Odyssey Systems Consulting Group, Ltd.

Odyssey Systems is a world-class technical, engineering, and integration company serving the warfighting ecosystem with airborne integration, ISR, C2, and warfighter readiness capabilities. Odyssey meets the military’s operational needs by integrating layered defense systems. Dedicated to excellent contract execution and fostering a workplace built on employee care. Core values include commitment, ambition, and respect.

Cybersecurity Engineer

Security EngineerSecurity EngineerOtherRemoteTeam 1,001-5,000

Location

United States

Posted

101 days ago

Salary

0

No structured requirement data.

Job Description

Cybersecurity Engineer

Odyssey Systems Consulting Group, Ltd.

Position Summary Odyssey Systems has an exciting opportunity for a Cybersecurity Engineer providing support to the Command, Control, Communications (C3C)/Kessel Run division. Kessel Run is an Air Force unit that delivers resilient command and control and targeting software capabilities that provide warfighters with decision advantage. Under the Department of the Air Force Program Executive Office for Command, Control, Communication, and Battle Management (DAF PEO C3BM), Kessel Run technologies make up the DAF BATTLE NETWORK, the systems-of-systems designed to help the Joint Force make operational decisions faster than our adversaries. The Division architects and acquires the means to connect weapon systems with warfighters and decision makers to enable the warfighter to win against the pacing challenge in an era of great power competition. This is a full time position located at Hanscom AFB, Bedford, MA and does have the ability to be worked remotely. Responsibilities Duties include, but not limited to: - Assist with development of System Security Management Plans, Program Protection Plans, Security Risk Analyses, OPSEC Plans, Computer Certification and Accreditation, Security Vulnerability and Countermeasures Analyses, Security Concepts of Operations, and other system security engineering-related documents identified in MIL-STD 1785, DoDI 5000.02, Operation of the Adaptive Acquisition Framework, and DoDI 8510.01 - Support the system/application Authorization and Accreditation (A&A) effort to include assessing and guiding the quality and completeness of A&A activities, tasks and resulting artifacts mandated by governing DoD and Air Force policies (i.e., Risk Management Framework (RMF) - Update, monitor, and manage information in systems for the program office - Process and manage system user account requests and process tools - Process and manage system port/protocol and access control list requirements - Process and manage system Public Key Infrastructure (PKI) identification and authorization requirements - Manage the distribution, implementation, remediation, and tracking of system security updates and configurations as required by the DoD - Recommend policies and procedures to ensure information systems reliability and accessibility to prevent and defend against unauthorized access to systems, networks, and data - Conduct risk and vulnerability assessments of planned and installed information systems to identify vulnerabilities, risk, and protection needs - Promote awareness of security issues among management and ensuring sound security principles are reflected in organizations’ vision and goals - Conduct systems security evaluations, audits and reviews - Recommend systems security contingency plans and disaster recovery procedures - Recommend and implementing programs to ensure that systems, network, and data users are aware of, understand, and adhere to systems security policies and procedures - Participate in network and systems design to ensure implementation of appropriate systems security policies - Recommend initial, or updates to, software and configurations to new or existing system security mechanisms - Obtain waivers to mandated security mechanisms/policies which would be detrimental to system performance and impact the system’s mission - Facilitate the gathering, analysis and preservation of evidence used in the prosecution of computer - Provide leadership assistance in the analysis of the design, development, integration, implementation and testing of cybersecurity requirements - Develop risk-based strategies to address identified gaps - Review, analysize, and assess implementations of cybersecurity (i.e. RMF security controls) throughout the open systems architecture and associated services, derived requirements specifications, design documents & design implementation - Collaborate with stakeholders (Government and commercial) to ensure the system is approved by all Authorizing Officials via the RMF A&A process - Provide technical advice in the area of systems security