Job Closed
This listing is no longer active.
Information Systems Security Officer
Location
United States
Posted
97 days ago
Salary
$125K - $180K / year
Seniority
Senior
Job Description
Information Systems Security Officer
CrowdStrike
• Establish, automate, and maintain the Continuous Monitoring (ConMon) strategy from the System Security Plan (SSP) • Participate in the vulnerability intelligence on-call rotation for 24/7 expert analysis and rapid response • Manage the full Authorization to Operate (ATO) lifecycle, including preparing documentation for initial and continuous security authorizations • Coordinate annual Third-Party Assessment Organization (3PAO) audits for successful outcomes • Manage the POA&M process, perform risk-based security impact analyses, and track vulnerability remediation to verified closure • Execute security control analyses, recommending infrastructure enhancements based on threat landscape changes • Serve as the expert authority on cloud security architecture, providing guidance and implementing defense-in-depth strategies for federal workloads • Develop and maintain cloud security architecture documentation (diagrams, data flows, controls) • Evaluate architectural changes for security impact and guide secure DevSecOps practices in federal clouds • Manage the Change Control Board (CCB) and Significant Change Request (SCR) process, providing authoritative security guidance • Maintain the System Security Plan (SSP) and all security authorization packages • Serve as the primary security point-of-contact for incident response, managing resolution from initial detection through root cause analysis
Job Requirements
- Bachelor's degree (or equivalent experience) in a relevant technical field (Engineering, Computer Science, Cybersecurity, IT); advanced degree preferred
- Must hold a DoD 8140/8570 IAM Level II Baseline Certification (CGRC, CASP+, CISM, CISSP/Associate, or CCISO)
- U.S. Citizenship and residency required for work on sensitive government systems
- Expert knowledge of NIST SP 800-53, RMF, FedRAMP, and FISMA, with significant hands-on experience implementing and assessing controls in cloud environments (e.g., AWS GovCloud)
- Proven success managing 3PAO audits and maintaining a sophisticated Continuous Monitoring (ConMon) program in federal settings
- Advanced technical familiarity with modern cloud infrastructure and security tools (e.g., SIEM, Endpoint Security, CI/CD, vulnerability management)
- Exceptional analytical, communication, and documentation skills essential for a highly regulated environment
- Experience performing comprehensive cyber architecture reviews, identifying weaknesses, and recommending improvements
Benefits
- Market leader in compensation and equity awards
- Comprehensive physical and mental wellness programs
- Competitive vacation and holidays for recharge
- Paid parental and adoption leaves
- Professional development opportunities for all employees regardless of level or role
- Employee Networks, geographic neighborhood groups, and volunteer opportunities to build connections
- Vibrant office culture with world class amenities
- Great Place to Work Certified™ across the globe
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Cybersecurity Lead
GuidehouseSolving big problems, building trust in society, and empowering our clients to shape the future.
Job Family: Cyber Consulting Travel Required: Up to 10% Clearance Required: Ability to Obtain Secret - The Senior Cybersecurity Lead will design, manage, and maintain the security posture for a multi-system Identity and Credential Management solution. This role will lead cross functional teams of infrastructure engineers, application specialists, analysts, and more to design, implement, and test IT security controls and cybersecurity operational best practices. What You Will Do: - Apply fundamental cybersecurity principles and concepts for a large DoD IT program - Develop and implement a plan to achieve cybersecurity and RMF objectives across the lifecycle of the program, to include close coordination across program workstreams and Government stakeholders - Maintain cybersecurity implementation plans, milestones, schedules, and resourcing requirements across cross-functional teams. - Apply NIST Risk Management Framework (RMF), NIST SP 800-53 controls, Assessment and Authorization processes for both on-prem and cloud-based systems, POA&M management, and System Security Plan development and maintenance. - Work with senior members of the program and client organization to ensure that overall cybersecurity program and project direction, strategy and expectations are met. - Understand of Governance Risk and Compliance (GRC) requirements, standards, and guidelines governing security within the Federal Government (e.g., NIST publications, FISMA, and OMB memoranda) and aligning IT with business objectives to effectively manage risk. - Design and implement system security plans and policies, such as account management policies or auditing policies. - Perform cybersecurity risk management, research and development, and leading practices. - Gather and organize technical information about an organization's mission goals and needs, existing security products, and ongoing programs in cybersecurity. - Develop strategies, roadmaps, assessments, and policies. - Work with solution architects