The Senior Audit Manager (SAM) of Cybersecurity and IT Risk Management will support the Director IA, CNB Cybersecurity and IT Risk Management, and the Senior Director, IA, US Technology in providing independent, objective assurance over the design and operation of CNB's IT risk management practices, governance processes and the system of internal controls.. Examples of audit subject matter includes cybersecurity operations, data protection and data privacy, identity and access management, IT risk management, security architecture and engineering, cloud computing, IT risk management, network securities, vulnerability management, API security, etc.. Plans, leads and executes on the annual Audit Plan for CNB IT Cybersecurity and IT Risk Management audit universe, ensuring that audits conform to local and global regulatory and internal audit requirements.. In depth knowledge of financial services banking technology and related risks (e.g. cloud technologies, IT operations, data center services, storage & databases, server virtualization, cybersecurity operations, data privacy, data protection, cryptography, data loss prevention).. CISM - Certified Information Security Manager
In this dynamic role, your primary focus will be leveraging Microsoft administration/support portals as well as Azure Entra capabilities to enhance customer's identity management, compliance, secure posture, and access control.. Strong understanding of identity and access management (IAM) principles, protocols, and standards such as SAML, OAuth, OpenID Connect, and SCIM.. Knowledge of cloud security best practices and understanding of regulatory requirements such as GDPR, HIPAA, SOX, etc.. In-depth knowledge of other Microsoft 365 services, including Intune, Autopilot, Defender, MFA and conditional access, GDAP.. Design and implement identity management strategies within tenant Microsoft 365 environments using Azure Entra or other identify management capabilities with the Microsoft suite of administration consoles.
The Cyber Security Engineer – Threat Management is a mid-level Cyber Security Engineer responsible for second level security event/incident response along with the collection, analysis, and dissemination of cyber threat intelligence.. Operate the processes necessary to collect threat intelligence, analyze the data for patterns and actionable information, and create intelligence products for other teams to consume using MITRE ATT&CK Framework.. CISSP, GSEC, GCIH, CEH or other security certifications preferred, but not required.. Familiar with compliance regulations such as SOX, PCI-DSS, GLBA, and Federal Banking regulations.. Headquartered in Memphis, TN, the banking subsidiary First Horizon Bank operates in 12 states across the southern U.S. The Company and its subsidiaries offer commercial, private banking, consumer, small business, wealth and trust management, retail brokerage, capital markets, fixed income, and mortgage banking services.
This is a hands-on role that includes oversite, investigation and resolution of end user support needs, customer service, infrastructure management including IT security, and recovery strategies and network administration, and strategic planning.. Responsible for day-to-day IT operations and governance: Oversees company IT operations including vendors (e.g., outsourced device management, managed cloud services, help desk support, etc. Provide IT help desk support for employees.. Managing the information security vendor to provide incident management and vulnerability management.. Perform as ISSM and ISSO.
Britive is at the forefront of the emerging cloud security industry with the only modern privileged access management platform that provides unified Privileged Access Visibility, Dynamic Privilege Management and Secrets Governance across cloud infrastructures, platforms & SaaS.. Our patent-pending technology is deployed at several large and Fortune 500 customers and we have repeatedly ranked among the hottest Cloud Security startups.. Backed by top-tier VCs and led by seasoned cybersecurity and cloud industry veterans, Britive combines innovation, expertise, and a strong vision for securing the cloud.. Tech Savvy: Proficient with productivity tools (e.g., Outlook, O365, web conferencing), CRM systems (e.g., Salesforce, Hubspot), and prospecting platforms (e.g., ZoomInfo, Outreach).. We are fully remote (US only, other areas are subject to review).
Bachelors Degree required from an accredited, not for profit university or college.. Minimum of 6 years of experience in data security, with a focus on risk assessment, incident response, and security architecture design.. Experience in regulated industries (e.g., healthcare, finance) and familiarity with GDPR, PCI-DSS, HIPAA, or other relevant regulations is a plus.. On-site fitness center and/or reimbursed fitness center membership costs (location dependent), with yoga studio, Pelotons, personal training, group exercise classes. Complimentary gourmet coffee, tea, hot chocolate, fresh fruit, and other healthy snacks
Job Title: Cybersecurity Penetration Tester. Cybersecurity Traditional Penetration Tester located at Peterson SFB, FL, will help form and manage multi-skilled test team members and efforts to conduct system security analysis on systems and/or software to understand and identify vulnerabilities.. This position provides support to the 48th Cyberspace Test Squadron at Peterson SFB, FL, and the DOD Cybersecurity community, to plan and conduct Cybersecurity Developmental and Operational Test & Evaluation for major DoD programs.. Knowledge of cybersecurity testing methodologies and tools, such as vulnerability scanning, penetration testing, and risk assessments. Cintel Inc. is a Small Business providing strategies and services to support an array of Government clients in Software Development, Operational/Tactical and Installation/Facilities Energy, Cyber Security, Modeling and Simulation, Data Science, and Programmatic support.