across all systems and supports - Develop recommendations for the Government regarding how well designs satisfy current requirements and business goals - Maintain databases that reflect receipt, storage, inventory, and disposition of classified information to include data entry, updates, and generation of reports - Support Government program office in audits of Government classified holdings to ensure proper accountability - Maintain databases of classified visits and clearance levels - Perform inspection, inventory, logging, storage, documentation, transmittal and internal distribution of classified information received - Evaluate Contractor classified data submittals for compliance with the appropriate System Security Classification Guide (SSCG) - Provide security inspection and protection to areas where classified information is being stored, and develop and establish security procedures and policies IAW DOD, USAF, AFMC, and local directives - Develop training and provide security awareness and other security education programs - Review and verify personnel qualifications for access to special access programs - Develop, implement and maintain a communications security program - Assess program disclosure issues and provide FMS case management support - Assist and advise FMS program office management and leadership in interfacing with FMS customers and all USG organizations, including but not limited to SAF/IA, Air Force Security Assistance Center (AFSAC), Air Force Security Assistance Training (AFSAT) squadron, Defense Finance and Accounting Services (DFAS) - Support execution of all aspects of acquisition program security throughout a program’s lifecycle - Assist with development of sound security practices and policies regarding acquisition, physical, personnel and documentation security - Update security classification guides - Prepare acquisition security related sections of acquisition program documentation - Review Contractor deliverables to ensure compliance with CDRLs - Plan and implement security-related surveys, assessments, and studies - Evaluate program security information and hardware throughout the program life cycle, to include studies, analyses, plans, procedures, production, test plans/results, transportation, technology, and storage of end items - Provide security support to source selections Qualifications Citizenship: Must be a US citizen Minimum Required Qualifications Clearance: Must have and be able to maintain a Secret Level Clearance Preferred Qualifications Education: Bachelor's or Master's Degree in a related field Years of experience: 3+ years of experience with 3+ years of experience in the DoD - Understanding of cybersecurity in DoD cloud infrastructure- Understanding of Agile methods, including CI/CD, DevSecOps, and DevOps- Possess the ability to effectively communicate in both written and verbal forms on highly technical topics Additional Information Location: Hanscom AFB, Bedford, MA but does have the ability to be worked remotely. #LI-MK1 Company Overview Odyssey Systems is a world-class technical, engineering, and integration company serving the warfighting ecosystem with airborne integration, ISR, C2, and warfighter readiness capabilities. Odyssey meets the military’s operational needs by integrating layered defense systems from equipment, technology, and services to data, information, and business operations. We streamline defense acquisition and sustainment, engineering the technical battlefield with domain-specific proficiency to ensure lethality. Odyssey is dedicated to excellent contract execution, peak organizational performance, and fostering a workplace built on employee care. Odyssey is proud to live out our core values of commitment, ambition, and respect in our work and communities through OdysseyCares, a philanthropic group focused on giving back through direct donations, an employer match program, and volunteering events. Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities Please Note: Final compensation for this position will be determined by various factors such as the Federal Government contract labor categories and contract wage rates, relevant work experience, specific skills and competencies, geographic location, education, and certifications. This position is filled through continuous recruitment and will remain open until a sufficient pool of applications has been received.Hired applicants may be eligible for benefits, including but not limited to, medical, dental, vision, life insurance, Tricare supplement, short-term disability, long-term disability, 401(k) match, flexible spending accounts, health savings accounts, employee assistance program, learning and development benefit, paid time off, and holidays.Odyssey Benefits

