Job Closed
This listing is no longer active.
Founded in 2023 and headquartered in Albuquerque, New Mexico, Crogl is a fast-growing cybersecurity company built by seasoned security professionals from both t
Community Lead, Security
Location
United States
Posted
87 days ago
Salary
0
Seniority
Senior
Job Description
Community Lead, Security
Crogl
• Build and manage the practitioner community presence across key platforms • Facilitate technical conversations and represent Crogl at industry events • Develop practitioner-grade skills and use cases inside Crogl • Test new features and report user feedback during product planning cycles • Create realistic demo scenarios and produce hands-on content for prospects
Job Requirements
- 7+ years in the security or observability space in a relevant role
- Direct hands-on experience with SIEM platforms (e.g., Splunk, CrowdStrike, etc.)
- Demonstrated ability to build community through content, programs, and events
- Working knowledge of common search and query languages (e.g., SPL, KQL)
- Comfortable with scripting in at least one language (Python preferred)
- Experience with cloud infrastructure basics (AWS preferred)
- Familiarity with CI/CD concepts and automation tooling is a plus
- Strong communication skills
Benefits
- 20-25% travel to conferences, field events, and team offsites
- Remote-first company
- Work async across time zones
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description The Cyber Security Engineer provides hands-on cybersecurity engineering and advisory services to Meriplex clients. This role works directly with client environments to design, deploy, configure, and support security technologies across infrastructure, cloud services, networks, and endpoints. The engineer partners with clients to understand their technical environment, security maturity, and business objectives, and delivers solutions that improve security outcomes while aligning with operational needs. This role also provides subject-matter expertise, documentation, and guidance to both clients and internal teams supporting client engagements. - Design and secure security infrastructure to ensure a robust and resilient security posture. - Perform complex deployments of security technologies. - Execute information security activities such as vulnerability management, application development security, business continuity, networking, risk management, etc. - Collaborate with cross-functional teams to integrate security controls and protocols into the client's infrastructure and applications. - Develop and maintain security documentation, including architecture diagrams, standard operating procedures, and incident response playbooks. - Understand various security framework standards and compliance requirements, such as NIST 800-53, ISO 270001, NIST CSF, CIS. - Stay up-to-date with emerging security threats, vulnerabilities, and industry trends, and proactively recommend and implement countermeasures to enhance clients’ security posture. - Provide technical expertise and guidance to clients and internal teams on security best practices, technologies, and regulatory compliance requirements. - Research, evaluate, and drive next generation security technologies and solutions to solve organizational needs. - Assist in incident response activities such as firewall log review, firewall configuration, SIEM review, XDR review. Qualifications - Strong customer service skills. - Strong networking and security knowledge. - Ability to apply secure system design tools, methods, and techniques. - Strong interpersonal skills and team-oriented attitude. - Coachable and able to turn feedback into results moving forward. - Ability to apply network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth). - Superior analytical and critical thinking skills. - Understanding of how information travels. - Familiar with incident response language. - Well-rounded technical knowledge in Windows, Mac, Linux OS, VMware, Fortinet, SonicWALL, Palo Alto preferred. - Strong experience with EDR/XDR technology such as Sentinel One and Crowdstrike. - Strong understanding of a range of compliance, regulatory, and legal requirements and relevant principles, best practices, and standards across multiple industries. - Knowledge of the MITRE ATT&CK framework and Cyber Kill Chain. - Familiarity with scripting languages such as bash, PowerShell, python, KQL. Requirements - 5+ years of security industry experience or equivalent skill level. - 5+ years of experience managing Active Directory and Windows Server. - Bachelor’s degree in a relevant field is a plus but not required. - Experience with systems administration and network infrastructure is required. - Previously assessed, developed, implemented, operationalized, and documented comprehensive security technologies and processes. Certifications - Security+, CCSP or similar desired. - (ISC)² Certified Information Systems Security Professional (CISSP) preferred. Physical Demands Sedentary Work – Exerts up to 10 pounds of force occasionally, a negligible amount of force frequently, and/or constantly having to lift, carry, push, pull or otherwise move objects, including the human body. Sedentary work involves sitting most of the time. Disclaimer The above information in this description has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.