for security requirements on network architecture - Conduct and lead risk assessments and managing risks. Develop and implement cybersecurity policies and procedures. What You Will Need: - Minimum TEN (10) years of experience in Cybersecurity. - Experience applying fundamental cybersecurity principles and concepts to tasks and projects. - Experience implementing multiple end-to-end packages using the Risk Management Framework (RMF) - Expert level experience with NIST 800-53 security controls - Cybersecurity certification - CISM, CISSP, or Security+ - Demonstrated ability leading successful teams and working in challenging situations. - Strong written and oral communication skills, and demonstrates leadership role with clients and fellow team members. - Strong client leadership skills and ability to recognize opportunities for improvement to existing or future capabilities. - Ability to lead teams to complete projects with attention to detail on tight timelines. - Assures high quality work by taking advantage of learning opportunities and self-motivated. - Must be able to OBTAIN and MAINTAIN a Federal or DoD "SECRET" security clearance; candidates must obtain approved adjudication of clearance prior to onboarding with Guidehouse. Candidates with an ACTIVE "SECRET" or higher-level clearance are preferred. - Understanding of identity management and role-based access controls What Would Be Nice To Have: - Experience working with Information Assurance tools such as DISA Enterprise Mission Assurance Support Service (eMASS). - FIVE (5) years of DoD experience - Experience implementing RMF in a DoD environment to include overseeing the full RMF lifecycle and obtaining an ATO - Experience working with networking, logging, server, and workstation security configuration. - Experience managing complex system-of-systems security postures, such as multi-application, multi-account, and multi-asset systems. - Experience with Identity Credential Access Management (ICAM), FIPS 201-3, or federal ICAM programs. The annual salary range for this position is $130,000.00-$216,000.00. Compensation decisions depend on a wide range of factors, including but not limited to skill sets, experience and training, security clearances, licensure and certifications, and other business and organizational needs. What We Offer: Guidehouse offers a comprehensive, total rewards package that includes competitive compensation and a flexible benefits package that reflects our commitment to creating a diverse and supportive workplace. Benefits include: - Medical, Rx, Dental & Vision Insurance - Personal and Family Sick Time & Company Paid Holidays - Position may be eligible for a discretionary variable incentive bonus - Parental Leave and Adoption Assistance - 401(k) Retirement Plan - Basic Life & Supplemental Life - Health Savings Account, Dental/Vision & Dependent Care Flexible Spending Accounts - Short-Term & Long-Term Disability - Student Loan PayDown - Tuition Reimbursement, Personal Development & Learning Opportunities - Skills Development & Certifications - Employee Referral Program - Corporate Sponsored Events & Community Outreach - Emergency Back-Up Childcare Program - Mobility Stipend About Guidehouse Guidehouse is an Equal Opportunity Employer–Protected Veterans, Individuals with Disabilities or any other basis protected by law, ordinance, or regulation. Guidehouse will consider for employment qualified applicants with criminal histories in a manner consistent with the requirements of applicable law or ordinance including the Fair Chance Ordinance of Los Angeles and San Francisco. If you have visited our website for information about employment opportunities, or to apply for a position, and you require an accommodation, please contact Guidehouse Recruiting at 1-571-633-1711 or via email at RecruitingAccommodation@guidehouse.com. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodation. All communication regarding recruitment for a Guidehouse position will be sent from Guidehouse email domains including @guidehouse.com or guidehouse@myworkday.com. Correspondence received by an applicant from any other domain should be considered unauthorized and will not be honored by Guidehouse. Note that Guidehouse will never charge a fee or require a money transfer at any stage of the recruitment process and does not collect fees from educational institutions for participation in a recruitment event. Never provide your banking information to a third party purporting to need that information to proceed in the hiring process. If any person or organization demands money related to a job opportunity with Guidehouse, please report the matter to Guidehouse’s Ethics Hotline. If you want to check the validity of correspondence you have received, please contact recruiting@guidehouse.com. Guidehouse is not responsible for losses incurred (monetary or otherwise) from an applicant’s dealings with unauthorized third parties. Guidehouse does not accept unsolicited resumes through or from search firms or staffing agencies. All unsolicited resumes will be considered the property of Guidehouse and Guidehouse will not be obligated to pay a placement fee.
Senior Security Detection Engineer (F/M/X)
Mondelēz InternationalWe’re a house of incredible brands providing people with the right snack, for the right moment, made the right way.
