Job Closed
This listing is no longer active.
Technology is our how. And people are our why.
Security Accreditation Lead
Location
United States
Posted
71 days ago
Salary
0
Seniority
Senior
Job Description
Security Accreditation Lead
Endava
• Provide experienced leadership to guide the development of the front-end of the NATO DIANA OS application through a successful NATO Office of Security (NOS) accreditation process • Lead the successful security approval for each DIANA OS release • Develop and maintain a continuously updated Accreditation Pack aligned with NATO requirements • Produce a complete set of security artefacts ready for NOS/NCIA review • Provide input into the accreditation process being managed by other DIANA OS vendors • Promote a security-by-design foundation for future migration to Luxembourg Cyber Defence Cloud (LCDC) and uplift to NATO RESTRICTED
Job Requirements
- Extensive experience leading accreditation of complex systems (NATO, MoD, DoD, EU defence, national security agencies)
- Capability to obtain or hold NATO SECRET security clearance; sponsorship is possible
- Demonstrated leadership with security approval frameworks: NATO C-M(2002)49-REV1 AC/35-D/2020 D32 Cloud Security Directive
- Deep understanding of DevSecOps, secure CI/CD, container hardening, and cloud-native security
- Experience operating in multi-vendor, multi-tenant environments
- Demonstrable experience securing modern web front ends in high-assurance environments
- Implementation of secure-by-design UI architectures, OWASP Top 10 mitigation (XSS, CSRF, auth/session handling), secure identity and access integration (SSO, MFA, role-based access), client-side data protection, and support to formal security accreditation and assurance processes aligned with NATO / public-sector standards.
- Prior experience working with NATO bodies (NCIA, NOS, NSPA) preferred
- Experience in cloud-agnostic architectures and migration across secure hosting environments
Benefits
- Robust healthcare and benefits including Medical, Dental, vision, Disability coverage, and various other benefit options
- Flexible Spending Accounts (Medical, Transit, and Dependent Care)
- Employer Paid Life Insurance and AD&D Coverages
- Health Savings account paired with our low-cost High Deductible Medical Plan
- 401(k) Safe Harbor Retirement plan with employer match with immediately vest
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Information Systems Security Officer I
Bellese TechnologiesImproving the healthcare journey through civic innovation.
• (1) SIA Maintenance (Primary Focus): You will proactively identify system changes in HQR and QMARS and document them in a Security Impact Analysis (SIA) to ensure the ATO remains valid. • CFACTS Governance: You will serve as the "Source of Truth" for the system's security posture in CFACTS, managing control implementation statements and evidence. • Audit Defense & Evidence Gathering: You will lead the "Audit Season" efforts, gathering screenshots, logs, and process documentation to prove to CMS auditors that controls are "Effective." • Risk Advising: You will attend sprint ceremonies for HQR (50%) and QMARS (50%) to advise developers on CMS security standards before they build, preventing "security rework" later. • POA&M Life-cycle: You will track security weaknesses from discovery to remediation, ensuring the program meets CMS's strict 30/60/90-day patching windows. • Policy Stewardship: You will ensure all program documentation (Contingency Plans, Incident Response Plans) is reviewed and signed off annually per FISMA requirements.
Manager, Information Security
Neovia LogisticsA leading contract logistics provider, we solve mission-critical supply chain needs for customers around the world.
• Responsible for leading and maturing the company’s global information security polices, governance framework across warehouse and corporate environments. • Ensures that Neovia maintains a structured, risk-based, and scalable security posture aligned with business objectives, customer expectations, regulatory obligations and the ever-evolving threat landscape. • Maintains awareness of new threats and creates vehicles for quickly addressing day zero risks. • Supports global locations, ensuring that information security policies, standards and control objectives are consistently defined, governed and aligned with operational reality. • Drives the development and maintenance of the Information Security Management System (ISMS), supports certificate initiatives (ISO 27001 etc), oversees enterprise security risk management, and ensures structured audit readiness across regions by partnering with Neovia’s internal GRC and legal teams. • Responsible for the security strategy, working with Engineering and leadership to recommend software and solutions to solve complex problems and make Neovia safer. • Helps evaluate security capabilities, identify maturity gaps, and provide structured recommendations to IT and executive leadership to ensure ongoing improvement of Neovia’s security posture. • Owns end-user testing and education.
