessment methodology
  • Previous experience within an internal Information Security team
Primary Duties & Responsibilities
  • Provide timely detection, identification, and alerting of possible attacks/intrusions, anomalous activities, and misuse activities and distinguish these incidents and events from benign activities
  • Architect, implement, and reevaluate any security service or product in our security stack with little technical guidance
  • Conduct and manage security threat and impact assessments and provide input on our overall information security strategy
  • Pick up service tickets within established SLAs including those that have been escalated to Tier Two/Three as needed
  • After hours or weekend work: for scheduled maintenance, incident response including evenings and weekends as required
  • On Call Support: Participate in a rotating on-call schedule for outages or incident response
  • Required to come to the office at least 2 times per week during the first 90 days
  • After 90 days, you will have the option to work remotely with at least 1 in-person engagement required monthly
  • 100% company-paid monthly insurance premiums for employees and dependents
  • Medical, Dental, Vision, and Life Insurance
  • Employee assistance program
  • 4% retirement matching
  • Long-Term & Short-Term Disability Coverage
  • Paid time off
  • 0-1 year – 15 day (pro-rated first year)
  • 1-5 years – 20 days
  • 5-10 years – 25 days
  • 10+ years – 30 days
  • Holidays – 13 paid holidays
  • Monthly cell phone reimbursement
  • Complimentary parking space or monthly reimbursement for DART public transportation
  • Team-building activities and events, including quarterly kick-off meetings and community volunteer day
  • Matching charitable gift program
  • Professional development & training opportunities
  • Wellness Program: Focuses on community, financial, mental, nutrition, physical and social health
  • Business casual, jeans allowed

*All benefits are subject to change with notice to the employee

All job offers will be contingent on successful completion of a drug screen and background check.

ISN is an equal opportunity employer. All applicants will be considered for employment without attention to race, color, religion, sex, sexual orientation, gender identity, national origin, veteran or disability status.

Apply Now

First Name

Last Name

Preferred First Name

Email

Phone

Resume/CV 25 MB limit. Allowed types: pdf doc docx txt rtf.

Enter text manually

25 MB limit. Allowed types: pdf doc docx txt rtf.

Enter text manually

Education

School - Select -

Degree - Select -

- Select -

School - Select - * Degree - Select - Discipline - Select - Start Date * Month Month * Year Year End Date * Month Month * Year Year

Are you legally authorized to work in the United States? - Select -

Are you currently residing in Dallas or willing to relocate upon offer?

The position requires you to reside within a commutable distance to ISN Dallas office.

- Select -

Home Address (City, State):

Do you now, or will you in the future, require sponsorship for employment visa status (e.g., H-1B visa status, etc.) to work legally in the United States?

This includes any required sponsorship after your current immigration status expires (e.g. CPT, OPT, etc.)

- Select -

What are your minimum salary requirements?

What is your required notice period?

Do you have a relative or family member that currently works, is planning to work or has worked at ISN? If yes, please provide their name and describe your relationship.

Read more on how ISN approaches working with relatives

* CCPA Notice at Collection for California Job Applicants

ISN is committed to protecting the privacy and security of personal information collected from job applicants. Please read the CCPA Notice and acknowledge/confirm.

- Select -

All information provided with this application is true, accurate and complete. I accept that any false, misleading, inaccurate or incomplete information I provided may lead to my application being rejected, or an offer of employment being withdrawn, or dismissal from my employment. - Select -

If you provided a phone number, do you consent to receiving follow-up communication via text message (or SMS message) regarding your application status?

If yes, you can always opt-out by replying STOP.

Voluntary Self-Identification

For government reporting purposes, we ask candidates to respond to the below self-identification survey. Completion of the form is entirely voluntary. Whatever your decision, it will not be considered in the hiring process or thereafter. Any information that you do provide will be recorded and maintained in a confidential file.

As set forth in ISN’s Equal Employment Opportunity policy, we do not discriminate on the basis of any protected group status under any applicable law.

Race - Select -

- Select -

If you believe you belong to any of the categories of protected veterans listed below, please indicate by making the appropriate selection. As a government contractor subject to the Vietnam Era Veterans' Readjustment Assistance Act (VEVRAA), we request this information in order to measure the effectiveness of the outreach and positive recruitment efforts we undertake pursuant to VEVRAA. Read More

- Select -

Voluntary Self Identification of Disability

Form CC-305
Page 1 of 1
OMB Control Number
Expires 04/30/2026

Why are you being asked to complete this form?

We are a federal contractor or subcontractor. The law requires us to provide equal employment opportunity to qualified people with disabilities. Read More

Disability Status - Select -

PUBLIC BURDEN STATEMENT: According to the Paperwork Reduction Act of 1995 no persons are required to respond to a collection of information unless such collection displays a valid OMB control number. This survey should take about 5 minutes to complete.