Job Description Are You Ready to Make It Happen at Mondelēz International? Join our Mission to Lead the Future of Snacking. Make It Uniquely Yours. Role Overview We are seeking a skilled and motivated Senior Security Detection Engineer to join our security team. In this role, you will design, build, and maintain detection content to identify and mitigate security threats across enterprise environments. You will work closely with threat intelligence, threat hunting, and incident response teams to translate adversary behavior into high-fidelity detections, proactively identify detection gaps, and improve detection coverage across the organization. This is a hands-on technical role focused on engineering, tuning, and operationalizing detection capabilities, with opportunities to influence detection strategy and collaborate across security and engineering teams. What You Will Bring / Key Responsibilities - Design, develop, and maintain detection rules, alerts, and analytics to identify cybersecurity threats across endpoints, network, identity, cloud, and application platforms. - Collaborate with threat intelligence, threat hunting, and security operations teams to understand emerging threats and translate TTPs into actionable detections. - Continuously monitor the threat landscape and proactively recommend improvements to detection coverage and methodology. - Validate, test, and tune detection content to reduce false positives and improve accuracy, performance, and signal-to-noise ratio. - Partner with incident response teams to provide detection insights, improve alert fidelity, and support investigation workflows. - Maintain and enhance the organization’s detection repository within SIEM and detection platforms, ensuring content stays current with evolving attack techniques. - Develop and refine Data Loss Prevention (DLP) detection policies and monitoring use cases to protect sensitive data and support compliance requirements. - Identify detection gaps and raise risks, working with engineering and security stakeholders to prioritize remediation and improvements. - Stay current on cybersecurity tools, frameworks, and adversary techniques to continuously evolve detection engineering practices. - Contribute technical guidance and peer mentorship, helping uplift detection quality and engineering standards across the team. Additional Job Description More About This Role This role is ideal for a hands-on detection engineer who enjoys building and tuning security analytics, collaborating across teams, and proactively improving security posture. You will have meaningful influence on detection coverage and technical direction without formal people management responsibilities. Job-Specific Requirements - Bachelor's degree in computer science, Information Security, or a related field (or equivalent practical experience). - 4–8+ years of experience in cybersecurity with a strong focus on detection engineering, threat hunting, SOC operations, or incident response. - Experience working with or alongside Red Team/Purple Team activities. - Strong knowledge of SIEM platforms, log pipelines, and detection engineering workflows. - Proficiency in scripting or programming languages such as Python, PowerShell, or Bash. - Familiarity with adversary tactics, techniques, and procedures (TTPs), MITRE ATT&CK, and detection engineering frameworks. - Experience with cloud environments and cloud-native attack/detection strategies (e.g., AWS, Azure, GCP). - Strong analytical and problem-solving skills with a creative approach to detection design. - Excellent collaboration and communication skills with the ability to work cross-functionally with security and engineering teams. - Relevant certifications (e.g., GCDA, GCFA, GCFR, GCIH, GREM, OSCP, CISSP) are a plus but not required. - Experience with Version Control Systems (VCS) (GitHub) - Experience working with SIGMA, YARA, and detection query language structures. Relocation Support Available? No Relocation support available Business Unit Summary We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is right for you, we encourage you to apply! Our people make all the difference in our succes Mondelēz International is an equal opportunity employer and all qualified applicants will receive consideration for employment without regard to race, color, religion, gender, sexual orientation or preference, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. Excited to grow your career? We value our talented employees, and whenever possible strive to help one of our associates grow professionally before recruiting new talent to our open positions. If you think the open position you see is right for you, we encourage you to apply! IF YOU REQUIRE SUPPORT TO COMPLETE YOUR APPLICATION OR DURING THE INTERVIEW PROCESS, PLEASE CONTACT THE RECRUITER Job Type Regular Information Security Technology & Digital
Senior Cybersecurity Engineer
OdysseyOdyssey sits at the intersection of GovTech, EdTech, and FinTech. We are a public-sector operator, a technology company, and a program delivery partner all at once. The work we do is civic infrastructure — it determines whether families can access life-changing educational opportunities.
• Conduct comprehensive security assessments and vulnerability assessments of applications. • Perform software security evaluations, including code reviews and secure coding verification. • Utilize penetration testing tools to identify and validate vulnerabilities. • Develop and maintain threat models and execute security risk assessments. • Evaluate system security controls, identify vulnerabilities, and propose mitigation strategies. • Review applications against established vulnerability standards (OWASP Top 10). • Ensure deliverables align with DoD and Air Force cybersecurity policies. • Stay up to date with emerging security advisories and regulations. • Provide expert guidance on secure design principles and cloud security best practices. • Prepare detailed reports including assessment results and vulnerability findings.
Chief Information Security Officer – CISO
CEX.IOA leading cryptocurrency ecosystem. Our Licenses & Registrations: https://cex.io/legal-security
• Lead the implementation and maintenance of the ICT risk management framework to meet CNMV and ESMA standards • Supervise and control ICT services provided by CEX.IO Ltd (UK), including cloud infrastructure, software development, and security operations • Identify, assess, and mitigate technological risks. Conduct annual reviews of the Business Impact Analysis (BIA) and the ICT Risk Assessment • Act as the ultimate authority for initiating the Incident Response Plan (IRP) for high and critical levels. Coordinate the notification of major incidents to the CNMV within mandated timelines (4h/72h/30 days) • Supervise critical ICT third-party service providers, with a focus on monitoring and ensuring compliance with agreed SLAs, RPOs, and RTOs • Oversee the security of crypto-asset custody solutions (Proprietary V2/V3 and external sub-custodians, like Coinbase). Ensure the integrity of MPC (Multi-Party Computation), HSM (Hardware Security Modules), and multisig signing processes. • Supervise the Secure Software Development Life Cycle and validate security testing in pre-production (UAT) environments before deployment • Approve and collaborate on operational resilience testing plans and specific tests regarding Distributed Ledger Technology (DLT) • Maintain a unified and centralized inventory of CEX.IO systems and infrastructure