This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description VulnCheck is looking for a Senior Exploit Developer with a background in reverse engineering and exploit development. This role is on our Initial Access Intelligence team, which delivers exploits and related artifacts designed to give VulnCheck customers visibility into exploitation from exposure through execution and detection. You’ll work with a seasoned team of hackers and threat researchers to help global enterprises, governments, and intelligence firms defend against emerging threats and get ahead of the attacker curve. This is a 100% remote role based in the United States, though we are primarily looking for candidates in Massachusetts, Maryland, and Texas. What You’ll Do - Reverse engineering software to discover the root cause of both zero-day and n-day vulnerabilities - Writing original software exploits for initial access vulnerabilities using VulnCheck’s open-source go-exploit framework, including when there are no public PoCs or vulnerability details - Implementing detections (such as Suricata & Snort signatures, YARA rules, etc.) that accurately identify initial access vulnerabilities being exploited on the wire - Writing Attack Surface Management (ASM) queries (e.g., Shodan, Census, FOFA, & ZoomEye) to find vulnerable systems likely to be targeted - Contributing to technical blogs and/or conference talks (optional) on exploit development and attack trends Qualifications - Prior experience with exploit development for RCE / initial access vulnerabilities (that do not require authentication to exploit) - Comfort with reverse engineering and patch diffing - Experience with Git-based project development - Experience working on technical projects remotely, alone, and on small teams Preferred Qualifications - Prior cybersecurity work experience (at a vendor or in government) - Ability to share example exploit code written - Some experience with programming / software development is helpful - Experience writing technical blogs and/or giving conference talks is a big plus Benefits - Competitive salary with employee equity program - Health, dental, and vision coverage - Unlimited PTO + All federal holidays observed - 401(k) program - 100% match on the first 3%, then 50% of the next 3-5% of compensation - Short and long-term disability coverage - Remote friendly environment with flexibility - Expense reimbursement for home internet and phone - Ongoing professional development, coaching, and learning resources - Opportunities for career advancement within a fast-growing team Company Description VulnCheck is transforming vulnerability intelligence by helping security teams act faster and with more confidence. Built on over two decades of cybersecurity experience, our team of experts understands the intricacies of vulnerabilities, their exploitation in the wild, and how to leverage this data to build more effective cybersecurity products that produce better outcomes for organizations. VulnCheck gives organizations a tactical advantage by providing best-in-class exploit & vulnerability intelligence information. We have a sense of duty to protect the critical infrastructure we rely on including medical devices, power grids and telecommunication networks. We were founded in 2021 in Lexington, Massachusetts. VulnCheck has a transparent, collaborative, and supportive culture - we are looking for people who have a growth mindset, are curious and innovative. Our team is smart, but humble, hardworking, and supportive. VulnCheck is proud to be an Equal Employer Opportunity employer. We do not discriminate based upon race, religion, color, national origin, gender (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. VulnCheck is committed to working with and providing reasonable accommodations to applicants with physical and mental disabilities.
Principal Application Security Engineer – AI & Agentic Systems
CVS HealthBringing our heart to every moment of your health.