Related Categories

Related Job Pages

More Security Engineer Jobs

University of Maryland Global Campus logo

Fundamentals of Computer Troubleshooting, Department of Cybersecurity - Adjunct Faculty

University of Maryland Global Campus

The University of Maryland Global Campus (UMGC), founded in 1947, is a pioneering institution dedicated to serving adult learners and military personnel worldwide. As a proud membe

Security Engineer101 days ago

Adjunct Faculty Fundamentals of Computer Troubleshooting Department of Cybersecurity UMGC Stateside Location: Stateside Remote University of Maryland Global Campus (UMGC) seeks adjunct faculty to teach remotely for the Cloud Computing & Telecommunications program. Specifically, we are seeking faculty for the following course: Fundamentals of Computer Troubleshooting (CMIT 202): A thorough review of computer hardware and software, with emphasis on the application of current and appropriate computing safety and environmental practices. The goal is to evaluate, install, configure, maintain, and troubleshoot computer hardware components and operating systems. Required Education and Experience - Master’s degree in Computer Science degree or related field from an accredited institution of higher learning - Interested faculty MUST have an ACTIVE and CURRENT CompTIA A+ certification. - Professional experience in Computer Networking and Security - Experience teaching adult learners online and in higher education is strongly preferred - Specifically, we are seeking faculty to teach remotely. Materials needed for submission - Resume/ Curriculum Vitae - Cover letter is highly preferred - If selected, candidates with international degrees may be required to submit translation/ degree evaluations from NACES-approved vendors. Who We Are and Who We Serve UMGC—one of 12 degree-granting institutions in the University System of Maryland (USM)—is a mission-driven institution with seven core values that guide us in all we do. At the top of the list is "Students First,” and we strive to do just that for our 90,000 students at home and abroad. From its start in 1947, UMGC has demonstrated its commitment to adult learners. We recognize that adult students need flexibility and options. UMGC is proud to be a global, 24-hour, institution of higher learning. The typical UMGC student is an adult learner juggling a career, family, and other priorities. Roughly 80% work full time, half are parents, and half are minority students. They are continuing their education to better themselves, their families, and their professional opportunities. UMGC is also a leading higher education provider to the U.S. military, enrolling 55,000 active-duty service members, reservists, National Guard members, veterans, and family members annually. We are proud of our military heritage and are committed to this service. The Adjunct Faculty Role at UMGC UMGC is committed to helping students achieve success not only with us but also in their professional fields. As a result, we actively seek faculty members who are scholar-practitioners: professionals who are actively and successfully engaged in their field and who additionally wish to help the next generation of professionals grow in their knowledge and expertise through education. Your role as an adjunct faculty member will be to: - Actively engage students through frequent interaction that motivates them to succeed, and conveys genuine energy and enthusiasm for their learning. - Guide students in active collaboration and the application