Job Closed

This listing is no longer active.

Clever Care Health Plan

Clever Care was created to meet the unique needs of the diverse communities we serve. Our innovative benefit plans combine Western medicine with holistic Eastern practices, offering benefits that align with our members’ culture and values. We’re on a mission! Our rapid growth reflects our commitment to making healthcare accessible for underserved communities. At Clever Care, you’ll have the opportunity to make a real difference, shape the future of healthcare, and be part of a fast-moving, game-changing organization that celebrates diversity and innovation.

Cybersecurity Analyst

Location

United States

Posted

72 days ago

Salary

$80K - $95K / year

Seniority

Mid Level

Job Description

Cybersecurity Analyst

Clever Care Health Plan

Job DetailsJob Location: Huntington Beach Office - Huntington Beach, CA 92647Position Type: Full TimeSalary Range: $80,000.00 - $95,000.00 SalaryAre you ready to make a lasting impact and transform the healthcare space? We are one of Southern California’s fastest-growing Medicare Advantage plans with an incredible 112% year-over-year membership growth. Who Are We? ✨ Clever Care was created to meet the unique needs of the diverse communities we serve. Our innovative benefit plans combine Western medicine with holistic Eastern practices, offering benefits that align with our members’ culture and values. Why Join Us? 🏆 We’re on a mission! Our rapid growth reflects our commitment to making healthcare accessible for underserved communities. At Clever Care, you’ll have the opportunity to make a real difference, shape the future of healthcare, and be part of a fast-moving, game-changing organization that celebrates diversity and innovation. Job Summary Review, create and test effectiveness of Information Security Policies, procedures, and controls. Maintain Security Awareness program. Investigate incidents. Maintain evidence of controls tests to ensure effectiveness of the controls and streamline audits. Remote in California. Functions & Job Responsibilities · Listen to associate customers and anticipate their needs to keep them productive. · Document and ensure there are effective controls to mitigate risks to data at rest and in transit. · Participate in various projects providing technical support and guidance where needed. · Establish policies, standards, practices and security measures to assure effective and consistent information and operations. Prepare and keep current documentation on all managed systems, including disaster recovery plans. · Plan and utilize our Security Awareness program, initiating quarterly trainings and following up with users to ensure they do their training. · Examine log generation to ensure all devices are feeding data to the SIEM and that data is sufficient to provide answers in the event of a breach. · Ensure security best practices are implemented and revised, as needed, to maintain the confidentiality, integrity and availability of the information under ownership of the company. · Collaborate with Compliance in protecting HIPAA and privacy. Maintain compliant procedures, documentation and workflows. QualificationsQualifications Education & Experience: · Bachelor’s Degree in a technical field. · CISSP or CISM or CISA certification highly desired. · Minimum of 3 years’ experience in working with a compliance framework such as HITRUST, NIST CSF, SOX or PCI. Skills: · Effective knowledge of HIPAA and privacy laws. Strong compliance record · Effective knowledge of Information Security management frameworks such as HITRUST, NIST CSF or ISO/IEC 27001 · Understanding of cyber attack vectors and mitigations · Understand how to perform risk assessments on vendors and within the organization · Working knowledge of using AI for productivity improvement and limiting risks · Some experience with forensic investigations of logs · Knowledge with vulnerability management and corrective action plans · Knowledge of current authentication technologies · Scripting or automation experience (e.g., PowerShell, Python) is a plus · Proven ability for creativity and flexibility in technical troubleshooting · Outstanding written and verbal communications skills · Detail oriented, well organized, strong decision making and problem-solving skills · Ability to balance security requirements with business needs Wage Range: $80,000 to $95,000 per year Physical & Working Environment. Typical Physical Demands. Position requires a great amount of driving, sitting and standing. Some standing, stooping, bending or reaching is required. May require lifting up to 15 pounds. Requires manual dexterity sufficient to operate a computer, calculator and telephone. Requires normal range of hearing and vision. Requires the ability to type and file. Typical Working Conditions. Work is performed in an office environment and/or remotely. The job involves frequent contact with staff and public. Work may be stressful at times. May occasionally work some irregular hours. Clever Care Health Plan is proud to be an Equal Employment Opportunity and Affirmative Action workplace. Individuals seeking employment will receive consideration for employment without regard to race, color, national origin, religion, age, sex (including pregnancy, childbirth or related medical conditions), sexual orientation, gender perception or identity, age, marital status, disability, protected veteran status or any other status protected by law. A background check is required. Salary ranges posted on the job posting are based on California wages. Salary may be higher or lower depending on the candidate’s state residency. #LI-Hybrid

