CardWorks is a leading credit and payments company, and a people-centric, compliance-focused organization.
Manager Security Compliance
Location
Utah + 3 moreAll locations: Utah | New York | Pennsylvania | Florida
Posted
40 days ago
Salary
$128.5K - $142.8K / year
Seniority
Lead
No structured requirement data.
Job Description
Manager Security Compliance
CardWorks
Title: Manager Security Compliance Locations: Woodbury, NY; South Jordan, UT; Horsham, PA; Pittsburgh, PA; Orlando, FL. Work Type: Hybrid, Full Time Job ID: JR100965 Job Description: What We Do At CardWorks, we aim to help people connect with possibility and opportunity using our financial servicing expertise. Building meaningful, long-term relationships with consumers, our employees, and our clients is what matters most. Who We Are CardWorks, Inc. is a diversified consumer finance service provider and parent company of CardWorks Servicing, LLC, Merrick Bank and Carson Smithfield, LLC. CardWorks Servicing, LLC provides end-to end operational servicing functions for credit cards, secured cards, and installment loans. We service consumer and small business loans across the credit spectrum and offers backup servicing and due diligence services to capital providers and trustees. Merrick Bank is an FDIC-insured Utah Industrial Loan Bank. Merrick operates three main business lines: credit cards, recreational lending, and merchant services. Caron Smithfield, LLC provides a variety of post-charge-off debt recovery services, including digital self-service, IVR, live agent, and external agency management. Position Summary: The Security Compliance Manager is an individual contributor responsible for operationalizing, executing, and maturing the enterprise security compliance program. This role reports to the Director of Security Risk & Compliance and ensures that the organization’s security compliance strategy is translated into effective operational processes, assessments, and workflows. Core responsibilities include managing compliance operations, executing assessments, reviewing controls, supporting audit readiness, coordinating documentation and evidence, and ensuring accuracy and consistency across compliance systems and reporting. Essential Functions: Compliance Program Execution - Execute and continuously improve enterprise security compliance processes and assessments, supporting the strategic direction established by the Manager. - Operate and maintain the security compliance technology platform, ensuring assessments, evidence collection, and issue tracking are completed accurately and on schedule. - Coordinate compliance assessment activities and ensure required documentation is complete and aligned with standards. - Create, manage, and maintain standardized templates, procedures, workflows, and reporting to support consistent compliance operations. Security Exception Management - Execute detailed assessments of security exception requests, documenting risks, mitigating controls, approvals, and expiration tracking, in accordance with governance defined by the Director. - Track exception approvals, expirations, and remediation requirements, ensuring timely reminders, escalations, and accuracy of exception data. Security Issue Escalation & Tracking - Manage execution of the Security Compliance Finding and Issue Escalation process, ensuring control gaps and audit findings are documented, monitored, and remediated on schedule. - Maintain and operationalize workflow steps aligned to governance requirements defined by the Director, ensuring appropriate escalation of overdue or high‑risk issues. - Align information security issue tracking with Enterprise Risk Management processes and escalate high‑risk issues through established governance forums. Documentation Governance - Oversee the Information Security documentation governance program, ensuring policies, standards, procedures, and guidelines are accurate, current, and aligned with regulatory, customer, and internal control requirements. - Implement and maintain the documentation lifecycle processes, including drafting, review, approval, publication, version control, retention, and retirement. - Coordinate updates to documentation to ensure alignment with applicable frameworks such as CRI, NIST CSF, PCI DSS, and CIS 18, reflecting changes in technology, controls, and risk posture. - Track documentation quality, exceptions, gaps, and remediation