#J-18808-Ljbffr
View Now

Information Security Engineer

Washington, District Of Columbia $122000 - $160000 year Consilio, LLC - Talent Solutions

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

One of our law firm clients is seeking an Information Security Engineer in the Washington, DC or New York area, may work 100% virtual/remote in a firm-approved U.S. state as part of the “Gideon” office. The Information Security Engineer is a technical security expert responsible for supporting security operations, engineering, and architecture functions and efforts. Under the direction of the Manager of Information Security, the Information Security Engineer helps to ensure the overall security posture of the organization and is expected to be involved in day-to-day security operations and contribute to ensuring the integrity and availability of IT and application infrastructure and the confidentiality, integrity, and availability of data in support of enterprise IT objectives and client service delivery needs.

Responsibilities include but are not limited to:

Security Operations

  • Performing security log and event analysis, taking appropriate action to address security risks or incidents using EDR, SIEM, and log aggregation systems.
  • Monitoring and executing the vulnerability management program to reduce IT hygiene risks.
  • Maintaining and managing assigned security toolsets, including:
    • Application control systems
    • EDR/AV
    • Email security platform
    • Attack simulation platform
    • Threat intelligence/hunting
    • Security-related AI tools
  • Supporting incident response and investigation efforts.
  • Validating and tracking IT operational activities for compliance with policies and standards.
  • Researching security vulnerabilities and cybersecurity trends.
  • Reporting and tracking security events and remediation activities.
  • Supporting third-party risk management and IT compliance efforts.
  • Assisting with security awareness training.
  • Participating in IT Security on-call rotation.

Security Engineering & Architecture

  • Advising on planning of security systems and standards, evaluating technologies, and developing security requirements.
  • Reviewing applications and SaaS changes for security impacts.
  • Participating in the enterprise Change Advisory Board (CAB).
  • Researching and recommending methods, software, and technologies to mitigate risks.
  • Contributing to security policies, standards, and procedures.

Qualifications:

Education/Experience

  • Four-year college degree preferred; equivalent experience considered.
  • Minimum of three (3) years in Information Security or related IT fields with security responsibilities.

Technical Skills

  • Experience with Windows, Unix/Linux, and Active Directory.
  • Solid understanding of networking protocols: TCP/IP, UDP, DNS, DHCP, HTTP/HTTPS, routing.
  • Knowledge in security engineering, system/network security, authentication, cryptography, application and cloud security.
  • Proficiency in Windows OS, Microsoft Office Suite.
  • Skilled in using AI tools for daily tasks.
  • Strong remote collaboration capabilities.

Communication & Writing

  • Ability to explain complex technical concepts to non-technical audiences.
  • Excellent oral and written communication skills.
  • Effective presenter to diverse audiences.
  • Skilled in choosing appropriate communication methods.

Professionalism & Judgment

  • Strong initiative, judgment, and professionalism.
  • High confidentiality and discretion.
  • Exceptional client service orientation.

Problem-Solving & Strategic Focus

  • Strong problem-solving and strategic thinking.
  • Goal-oriented with strong task prioritization.
  • Detail-oriented with excellent organizational skills.
  • Capable of multitasking in fast-paced environments.

Flexibility & Commitment

  • Reliable, dependable, and motivated.
  • Willing to work additional hours as needed.
  • Willingness to travel (1–4 weeks per year, or more if required).

Company Description

We work with top law firms, associations and corporations to connect professionals to jobs they can't find anywhere else. The recruiters at Consiliio, LLC are vested in taking the time to get to know each candidate and finding the right match for each individual. Our extensive industry knowledge is a resource that we share with every candidate to help prepare for each step of the interview process and negotiate the best possible salary. In working with us, you are able to have direct access to hundreds of hiring decision makers in the country.

Company Description

We work with top law firms, associations and corporations to connect professionals to jobs they can't find anywhere else. The recruiters at Consiliio, LLC are vested in taking the time to get to know each candidate and finding the right match for each individual. Our extensive industry knowledge is a resource that we share with every candidate to help prepare for each step of the interview process and negotiate the best possible salary. In working with us, you are able to have direct access to hundreds of hiring decision makers in the country.

View Now

Information Security Analyst

Concord, New Hampshire $49 - $59 hour New Hampshire Retirement System

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

NHRS Is hiring for an Information Security Analyst. This position is assessed in Band M. $45.76-$9.00

We are hiring in the range of 48.53- 58.99

Information Security Analyst
NHRS is seeking an experienced Information Security Analyst (ISA) to lead the development and continuous improvement of our cybersecurity program. This role ensures the confidentiality, integrity, and availability of NHRS systems and data by proactively defending against cyber threats and advising leadership on security strategies.

Key Responsibilities:

  • Assess and monitor information security controls and risks.

  • Ensure compliance with NIST, NHRS policies, and industry best practices.

  • Lead third-party risk assessments and support IT audits.

  • Manage security awareness training and enforce policy adherence.

  • Maintain the risk register and provide reports on NHRS’ security posture.