of their learning in problem- and project-based learning demonstrations. - Provide rich and regular constructive feedback, utilizing rubrics effectively for the assessment of student work, and acknowledging student accomplishments. - Demonstrate relevant and current subject-matter expertise, and help students connect concepts across their academic program. - Provide feedback to your program chair on possible curricular improvements. The Cloud Computing program at UMGC: Please visit the following link to learn more about this program, including its description, outcomes, and coursework: Online Cloud Computing Degree Programs | University of Maryland Global Campus Faculty Training at UMGC We are committed to your professional success at UMGC. Each new faculty member is required to complete our online two-week new faculty orientation, FacDev 411, as a condition of hire. Position Available and will Remain Open until Filled Salary Commensurate with Experience All submissions should include a cover letter and resume. The University of Maryland Global Campus (UMGC) is an equal opportunity employer and complies with all applicable federal and state laws regarding nondiscrimination. UMGC is committed to a policy of equal opportunity for all persons and does not discriminate on the basis of race, color, national origin, age, marital status, sex, sexual orientation, gender identity, gender expression, disability, religion, ancestry, political affiliation or veteran status in employment, educational programs and activities, and admissions. Workplace Accommodations: The University of Maryland Global Campus Global Campus (UMGC) is committed to creating and maintaining a welcoming and inclusive working environment for people of all abilities. UMGC is dedicated to the principle that no qualified individual with a disability shall, based on disability, be excluded from participation in or be denied the benefits of the services, programs, or activities of the University, or be subjected to discrimination. For information about UMGC’s Reasonable Workplace Accommodation Policy or to request an accommodation, applicants/candidates can contact Employee Accommodations via email at employee-accommodations@umgc.edu. Benefits Package Highlights: - Health Coverage: Access to health care, medical with vision, dental, and prescription plans for both individuals and families, effective from the 1st of the month following your hire date. NOTE: Adjuncts are not eligible for the State of Maryland subsidized rates. Adjuncts would be responsible for the total cost if enrolled. - Insurance Options: Term Life Insurance and Accidental Death and Dismemberment Insurance. - Supplemental Retirement Plans: include 401(k), 403(b), 457(b), and various Roth options. The university does not provide matching funds. For additional information please see: SS Adjunct Faculty_2020.pdf (umgc.edu) Hiring Range by Rank and Degree: Instructor: No Terminal Degree: Step 1 $806 - Step 11 $1,050 per credit hour Assistant Adjunct Professor: No Terminal Degree Step 1 $877 - Step 11 $1,127 per credit hour Assistant Adjunct Professor: Terminal Degree Step 1 $1,023 - Step 11 $1,288 per credit hour Associate Adjunct Professor: No Terminal Degree Step 1 $947 - Step 11 $1,205 per credit hour Associate Adjunct Professor: Terminal Degree Step 1 $1,202 - Step 11 $1,483 per credit hour Adjunct Professor: No Terminal Degree Step 1 $1,023 - Step 11 $1,288 per credit hour Adjunct Professor: Terminal Degree Step 1 $1,347 - Step 11 $1,645 per credit hour

