Familiarity with M365 security and compliance features, such as Microsoft Defender, Microsoft Information Protection, and Data Loss Prevention (DLP). Cloud Security: Knowledge of how to protect sensitive information within Microsoft 365 by using security and compliance features is crucial. Active Directory: Knowledge of identity and access management through Active Directory (now Entra), Windows Azure AD, and identity synchronization tools is very important. California residents: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act. Beacon Hill Technologies covers a broad spectrum of IT positions, including Project Management and Business Analysis, Programming/Development, Database, Infrastructure, Quality Assurance, Production/Support and ERP roles.
The Information Security Architect - Data Protection develops and guides the implementation of security architectures that protect sensitive data and ensure business continuity by mitigating associated risks.. This position focuses on supporting Data Protection solutions, including Data Loss Prevention, File and Database activity monitoring, and encryption technologies, and requires collaboration with various stakeholders to ensure compliance with IT, privacy, and security standards.. Participate in evaluations and recommend solutions to support enterprises security controls including: networking, firewalls, IDS/IPS, data loss prevention, application security, infrastructure security, and data security. Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Information Security Auditor (CISA), etc.. In connection with this, all employees must comply with both the Health Insurance Portability Accountability Act of 1996 (HIPAA) as described in the Notice of Privacy Practices and Privacy Policies and Procedures as well as all data security guidelines established within the Company’s Handbook of Privacy Policies and Practices and Information Security Policy.
At Elanco (NYSE: ELAN) – it all starts with animals!. We’re driven by our vision of ‘Food and Companionship Enriching Life’ and our approach to sustainability – the Elanco Healthy Purpose™ – to advance the health of animals, people, the planet and our enterprise.. The Network Security Engineer will be part of the team responsible for developing and supporting Elanco’s Network and Security Platform.. Proactively research emerging technologies and approaches to enhance Elanco’s network security posture.. Location: Global Elanco Headquarters - Greenfield, IN - Hybrid Work Environment
The Federal Reserve System (FRS) National Incident Response Team (NIRT) has an immediate opening for an Intermediate SOC Analyst (Incident Response) position, reporting to a Senior Manager Information Security.. The NIRT, a national service provider for the FRS, delivers effective intrusion detection, incident response, forensics, security intelligence, threat assessment, and penetration testing services.. This role will be a combination of SOC analyst (providing triage of potential security events) and incident handler (investigating and responding to actual security incidents).. You can also expect to develop more specialized skills such computer forensics, phone forensics, malware analysis, and threat hunting on the job and through external training.. The national hiring range for the Intermediate SoC Analyst is $87,800- $120,780 annually.
Start Date ASAPPosition PermanentHybrid Work Environment (3 days in office, 2 days remote with flexible hours)Dress Code Business CasualLocation Downtown Toronto, Outside of Union Station (TTC & GO accessible)A Great Place to WorkWho We AreKinross is a Canadian-based global senior gold mining company with operations and projects in the United States, Brazil, Mauritania, Chile and Canada.. In 2021, Kinross committed to a greenhouse gas reduction action plan as part of its Climate Change strategy, reached approximately 1 million beneficiaries through its community programs, and recycled 80% of the water used at our sites.. Visit Home - Kinross Gold CorporationPurpose of RoleThe Senior IT Security Analyst will be responsible for leading cybersecurity initiatives with a focus on incident response, endpoint protection, security event monitoring, and identity & access management.. Preferred: GCIH - GIAC Certified Incident Handler. CEH - Certified Ethical Hacker OSCP - OffSec Certified ProfessionalBonus: Splunk certifications (e.g., Splunk Certified Power User)Key Competencies Strong analytical and problem-solving skills High attention to detail and critical thinking Excellent communication skills (written and verbal) Ability to work independently and manage multiple priorities Leadership and mentoring abilities
Rearc is looking for a Cybersecurity Threat Detection Engineer with proactive communication skills, a foundation in DevSecOps, Detection-As-Code, deep purple team technical expertise, and an entrepreneurial approach to join our growing Cybersecurity practice.. You will craft tailored security detections to strengthen our clients' cybersecurity efforts by leveraging Security Information and Event Management (SIEM), Security Orchestration Automation and Response (SOAR), Endpoint Detection and Response (EDR), and Network Detection and Response (NDR) services.. Strong cloud, security, SIEM and data engineering fundamentals.. Prior programming experience in Python, Golang, or PowerShell. Founded in 2016 by engineers instrumental in The Wall Street Journal's transformation to a cloud-native architecture, we recognize that engineers are the driving force behind digital transformation and cloud adoption efforts.