  • Support incident response planning and execution.

Qualifications:

  • Bachelor’s degree in computer science or related field (Master’s preferred).

  • 15+ years combined experience in Information Security and Windows administration.

  • Security certifications (CISSP, CISM, Security+, CySA+) preferred.

  • Strong knowledge of cybersecurity principles, regulatory frameworks, incident response, and SIEM/security tools.

  • Excellent communication and analytical skills.

NHRS offers professional development opportunities and encourages certification and training.

View Now

Information Security Manager

Denver, Colorado $95000 - $115000 year Center For Improving Value In Health Care

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

Position Title: Information Security Manager

Department: Data Solutions

Reports To: Chief Technology Officer

FLSA Classification: Exempt, full-time

About Us:

The Center for Improving Value in Health Care (CIVHC) is an independent non-profit that equips partners and communities in Colorado and across the nation with the resources, services and unbiased data needed to improve health and health care. As the designated administrator of Colorado’s All Payer Claims Database (CO APCD), CIVHC oversees the collection of health care claims from Colorado’s public and private health care insurers and uses that information to promote price transparency, inform policy, advance health equity, conduct research, and much more. We are objective, solution-oriented, and maintain the highest integrity in the work we do.

Job Summary:

The Information Security Manager leads the oversight and strategic direction of information security at CIVHC, with a focus on policy development, vendor security assurance, and regulatory compliance. This is not a hands-on systems administration or SOC (Security Operations Center) role.

The Information Security Manager serves as the internal point of accountability for ensuring that CIVHC’s data infrastructure, cloud migration initiatives, and vendor relationships meet the highest security and privacy standards. The Information Security Manager collaborates with the Finance, Compliance, Data Solutions, and Data Access and Impact departments to ensure the integrity, confidentiality, and availability of CO APCD information systems.

As the administrator of the Colorado All Payer Claims Database (CO APCD), CIVHC contracts with external vendors for data ingestion, storage, and analytics. This position provides oversight support of those partnerships to ensure compliance with HIPAA, NIST, and other regulatory standards.

This position is especially critical for cloud migration, increased API use, and AI exploration, and plays a lead role in risk evaluation. The role also includes business-aligned responsibilities such as documentation of database architecture and governance planning, working closely with technical and compliance teams.

The Information Security Manager will integrate forward-thinking, community-centered innovation with scalable data services. The ideal candidate brings a strong commitment to equity, the ability to communicate complex information to diverse audiences, and a visionary mindset to leverage data for transformative health outcomes across Colorado and beyond.

Supervisory Responsibilities:

  • Direct oversight of the IT & Network Specialist. Future supervisory responsibility may expand with organizational growth.
  • Collaborate with the IT & Network Specialist to ensure that device management, internal network configurations, and endpoint protections align with the organization’s overall security and compliance framework.
  • Set priorities, approve technology purchases, and support professional development for the IT & Network Specialist in alignment with organizational goals.
  • Ensure proper documentation and incident handling for IT issues involving internal hardware, user access, and system configurations.
  • Integrate business-side IT practices into enterprise-wide risk management, business continuity planning, and security training initiatives.

Duties/Responsibilities/Essential Functions:

  • Develop information security policies, procedures, and documentation.
  • Ensure organizational policies are compliant with relevant security and privacy regulations (e.g., HIPAA, NIST, SOC 2, FISMA).
  • Support external partnerships on security matters, working closely with Legal & Compliance. In some cases, Legal & Compliance may lead, with the Information Security Manager providing technical input and documentation.
  • Evaluate and oversee vendor risk related to data handling, system architecture, and regulatory adherence.
  • Lead internal risk assessments, documentation, and architecture reviews related to cloud environments and APIs.
  • Oversee incident response planning and coordinate post-incident reporting and improvement.
  • Guide the documentation and improvement of database architecture.
  • Define and implement security and ethical guidelines for AI, automation, and emerging technology adoption.
  • Collaborate with technical staff and vendors to review and document security controls during infrastructure changes.
  • Partner with Legal & Compliance and executive leadership to interpret and operationalize applicable laws, regulations, and contractual obligations in a rapidly evolving healthcare, IT, and data landscape.
  • Develop training materials, best-practice guides, and onboarding resources for data and technology users.

Reasonable accommodations may be made to enable individuals with disabilities to perform these essential functions.

Required Skills/Abilities:

  • Excellent communication and collaboration skills across technical and non-technical teams.
  • Strong understanding of security compliance frameworks: HIPAA, NIST, ISO 27001, SOC 2.
  • Experience conducting or overseeing security assessments, risk reviews, and audits.
  • Familiarity with cloud architecture documentation, vendor oversight, and system migration planning.
  • Experience reviewing and documenting data structures, schema, or database system architecture.
  • Familiarity with AI/ML governance, automation policy development, or responsible technology evaluation.