We’re building a world of health around every individual — shaping a more connected, convenient and compassionate health experience. At CVS Health®, you’ll be surrounded by passionate colleagues who care deeply, innovate with purpose, hold ourselves accountable and prioritize safety and quality in everything we do. Join us and be part of something bigger – helping to simplify health care one person, one family and one community at a time. Position Summary Development, Standards & Secure Design - Lead development and enforcement of application and AI security policies, standards, and guardrails, embedding security-by-design across both traditional and AI-driven systems. - Establish secure design patterns for AI agent frameworks, covering prompt management, tool invocation, memory handling, autonomy boundaries, and escalation controls. - Promote organization-wide awareness of AI-specific risks such as model misuse, prompt injection, data leakage, and unsafe agent behavior. AI & Agentic Security Architecture - Serve as the principal SME for securing AI-enabled applications and agentic system architectures. - Architect and review secure designs for systems leveraging LLMs/foundation models, autonomous and semi-autonomous agents, RAG pipelines, and tool‑using or decision‑making workflows. - Define identity, authorization, data access, and observability controls specific to agentic environments while partnering closely with AI platform, product, and data teams to ensure responsible AI delivery. Collaboration, Leadership & Influence - Influence engineering and product teams to integrate secure engineering practices and align security with compliance, privacy, and responsible AI initiatives. - Advise senior leadership on AI security implications, architectural decisions, and long-term strategy while shaping roadmaps that anticipate emerging AI threats and regulatory requirements. Testing, Analysis & Risk Management - Lead advanced security testing and risk assessments for AI-enabled systems, including threat modeling of agent workflows, abuse/misuse analysis, and secure design reviews of AI pipelines. - Evaluate and guide adoption of new AI security tools, ensuring protections maintain confidentiality, integrity, availability, and responsible data use. Operational Response & Continuous Improvement - Provide senior technical leadership during incidents involving application or AI systems, guiding response strategies for misuse, data exposure, and autonomous failures. - Translate operational learnings into improved security architecture, controls, and system resilience. Mentorship, Innovation & Strategy - Mentor senior and principal engineers to elevate security maturity across the organization. - Contribute to research and evaluation of emerging AI security practices and play a key role in shaping the long-term application and AI security roadmap, advocating for security as a strategic accelerator for AI adoption. Required Qualifications - 10+ years of experience designing, building, and securing large-scale applications and platforms. - 7+ years of expertise in application security, including threat modeling, secure design, and vulnerability management. - 7+ years of programming experience in one or more languages such as Python, Java, JavaScript, C#, or Go. - 5+ years of experience with AI-enabled systems, including LLM-based applications or agentic workflows. - 5+ years of experience public cloud platforms (AWS, Azure, and/or GCP) and modern application architectures. - 3+ years of experience with containerized, serverless, and microservice-based architectures. Preferred Qualifications - Hands-on experience securing AI agents, RAG pipelines, and tool-using LLM systems. - Proven ability to lead complex security initiatives from concept through enterprise-scale adoption. - Familiarity with AI governance, responsible AI principles, and emerging AI security standards. - Experience integrating security controls into CI/CD pipelines for AI and application workloads. - Strong understanding of compliance frameworks (PCI, HIPAA, NIST, HITRUST, CSA). - Experience influencing security strategy beyond a single team, including enterprise or platform-level impact. - Contributions to security research, open-source projects, or industry communities. Education - Bachelor’s degree or equivalent experience (High School Diploma and 4 years relevant experience) Pay Range The typical pay range for this role is: $144,200.00 - $288,400.00 This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company’s equity award program. Our people fuel our future. Our teams reflect the customers, patients, members and communities we serve and we are committed to fostering a workplace where every colleague feels valued and that they belong. Great benefits for great people We take pride in our comprehensive and competitive mix of pay and benefits – investing in the physical, emotional and financial wellness of our colleagues and their families to help them be the healthiest they can be. In addition to our competitive wages, our great benefits include: - Affordable medical plan options, a 401(k) plan (including matching company contributions), and an employee stock purchase plan. - No-cost programs for all colleagues including wellness screenings, tobacco cessation and weight management programs, confidential counseling and financial coaching. - Benefit solutions that address the different needs and preferences of our colleagues including paid time off, flexible work schedules, family leave, dependent care resources, colleague assistance programs, tuition assistance, retiree medical access and many other benefits depending on eligibility. For more information, visit https://jobs.cvshealth.com/us/en/benefits We anticipate the application window for this opening will close on: 03/18/2026 Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