Job Requirements

  • Bachelor’s Degree in a technical field.
  • CISSP or CISM or CISA certification highly desired.
  • Minimum of 3 years’ experience in working with a compliance framework such as HITRUST, NIST CSF, SOX or PCI.
  • Effective knowledge of HIPAA and privacy laws. Strong compliance record.
  • Effective knowledge of Information Security management frameworks such as HITRUST, NIST CSF or ISO/IEC 27001.
  • Understanding of cyber attack vectors and mitigations.
  • Understand how to perform risk assessments on vendors and within the organization.
  • Working knowledge of using AI for productivity improvement and limiting risks.
  • Some experience with forensic investigations of logs.
  • Knowledge with vulnerability management and corrective action plans.
  • Knowledge of current authentication technologies.
  • Scripting or automation experience (e.g., PowerShell, Python) is a plus.
  • Proven ability for creativity and flexibility in technical troubleshooting.
  • Outstanding written and verbal communications skills.
  • Detail oriented, well organized, strong decision making and problem-solving skills.
  • Ability to balance security requirements with business needs.

Benefits

  • Wage Range: $80,000 to $95,000 per year.
  • Physical & Working Environment
  • Typical Physical Demands: Position requires a great amount of driving, sitting and standing. Some standing, stooping, bending or reaching is required. May require lifting up to 15 pounds. Requires manual dexterity sufficient to operate a computer, calculator and telephone. Requires normal range of hearing and vision. Requires the ability to type and file.
  • Typical Working Conditions: Work is performed in an office environment and/or remotely. The job involves frequent contact with staff and public. Work may be stressful at times. May occasionally work some irregular hours.

Related Job Pages

More Security Analyst Jobs

Mercor logo

AI Security Analyst

Mercor

Cincinnatus is an enterprise staffing company that partners with leading technology companies to source and employ highly skilled professionals for full-time and long-term contingent roles. Cincinnatus serves as the employer of record for these engagements, providing W-2 employment, payroll, benefits, and compliance, while placing employees directly within client teams to work on high-impact initiatives. Roles hired through Cincinnatus are not project-based or freelance engagements. They are structured, role-based positions that typically involve full-time or fixed-term commitments, close collaboration with a client's internal teams, and integration into standard enterprise workflows. Cincinnatus is a legal entity separate from Mercor. While opportunities may be discovered through Mercor's platform, employment, onboarding, payroll, and benefits for these roles are administered by Cincinnatus. Equal Employment Opportunity Cincinnatus is proud to be an Equal Employment Opportunity employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or any other legally protected characteristic. Cincinnatus is committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans throughout the job application process.