Education and Experience:

  • Minimum 7 years of experience in information security oversight, Information Technology risk management, or technology compliance.
  • Bachelor’s degree in Cybersecurity, Information Systems, Information Technology, IT Governance, or a related field; or a 7-year combination of education and/or progressive experience.
  • Experience with healthcare data environments or privacy-sensitive data ecosystems.
  • Prior involvement with cloud migration projects or multi-vendor data infrastructure preferred.
  • Knowledge of CMS Incidental Disclosure protocols preferred.
  • Experience working in public sector, nonprofit, or mission-driven organizations preferred.
  • Professional certifications: CISSP, CISM, CISA, CCSP, are strongly preferred but not required.

Physical Requirements: Primarily computer-based work with extended periods of sitting, typing, and concentration. May occasionally require light lifting of office materials.

  • Sitting for extended periods of time.
  • Using a computer and keyboard for typing and data entry.
  • Reaching and stretching to access files or equipment.
  • Lifting and carrying light objects such as papers or office supplies.
  • Walking short distances within the office environment.
  • Operating office equipment such as printers, copiers, and fax machines.
  • Occasionally bending or stooping to retrieve items from lower shelves or cabinets.
  • Maintaining good posture to prevent discomfort or strain.
  • Using a telephone or headset for communication.
  • Ability to focus and concentrate for prolonged periods.

Other duties:

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

Position Timeline:

Our target is to fill this position by October 24 , 2025 . Application review will begin immediately and will continue on a rolling basis until the position is filled. We encourage interested candidates to apply as soon as possible for full consideration.

Compensation and Benefits:

The salary range for this position is $95,000 - $115,000 annually, based on relevant experience, education, and internal equity. CIVHC offers a comprehensive benefits package including medical, dental, and vision coverage; paid time off; life and disability insurance; and retirement plan contributions.

Equal Opportunity Employer:

CIVHC is proud to be an Equal Opportunity Employer. We celebrate diversity and are committed to creating an inclusive environment for all employees. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, disability, age, or any other legally protected status.

View Now

Director, Information Security

Denver, Colorado Frontline Road Safety Group

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description



Frontline Road Safety Group is the undisputed North American pavement marking leader . Our company, owned by Bain Capital and proudly provides its customers with unparalleled customer service and the use of innovative technology to ensure timely and value-added results.

In our time of growth, we are currently looking to add a Director of Information Security to our Denver HQ team. This is an on-site position in our downtown Denver headquarters. We are not considering relocation for out of state candidates or candidates who are not in metro Denver.

Pay Range Commensurate With Experience : $180-210K

Collaborates With: MSP/MDR, IT Operations, HR, Legal, Compliance, Business Units

Role Overview

Reporting to the Chief Information Officer, the Director of Information Security serves as the organization’s key cybersecurity authority, responsible for establishing, managing, and continually enhancing a robust, enterprise-wide information security and data privacy program. This role provides strategic direction, ensures regulatory compliance, leads incident response efforts, and fosters a strong security culture across the enterprise. The role also governs relationships with third-party vendors and managed security partners and drives business-aligned risk management and resiliency efforts.

Key Responsibilities

Strategic Leadership & Governance

  • Develop, implement, and maintain the organization's information security and data privacy strategy, policies, and governance framework, aligning with frameworks such as NIST CSF 2.0 and CIS Controls.
  • Serve as a trusted advisor to leadership on cyber risk, compliance obligations (e.g., PCI, CJIS), and emerging threats.
  • Establish and manage key performance indicators (KPIs) and dashboards to measure program effectiveness and foster continuous improvement.
  • Develop and communicate a strategic vision for the security program that balances business enablement with risk mitigation.

Security Operations & Incident Response

  • Lead incident response efforts, exercises, and investigations in collaboration with the MSP/MDR Security Operations Center (SOC).
  • Coordinate real-time monitoring, triage, and response to security alerts and vulnerabilities.
  • Monitor and oversee the organization’s Disaster Recovery (DR) and Business Continuity Plans (BCP), ensuring readiness through regular testing.
  • Lead enforcement and tuning of core security platforms, including EDR (e.g., SentinelOne), SIEM (e.g., Rapid7 MTC), and the secure email gateway (e.g., Checkpoint Harmony).

Risk Management & Compliance

  • Implement third-party vendor risk management program, including onboarding security reviews and continuous monitoring.
  • Conduct and oversee regular security and risk assessments of infrastructure, applications, and new technologies.
  • Monitor and ensure compliance with data privacy and cybersecurity regulations, participating in audits, litigation holds, and access reviews.
  • Implement controls and tracking mechanisms for compliance with frameworks like NIST, ISO, and Privacy Laws like PRA/CCPA (California), and CPA (Colorado) to name a few, and sector-specific mandates.