Perform regular platform upgrades, vulnerability management, troubleshooting, and performance tuning. Administer data backups and disaster recovery policies. Work closely with DevSecOps teams to design and implement cloud- solutions. Certifications such as: Azure Solutions Architect Expert, AWS Solutions Architect Professional, CISSP. Experience with Microsoft Intune, Azure Policy, or Azure EntraID
Myers and Stauffer LC is a certified public accounting and health and human services reimbursement consulting firm, specializing in audit, accounting, data management and consulting services to government-sponsored health and human services programs (primarily state Medicaid agencies, and the federal Center for Medicare & Medicaid Services).. The Information Security Administrator will conduct network and application vulnerability/risk assessments for the organization, participate in penetration testing and detection activities, and perform security incident response procedures utilizing internal and external resources.. Conduct reviews of Active Directory Group Policy Object (GPO) and Intune device compliance policies to make recommendations that align with industry best practices as well as security baselines.. CISSP, SSCP, SEC+, CISA, CISM, or equivalent certifications preferred. Internal, external and third-party identity access management (IAM) solutions.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology solutions as we consider the entire security lifecycle.. Responsibilities include performing digital forensic analysis, following security incident response standard methodologies, malware analysis, identify indicators of compromise, support remediation or coordinate remediation efforts of a security incident, and develop documentation to support the security incident response process.. 5+ years experience in incident response, computer forensics analysis and/or malware reverse engineering;. Understanding of electronic investigation, forensic tools, and methodologies, including: log correlation and analysis, forensically handling electronic data, knowledge of the computer security investigative processes, malware identification and analysis;. Ideally, you’ll also have Hold or be willing to pursue related professional certifications such as GCFE, GCFA or GCIH
Start Date ASAPPosition PermanentHybrid Work Environment (3 days in office, 2 days remote with flexible hours)Dress Code Business CasualLocation Downtown Toronto, Outside of Union Station (TTC & GO accessible)A Great Place to WorkWho We AreKinross is a Canadian-based global senior gold mining company with operations and projects in the United States, Brazil, Mauritania, Chile and Canada.. In 2021, Kinross committed to a greenhouse gas reduction action plan as part of its Climate Change strategy, reached approximately 1 million beneficiaries through its community programs, and recycled 80% of the water used at our sites.. Visit Home - Kinross Gold CorporationPurpose of RoleThe Senior IT Security Analyst will be responsible for leading cybersecurity initiatives with a focus on incident response, endpoint protection, security event monitoring, and identity & access management.. Preferred: GCIH - GIAC Certified Incident Handler. CEH - Certified Ethical Hacker OSCP - OffSec Certified ProfessionalBonus: Splunk certifications (e.g., Splunk Certified Power User)Key Competencies Strong analytical and problem-solving skills High attention to detail and critical thinking Excellent communication skills (written and verbal) Ability to work independently and manage multiple priorities Leadership and mentoring abilities
Employment Type: Full Time Position Description: We are seeking an experienced Okta Architect to design, implement, and manage identity and access management (IAM) solutions using the Okta platform.. The Okta Architect will collaborate with cross-functional teams to ensure secure, scalable, and efficient identity management systems that align with organizational goals.. Configure and deploy Okta services, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), Lifecycle Management, and Universal Directory.. Strong understanding of IAM concepts, including SSO, MFA, role-based access control (RBAC), and privileged access management (PAM).. Experience with other IAM platforms (e.g., SailPoint, Ping Identity, CyberArk) is a plus.
Contact role between InfoSec and TechOps teams to improve the execution of network security design reviews by the operational team. At least 3 years’ experience in network security engineering, including hands-on experience with next-generation firewalls, which must include Palo Alto Networks. Experience maintaining Palo Alto Panorama, Logger, licensing and other Palo Alto Cloud solutions. Experience with public cloud platforms (Azure or GCP), including integration of Palo Alto VM series firewalls into cloud networks. Palo Alto, Cisco CCNP-Security, CISSP, or other security certification
Relevant certifications such as CISSP, CCSP, SABSA, TOGAF, or vendor-specific Zero Trust credentials are highly valued.. Hands-on experience with identity and access management (IAM), multi-factor authentication (MFA), data protection, and endpoint security.. Experience with Zero Trust technologies such as Zscaler, Palo Alto Networks, Okta, Microsoft Entra, or similar platforms.. Familiarity with DevSecOps, CI/CD pipelines, and secure software development practices.. Prior involvement in digital transformation, hybrid workforce, or cloud migration projects with a Zero Trust focus.