activities; prepare reports and metrics to support leadership visibility and compliance oversight. - Partner with security, risk, IT, and compliance stakeholders to ensure documentation supports audits, assessments, and ongoing control operation. Education and Experience - 8+ years of experience in information security, risk management, compliance, or related disciplines. - Bachelor’s degree in IT or related field preferred or equivalent work experience in lieu of degree. - Working knowledge of security frameworks such as Cyber Risk Institute, NIST CSF, CIS Controls, and PCI DSS along with experience applying these and other industry-specific regulations to projects and infrastructure. - Experience in collaborating across diverse teams, including IT, business units, and external stakeholders, to address security requirements and align with project objectives. - Strong understanding of security risk assessment methodologies, controls implementation, and process optimization, with a track record of successfully mitigating risks and enhancing security practices. Summary of Qualifications: - Strong working knowledge of major security frameworks and regulatory requirements, including CRI, NIST CSF, PCI DSS, and CIS Controls, with experience aligning compliance platforms to support assessments and evidence management. - Skilled in optimizing compliance workflows, dashboards, templates, and reporting to enhance operational efficiency and audit readiness. - Proficient with core security technologies such as vulnerability management, encryption, and identity and access management. - Strong analytical and communication skills, able to identify trends, explain complex technical and regulatory concepts, and support cross‑functional collaboration. - Highly organized, detail‑oriented, and capable of managing multiple priorities while improving processes, automation, and program scalability. Ideally, the qualified candidate will work at the following location(s): South Jordan, UT; Woodbury, NY; Horsham, PA; Pittsburgh, PA; Orlando, FL. A hybrid work model or fully remote model can be considered based on hiring manager decision and priorities of the role. The salary range for this position, if located in NY Metro/NY State is $128,490 to $142,767. However, please note that the salary range will vary for other geographic areas. #INDHP Our Employee Value Proposition - Competitive Pay, including a Bonus Target or Variable Pay Incentive Program - Benefits Package -Medical, Dental, and Vision (plus much more) - 401(k) Plan with Company Match - Short- & Long-Term Disability - Wellness Programs - Group Life and AD&D Insurance - Paid Vacation, Sick Days and bank Holidays - Employee Engagement Activities including Employee Appreciation Day, DEI Employee Resource Groups, Corporate Social Responsibility, Service Recognition We offer a total rewards package comprised of a competitive base rate of pay, variable pay incentive programs based on the role, and a comprehensive benefit suite. Offered rates of pay are determined based on job-related knowledge, relevant experience, skills, certifications, and geographic location.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Define Product Strategy & Vision: Establish and communicate the vision, roadmap, and success metrics for security products aligned to enterprise risk posture and compliance requirements. • Set Clear Outcomes: Define what success looks like for each product, including measurable KPIs. • Plan for Scalability & Future Needs: Anticipate evolving security threats and compliance requirements. Design products that scale and adapt to future enterprise needs. • Incorporate AI for Efficiency: Identify opportunities to integrate AI into daily workflows to automate repetitive tasks, improve decision-making, and maximize efficiency. • Manage Product Development: Collaborate with engineering and security teams to design and deliver secure-by-default capabilities integrated into developer workflows (IDE, CI/CD pipelines). Maintain backlog, write and groom user stories, and drive iterative releases using Agile methodologies. • Enable Data-Driven Decisions: Define and monitor KPIs for success. Use analytics and risk reporting to validate assumptions and optimize adoption. • Stakeholder Communication: Lead product ceremonies and communicate progress, risks, and trade-offs to engineering leadership, security teams, and partners.