Cybersecurity Engineer - Autonomous Vehicle Platform Date: May 6, 2024. PACCAR is a global technology leader in the design, manufacture and customer support of high-quality light-, medium- and heavy-duty trucks under the Kenworth, Peterbilt and DAF nameplates.. Collaborate with corporate purchasing and supplier quality to establish standard contract terms and assessments that enhance cyber-security in the supply chain.. Experience in a combination of real-time software, vehicle electronics and controls, embedded systems or similar areas, and information security, penetration testing, threat modeling/analysis, or related fields.. EAP services include wellness plans, estate planning, financial counseling, and more
Serve as a subject matter expert in incident response practices, including the design of incident management and response policy and procedures, and execution of the incident response program. Supports the daily incident identification, assessment, and response for the company's Security Information and Event Management System (SIEM). Leads ongoing initiatives to develop, collect, and analyze integrated logs for the SIEM to assist in forensic analysis and cyber event response. CEH, SANS GCIH, CompTIA Network+, CompTIA Security+ - 1 or more preferred. Cyber Security Operation Center experience in monitoring, incident response, or digital forensics - Preferred
Conduct detailed analysis of security events, using SIEM, EDR, and other security technologies to investigate incidents.. You have 5+ years of experience with incident response tools such as SIEM, SOAR, EDR, IDS/IPS, and forensic investigation tools.. You have some experience in threat intelligence analysis and threat hunting techniques. You are certified in areas relating to digital forensics and incident response.. Last year, we became a billion-dollar business , and our tribe expanded by a cool thousand people - theres nearly 5,000 of us now.
Backed by funds managed by Apollo Global Management, our vision is to accelerate the upgrade of copper to fiber optic technologies, bringing faster and more reliable internet service to many rural markets traditionally underserved by broadband providers, while delivering best-in-class customer experience.. In addition, the individual will assist the SOC analysts during incident triage and handling when needed (internal, customer-facing, Telcom, etc. Use SIEM, SOAR, DLP tools, Cloud Posture Management, Endpoint Management, Endpoint Protection Systems (EDR/XDR), and other security tools to support a strong and healthy SOC. Information Security Certifications preferred: CEH GPEN CPT CEPT OSCP. Recognized as a Top Workplace by the Charlotte Observer, Brightspeed HQ is located on the 7th floor of the new Vantage South End - East Tower in Charlotte, NC. We prioritize hiring talent in the Charlotte area, whenever possible, to make it a truly vibrant destination for our hybrid workforce.
The Role: The PCI-DSS Compliance Program Manager will be responsible for overseeing and managing the organization's PCI-DSS compliance program, ensuring that all processes, systems, and product offerings adhere to the latest audit requirements.. You Will: Develop, implement, and continuously improve the organization's PCI-DSS compliance program, including governance, gap assessments, remediation planning, and ongoing monitoring.. Coordinate with third-party risk management, privacy, legal, and other teams to maintain a comprehensive view of compliance and business needs.. Familiarity with cloud architecture (Azure, Entra ID), shared responsibility models, data loss prevention (DLP), and cloud security best practices (DevSecOps, Secure SDLC, etc. Expertise in security concepts like cryptography, identity and access management, logging and monitoring, network/endpoint vulnerability scanning and remediation, pen testing, and data discovery / protection.