United States
Job Closed
OtherRemoteTeam 1,001-5,000Since 2005H1B Sponsor

For over 20 years, Smartsheet has helped people and teams achieve–well, anything. From seamless work management to smart, scalable solutions, we’ve always worked with flow. We’re building tools that empower teams to automate the manual, uncover insights, and scale smarter. But more than that, we’re creating space– space to think big, take action, and unlock the kind of work that truly matters. Because when challenge meets purpose, and passion turns into progress, that’s magic at work, and it’s what we show up for everyday. The Sr. Security Engineer I is a critical technical role focused on deal acceleration, platform security evangelism, and the development of security features and capabilities that enhance our customer security and governance capabilities. You will support security and compliance during sales motions and bridge communication between complex customer security requirements and technical product engineering. You will work directly with customer security leaders (security engineers through CISOs) to communicate and clarify product security posture and controls results (such as pen test results), and will work with Smartsheet engineering to build security features that meet real-world customer requirements.. You will display product understanding through highly customized presentation demonstrations to customers and at conferences and events. This role reports to the Manager, Customer Trust and Engineering and can be based in our Bellevue, WA office or remotely from anywhere in the US where Smartsheet is a registered employer. You Will: - Serve as a trusted advisor to enterprise customers, CISOs, CIOs, and guiding them on Smartsheet security, compliance, and risk management. - Evaluate customer infrastructure diagrams and data flows, and how Smartsheet can help with automation without compromising security. - Present scanning results (NIST 800-53 gaps, vulnerability scans, DAST/pen test, IaC scans) to customers including walking through remediations. Help customers interpret scan results and develop deviation rationales for findings that can't be directly remediated. - Bridge the gap between FedRAMP, NIST 800-53 control language and Smartsheet implementation. Explain what NIST 800-53 controls mean in terms of Terraform configs, Kubernetes manifests, CI/CD pipelines and cloud configuration of Smartsheet across AWS and GCP. - Provide executive-level support during major customer security incidents and ensure lessons learned inform improvements. Understand and adhere to legal, regulatory and compliance requirements while working on sensitive security incidents. - Represent our cloud and AI security strategy at industry events, conferences, and customer councils. - Capture new business by responding to complex customer security questionnaires and technical inquiries using automation and AI tooling, ensuring security-related impediments to closing deals are removed efficiently. - Work alongside product engineering and Corporate IT to define technical specs for security features and protective measures that meet evolving customer requirements. - Translate customer security concerns and regulatory needs into clear technical problem definitions for internal teams. - Create and distribute technical assets (white papers, solution code, blog posts, and video demonstrations). You Have: - Strong analytical and problem solving skills - Ability to explain CI/CD and SDLC best practices and how Smartsheet is deployed. - Hands-on experience with AAA implementations (SSO, IdP, MFA enforcement, session management, etc.). - Hands-on experience with enterprise system and application integrations, and with security tooling such as EDR, VPNs, Vulnerability scanners, CSPM, and SIEM/CASB. - 5+ years of total experience in cyber security, specifically within security engineering, security architecture, or sales engineering. - Familiarity with NIST 800-53, ISO, SOC 2, FedRAMP, GDPR, and HIPAA. - Excellent written and verbal communication skills, with the ability to influence stakeholders at all levels and create external-facing technical content. - Bachelor’s degree in a related field or equivalent experience, and/or professional certifications such as CISSP, CCSP, GCSA, CISA, or CRISC. - Experience conducting security reviews and threat modeling on infrastructure, software, and services. Current US Perks & Benefits: - Medical/vision and dental coverage options for full-time employees - 401k Match to help you save for your future (50% of your contribution up to the first 6% of your eligible pay) - Monthly stipend to support your work and productivity - Flexible Time Away Program, plus Sick Time Off - US employees are automatically covered under Smartsheet-sponsored life insurance, short-term, and long-term disability plans - US employees receive 12 paid holidays per year - Up to 24 weeks of Parental Leave - Personal paid Volunteer Day to support our community - Opportunities for professional growth and development including access to Udemy online courses - Company Funded Perks, including a counseling membership, local retail discounts, and your own personal Smartsheet account - Teleworking options from any registered location in the U.S. (role specific) Smartsheet provides a competitive base salary range for roles that may be hired in different geographic areas we are licensed to operate our business from. Actual compensation is determined by several factors including, but not limited to, level of professional, educational experience, skills, and specific candidate location. In addition, this role will be eligible for a market competitive incentive opportunity. US Base Salary Pay Range $145,000—$193,750 USD Get to Know Us: At Smartsheet, your ideas are heard, your potential is supported, and your contributions have real impact. You’ll have the freedom to explore, push boundaries, and grow beyond your role. We welcome diverse perspectives and nontraditional paths—because we know that impact comes from individuals who care deeply and challenge thoughtfully. When you’re doing work that stretches you, excites you, and connects you to something bigger, that’s magic at work. Let’s build what’s next, together. Equal Opportunity Employer: Smartsheet is an Equal Opportunity (EEO) employer committed to fostering an inclusive environment with the best employees. It is our policy to provide equal employment opportunities to all qualified applicants in accordance with applicable laws in the US, UK, Australia, Germany, Costa Rica, Japan, Bulgaria, and India. All qualified applicants will receive consideration without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, protected veteran or disabled status, or genetic information. If there are preparations we can make to help ensure you have a comfortable and positive interview experience, please let us know. #LI-Remote