Security Architecture & Technology Oversight

  • Evaluate and implement advanced security solutions (e.g., DLP, SASE, CASB, PAM, CSPM, LAPS) to enhance the organization's risk posture.
  • Collaborate with other IT teams to secure infrastructure, cloud services, and applications through defense-in-depth strategies.
  • Define and enforce technical security standards, including secure configuration baselines and secure coding guidelines.
  • Own oversight for external access controls, firewall policy governance, DNS protection, DMARC/SPF, and log management.

Security Awareness & Culture Building

  • Lead and enhance the Security Awareness Training (SAT) program (e.g., KnowBe4), including phishing simulations and compliance reporting.
  • Advocate for a security-first culture across IT and business teams through ongoing engagement, communication, and training.
  • Drive remediation campaigns based on audit findings or security control gaps identified.

Key Tools & Platforms

Function

Tools / Partners

SIEM/SOC

Rapid7 MTC (IDR, IVM) – MDR Provider

Endpoint Detection

SentinelOne (S1)

Email Security

Checkpoint Harmony SEG

SAT/Phishing

KnowBe4

Log Management

MSP – Log Source Management

DNS, SPF, DMARC

MSP – Configuration Management

Qualifications:

  • Education: Bachelor’s degree in Information Security, Computer Science, or related field (Master’s preferred).
  • Experience: 8+ years in information security leadership roles, with expertise in managing enterprise-wide programs in federated, M&A, or regulated environments.
  • Certifications: CISSP, CISM, or equivalent strongly preferred.
  • Technical Proficiency: Deep knowledge of risk management, security technologies, and compliance frameworks (NIST, CIS, ISO).
  • Business Acumen: Ability to balance cybersecurity strategy with business growth goals, using risk-based prioritization.
  • Communication Skills: Strong ability to articulate security concepts to non-technical stakeholders and executive leadership.
  • Leadership: Experience managing cross-functional teams and vendor relationships, including MDR governance and performance measurement.

What Success Looks Like?

  • A measurable reduction in organizational cyber risk through improved controls and visibility.
  • Security events are detected, contained, and remediated with minimal business disruption.
  • A well-established, compliant, and auditable information security program.
  • A workforce that demonstrates security awareness and embraces shared accountability.
  • Security technologies are optimized and integrated across IT towers and business units.

In recognition of your commitment to us, Frontline Road Safety Group offers the following:

SAFETY FIRST

  • Work for an industry leader in pavement marking that puts the safety of their employees at the highest priority.

WE ARE GROWING

  • Frontline Road Safety is already North America’s leader in pavement marking, but we are not slowing down. We are continuing to grow our footprint and expand our operation. It’s an exciting time to be with us!

COMPETITIVE PAY/BENEFITS PACKAGE

  • Pay range will be commensurate with knowledge/skills/abilities but should fall in the range of $180K-210K.
  • Excellent medical, dental, vision, life insurance and 401(k) benefits including a company match

Frontline Road Safety Group is an equal opportunity employer. We are committed to creating an inclusive environment for all employees.

View Now

Information Security Engineer

Washington, District Of Columbia Palantir Technologies

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

A World-Changing Company


Palantir builds the world’s leading software for data-driven decisions and operations. By bringing the right data to the people who need it, our platforms empower our partners to develop lifesaving drugs, forecast supply chain disruptions, locate missing children, and more.


The Role


As an Information Security Engineer, you are responsible for the security of Palantir’s people and infrastructure around the globe. Your technical expertise is second only to your integrity and real passion for security and technology in general. Our ideal candidate works well on a team, is highly motivated, and enjoys solving problems and taking on new challenges.


In this role, you’ll be the first line of defense for protecting Palantir. Your team is responsible for the 24/7 prevention, detection, and investigation of security events and active attacks across our entire infrastructure. Your work will directly impact the success of Palantir's mission as you seek to make it challenging for our adversaries and protect our global network.

Core Responsibilities
  • Build, run, and own infrastructure and automation to detect, contain, and eradicate security threats.
  • Develop alerting and detection strategies to identify malicious or anomalous behavior.
  • Develop new and novel defensive techniques to identify or counteract changes in adversary techniques and tactics.
  • Dissect network, host, memory, and other artifacts originating from multiple operating systems and applications.
  • Investigate enterprise-wide operations to uncover sophisticated and undetected threats.
  • Partner closely with other members of the Information Security team to lead changes in the company's network defense posture.
What We Value
  • Broad exposure to multiple security subject areas, including a strong background in forensics or threat intelligence.
  • Deep exposure in Incident Response or Detection Engineering.
  • Desire to further the information security community through substantive contributions (e.g. conference talks, blog posts, public tool development, etc.).
  • Strong working knowledge of TCP/IP networking and common protocols.
What We Require
  • Extensive security experience (3+ years) in at least one major platform (e.g. AWS, Azure, Windows, OS X, Linux, etc.).
  • Proficiency in Python (preferred), PowerShell, or similar.
  • Active TS/SCI security clearance or eligibility to obtain a security clearance.