Security Analyst72 days ago
OtherRemoteH1B No Sponsor

Role Description - Red team conversational AI models and agents to identify jailbreaks, prompt injections, misuse cases, and bias exploitation. - Generate high-quality human data by annotating failures, classifying vulnerabilities, and flagging systemic risks. - Apply structure by following taxonomies, benchmarks, and playbooks to maintain consistent testing. - Document reproducibly by producing reports, datasets, and attack cases that customers can act on. - Work independently and asynchronously to meet deadlines while improving AI model performance. Qualifications - Must-Have: - Prior red teaming experience in AI adversarial work, cybersecurity, or socio-technical probing. - Native-level fluency in English and Chinese (Mandarin). - Strong communication skills to explain risks to technical and non-technical stakeholders. - Ability to thrive on moving across projects and customers. - Preferred: - Experience in Adversarial ML: jailbreak datasets, prompt injection, RLHF/DPO attacks, model extraction. - Background in Cybersecurity: penetration testing, exploit development, reverse engineering. - Expertise in socio-technical risk: harassment/disinfo probing, abuse analysis, conversational AI testing. - Creative probing skills: psychology, acting, writing for unconventional adversarial thinking. Requirements - Type: Full-time or Part-time Contract Work - Compensation: $50/hour - Location: Remote - Commitment: 20+ hours/week Benefits - Hourly contractor - Paid weekly via Stripe Connect Application Process - Upload resume - AI interview based on your resume - Submit form Resources & Support - For details about the interview process and platform information, please check: Interview Process - For any help or support, reach out to: support@mercor.com - PS: Our team reviews applications daily. Please complete your AI interview and application steps to be considered for this opportunity.

United States
$50 / hour
Job Closed
Lowe's Companies, Inc. logo

Senior Asset Protection Manager

Lowe's Companies, Inc.

Do it right for less. Start with Lowe's.

Security Analyst72 days ago
OtherRemoteTeam 10,001+Since 1946H1B No Sponsor

Innovate Remotely This position is fully remote, allowing you to enjoy the flexibility of working from home while collaborating with skilled team members and contributing to groundbreaking solutions. Pay Range: $50,100.00 - $83,700.00 annually Starting rate of pay may vary based on factors including, but not limited to, position offered, location, education, training, and/or experience. For information regarding our benefit programs and eligibility, please visit our benefits page. Lowe's hourly remote associates cannot reside in Alaska, California or Hawaii. Lowe's salaried remote associates cannot reside in Alaska or Hawaii. Lowe’s is an equal opportunity employer and administers all personnel practices without regard to race, color, religious creed, sex, gender, age, ancestry, national origin, mental or physical disability or medical condition, sexual orientation, gender identity or expression, marital status, military or veteran status, genetic information, or any other category protected under federal, state, or local law. Qualified applicants with arrest or conviction records will be considered for Employment in accordance with applicable laws, including the Los Angeles County Fair Chance Ordinance for Employers, the Los Angeles Fair Chance Ordinance, the San Francisco Fair Chance Ordinance, and the California Fair Chance Act. Lowe’s believes that conviction records may have a direct, adverse, and negative relationship to the following job duties: accessing company property, assets, information and products; partnering, supervising, and regularly working with other Lowe’s employees; and adhering to and monitoring compliance and safety guidelines. It is unlawful in Massachusetts to require or administer a lie detector test as a condition of employment or continued employment. An employer who violates this law shall be subject to criminal penalties and civil liability.

United States
$50.1K - $83.7K / year
Job Closed
ICF logo

Cyber Security Analyst- Remote

ICF

We are not a typical consulting firm and our people are not typical consultants.

