Job Closed

This listing is no longer active.

Octave logo
Octave

Mental health, built around you.

Director, IT – Security

Security EngineerSecurity EngineerFull TimeRemoteLeadTeam 201-500H1B SponsorCompany SiteLinkedIn

Location

United States

Posted

106 days ago

Salary

$190.2K - $220K / year

Seniority

Lead

Bachelor Degree10 yrs expEnglishCloudJamf

Job Description

Director, IT – Security

Octave

• Develops, coordinates, and implements systems, policies, procedures, and productivity standards • Foster a positive and collaborative work environment • Oversee the planning, execution, and completion of projects and initiatives within the team • Establish and monitor operational processes and workflows to enhance efficiency and productivity • Implement best practices, monitor key performance indicators (KPIs), and develop strategies to achieve operational excellence • Ensures a safe, secure, and compliant work environment • Build and manage a high-performing team, including hiring, training, and development • Provide leadership to the team, including setting goals/objectives, providing guidance/feedback, and ensuring the team's overall success • Identify skill gaps within the team and develop strategies for filling those gaps • Define and own the company IT and security strategy, aligning infrastructure, systems, and risk posture with company growth, product evolution, and regulatory requirements • Build, lead, and scale a high-performing IT and Security organization • Oversee end-to-end IT operations and employee technology experience, including onboarding/offboarding and identity and access management • Own and mature the security program, including governance, risk management, and threat detection and response (SOC) • Drive the management of risk, compliance, and audit • Partner cross-functionally with Engineering, Product, Data, Legal, and People teams to embed security and IT best practices • Drive company initiatives to enhance system reliability, scalability, security, and business continuity • Own the IT vendor and partner strategy.

Job Requirements

  • Minimum 10 years of IT or technical security experience
  • at least 6 years in a leadership role
  • Proven track record of scaling enterprise IT and security programs in high-growth startup environments
  • Experience partnering with executive teams on strategic technology decisions
  • Hands-on experience managing enterprise security operations, cloud environments, and IT infrastructure
  • Proven track record of leading security audits, risk assessments, and compliance initiatives
  • Experience with scripting, automation, and system integrations to streamline IT operations
  • Deep expertise across enterprise security, cloud infrastructure, networking, and IT systems
  • Strong background in security governance, risk management, and compliance frameworks (HIPAA, SOC 2, or similar)
  • Proven ability to set strategy and influence executive stakeholders, translating technical concepts into business impact
  • Demonstrated success building and leading high-performing, multi-functional teams
  • Strong cross-functional leadership and systems thinking in complex environments
  • Experience developing AI governance frameworks, acceptable use policies, or responsible AI programs
  • Excellent communication skills, including experience with executive-level presentations and company-wide initiatives
  • Expertise in identity and access management and enterprise tooling (Google Workspace, JAMF/MDM, Okta/OneLogin, Slack, etc.)
  • Experience defining and operationalizing metrics and performance frameworks.

Benefits

  • company sponsored life insurance
  • disability and AD&D plans
  • Voluntary benefits such as 401k retirement
  • medical, dental, vision, FSA, HSA, dependent care and commuter/parking options
  • generous Paid Time Off
  • paid parental leave benefits

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 5,001-10,000Since 1995H1B No Sponsor

• Enterprise Cybersecurity Risk Management: Continuously identify, log, and analyze control nonconformities and unresolved/high-risk vulnerabilities across different sources. Maintain the Risk Registry and deliver timely risk treatment updates and reports to stakeholders. • Third-party Cybersecurity Risk Assessments: Executed annually, ensuring alignment with internal risk standards and external compliance requirements. • Cybersecurity Controls Management: Maintain and enhance the cybersecurity control framework by mapping existing controls, collecting evidence of execution, identifying gaps or nonconformities, and aligning overlapping requirements under a unified structure. Ensure adherence to frameworks such as HITRUST, HIPAA, Spain ENS certification. • Policies and Procedures Development: Create and maintain cybersecurity-related policies and procedures. Ensure documentation complies with regulatory and contractual standards.

Brazil
Job Closed
Full TimeRemoteTeam 10,001+Since 1934H1B No Sponsor

• Serve as the primary security point of contact for external customers, owning the end-to-end customer security relationship. • Lead customer security programs for managed services, ensuring alignment with contractual obligations, regulatory requirements, and enterprise security standards. • Translate customer security requirements into actionable security objectives, coordinating delivery across internal Information Security, Engineering, Cloud Platform, and Application Security teams. • Provide oversight and governance of MSSP-delivered Security Operations, including monitoring, incident detection, response coordination, and SLA adherence. • Own and coordinate customer-specific governance, risk, and compliance (GRC) activities, including risk assessments, control mapping, and remediation tracking. • Lead customer security governance forums, periodic security reviews, and executive-level briefings. • Coordinate customer security questionnaires, audits, certifications, and assurance activities in partnership with internal GRC and compliance teams. • Ensure timely and effective communication of security posture, risks, incidents, and remediation plans to customers and executive stakeholders. • Oversee security incident coordination affecting customer environments, ensuring appropriate response, customer communication, and post-incident follow-up. • Track and manage customer security risks, exceptions, and remediation activities through formal governance processes. • Support the continuous improvement and scalability of the enterprise customer security program model. • Perform additional duties as assigned by the Director of Information Security.