Lead the design and implementation of security controls and policies within the GCP environment, leveraging Terraform for infrastructure provisioning and configuration management.. Configure and manage Google Cloud security products and services like Cloud Identity & Access Management (IAM), Cloud Key Management Service (KMS), and Cloud Security Command Center (SCC).. Strong understanding of GCP services and technologies, including Compute Engine, Kubernetes Engine, Cloud Storage, Cloud IAM, and Cloud Security Command Center.. Experience with Infrastructure as Code (IaC) tools like Terraform. Familiarity with Google Cloud Security Command Center (SCC)
Position Title and Salary : Network Security Engineer, grade 47, $36.78 hourly. The Network Security Engineer works to secure the Kansas Judicial Branch’s network infrastructure by configuring, testing, and optimizing networks and implements solutions to improve overall information security.. Performing vulnerability and penetration tests, identifying, defending against and remediating threats, and developing disaster recovery plans.. This position shares responsibilities with the Manger of Network Services in a variety of different areas, including but not limited to firewalls, routers, switches, video applications, wireless QoS, proxy, VPNs and access control systems.. At least one of these security certifications is required: CCNP, CISSP, SSCP, CEH, GIAC, Security +, OSCP, CCNA.
This position is based at the Loews Hotels & Co Business Services Center in Franklin, TN.. Located in major city centers and resort destinations from coast to coast, the Loews portfolio features one-of-a-kind properties that go beyond Four Diamond standards and embrace their “uniquely local” community to curate exciting, approachable and local travel experiences for guests.. Enhance and maintain endpoint security platforms and processes including Anti-Virus, Anti Malware, Encryption, System Hardening, EDR, MDM, Web Content Management, DNS Security, Identity Solutions SIEM and Patch Management.. Mobile device management, Cloud, security, and investigations. Knowledge of Security Technologies from Ivanti, Mobile Iron, Sentinel One, LogRhythm, Sophos, Cisco Umbrella and CyberArk
To support our extraordinary teams who build great products and contribute to our growth, we're looking to add a/an Information Security Sr. Compliance Manager located in US Pennsylvania Remote.. Reporting to the Sr Director, Information Technology the Information Security Sr. Compliance Manager , will be responsible for driving cybersecurity initiatives and ensuring compliance across regional locations.. Lead and manage a team of IT Security Field Managers to achieve security objectives and align with organizational goals. In-depth understanding of technical aspects of cybersecurity, including threat detection, vulnerability management, and incident response.. Relevant certifications such as CISSP (Certified Information Systems Security Professional), CISM (Certified Information Security Manager), or CRISC (Certified in Risk and Information Systems Control).
Proficiency in Microsoft Azure services, including virtual machines, storage, networking, and databases.. Experience with infrastructure as code tools, such as Azure Resource Manager (ARM) templates or Terraform.. Proficient in Azure Active Directory (AAD) for identity and access management and scripting languages such as PowerShell or Azure CLI for automation.. Experience with Azure DevOps for continuous integration and deployment.. A minimum of five years of experience as a solution architect, principal/senior engineer, lead developer, or similar role with experience architecting cloud native solutions and an understanding of cloud security best practices and compliance standards.
We are a financially strong, international company with no debt and have been in business for over 40 years.. Using advanced optics, image sensors and artificial intelligence software Cognex vision and ID systems capture an image then analyze it to make sense of what’s being seen.. As a senior team member, you will champion, lead, and operate the architecture and solutions that ensure the backup and recovery of Cognex systems, applications, and data worldwide.. In the cloud environment, you will be responsible for architect and prescribing the virtualization and storage products, standards, policies, and configurations that will accompany provisioned assets, relying on the elasticity of the cloud and product selection of the cloud teams to manage the effectiveness of compute and storage relative to cost (efficiency).. Your ability to influence and champion the optimization and evolution of the technologies and services required to provide these infrastructure services is critical, including managing vendors, maintaining budgets, and developing and presenting business cases that facilitate decision-making.
You will be working with our more established contractors and staff to focus on several web and Windows applications used both by internal ELECT staff and constituents of the Commonwealth of Virginia.. The candidate will need expertise in all aspects of IT security and cloud security and experience working in an Agile/Scrum development environment interacting with technical and non-technical stakeholders.. Skill Required / Desired Amount Experience 5+ years in IT security or cloud security roles required.. Required 5 Years Experience with Azure Active Directory (AAD), including conditional access, MFA, and identity protection required.. Question 1 Commonwealth of Virginia security policies prohibit the use of offshore IT contractors.
Authorized to work in the US & ability to obtain a DHS PT (Heavy Financial/Criminal Check). Experience with Cisco devices & Palo Alto Firewall. Responsible for the implementation, deployment, and maintenance of networks for a federal government customers distributed enterprise network environment supporting voice, data, and video services.. Configure, install, troubleshoot various network devices and services (e.g., routers, switches, firewalls, VPN), LAN, and WAN.. Provide recommended patching and upgrades ensuring mitigation of non-compliant and vulnerable hardware and software.