Salary


The estimated salary range for this position is estimated to be $135,000 - $200,000/year. Total compensation for this position may also include Restricted Stock units, sign-on bonus and other potential future incentives. Further note that total compensation for this position will be determined by each individual’s relevant qualifications, work experience, skills, and other factors. This estimate excludes the value of any potential sign-on bonus; the value of any benefits offered; and the potential future value of any long-term incentives.



Our benefits aim to promote health and wellbeing across all areas of Palantirians’ lives. We work to continuously improve our offerings and listen to our community as we design and update them. The list below details our available benefits and some of the perks that can be enjoyed as an employee of Palantir Technologies.


Benefits


•  Employees (and their eligible dependents) can enroll in medical, dental, and vision insurance as well as voluntary life insurance

•  Employees are automatically covered by Palantir’s basic life, AD&D and disability insurance

•  Commuter benefits

•  Relocation assistance

•  Take what you need paid time off, not accrual based

•  2 weeks paid time off built into the end of each year (subject to team and business needs)

•  10 paid holidays throughout the calendar year

•  Supportive leave of absence program including time off for military service and medical events

•  Paid leave for new parents and subsidized back-up care for all parents

•  Fertility and family building benefits including but not limited to adoption, surrogacy, and preservation

•  Stipend to help with expenses that come with a new child

•  Employees can enroll in Palantir’s 401k plan


Life at Palantir


We want every Palantirian to achieve their best outcomes, that’s why we celebrate individuals’ strengths, skills, and interests, from your first interview to your longterm growth, rather than rely on traditional career ladders. Paying attention to the needs of our community enables us to optimize our opportunities to grow and helps ensure many pathways to success at Palantir. Promoting health and well-being across all areas of Palantirians’ lives is just one of the ways we’re investing in our community. Learn more at Life at Palantir and note that our offerings may vary by region.


In keeping consistent with Palantir’s values and culture, we believe employees are “better together” and in-person work affords the opportunity for more creative outcomes. Therefore, we encourage employees to work from our offices to foster connectivity and innovation. Many teams do offer hybrid options (WFH a day or two a week), allowing our employees to strike the right trade-off for their personal productivity. Based on business need, there are a few roles that allow for “Remote” work on an exceptional basis. If you are applying for one of these roles, you must work from the state in which you are employed. If the posting is specified as Onsite, you are required to work from an office.


If you want to empower the world's most important institutions, you belong here. Palantir values excellence regardless of background. We are proud to be an Equal Opportunity Employer for all, including but not limited to Veterans and those with disabilities. Palantir is committed to making the application and hiring process accessible to everyone and will provide a reasonable accommodation for those living with a disability. If you need an accommodation for the application or hiring process, please reach out and let us know how we can help.

View Now
Be The First To Know

About The Latest Threat modeling Jobs in United States!

Information Security Analyst

Arlington, Virginia Saliense Consulting LLC

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

Who is Saliense?

Saliense is a growing Management and Technology Consulting Solutions provider based out of Mclean, VA. We work to solve our client’s toughest challenges within the Defense, Civilian, Financial, and Healthcare industries. Our diverse employees support vital missions for government and commercial customers. For more information, visit


Why Saliense?

In addition to providing a fun, energetic environment that promotes innovation and personal growth, we offer excellent compensation packages with plenty of opportunities for advancement. We pay 100% of the premiums for employee Healthcare, including medical, dental, and vision. We offer a 401K match, and all company contributions are 100% vested immediately. Since we believe in work-life balance so much, we offer 20 days of paid leave per year. Use it as you need it or use it all at once and go travel for a month! We are proud to offer parental leave.


There are many more - connect with us to get a preview of the full benefits package.



Saliense has a new opportunity for an Information Security Analyst to support the U.S. Marshals in Arlington, VA.


This is a hybrid position that requires 2 days onsite every other week in Arlington, VA.


Information Security Analyst must have experience (i.e., a minimum of one (1) year) within federal information systems security policy and implementation. At a minimum, a core set of knowledge of federal information system security policy, industry best practices, security control assessments, Plan of Action and Milestones (POA&M) management, system authorizations, configuration management, and system analysis.


Responsibilities:


  • Develop and execute test plans of the OMB Circular A-123 internal control assessments.

  • Develop and execute test plans of the FISMA internal control assessments.

  • Determine, gather, examine, and analyze artifacts related to OMB Circular A-123 security control assessments and remediation verification.

  • Determine, gather, examine, and analyze artifacts related to FISMA security control assessments and remediation verification.

  • Document all assessment activities and results in sufficient detail to enable external review of all assessment processes, activities, results, and conclusions.

  • Provide recommendations and guidance for corrective action of all non-compliant security controls.

  • Provide security expertise to ensure security controls are implemented and the resulting documentation and artifacts are current.

  • Provide support for verifying compliance with the Federal Information System Modernization Action (FISMA) as part of both internal and external control assessments/audits across all accredited agency information technology systems.