Associate Director, CyberSecurity Engineering
HumanaLouisville, Kentucky-based Humana is a leading healthcare company that offers a variety of health, wellness, and insurance products and services designed to offer an integrated app
Become a part of our caring community (Candidate should be located in one of the following Metro locations: Louisville KY, NYC Metro, Dallas Metro, Charlotte NC Metro, South Florida, Washington DC metro, Chicago, Boston, Atlanta, Nashville). The Associate Director, CyberSecurity Engineering will lead the enterprise Privileged Access Management (PAM) program, overseeing privileged account security, vaulting, and governance across cloud, on-premises, and subsidiary environments. This role is responsible for advancing PAM strategy and improving the consistency of privileged controls across the organization. The leader will guide modernization efforts and partner with stakeholders to improve privileged access hygiene. This position requires strong technical leadership, operational excellence, and effective cross-functional collaboration. Key Responsibilities: - Lead and mentor direct reports and other teammates, fostering a culture of technical excellence, service, and accountability. - Drive the enterprise privileged cloud migration (Pcloud), including planning, stakeholder engagement, change-champion coordination, and post-cutover stabilization. - Lead privileged access efforts across subsidiaries, establishing a repeatable framework for onboarding new entities and remediating posture gaps. - Manage high-risk privileged reduction initiatives with a focus on strong organizational change management execution. - Partner across engineering, security, and business teams to resolve blockers, improve privileged access design, and implement consistent vaulting and governance controls. - Develop and deliver a unified application onboarding experience for PAM, including playbooks, checklists, and privilege-mapping guidance. - Build VP-level privileged access scorecards and integrate PAM metrics into enterprise Problem Management to identify incidents involving privileged misuse. - Serve as the primary liaison for Risk and Compliance partners to address audit findings, risks, and control improvements. - Support operational processes including vendor renewals, case management, program reporting, and on-call escalation responsibilities. - Stay current on industry trends, emerging PAM technologies, and regulatory expectations related to privileged access security. Use your skills to make an impact Role Essentials: - 7+ years of experience in technical leadership roles driving complex cybersecurity or IAM programs. - Proven experience leading PAM engineering or operations teams and delivering privileged access solutions at enterprise scale. - Deep technical expertise in privileged access concepts including vaulting, rotation, service accounts, SUDO policies, and elevated-access governance. - Strong understanding of Active Directory/Entra ID, Windows/Linux/Mac operating systems, and cloud privileged access patterns. - Demonstrated success driving modernization initiatives and reducing high-risk privileged access. - Excellent leadership, communication, and stakeholder engagement skills. - Hands-on, collaborative approach to problem-solving and solution delivery. - Ability to participate in and oversee on-call support for PAM services. Preferred Requirements: - Master's degree in Cybersecurity, Information Technology, Computer Science or related field. - Industry certification such as, but not limited to, CISSP, CCSP or CISM. - Experience leading projects in both agile and waterfall methodologies. Project management certifications such as PMP or CSM preferred. - Experience in budget planning and management for technologies, services, and staffing resources Remote/WAH requirements: - WAH requirements: Must have the ability to provide a high speed DSL or cable modem for a home office. Associates or contractors who live and work from home in the state of California will be provided payment for their internet expense. - A minimum standard speed for optimal performance of 25x10 (25mpbs download x 10mpbs upload) is required. - Satellite and Wireless Internet service is NOT allowed for this role. - A dedicated space lacking ongoing interruptions to protect member PHI / HIPAA information Travel: While this is a remote position, occasional travel to Humana's offices for training or meetings may be required. Scheduled Weekly Hours 40 Pay Range The compensation range below reflects a good faith estimate of starting base pay for full time (40 hours per week) employment at the time of posting. The pay range may be higher or lower based on geographic location and individual pay will vary based on demonstrated job related skills, knowledge, experience, education, certifications, etc. $156,600 - $215,400 per year This job is eligible for a bonus incentive plan. This incentive opportunity is based upon company and/or individual performance. Description of Benefits Humana, Inc. and its affiliated subsidiaries (collectively, “Humana”) offers competitive benefits that support whole-person well-being. Associate benefits are designed to encourage personal wellness and smart healthcare decisions for you and your family while also knowing your life extends outside of work. Among our benefits, Humana provides medical, dental and vision benefits, 401(k) retirement savings plan, time off (including paid time off, company and personal holidays, volunteer time off, paid parental and caregiver leave), short-term and long-term disability, life insurance and many other opportunities. Application Deadline: 04-19-2026 About us About Humana: Humana Inc. (NYSE: HUM) is a leading U.S. healthcare company. Through our Humana insurance services and our CenterWell healthcare services, we make it easier for the millions of people we serve to achieve their best health – delivering the care and service they need, when they need it. These efforts are leading to a better quality of life for people with Medicare and Medicaid, families, individuals, military service personnel, and communities at large. Learn more about what we offer at Humana.com and at CenterWell.com. Equal Opportunity Employer It is the policy of Humana not to discriminate against any employee or applicant for employment because of race, color, religion, sex, sexual orientation, gender identity, national origin, age, marital status, genetic information, disability or protected veteran status. It is also the policy of Humana to take affirmative action, in compliance with Section 503 of the Rehabilitation Act and VEVRAA, to employ and to advance in employment individuals with disability or protected veteran status, and to base all employment decisions only on valid job requirements. This policy shall apply to all employment actions, including but not limited to recruitment, hiring, upgrading, promotion, transfer, demotion, layoff, recall, termination, rates of pay or other forms of compensation and selection for training, including apprenticeship, at all levels of employment.