Security Analyst72 days ago
OtherRemoteTeam 5,001-10,000Since 1969H1B Sponsor

Description ICF is seeking a Cyber Security Analyst that is involved in the testing, implementation and operation of secure state-of-the-art internet-facing services, systems, networks, and database products in both hosted and cloud environments. Conducts risk assessments and provides recommendations for system and application design. Participates in a wide range of security activities including event correlation, alerting, vulnerability management, access management, incident response, troubleshooting, infrastructure management, audit support and more. Analyses are performed through all stages of the system lifecycle, including: concept, design, build, test, integration, operation, maintenance and disposal. Provides analysis, evaluations, and recommendations to improve system consistency, efficiency, and effectiveness. Helps ensure solution requirements meet timing, technical, and financial constraints. Integrates new features into existing solutions, provides analysis to evaluate existing systems against future needs and trends. Uses advanced forensic tools and techniques for investigation and attack reconstruction. Provides recommendations for enhancements to systems, testing and processes. Interacts with other internal groups and external entities including customers, law enforcement, and intelligence/government agencies. Performance Objectives: Technical Work - Operation of infrastructure and application vulnerability detection systems - Review and validation of vulnerability findings - Analyze log data for emerging or unusual patterns - Modify, create, or propose alerts for events of interest - Work with stakeholders to resolve vulnerabilities and respond to events - Help monitor common channels for priority communications - Ensure systems meet documented standards - Assist with obtaining or creating artifacts for audit and compliance - Request and incident ticket intake and escalation - Learn and document common processes with senior resources - Participate in on-call rotation - Assist with disaster recovery and incident response testing and processes - Research and test emerging threats Basic Qualifications: - 3+ years general technology experience - 1+ year of general security experience - 1+ year of experience with basic information security practices (ie Least Privilege, Zero Trust, OWASP Top 10, control frameworks) - Ability to travel 1-2 times a year Preferred Qualifications: - Azure and/or AWS cloud familiarity and experience is highly desirable - Scripting and automation experience is a plus - CompTIA Security+, CEH, GIAC, or equivalent certification - Experience using commercial and open source security software such as Nmap, Nessus, Wireshark, Rapid7, WebInspect, Metasploit Framework, Kali Linux, etc. - Experience with log monitoring, analysis, and correlation - Experience performing enterprise incident monitoring, response, and analysis - Familiarity with generative and agentic AI machine learning algorithms, data preprocessing, and model deployment - Ethical hacking experience - Strong desire for growth and development of security skills - Excellent verbal and written communication skills - Strong ability to multi-task, react, and think quickly - Ability to maintain a high level of confidentiality - Must be flexible enough to work overtime when needed Scope Learning to use professional concepts. Applies company policies and procedures to resolve routine problems. Develops competence by performing structured assignments. Complexity Works on problems of limited scope. Follows standard practices and procedures in analyzing situations or data from which answers can be readily obtained. Builds stable working relationships internally. Discretion Work is closely managed. Normally receives detailed instructions on all work. Interaction Regularly interacts with functional peers within the immediate organization. Interaction normally involves exchange or presentation of factual information. Fairly limited interaction with external contacts. Working at ICF ICF is a global advisory and technology services provider, but we’re not your typical consultants. We combine unmatched expertise with cutting-edge technology to help clients solve their most complex challenges, navigate change, and shape the future. We can only solve the world's toughest challenges by building a workplace that allows everyone to thrive. We are an equal opportunity employer. Together, our employees are empowered to share their expertise and collaborate with others to achieve personal and professional goals. For more information, please read our EEO policy. We will consider for employment qualified applicants with arrest and conviction records. Reasonable Accommodations are available, including, but not limited to, for disabled veterans, individuals with disabilities, and individuals with sincerely held religious beliefs, in all phases of the application and employment process. To request an accommodation, please email Candidateaccommodation@icf.com and we will be happy to assist. All information you provide will be kept confidential and will be used only to the extent required to provide needed reasonable accommodations.  Read more about workplace discrimination rights or our benefit offerings which are included in the Transparency in (Benefits) Coverage Act. Candidate AI Usage Policy At ICF, we are committed to ensuring a fair interview process for all candidates based on their own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) tools to generate or assist with responses during interviews (whether in-person or virtual) is not permitted. This policy is in place to maintain the integrity and authenticity of the interview process.  However, we understand that some candidates may require accommodation that involves the use of AI. If such an accommodation is needed, candidates are instructed to contact us in advance at candidateaccommodation@icf.com. We are dedicated to providing the necessary support to ensure that all candidates have an equal opportunity to succeed.   Pay Range - There are multiple factors that are considered in determining final pay for a position, including, but not limited to, relevant work experience, skills, certifications and competencies that align to the specified role, geographic location, education and certifications as well as contract provisions regarding labor categories that are specific to the position. The pay range for this position based on full-time employment is: $81,499.00 - $138,549.00 Nationwide Remote Office (US99)

United States
$81.5K - $138K / year
Job Closed
Nametag logo

Senior GRC Analyst

Nametag

Deepfake Defense™ identity verification and account protection solutions.