United States
$110.4K - $130K / year
Job Closed
KBR, Inc. logo

RMF Cybersecurity ISSO/SME 3

KBR, Inc.

We deliver science, technology and engineering solutions to governments and companies around the world.

Security Engineer106 days ago
Full TimeRemoteTeam 10,001+Since 1901H1B No Sponsor

Title: RMF Cybersecurity ISSO/SME 3 Program Summary: KBR’s Mission Engineering Division delivers complex technical solutions and expert support to the U.S. Department of War, specializing in modeling and simulation, cyber transformation, air vehicle mission integration, and lifecycle support. As a trusted partner with a proven history in mission technology, KBR collaborates closely with clients to develop innovative and effective solutions. With a strong ethical framework, KBR prioritizes data security, privacy, and responsible information management to ensure mission success. Job Summary: KBR is seeking a Cybersecurity Risk Management Framework (RMF) Information System Security Officer (ISSO) to support the DHA Solution Delivery Division (SDD). In this role, you will lead Assessment & Authorization (A&A) activities and guide systems through the RMF lifecycle to achieve and maintain Authorizations to Operate (ATOs) for mission-critical medical systems. You will work closely with engineers, developers, and government stakeholders to ensure compliance with NIST, DoD, and DHA cybersecurity requirements while supporting continuous monitoring and risk management efforts. This 100% remote position requires availability during standard Eastern Time (ET) day shift hours. Join KBR to contribute directly to protecting critical healthcare systems supporting warfighters and their families. Roles and Responsibilities: - Manage one or more information systems throughout the full six-step RMF lifecycle, including assessment, authorization, and continuous monitoring activities - Serve as an RMF Subject Matter Expert (SME), advising stakeholders on cybersecurity compliance, risk posture, and ATO readiness - Develop, review, and maintain RMF packages and associated documentation, including Security Plans, POA&Ms, Risk Assessment Reports, and security control policies - Assess system compliance against NIST SP 800-53 controls and DHA RMF requirements as part of self-assessment and annual reviews - Document and maintain evidence supporting control implementation and compliance - Lead and participate in A&A and stakeholder meetings to track system status, resolve issues, and drive RMF progress - Coordinate with engineers and system owners to develop architecture diagrams, system asset inventories, and security policies - Prepare and deliver status reports to DHA leadership on system authorization and compliance efforts Basic Qualifications: - Active DoD Secret security clearance - Bachelor’s degree in cybersecurity, information technology, or related field with 6+ years of experience; or 14+ years of relevant cybersecurity/IT experience in lieu of degree. - DoD Manual 8140.03 (formerly 8570.01)-compliant certification (e.g., Security+, CISSP, CASP+/SecurityX) - Demonstrated experience performing RMF activities as an ISSO/ISSM/SME, including ATO process support and RMF package development (Security Plans, POA&Ms, architecture diagrams, system security policies, etc.) - Demonstrated experience assessing and documenting NIST SP 800-53 controls - Experience using Microsoft Office applications: Word, PowerPoint, Excel, and SharePoint Preferred Qualifications: - Experience using eMASS or equivalent compliance-tracking application - Experience supporting RMF processes under DHA - Familiarity with ACAS and DISA STIGs/SRGs and tools such as STIG Viewer and SCAP Compliance Checker - Familiarity with Continuous Monitoring and Risk Scoring (CMRS) - Experience using Microsoft Project to build Integrated Master Schedules (IMS) Compensation: $107,600.00 - $161,400.00. The salary range posted is based on the national average. The offered rate will be based on the selected candidate’s location, knowledge, skills, abilities, and/or experience, contract affordability, and in consideration of internal parity. Benefits: KBR offers a selection of competitive lifestyle benefits which could include a 401K plan with company match, medical, dental, vision, life insurance, AD&D, flexible spending account, disability, paid time off, or flexible work schedule. We support career advancement through professional training and development. Belong, Connect and Grow at KBR At KBR, we are passionate about our people and our Zero Harm culture. These inform all that we do and are at the heart of our commitment to, and ongoing journey toward being a People First company. That commitment is central to our team of team’s philosophy and fosters an environment where everyone can Belong, Connect and Grow. We Deliver – Together. KBR is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, disability, sex, sexual orientation, gender identity or expression, age, national origin, veteran status, genetic information, union status and/or beliefs, or any other characteristic protected by federal, state, or local law.

United States
$107K - $161K / year
CloudWalk, Inc. logo

Offensive Security Engineer

CloudWalk, Inc.

The interplanetary payment network.

Security Engineer106 days ago
Full TimeRemoteTeam 201-500H1B No Sponsor

• Pentest applications across our stack, identifying vulnerabilities in APIs, mobile apps (Android/iOS), and infrastructure before attackers do. • Plan and execute realistic attack campaigns: phishing with custom domains, social engineering, lateral movement, privilege escalation. Measure real organizational resilience, not checkbox compliance. • Engineer security platforms, scanning pipelines, and automation that multiply the team's impact. • Design and build LLM-powered agents that detect, classify, triage and fix vulnerabilities in real time.

Brazil