Senior Security Research Engineer-Microsoft Defender Experts Team
MicrosoftMicrosoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to any characteristic protected by applicable local laws, regulations, and ordinances.
Overview Microsoft Defender Experts Team is looking for an experienced professional to join our detection and response team. No matter how sophisticated attacker behaviors become, Microsoft 365 Defender will help enterprises detect, investigate, and respond to advanced attacks and data breaches on their networks. Our team uses deep knowledge of the attacker landscape and rich telemetry from our sensors to perform root-cause analysis and generate custom alerts, ensuring that Microsoft 365 Defender customers are well equipped to quickly respond to human adversaries identified in their unique environments. Ensuring that no human adversary can operate silently begins with experts harnessing the powerful optics provided by Microsoft 365 Defender, across the attacker kill-chain, coupled with world-class detections. We are looking for someone who is passionate about this work to help us harness the power of Microsoft’s trillions of security signals to quickly identify and report the latest human adversary behaviors, drive critical context-rich alerts, build new tools and automations in support of hunting objectives, and drive innovations for detecting advanced attacker tradecraft. Responsibilities · Work directly with senior leaders of our customers’ security organizations as design partners on new cloud detection and response innovations, as well as to ensure excellent customer satisfaction with our products and services. · Partner with your team of Microsoft Threat Experts providing deep research and analysis of threats impacting our customers. · Work cross-functionally with engineering, marketing, and business leaders to innovate and deliver new security service offerings at a global scale. · Investigate, analyze, and learn from security researchers, attackers, and real incidents to develop durable detection solutions/strategies across customer tools. · Work with other internal and external teams to forge new and improve existing partnerships that help mature the products that support Defender Experts service offerings. · Provide technical leadership in a challenging and rewarding environment and influence the organization. Qualifications Required Qualifications: - Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 4+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience. - Over 7 years of hands‑on experience in technical cybersecurity roles—including Security Operations, Threat Intelligence, Incident Response, and Penetration Testing/Red Team—demonstrating deep expertise in industry best practices, emerging threats, and SOC operations, along with advanced proficiency in deploying and configuring the Microsoft Defender XDR suite to strengthen enterprise security posture. - Advanced English level - Advanced Portuguese level. Additional or preferred qualifications: - Doctorate in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 3+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Master's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 6+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR Bachelor's Degree in Statistics, Mathematics, Computer Science, Computer Security, or related field AND 8+ years experience in software development lifecycle, large-scale computing, threat analysis or modeling, cybersecurity, vulnerability research, and/or anomaly detection OR equivalent experience. - Ideally 300-level proficiency in Microsoft Defender Endpoint and Microsoft Defender Office, and 200-level in Microsoft Defender Cloud Apps, Microsoft Defender Identity, and Microsoft Defender Cloud. - Customer-Centric Mindset: Comfortable engaging with diverse stakeholders, possessing exceptional communication and interpersonal skills to navigate complex organizational landscapes. - Experience evaluating and translating customer needs, requirements, and challenges, and communicating solutions (positioning, technology, value, priority) and improvements to technical and non-technical stakeholders. - Experience leading a security function for a customer (i.e.: SOC manager, solution lead, Security engineer) - Knowledge of operating system internals and attack techniques in Windows, Linux, Mac, Android & iOS platforms - Experience with data analysis and cyber