United States
$145K - $193K / year
Harmonia Holdings Group, LLC logo

Security Control Assessor

Harmonia Holdings Group, LLC

Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: Recognized as a Top 20 "Best Place to Work in Virginia" Recipient of Department of Labor's HireVets Gold Medallion Great Place to Work Certification for five years running A Virginia Chamber of Commerce Fantastic 50 company A Northern Virginia Technology Council Tech 100 company Inc. 5000 list of fastest growing companies for eleven years Two-time SBA SBIR Tibbett's Award winner Virginia Values Veterans (V3) Certification

Security Engineer101 days ago
OtherRemoteTeam 201-500

Harmonia Holdings Group, LLC is an award-winning, rapidly growing federal government contractor committed to providing innovative, high-performing solutions to our government clients and focused on fostering a workplace that encourages growth, initiative, creativity, and employee satisfaction. Description Title: Security Control Assessor Location: Remote Terms: Full-time Clearance: Public Trust Travel: <10% Position Description We have an opening for a full-time Security Control Assessor to join our talented, dynamic team in support of the Department of Veterans Affairs. As a Security Control Assessor, you will be trusted to support the delivery of our cybersecurity solutions and services. In this role, you will be a part of a security control assessment team working on the tasks outlined below. Veterans are encouraged to apply. Responsibilities: - Conducts independent comprehensive assessments of the management, operational, and technical security controls and control enhancements employed within or inherited by an information technology (IT) system to determine the overall effectiveness of the controls (as defined in NIST SP 800-37). - Plans and conducts security authorization reviews and assurance case development for initial installation of systems and networks. - Reviews authorization and assurance documents to confirm that the level of risk is within acceptable limits for each software application, system, and network. - Verifies that application software/network/system security postures are implemented as stated, document deviations, and recommend required actions to correct those deviations. - Develops security compliance processes and/or audits for external services (e.g., cloud service providers, data centers). - Performs security reviews and identifies security gaps in security architecture resulting in recommendations for inclusion in the risk mitigation strategy. - Performs risk analysis (e.g., threat, vulnerability, and probability of occurrence) whenever an application or system undergoes a major change. - Provide input to the Risk Management Framework process activities and related documentation (e.g., system life-cycle support plans, concept of operations, operational procedures, and maintenance training materials). Requirements - Bachelor's degree in computer science, electronics engineering or other engineering or technical discipline is required, and will accept relevant experience in lieu of degree. - 1+ years hands-on experience with Cybersecurity policy, risk management, or security and privacy control assessments. - Knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation). - Knowledge of system and application security threats and vulnerabilities. - Knowledge of Personally Identifiable Information (PII), Payment Card Industry (PCI), and Personal Health Information (PHI) data security standards. Desired - Experience with security control assessments within the VA using the NIST Risk Management Framework (RMF) is a plus. - Certifications such as SCA and CISA are a plus. - Exceptional written and verbal communication skills. - Strong planning, organizational, and time management skills. - Exceptional analytical and conceptual thinking skills. - Ability to work collaboratively with a team of peers. ___________________________________________________________________________________________________________ Here at Harmonia we are pleased to have been repeatedly recognized for our outstanding work culture, the innovative work we do, and the employees on our team who make a difference each day. Some of these recognitions include: - Recognized as a Top 20 "Best Place to Work in Virginia" - Recipient of Department of Labor's HireVets Gold Medallion - Great Place to Work Certification for five years running - A Virginia Chamber of Commerce Fantastic 50 company - A Northern Virginia Technology Council Tech 100 company - Inc. 5000 list of fastest growing companies for eleven years - Two-time SBA SBIR Tibbett's Award winner - Virginia Values Veterans (V3) Certification We recognize that every bit of our success is the result of our teams of hard-working, motivated, and innovative professionals who are proud to call themselves part of the Harmonia family! In addition to competitive compensation, a family-focused culture, and a dynamic, productive work environment, we offer all full-time employees a variety of benefits including, but not limited to - Traditional and HSA- eligible medical insurance plans - 100% employer-paid dental and vision insurance options - 100% employer-sponsored STD, LTD, and life insurance - 5% 401(k) company matching - Flexible-schedules and teleworking options - Paid holidays and PTO Accrual Plans - Paid Parental Leave - Professional development and career growth opportunities - Team and company-wide events, recognition, and appreciation-- and so much more! Check out our LinkedIn, Facebook, and Instagram to find out a little more about who we are and if we are the right next step for your career! Harmonia is an Equal Opportunity Employer providing equal employment opportunity to all employees and applicants for employment without regard to race, color, religion, national origin, age, gender, gender identity, sexual orientation, disability, or genetics. Harmonia does and will take affirmative action to employ and advance in employment individuals with disabilities and protected veterans. To perform the above job successfully, an individual must possess the knowledge, skills, and abilities listed; meet the education and work experience required; and must be able to perform each essential duty and responsibility satisfactorily. Other duties in addition to those listed may be assigned as necessary to meet business needs. Reasonable accommodation will be made to enable an applicant with a disability to successfully apply for and/or perform the essential duties of the job. If you are in need of an accommodation, please contact HR@harmonia.com.

United States
Job Closed

Chief Information Security Officer (CISO)

Nymbus, Inc.

Nymbus, Inc. provides banking technology solutions that enable financial institutions to automate workflows and create user-friendly digital banking systems. With an innovative app