FedRAMP Information System Security Officer / GRC Manager
IFSBe your best when it really matters. At the #MomentOfService
Company Description IFS is a billion-dollar revenue company with 7000+ employees on all continents. Our leading AI technology is the backbone of our award-winning enterprise software solutions, enabling our customers to be their best when it really matters–at the Moment of Service™. Our commitment to internal AI adoption has allowed us to stay at the forefront of technological advancements, ensuring our colleagues can unlock their creativity and productivity, and our solutions are always cutting-edge. At IFS, we’re flexible, we’re innovative, and we’re focused not only on how we can engage with our customers but on how we can make a real change and have a worldwide impact. We help solve some of society’s greatest challenges, fostering a better future through our agility, collaboration, and trust. We celebrate diversity and understand our responsibility to reflect the diverse world we work in. We are committed to promoting an inclusive workforce that fully represents the many different cultures, backgrounds, and viewpoints of our customers, our partners, and our communities. As a truly international company serving people from around the globe, we realize that our success is tantamount to the respect we have for those different points of view. By joining our team, you will have the opportunity to be part of a global, diverse environment; you will be joining a winning team with a commitment to sustainability; and a company where we get things done so that you can make a positive impact on the world. We’re looking for innovative and original thinkers to work in an environment where you can #MakeYourMoment so that we can help others make theirs. With the power of our AI-driven solutions, we empower our team to change the status quo and make a real difference. If you want to change the status quo, we’ll help you make your moment. Join Team Purple. Join IFS. Job Description IFS is expanding secure cloud capabilities to support U.S. Federal Civilian agencies, DoD, and the Defense Industrial Base. Responsibilities: - Support ongoing FedRAMP authorization including SSP, POA&M, evidence, and 3PAO coordination. - Manage and oversee NIST SP 800-53 compliance. - Oversee continuous monitoring, vulnerabilities, incidents. - Collaborate cross-functionally across various IFS teams. - Lead future FedRAMP system readiness. - Serve as a primary liaison with 3PAO during annual assessments. - Track and remediate findings within FedRAMP SLAs (30/90/180 days). - Develop and maintain security policies and procedures. - Support customer security questionnaires and audits. Success Criteria: - Achieve FedRAMP ATO. - Maintain high compliance posture. - Enable scalable governance for Defense programs. Travel: - Up to 10% travel for assessments and agency meetings Qualifications Required Qualifications: - 6+ years in ISSO, GRC, cybersecurity. - Expertise with FedRAMP, NIST SP 800-53, CMMC. - Experience with SSPs and security documentation. - Familiarity with AWS and Azure Gov Cloud. - U.S. Citizenship. - Strong documentation and technical writing skills - Ability to obtain and maintain security clearance Preferred Qualifications - DoD IL4/IL5 or DIB experience. - Certifications (CISSP, CISM, CISA, CAP, CCSP). - Experience with vulnerability scanning tools (Nessus, Qualys, ZAP, etc.) - Background in SaaS or cloud service provider environments Additional Information What We’re Offering - Salary Range: $150,000 to $200,000 plus bonus potential - Flexible paid time off, including sick and holiday - Medical, dental, & vision insurance - 401K with Company contribution - Flexible spending accounts - Life insurance and disability benefits - Tuition assistance - Community involvement and volunteering events M/F/Disabled/Vet VEVRAA Federal Contractor. We are a Drug-Free Workplace. Interested candidates should apply at: www.ifs.com/about/careers-at-ifs All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. VEVRAA Federal Contractor, Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. VEVRAA Federal Contractor, Equal Opportunity Employer All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran. VEVRAA Federal Contractor, Equal Opportunity Employer - IFS Referral Bonus Code: SH - Job Location: Remote