threat investigations in Sentinel - Knowledge of kill-chain model, ATT&CK framework, and modern penetration testing techniques - Knowledge of major cloud and productivity platforms as well as identity systems and related security concerns - Experienced with curation of Threat Intelligence and delivering customer briefings - Strong ability to use data to 'tell a story' - Experience with reverse engineering, digital forensics (DFIR) or incident response, or machine learning models - Experience with system administration in a large enterprise environment including Windows and Linux servers and workstations, network administration, cloud administration - Experience with offensive security including tools such as Metasploit, exploit development, Open Source Intelligence Gathering (OSINT), and designing ways to breach enterprise networks - Additional advanced technical degrees or cyber security certifications such as CISSP, OSCP, CEH, or GIAC certifications This position will be open for a minimum of 5 days, with applications accepted on an ongoing basis until the position is filled. Microsoft is an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to age, ancestry, citizenship, color, family or medical care leave, gender identity or expression, genetic information, immigration status, marital status, medical condition, national origin, physical or mental disability, political affiliation, protected veteran or military status, race, ethnicity, religion, sex (including pregnancy), sexual orientation, or any other characteristic protected by applicable local laws, regulations and ordinances. If you need assistance with religious accommodations and/or a reasonable accommodation due to a disability during the application process, read more about requesting accommodations.
Cybersecurity Intern
DayforceDayforce is a global HCM platform offering a comprehensive array of services encompassing payroll, HR, benefits, workforce management, talent, and analytics. With the mission of "m
Role Description As a Cybersecurity Intern, you will collaborate closely with the Cybersecurity Operations team to support shared services and enhance operational efficiency across the organization. In this role, you’ll gain hands-on experience in daily cybersecurity operations while contributing to initiatives focused on automation and process improvement. You will be exposed to real-world enterprise environments, assisting in managing operational workflows and identifying opportunities to streamline processes using automation and AI-driven solutions. What you’ll get to do: - Support daily IAM and Messaging operations, including monitoring the cybersecurity mailbox - Help triage and categorize cybersecurity-related inquiries and incidents - Identify repetitive operational tasks and propose opportunities for automation - Assist in building simple automation workflows using tools such as: - Microsoft Power Platform (Power Automate) - Python scripting (basic) - SOAR platforms (e.g., XSOAR – exposure level) - Explore use of AI tools (e.g., internal AI platforms, ChatGPT, etc.) to support operational tasks - Contribute ideas on how AI can improve cybersecurity workflows and decision-making Qualifications - Currently enrolled in an undergraduate or postgraduate program in Cybersecurity, Information Security, Computer Science, Information Systems, or a related technical discipline - Curiosity, a passion for data, and cybersecurity - Basic understanding of Identity and Access Management (IAM) concepts - IT systems, networks, or cloud fundamentals - Familiarity with MS Office tools (Excel, Teams, Outlook) - Basic scripting (Python or similar) is a plus - Strong analytical thinking and attention to detail - Good communication skills and willingness to collaborate in a global team environment Requirements - Full-time availability of 37.5 – 40 hours weekly is required to be eligible for this opportunity. Benefits - Experience working for one of the fastest growing Human Capital Management technology companies in the world - Access to Dayforce’s development programs and resources - Ability to work with as well as create relationships with members across the globe - Autonomy to bring forth new ideas and optimize existing structures within the organization - Meaningful responsibilities, enabling you to obtain ‘real-world’ experience - Dynamic hands-on exposure to multiple business-units and stakeholders across Dayforce