Security Analyst72 days ago
OtherRemoteTeam 11-50Since 2020H1B No Sponsor

Nametag is building the future of secure digital identity. Our mission is to make it easy for people and organizations to prove who they are online - safely and seamlessly. We’re pioneering next-generation identity verification and account protection so that users can control their own identity, and companies can build trust without friction. About the Role Nametag is seeking an experienced Senior GRC Analyst to own and evolve our security and compliance program. This role is ideal for someone who thrives in a fast-paced startup environment, has deep experience with SOC 2 and other compliance frameworks, and is comfortable building and running programs with limited resources. You will report directly to the Head of Engineering and partner closely with the engineering team to ensure security is built into everything we do. As a Senior GRC Analyst, you will own the entire security and compliance function as an individual contributor, maintaining our existing certifications, driving new compliance initiatives, coordinating penetration tests, and building trust with customers and prospects. You will work closely with engineering, product, sales, and customer success to ensure security enables the business rather than blocking it. What You'll Do Compliance Program Management - Own and maintain SOC 2 Type II certification, including evidence collection, control monitoring, and audit coordination - Drive IAL3 compliance readiness and implementation - Manage accessibility compliance (WCAG) requirements - Identify and pursue additional certifications as needed based on customer and market requirements Security Operations - Coordinate penetration testing cycles and drive remediation with engineering - Maintain a living view of organizational risk and surface it to leadership - Develop and maintain security policies, procedures, and controls - Respond to security incidents with speed and clarity Customer Trust - Respond to customer security questionnaires promptly and accurately - Support sales in security-sensitive enterprise deals - Maintain public-facing trust documentation - Participate in customer security calls and reviews as needed Cross-Functional Partnership - Partner with engineering to build security into the development process - Provide clear security guidance and timely reviews so teams can ship with confidence - Collaborate with product on security and accessibility features - Work with customer success to address customer security concerns Ideal Qualifications We know that no candidate will perfectly match every requirement, and that's okay. If you're passionate about what we're building and have most of the skills below, we'd love to hear from you. - 5+ years of experience in security, compliance, or GRC, with demonstrated hands-on ownership of SOC 2 Type II programs - Experience building or running compliance programs in startup or resource-constrained environments - Strong understanding of how auditors think, ideally from auditor-side experience or running multiple audit cycles - Technical fluency to read pen test reports, understand cloud architecture, and have informed conversations with engineers - Knowledge of GRC tooling and vendors, with opinions on what's worth investing in at different company stages - Excellent communication skills, able to translate security topics for executives, salespeople, and customers - Experience with identity verification, authentication, or security-focused products is a strong plus - Familiarity with IAL2/IAL3 or NIST 800-63 identity proofing standards is a strong plus - CISSP, ISO 27001 Lead Auditor, or similar certifications are a plus but not required What We Value - Intellectual horsepower: quickly grasping complex technical and business concepts - Kindness and integrity: earning trust is central to how we build relationships with customers and colleagues - Bias for action: we move quickly to deliver impact and protect our customers against fast-moving threats Compensation The base salary range for this full-time position is $120,000-$160,000, plus equity and benefits. Nametag is a founding member of the Open Imperative, publicly committed to pay equity in the technology industry. We post positions with ranges to encourage people of different backgrounds and experiences to apply. Every offer is benchmarked against market data to ensure fairness and consistency. Final compensation is determined by role, level, and additional factors such as skills, experience, and education. Your recruiter or hiring manager can share more details during the hiring process. Culture & Perks At Nametag, we believe trust starts with how we treat each other. We are a remote-first team that values autonomy, inclusivity, and collaboration, with regular in-person time to stay connected and innovate together. - Remote-first: Work from anywhere in the US. Our team spans Seattle, San Francisco, Ann Arbor, Denver, New York City, and beyond - Quarterly off-sites: We bring the team together once per quarter for in-person collaboration, often off-site in new places - Flexible schedules: Work in your own time zone; we align key meetings across a shared window We Offer - Competitive salary - Meaningful equity ownership - Comprehensive health benefits (medical, dental, vision) - Flexible paid time off - Quarterly team off-sites and travel support - New computer hardware and equipment - An inclusive environment where your voice has impact and your work drives change

United States
$120K - $160K / year