CBO - Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50

Location

United States

Posted

34 days ago

Salary

0

Seniority

Senior

Job Description

CBO - Senior Security Engineer

cFocus Software Incorporated

cFocus Software seeks a Senior Security Engineer to join our program supporting the Congressional Budget Office (CBO). This position is remote. This position requires a Public Trust clearance. Qualifications: - Active Public Trust clearance - B.S. Computer Science, Information Technology, or a related field - 8+ years of Security Engineering experience - Strong experience with Microsoft Sentinel (SIEM) operations and engineering - Experience with Microsoft Defender for Endpoint (MDE) and Defender for Identity (MDI) - Knowledge of AWS logging (CloudTrail, VPC Flow Logs) and cloud security monitoring - Experience with log ingestion, normalization, and schema mapping - Understanding of incident response, threat detection, and SOC operations - Familiarity with NIST frameworks (800-53, 800-61, 800-92) and Zero Trust principles - Experience with detection engineering and threat hunting methodologies - Preferred certifications include but are not limited to - GCIA, GCIH, CISSP, CEH, or equivalent cybersecurity certifications - Microsoft Sentinel or Microsoft security platform certifications - Relevant cloud security certifications (e.g., AWS security) - Privacy certifications (e.g., CIPP/US, CIPM) where applicable Duties: - Review Microsoft Sentinel log ingestion, pipeline health, and monitoring coverage - Validate, develop, and tune detection use cases aligned with MITRE ATT&CK - Identify telemetry gaps and ensure proper ingestion and normalization of logs - Coordinate remediation activities with CBO IRM staff - Support vulnerability prioritization and patch governance validation - Validate log routing, transformation, and normalization (e.g., Cribl or similar tools) - Provide technical support during security incidents and escalation events - Support detection engineering, threat hunting, and SOC automation initiatives - Ensure alignment with Microsoft Defender (Endpoint, Identity) and AWS log sources

Related Categories

Related Job Pages

More Security Engineer Jobs

Function Health logo

Senior Product Security Engineer

Function Health

At Function, we celebrate diversity and are committed to building a diverse and inclusive workforce. As an equal opportunity employer, we do not discriminate on the basis of race, color, gender identity, ancestry, religion, age, sexual orientation, national origin, disability, marital status, Veteran status, or any other occupationally irrelevant criteria. Join the Function Health team and become a part of our mission to build a healthier future for all. Discover more about us and how we're changing the face of healthcare at Function Health. Important Notice: Legitimate communication from the Function Health team will always come from an email address ending in @functionhealth.com. Function Health will never request personal information such as banking details or payment during the hiring process. Please be cautious of communications or job offers that come from other email domains, instant messaging platforms, or unsolicited calls. If you ever have doubts about the legitimacy of a communication, please reach out to us directly at talent@functionhealth.com.