  • Provides technical evaluations of customer systems and assists with making security improvements.

  • Conducts security product evaluations, and recommends products, technologies, and upgrades to improve the customer’s security posture.



Required Experience:

  • Must have a minimum of one (1) year of federal information systems security experience.

  • Minimum Educational Requirements: BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline.

***Saliense Consulting LLC provides equal employment opportunities to all employees and applicants for employment and prohibits discrimination and harassment of any type without regard to race, color, religion, age, sex, national origin, disability status, genetics, protected veteran status, sexual orientation, gender identity or expression, or any other characteristic protected by federal, state or local laws.

This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall,

View Now

Information Security Analyst

Austin, Texas AVIAT US INC

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

Are you looking for an exciting opportunity working for a Global Technology Leader?

At Aviat Networks, we take great pride in hiring a workforce that is committed to supporting and strengthening our values and attributes. If you are a results-oriented, customer centric and innovative thinker who also takes pride in personal and professional integrity, Aviat Networks is the ideal next step in your career. We are looking for people who love to solve problems, enjoy change, and know how to have fun so come and join a dynamic team that strives to bring communications to the world.

Aviat Networks is the world’s largest independent supplier of wireless transmission systems. We are recognized worldwide for cutting-edge 5G, backhaul, networking solutions and services. Customers in more than 135 countries depend on Aviat Networks to build, expand, and upgrade their voice, data, and video solutions

About the Role: The Information Security Analyst will serve as a key technical resource for multiple security technologies, including Firewalls, VPN, Endpoint Security, Microsoft 365 Security, and more. They will build relationships with various IT teams, establishing themselves as a trusted source of solutions and support. They will spend time with their functional team to understand the current processes and recommend solutions to improve workflow, business continuity, and productivity. The Information Security Analyst is responsible for monitoring and responding to security incidents, as well as maintaining various security technologies. The Information Security Analyst will support operational excellence with a primary focus on reliable execution and technical prowess.

Responsibilities:

  • Interact with management and staff to provide technical assistance and monitoring of security solutions.
  • Provide support to business unit security requests.
  • Ongoing maintenance of ISO27001 controls and requirements.
  • Actively monitor and hunt for potential security threats across the security solutions.
  • Regularly audit and ensure that access controls are up to date and follow the zero-trust methodology.
  • Troubleshoot hardware and software issues related to security solutions.
  • Establish and maintain a positive, productive relationship with operational partners and staff.
  • Other duties as assigned.

Qualifications & Competencies:

  • Bachelor’s degree in information technology, Computer Science, Cyber Security, Information Systems, or a related field, or equivalent experience is desirable but not required.
  • 2+ years of experience working in IT. Emphasis on Network and Endpoint Security.
  • Knowledge of firewall administration, endpoint security technologies, and SIEM solutions.
  • Familiarity with EDR and Email Security solutions is a plus.
  • Working knowledge of computer systems, security, network and systems administration, databases, and data storage systems.
  • Strong critical thinking and decision-making skills.
  • Having a CISSP, Security+, or other cybersecurity-related certification is a plus.
  • FortiGate Firewall administration and Juniper knowledge and experience are a plus.
  • ISO27001 and NIST 800 series knowledge.
  • Experience with Endpoint Protection (EDR) would be desirable.
  • SIEM experience would be desirable.
  • Experience working with Microsoft 365 Security & Compliance.
  • Working understanding of Windows Services to include DNS, DHCP, and Group Policy.
  • Working understanding of Linux systems.
  • Working understanding of IP, subnetting, and general networking technologies. Knowledge of Juniper and Fortinet systems and OS is a plus.
  • Knowledge of virtualization technologies, including VMWare and Hyper-V.

We encourage you to read our Candidate Privacy Notice. You have the right to withdraw your consent at any time. To do this you can email us at .

Aviat Networks provides equal employment opportunity for all applicants and employees. The Company does not discriminate against applicants or employees on the basis of race, color, sex, age, national origin, religion, sexual orientation, gender identity, veteran or military status, disability or any other legally recognized protected basis under federal, state or local law.

Aviat Networks offers a competitive benefits package. Apply NOW to learn more!


For positions in California, Colorado, or New York City you may contact us at for the salary range for this position (include the exact Job Title as it reads above).

View Now

Information Security Officer

Washington, District Of Columbia Sparks Group

Posted today

Job Viewed

Tap Again To Close

Job Descriptions

full_time
Job Description

Job Description

Summary:
The Director of Information Security leads the design and execution of the organization’s cybersecurity strategy, overseeing programs that protect data, systems, and members from evolving threats. This role balances strategic vision with hands-on operational leadership, ensuring compliance, resilience, and alignment with business goals. The Director will collaborate closely with executive leadership and IT teams to strengthen the credit union’s overall security posture.

Key Responsibilities:

  • Develop, implement, and manage the organization’s enterprise cybersecurity program, policies, and risk management framework.