GEICO is seeking an experienced Senior Staff Engineer to solve complex Identity and Access Management-related challenges.. You will help drive our insurance business transformation as we redefine our Identity, Access Management, and Governance strategies.. Position Description Our Senior Staff Engineer works with our Staff and Sr. Engineers to innovate and build new systems, improve, and enhance existing systems as well as identify new opportunities to apply your knowledge to solve critical problems.. You will lead and drive design, implementation, and maintenance of a robust workforce and workload identity management solutions and governance framework.. to help secure your financial future and preserve your health and well-being, including: Premier Medical, Dental and Vision Insurance with no waiting period
You will be hands-on, driving security initiatives, and providing expert guidance across a range of security domains.. Support and implement security operations and IT cloud service infrastructure projects, focusing on incident response, cyber program development, and security technology , enhance, install, configure, and maintain specialized cyber security and cloud infrastructure solutions (e.g., incident response solutions, infrastructure modernization, vulnerability management, identity and access management).. Mature and develop security governance standards and supporting processes in cyber risk, including vulnerability management and incident response activities.. Conduct Third-Party Risk Management evaluations in accordance with defined processes.. Support and implement Computer Forensics capabilities for risk mitigation, investigation, and incident response.
Translational Research in Oncology (TRIO) is a global academic clinical research organization dedicated to advancing translational cancer research in the clinical trial setting.. TRIO is looking for a highly skilled and experienced Information Services Security Analyst to join our Information Services team.. In-Depth knowledge and experience with current industry standard cryptographic techniques & technologiesExperience with security tools and technologies such as SIEM, threat management, and scanning tools.. Experience with cloud security and knowledge of Microsoft Azure.. Familiarity with regulatory requirements such as GDPR, HIPAA, and PCI-DSS.Excellent analytical, investigative, and problem-solving skills.
Support annual PCI-DSS assessments by coordinating with QSAs, internal teams, and business units to validate compliance and resolve findings.. Manage third-party risk through contract reviews, vendor security assessments, and RFP processes throughout the procurement lifecycle.. Support the GRC team in the development of security-compliant solutions and risk management strategies.. Required Qualifications: One or more of the following certifications: CISSP, CISM, CCSP, or CISA (mandatory).. Solid understanding of third-party risk management practices and contractual security requirements.
We currently have a full-time job opening for a Senior Security Engineer of Cyber Risk Management. The Cyber Risk and Customer Security Assurance team fulfils our mission to strengthen our shield against cyber threats by providing a framework of processes and methodologies to manage Cardinal Health’s cybersecurity risks through issue and exception management, cyber risk management, and customer third party risk assessment engagement.. Sr. Engineer, Cyber Risk Management, applies knowledge of Information Security, Risk Management, and Information Technology to lead the maturity of our Cyber Risk program.. This role is a senior position within the team and will work with all members of the Information Security team as well as Senior Leadership, Enterprise Risk Management, Business leaders, and IT teams.. Leverage and integrate with existing IT risk management and risk escalation / approval processes
Perform regular platform upgrades, vulnerability management, troubleshooting, and performance tuning. Administer data backups and disaster recovery policies. Work closely with DevSecOps teams to design and implement cloud-native solutions. Certifications such as: Azure Solutions Architect Expert, AWS Solutions Architect Professional, CISSP. Experience with Microsoft Intune, Azure Policy, or Azure EntraID
Plan and design modern telco services to replace legacy copper-based telco solutions.. Degree and minimum 4 years of prior WAN Telecommunications networks experience or 2 years post-Secondary/ Associates Degree and a minimum of 8 years of prior WAN Telecommunications networks experience. Experience designing and implementing network technologies such as SONET, Carrier Ethernet, LTE. Knowledge of WAN/LAN, TDM and Voice switching systems; TCP/IP, specific routing protocols such as OSPF, BGP and RIP; VoIP, DWDM, CTI and VPN technologies. Experience with leading network vendors such as Cisco, Juniper, Ciena, RAD