Who We Are Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable. Role Trail of Bits seeks a Senior Security Engineer specializing in Application Security for Agentic AI systems, within our growing Software Assurance team. You will conduct comprehensive security assessments of large language model systems, examining software across the AI supply chain and application stack — such as LLM web applications, agentic coding tools, training data and inference pipelines, and guardrail mechanisms. Additionally, this role will be responsible for development, and operationalization of prompt injection techniques, for use in end-to-end application security reviews. You will identify and analyze novel attack vectors and vulnerabilities specific to AI and agentic environments, focusing on real-world failure modes, system integration issues, and unauthorized access vectors. This role allows you to apply application security experience and adversarial thinking to the latest agentic systems and buisness integrations. In addition to performing technical assessments, you will contribute to threat modeling, adoption risk frameworks for generative AI tooling, and delivering specialized training to clients on Agentic AI security concepts, including prompt injection, ML-specific attacks, and data pipeline threats. What You'll Achieve - Agentic AI Security Assessments: Conduct comprehensive application security assessments of agentic AI pipelines, tools, and frameworks for leading companies and labs. Examine vulnerabilities in model architectures, guardrails, and deployment infrastructure while developing mitigation strategies. - Prompt Injection Research & Development: Develop and share novel prompt injection techniques targeting agentic workflows, including indirect injection via tool outputs, multi-turn manipulation, and cross-agent exploitation. Produce actionable attack libraries and defensive countermeasures for client engagements. - Application Security Assessment: Conduct security assessments of client code bases using a combination of static analysis, dynamic testing, and manual code review, identifying vulnerabilities and developing mitigation strategies, with a focus on findings at the intersection of application security and Agentic AI security. - Threat Modeling: Conduct threat modeling and risk assessments to proactively identify potential risks for clients and develop mitigation strategies for future prevention, with particular attention to prompt injection attack surfaces in agentic orchestration layers. - Client Engagement: Work with leading industry teams to review system code and architecture, and help assure their products through system analysis and modeling. - AI Policy & Compliance Initiatives: Develop and contribute to AI regulatory frameworks, establishing assurance methods and auditing processes for mission-critical AI applications while ensuring alignment with emerging industry standards and safety requirements. What You'll Bring - AI Security Expertise: Demonstrated interest and experience in agentic AI security, with demonstrated ability to identify and mitigate AI-specific vulnerabilities across complex systems, including hands-on experience with prompt injection attacks and defenses. - Technical AI Knowledge: Deep understanding of AI/ML architectures, frameworks (PyTorch, Jax, LangChain, RAG systems, etc.), and MLOps practices, combined with robust security engineering expertise. - Application Security Skills: Track record of conducting technical security assessments of software, including software and system hardening, security policy analysis, and implementing effective security measures. - Prompt Injection Proficiency: Practical experience designing and executing prompt injection workflows against production LLM systems, agentic pipelines, and tool-use environments, including familiarity with emerging taxonomies and mitigation approaches. - Programming Proficiency: Strong knowledge of multiple programming languages such as Rust, Golang, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, Ruby, C and/or C++ for both security analysis and tool development. - Hacker Mindset: A creative and adversarial mindset, with a passion for discovering novel attack vectors and understanding how systems work across many layers of abstraction. - Communication Skills: Ability to effectively communicate complex security concepts to diverse stakeholders and deliver clear, actionable recommendations. The base salary for this full-time position ranges from $100,000 to $200,000 excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more. Only applications completed via our Careers page will be considered for further review. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime.
• Responsible for executing comprehensive information security risk assessments of third-party vendors engaged by PPFA, Affiliate, and Ancillary organizations. • Evaluate vendors across multiple risk tiers to ensure they meet information security policies, HIPAA and PCI DSS requirements, and applicable regulatory standards. • Thoughtfully analyze vendor-provided documentation, identify potential risks, collaborate with key parties, and produce detailed and accurate assessment reports. • Manage the end-to-end TPRM process for assigned vendors including initiating communications, reviewing security documentation, identifying risks, and producing assessment reports. • Engage with internal and external partners to facilitate information gathering, clarify responses, and resolve risks. • Collaborate with internal stakeholders to ensure vendor assessments align with contract and compliance requirements.