Full TimeRemoteTeam 11-50

Company Overview: Function Health is the AI operating system for health, designed to empower people to live 100 healthy years. We are redefining how individuals understand, measure, and improve their health by moving beyond reactive care and enabling proactive, data-driven insight into human biology. Function has been recognized as one of Fast Company’s Most Innovative Companies of 2024, and is venture-backed by Andreessen Horowitz (a16z). Hundreds of thousands of members have joined Function to take control of their health. Through advanced diagnostics, deep biomarker testing, longitudinal data, and AI-enabled insights, Function equips members with actionable intelligence to take control of both the quality and length of their lives. Function recently announced a $298M Series B and is entering its next chapter of growth. As we scale, the quality and durability of our People systems, data, and insights will directly shape our ability to attract, retain, and support exceptional talent. We are growing our team and seeking out world-class talent that deeply believes in our mission to positively impact global health, has a relentless bias toward action, and a growth mindset. Function fosters a collaborative and dynamic environment where every day we build the future. Role: Function Health is building out a dedicated product security team to protect our members and platform as we scale. As a Senior Product Security Engineer, you'll work shoulder-to-shoulder with engineering and product teams to embed security into every stage of development: design, code, test, and deploy. This role is hands-on and impact-driven. You'll be expected to identify risks, build guardrails, and ship tools that raise the security bar without slowing teams down. Our engineering org is moving toward AI-first code review, autonomous adversarial testing, and security gates that run without human approval for low-risk changes. You'd be building the systems that make that possible and safe. If you've been waiting for a security role where the answer to "can we automate this?" is usually yes, this is it. We're looking for someone who thrives on solving hard technical problems, knows how to build security into systems the right way, and is excited about what AI-assisted engineering means for the future of the discipline. Key Responsibilities: - Design and deploy AI-powered security agents into CI/CD: automated code review, risk classification, escalation logic, and where possible, auto-remediation. - Build and operate the security tooling layer across our pipelines: SAST, SCA, secrets scanning, IaC validation, and supply chain integrity checks. - Conduct threat modeling, secure design reviews, and manual security assessments across our apps, APIs, and infrastructure. - Find vulnerabilities through proactive testing, not just scanner output, and drive them to remediation. - Partner with engineering teams across our product pillars as the embedded security voice in the room, without being a blocker. - Own the rollout of secure-by-default development frameworks and controls. - Connect application-level telemetry to detection and response systems. - Contribute to incident response and postmortems when product security is involved. - Shape our long-term product security strategy and roadmap. Qualifications/Skills: - 5+ years of experience in product or application security, software engineering, or a combination of both. - You've built or operated AI-assisted security tooling, whether that's an agent doing code review, an automated triage pipeline, or custom security automation you designed from scratch. - Strong Python experience. Familiarity with FastAPI, LangChain, or agentic frameworks is a plus. - Deep fluency in identifying and exploiting web, API, and application vulnerabilities, well beyond OWASP Top 10. - Experience embedding security into CI/CD, not just recommending it. - You can guide engineers through secure design decisions without slowing them down. - You write documentation and design docs without being asked. - Bonus: experience with HIPAA or healthcare data, red teaming, or security architecture at scale. Your dedication to these responsibilities will directly contribute to the success of our platform and the satisfaction of our users. We are looking for a proactive, skilled, and forward-thinking individual to join our team and help shape the future of our services. To be a strong fit, you embody our Core Values: - Ruthless Prioritization: - We don’t let perfect get in the way of progress. - We move quickly to drive value, not perfection. - We prioritize what drives impact. - We never compromise on standards of excellence. - Member-First, Always: - We design and deliver like we’re caring for someone we love. - We create calendar, actionable, human experience. - We prioritize responsiveness, peace of mind, and outcomes. - We empower members with truth, clarity, and care. - One Team, Moving Fast: - We are aligned in purpose, prioritization, and speed. - We gather diverse perspectives to make informed decisions. - We clear paths for each other and move fast together. - We communicate clearly and respectfully, rallying around shared goals. - Radical Ownership, Relentless Execution: - We don’t just ship– we own outcomes and drive results. - We act with urgency and precision - We anticipate, initiate, and follow through. - We meet challenges with grit and pragmatism. - We embrace new tech to deliver better outcomes. - Mission Over Ego: - We are ruthlessly aligned to our mission– and leave ego at the door. - We disagree and commit. - We don't tolerate politics or withholding information. - We operate with honesty, transparency, and respect. - Sustained Integrity in Every Detail: - We earn trust by obsessing over accuracy, quality, and clarity in everything we do. - We prioritize clinical precision– data must be right. - We sweat the details because outcomes depend on them. Why You'll Love Working With Us: We value our team at Function and offer a competitive salary and benefits package, flexible working hours, and a dynamic work environment where creativity and innovation are encouraged. If you are a highly motivated and experienced individual who is passionate about using technology to improve people’s lives, we would love to hear from you. At Function, we celebrate diversity and are committed to building a diverse and inclusive workforce. As an equal opportunity employer, we do not discriminate on the basis of race, color, gender identity, ancestry, religion, age, sexual orientation, national origin, disability, marital status, Veteran status, or any other occupationally irrelevant criteria. Join the Function Health team and become a part of our mission to build a healthier future for all. Discover more about us and how we're changing the face of healthcare at Function Health. Important Notice: Legitimate communication from the Function Health team will always come from an email address ending in @functionhealth.com. Function Health will never request personal information such as banking details or payment during the hiring process. Please be cautious of communications or job offers that come from other email domains, instant messaging platforms, or unsolicited calls. If you ever have doubts about the legitimacy of a communication, please reach out to us directly at talent@functionhealth.com.

United States
Self Financial, Inc. logo

Principal Information Security Engineer

Self Financial, Inc.

Build credit. Build savings. Build dreams.