  • Lead security operations, incident response, and technology oversight to maintain regulatory compliance and operational resilience.

  • Provide strategic leadership, budgeting, and staff development for the information security team, while reporting progress and risks to executive management.

Qualifications:

  • Minimum 8 years of IT experience, including 6 in cybersecurity and 4 in a leadership role.

  • Deep understanding of security frameworks (NIST, ISO 2700x, COBIT) and regulatory requirements (GLBA, FFIEC, PCI).

  • Bachelor’s degree in Computer Science or related field; CISSP, CISM, or similar certifications strongly preferred.

---

This job is Hybrid Remote.

Pay Range: Salary $200,000.00 to $250,000.00

We offer several comprehensive benefits package including health and life insurance, paid and unpaid time off, and retirement and savings plans to qualifying employees.

Download the Sparks Group mobile app from Apple App Store or Google Play .

---

Sparks Group is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, pregnancy, citizenship, family status, genetic information, disability, or protect veteran status.

View Now

Principal Information Security Engineer

32801 Orlando, Florida $140000 Annually ClickaJobs

Posted 2 days ago

Job Viewed

Tap Again To Close

Job Descriptions

full-time
Our client is seeking a highly experienced and visionary Principal Information Security Engineer to join their world-class cybersecurity division. This is a fully remote position, allowing you to contribute your expertise from anywhere within the US. You will be at the forefront of designing, implementing, and managing robust security architectures and protocols to protect sensitive data and critical infrastructure. This role demands a deep understanding of threat landscapes, vulnerability management, incident response, and security best practices across cloud and on-premise environments. Responsibilities include leading security initiatives, developing and enforcing security policies, performing risk assessments, and architecting security solutions that scale with business growth. You will collaborate with engineering and development teams to integrate security best practices into the software development lifecycle (SDLC) and mentor junior security engineers. The ideal candidate will possess exceptional problem-solving abilities, a proactive approach to identifying and mitigating threats, and a proven ability to articulate complex security concepts to both technical and non-technical audiences. A strong command of network security, endpoint security, cryptography, and cloud security (AWS, Azure, GCP) is essential. Experience with SIEM tools, IDS/IPS, and security automation is highly valued. Candidates should have a Bachelor's or Master's degree in Computer Science, Cybersecurity, or a related field, coupled with at least 10 years of progressive experience in information security. Relevant certifications such as CISSP, CISM, or OSCP are strongly preferred. This is a unique opportunity to drive security innovation and shape the future of our company's digital defenses in a flexible, remote-first setting.
Apply Now

Nearby Locations

Other Jobs Near Me

Industry

  1. request_quote Accounting
  2. work Administrative
  3. eco Agriculture Forestry
  4. smart_toy AI & Emerging Technologies
  5. school Apprenticeships & Trainee
  6. apartment Architecture
  7. palette Arts & Entertainment
  8. directions_car Automotive
  9. flight_takeoff Aviation
  10. account_balance Banking & Finance
  11. local_florist Beauty & Wellness
  12. restaurant Catering
  13. volunteer_activism Charity & Voluntary
  14. science Chemical Engineering
  15. child_friendly Childcare
  16. foundation Civil Engineering
  17. clean_hands Cleaning & Sanitation
  18. diversity_3 Community & Social Care
  19. construction Construction
  20. brush Creative & Digital
  21. currency_bitcoin Crypto & Blockchain
  22. support_agent Customer Service & Helpdesk
  23. medical_services Dental
  24. medical_services Driving & Transport
  25. medical_services E Commerce & Social Media
  26. school Education & Teaching
  27. electrical_services Electrical Engineering
  28. bolt Energy
  29. local_mall Fmcg
  30. gavel Government & Non Profit
  31. emoji_events Graduate
  32. health_and_safety Healthcare
  33. beach_access Hospitality & Tourism
  34. groups Human Resources
  35. precision_manufacturing Industrial Engineering
  36. security Information Security
  37. handyman Installation & Maintenance
  38. policy Insurance
  39. code IT & Software
  40. gavel Legal
  41. sports_soccer Leisure & Sports
  42. inventory_2 Logistics & Warehousing
  43. supervisor_account Management
  44. supervisor_account Management Consultancy
  45. supervisor_account Manufacturing & Production
  46. campaign Marketing
  47. build Mechanical Engineering
  48. perm_media Media & PR
  49. local_hospital Medical
  50. local_hospital Military & Public Safety
  51. local_hospital Mining
  52. medical_services Nursing
  53. local_gas_station Oil & Gas
  54. biotech Pharmaceutical
  55. checklist_rtl Project Management
  56. shopping_bag Purchasing
  57. home_work Real Estate
  58. person_search Recruitment Consultancy
  59. store Retail
  60. point_of_sale Sales
  61. science Scientific Research & Development
  62. wifi Telecoms
  63. psychology Therapy
  64. pets Veterinary
View All Threat Modeling Jobs