Security Engineer101 days ago

ABOUT NYMBUS: Nymbus is a modern fintech company delivering technology solutions to banks and credit unions. We operate in a highly regulated environment and partner closely with financial institutions to power modern core transformations and broader outsourced digital banking brand solutions. As we continue to scale, we are seeking a strong, decisive Chief Information Security Officer (CISO) to lead and evolve our enterprise security program with confidence and an ability to articulate strong positioning. A strong candidate for this role would avoid passive decisioning and would lead with knowledge and expertise when articulating decisions surrounding our overall security posture. WORK ENVIRONMENT: Nymbus is a remote-first organization. This position is fully remote; however, occasional travel may be required for client meetings or designated team gatherings. POSITION SUMMARY: This is a strategic and operational executive leadership role. We are looking for a CISO who brings deep banking regulatory expertise (NIST, FFIEC, PCI, SOC) and can proactively assess and continue to enhance a security program in a fast-moving fintech environment supporting banking services for regulated financial institutions. This role requires someone who: - Understands regulated financial services environments. - Has a strong skillset for pivoting to address any security gaps identified, influencing and leading any remediation needed. - Forms independent, informed perspectives on risk. - Moves initiatives forward without heavy executive oversight. - Partners effectively with technology, product, and operations leaders. - Balances innovation velocity with sound risk management. - Is comfortable operating in a company leaning into AI in banking. - Drives timely remediation of identified risks through disciplined follow-through and executive accountability. - This is not a policy-only oversight role. We need a strategic builder, operator, and leader. ESSENTIAL JOB FUNCTIONS/RESPONSIBILITIES: Security Strategy & Program Maturity - Own and continuously mature the enterprise Information Security Program. - Align controls and architecture with NIST CSF, NIST 800-53, FFIEC guidance, PCI DSS, and SOC requirements. - Conduct proactive program assessments and identify security gaps before they become issues, working cross-functionally to execute upon risk mitigation objectives. - Develop and execute a multi-year security roadmap aligned to business growth and regulatory expectations. - Present clear, risk-based recommendations to executive leadership and the Board. Operational Execution - Translate strategy into measurable execution plans with defined milestones. - Drive remediation of audit, regulatory, and penetration testing findings. - Ensure strong incident response, vulnerability management, and change management and development programs. - Implement metrics that demonstrate real risk reduction and program effectiveness. - Deliver results. Security Team Leadership & Operational Oversight - Lead and develop a high-performing Information Security team. - Provide clear direction, prioritization, and performance accountability across detection engineering, vulnerability management, application security, and security architecture functions. - Oversee operation and optimization of core security tooling, budget, and contract renewal management, including SIEM/XDR platforms (e.g., Wazuh), vulnerability management (e.g., Tenable), application security testing (e.g., Veracode), and related monitoring and detection systems. - Ensure security diagrams, architecture artifacts, and workflow documentation accurately reflect implemented controls and are audit-ready. - Establish measurable performance objectives and operational KPIs for the security team in collaboration with teams responsible for execution (MTTR, vulnerability remediation SLAs, detection coverage, control validation, etc.). - Drive automation and continuous improvement across monitoring, alert triage, vulnerability remediation, and DevSecOps integration. - Build a culture of ownership, urgency, and technical depth cross-functionally associated with the program. - Maintain sufficient hands-on familiarity with security tooling and architecture to effectively challenge assumptions, validate control effectiveness, and provide technical direction when needed. - Assist in the management of Nymbus’ risk log with the ability to identify, manage, and make security risk recommendations. Technology & Product Partnership - Develop a deep understanding of our platform, cloud architecture (AWS/GCP), integrations, and AI initiatives. - Partner with the CTO, engineering, product, NOC, and operations leaders. - Ensure strong embedded security controls into SDLC, DevOps, and cloud-native development practices. - Enable secure innovation rather than slow it down. Regulatory & Client Engagement - Serve as the subject matter expert in banking security and regulatory expectations. - Lead SOC/PCI audit readiness and regulatory exam preparedness. - Engage confidently with regulators, auditors, and bank and credit union clients and prospects. AI Governance & Emerging Risk - Establish governance frameworks for secure and responsible AI usage. - Assess model risk, data protection, and security implications of AI-driven products. - Stay ahead of evolving regulatory expectations in AI and fintech. QUALIFICATIONS: - 10+ years of progressive experience in information security leadership. - Significant experience in banking, financial services, or regulated fintech. - Deep knowledge of: - NIST CSF & NIST 800-53 - FFIEC guidance - PCI DSS - SOC audits - Experience leading cloud-first security programs (AWS and/or GCP). - Demonstrated ability to independently assess risk and make defensible decisions. - Strong executive communication and cross-functional leadership skills. - Experience operating in high-growth or fast-changing environments. - Preferred certifications: CISSP, CISM, CRISC or equivalent. WHAT SUCCESS LOOKS LIKE: Within the first ninety days, the CISO will: - Deliver a clear assessment of current security maturity and risk posture. - Execute against agreed remediation priorities on time. - Establish strong partnerships across engineering, product, and operations. - Build executive confidence through decisive, informed risk leadership. - Position security as a strategic enabler of innovation. SALARY & BENEFITS: - Annual Cash Bonus and Equity Options commensurate with the role level and experience. - Fully Remote. - 401(k) plan. - Insurance - Health, Dental and Vision. - Time Off. Ready to join? We invite you to watch this video and learn who we are and how we build and innovates together! Let’s Go!

United States
$100K - $120K / year