Full TimeRemoteTeam 51-200Since 2015H1B No Sponsor

Self Financial is a venture-backed, high-growth FinTech company with a mission to increase economic inclusion and financial resilience by empowering people to build credit and build savings. We're looking for people who share our passion and are driven to tackle challenges, find solutions and make the financial space better for the communities we serve. Our team is passionate about challenging the status quo of the credit industry by providing people accessible tools to take control of their credit. Executing on our mission requires deep collaboration across our teams to ensure our products reach the people who can benefit from them the most, particularly the 100 million+ Americans who have no or low credit. We celebrate diversity and are committed to creating an inclusive environment for all employees. To that end, we seek to recruit, develop and retain the most talented people from a diverse candidate pool. Role Summary The Principal Information Security Engineer is responsible for owning cybersecurity operations and defense across all Self products and infrastructure. This role plays a critical part in protecting customer data, ensuring compliance with SOC 2 and PCI requirements, and partnering closely with engineering and IT teams to detect, investigate, and respond to security threats. The ideal candidate brings deep expertise in security operations, threat detection, and incident response with hands-on experience in tools like Splunk Enterprise, CrowdStrike, Wiz, and Netskope. What You Will Do - Own end-to-end cybersecurity operations, including threat detection, incident response, and vulnerability management across all Self products and infrastructure - Build, tune, and maintain detection content in Splunk Enterprise (SIEM) to identify threats, anomalies, and policy violations - Operate and optimize CrowdStrike for endpoint detection and response (EDR), including alert triage, threat hunting, and containment - Manage cloud security posture using Wiz, including misconfiguration identification, risk prioritization, and remediation tracking - Administer and optimize Netskope for CASB and secure web gateway (SWG) functions, including DLP policy enforcement, shadow IT visibility, and web threat protection - Design, manage, and optimize Next-Generation Firewalls (NGFW) and cloud native networking to enforce zero-trust principles and secure perimeter defenses. - Lead incident response efforts - from detection through containment, eradication, and post-incident review - Conduct proactive threat hunting across endpoint, network, and cloud environments - Partner with engineering and infrastructure teams to remediate critical security findings and reduce attack surface - Lead and perform third-party vendor security reviews and risk assessments - Support SOC 2 and PCI compliance efforts, including audit preparation and evidence collection - Identify security risks across the environment and recommend mitigation strategies - Monitor emerging cybersecurity threats and translate them into actionable detection and prevention controls Who You Are - 12+ years of experience in cybersecurity, security operations, or information security engineering - Hands-on experience with Splunk Enterprise for SIEM, log management, and detection engineering - Proficiency with CrowdStrike for endpoint detection, response, and threat hunting - Experience using Wiz or similar CSPM tools for cloud security visibility and risk remediation - Hands-on experience with Netskope or similar CASB/SSE platforms for data loss prevention, shadow IT, and secure web access - Strong background in incident response, including investigation, containment, and root cause analysis - Experience with vulnerability management programs and remediation workflows - Solid understanding of network security, cloud security (AWS/GCP/Azure), and identity and access management - Experience supporting or operating within SOC 2 and PCI compliance environments - Ability to partner effectively with engineering and infrastructure teams to drive security outcomes - Strong risk assessment, prioritization, and communication skills Preferred Qualifications - Experience performing third-party vendor security assessments - Familiarity with cloud-native architectures and container security - Prior experience in fintech, regulated industries, or environments handling sensitive customer data - Experience with threat intelligence platforms and integrating feeds into detection workflows - Security certifications such as CISSP, CISM, GCIA, GCIH, GCED, or equivalent experience Base salary range: $ 180,000-210,000 annually. Individual pay is based on factors unique to each candidate, including skill set, experience, and other job-related reasons. Benefits and Perks: We have the compensation and benefits you expect. But there's one thing that Self Financial can offer that many companies cannot: we can positively change the world, while making a profit. We are a team of Builders, empowering our customers to build their dreams. We have a Do the Right Thing ethos in all that we do, and we hope you value that approach, too. Our perks include: - Company equity in the form of Stock Options - Performance-based bonuses - Generous employer-paid health, vision and dental insurance coverage - Flexible vacation policy - Educational assistance - Free gym membership - Casual dress code - Team building events and activities - Remote work arrangements/ flexible work schedule - Paid parental leave Self Financial requires all employees hired to successfully pass a background check. We are an Equal Opportunity Employer. At this time, we are only able to consider applicants who are U.S. Citizens or Green Card Holders for employment opportunities. We appreciate your understanding.

United States
$180K - $210K / year
Huntington National Bank logo

Facilities Technician - Pickerington

Huntington National Bank

Sine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona

Description This position is considered remote; however, you must be located in the southern Columbus/Pickerington area. You will be responsible for 20-30 Huntington Bank branch locations. Summary: The Facilities Technician manages retail & corporate bank properties in various counties. They are an emergency responder - on call and overtime is mandatory based on business need. Primary focus is to self-perform 40-60% of maintenance work. Duties & Responsibilities: - Project planning, budgeting and all aspects of maintenance, construction, relocation, and remodeling. - Supply own basic tools including hammer, wrenches, screwdrivers, pliers, saws. Power tools will be supplied if needed. - Develops work processes for vendors and contractors. - Communicates with internal customers/natural owners. - Computer proficiency, general maintenance skills and HVAC knowledge required. - Operate Facilities Management work order system - Participate in staff and departmental meetings - Complete required in-person & on-line training sessions - Visit every assigned property quarterly - Complete annual site assessments and record in work order software program - Provide support to Functional Coordinator, Facilities Manager II & Regional Facility Manager - Primary focus will be to self -perform 40-60% of non-contracted services - Verify Vendor performance and pricing - Interim HVAC filter changes - Lighting repairs - Plumbing repairs - Electrical repairs - Exterior repairs - Interior repairs - Non Specific task - Other duties as assigned This position is considered remote; however, you must be located in the southern Columbus/Pickerington area. You will be responsible for 20-30 Huntington Bank branch locations. Basic Qualifications: - High School Diploma or equivalent - Valid Driver's License. Huntington will provide a company vehicle to use for work purposes - 3+ years Facilities Management experience to include basic preventative maintenance of multiple facilities, minor repairs involving plumbing, heating/cooling, basic electrical repairs and furniture moves, and the coordination and scheduling of maintenance with various vendors - Prior experience with creating and maintaining a budget for facility repairs & vendor proposal reviews Preferred Qualifications: - Trade Certifications preferred - Computer Proficiency to include MS Outlook, Word, and Excel. - Experience with Facilities Management software - Knowledge and skills related to building Maintenance incl. HVAC - Ability to lift loads of up to 50 pounds. - Excellent written and verbal communication skills - Good project management skills including budgeting and documentation - Time Management - Leadership: Organizes work flow for designated group and/or projects: reviews the work of others, sets team goals - Quality Assurance: Adheres to bank policies and procedures and complies with legal and regulatory requirements. Follows, or in some cases establishes, as required, effective controls and processes to ensure risks are measured, monitored and controlled and compliance requirements are adhered to on an on-going basis. Keep abreast of risk-related changes that may impact assigned work functions and processes. - Qualified individual must be self-motivated requiring minimal supervision and possess a desire to promote "Best in Class" service through their actions. Exempt Status: (Yes = not eligible for overtime pay) (No = eligible for overtime pay) No Workplace Type: Remote Our Approach to Office Workplace Type Certain positions outside our branch network may be eligible for a flexible work arrangement. We’re combining the best of both worlds: in-office and work from home. Our approach enables our teams to deepen connections, maintain a strong community, and do their best work. Remote roles will also have the opportunity to come together in our offices for moments that matter. Specific work arrangements will be provided by the hiring team. Huntington will not sponsor applicants for this position for immigration benefits, including but not limited to assisting with obtaining work permission for F-1 students, H-1B professionals, O-1 workers, TN workers, E-3 workers, among other immigration statuses. Applicants must be currently authorized to work in the United States on a full-time basis. Huntington is an Equal Opportunity Employer. Tobacco-Free Hiring Practice: Visit Huntington's Career Web Site for more details. Note to Agency Recruiters: Huntington will not pay a fee for any placement resulting from the receipt of an unsolicited resume. All unsolicited resumes sent to any Huntington colleagues, directly or indirectly, will be considered Huntington property. Recruiting agencies must have a valid, written and fully executed Master Service Agreement and Statement of Work for consideration.

United States
Humana logo

Senior CyberSecurity Engineer

Humana

Louisville, Kentucky-based Humana is a leading healthcare company that offers a variety of health, wellness, and insurance products and services designed to offer an integrated app

• Design, implement, and maintain PAM solutions, including vaulting, credential rotation, session management, and privileged access workflows. • Drive hands-on remediation of high-risk privileged access to ensure principle of least privilege is adhered to and comprehensive controls safeguard existing privileged entitlements. • Implement and enhance privileged access controls across Windows, Linux/AIX, MacOS, Active Directory/Azure AD, cloud platforms, and databases. • Partner with application, infrastructure, and cloud engineering teams to ensure privileged access is correctly inventoried, vaulted, rotated, and governed. • Support onboarding of applications and services into PAM solutions, including privilege mapping, configuration, and testing. • Collaborate with the Associate Director on roadmap execution, technical design decisions, and delivery of program initiatives. • Provide technical input into PAM posture reporting, risk remediation efforts, and audit/compliance responses. • Develop and maintain technical documentation, standards, runbooks, and operational procedures for PAM services. • Participate in incident response, troubleshooting, and root-cause analysis for PAM-related issues. • Support on-call responsibilities and escalation handling for privileged access services as required. • Stay current on emerging PAM technologies, threats, and best practices to continuously improve PAM capabilities.

Florida + 8 moreAll locations: Florida | Illinois | Kentucky | New York | North Carolina | Massachusetts | Tennessee | Texas | Virginia
$117.6K - $161.7K / year
Job Closed