Job Closed
This listing is no longer active.
Monks is the global, digital-first, data-driven, unitary operating brand of S4 Capital plc. With a legacy of innovation and specialized expertise, Monks combines an extraordinary range of global Marketing and Technology Services to redefine how brands interact with the world. Through Monks.Flow, its flagship AI ecosystem for marketing orchestration, Monks transforms marketing into a growth engine, collapsing timelines and connecting brands to culture in real time. Monks was named a Contender in The Forrester Wave™: Global Marketing Services. Ranks among Cannes Lions' Top 10 Creative Companies (2022-25). Remains the only partner featured in AdExchanger’s Programmatic Power Players list every year (2020-24). Named Adweek’s first AI Agency of the Year (2023). Awarded Business Intelligence Group’s 2025 Excellence in Artificial Intelligence Award in both the Organizational and AI Product categories. Earned titles such as Optimizely Experimentation Partner of the Year (2025) and runner-up for the Adobe Firefly Partner Award (2024). Achieved a record-breaking number of FWAs and continues to hold the most of any partner.
Information Security Compliance Specialist
Location
Worldwide
Posted
50 days ago
Salary
0
Seniority
Mid Level
Job Description
Information Security Compliance Specialist
Monks
Role Description As an Information Security Analyst, your core responsibility will be safeguarding customer and company data, protecting the company's reputation, and making vital decisions that are integral to shaping the state-of-the-art security posture for the business's future success. This person should detect new threats, understand the risk assessment process, contribute to the action plan development, and promote the progress of mitigation implementation and evolution. The position will cover security assessment activities, technical controls evaluation, risk assessments, management of clients' requirements, and internal awareness. As a valuable member of our global Infosec Team, you will have the opportunity to collaborate with colleagues across the globe, fostering a dynamic and diverse work environment. Your role will involve working closely with stakeholders from various departments, forging strong partnerships to ensure the collective success of our information security initiatives. Responsibilities: - Assess and track security posture across platforms and systems, following up on remediation tasks to close gaps efficiently. - Collaborate with stakeholders across technology, legal, and business units to integrate security requirements into projects, services, and vendor relationships. - Perform regular assessments of technical environments to ensure compliance with internal policies and external standards. - Identify and document risks associated with third-party vendors, cloud infrastructure, access management, and system configurations. - Evaluate and recommend technologies that enhance our security and compliance posture (e.g., DLP, EDR, network segmentation, cloud security tools). - Collaborate with the alignment to the global Information Security Management System (ISMS), based on ISO/IEC 27001:2022 and best practices from well-known frameworks such as NIST. - Maintain comprehensive documentation of security processes, audit reports, compliance controls, and risk assessments. - Utilize tools and platforms to automate compliance checks and reporting across the environment. - Stay current with industry trends, technologies, and regulatory changes, proactively suggesting enhancements to the security baseline. - Contribute to security awareness programs and training efforts within the organisation. - Mentor and support colleagues to encourage growth and a strong security culture across teams. Qualifications - Bachelor's degree/advanced education in Computer Science, Cybersecurity, Computer or Systems Engineering or equivalent. - Minimum of 4 years of experience in security. - Solid understanding of core information security concepts, including confidentiality, integrity, and availability (CIA Triad). - Solid understanding of technical concepts and security hardening practices in the following areas: - Network architecture and segmentation - Firewalls, IDS/IPS (Intrusion Detection/Prevention Systems) - Encryption and Public Key Infrastructure (PKI) - Endpoint protection and hardening (EDR, DLP) - Operating system security (Windows, Linux, macOS) - Databases - Single Sign-On (SSO), SAML, and OIDC - Role-Based Access Control (RBAC) and least privilege principles - Cloud security hardening (AWS, Azure, GCP) - Secure Software Development Lifecycle (S-SDLC) - Patch management strategy and tooling - Logging and monitoring - API security and secure integrations - Strong analytical and problem-solving skills, capable of diagnosing issues and implementing effective solutions. - Ability to self-organize and plan activities with commitment towards results. - Good communication and social skills. - Upper Intermediate English level. Requirements - Not a must, but a plus: - Certifications such as CISSP, CISM, CCSK, Security+, AWS Security Specialty, or similar. - Experience designing or optimizing a compliance program across multiple business units or geographies. - Familiarity with security automation platforms and compliance monitoring tools. - Exposure to scripting or automation for reporting and process efficiency. - Experience collaborating with third-party auditors, client security teams, or legal/compliance units. Benefits - We believe in fostering an environment where a diversity of perspectives can thrive. - We proactively work to design hiring processes that promote equity and inclusion while mitigating bias. - We celebrate diversity and are committed to building a team that reflects the communities we serve. - We welcome and encourage qualified applicants from all backgrounds who are excited to contribute to our mission.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Date Posted: 2026-04-17Country: United States of AmericaLocation: US-PR-SANTA ISABEL-B1 ~ Felicia Industrial Park - St B1 ~ BLDG 1Position Role Type: RemoteU.S. Citizen, U.S. Person, or Immigration Status Requirements: U.S. citizenship is required, as only U.S. citizens are authorized to access information under this program/contract.Security Clearance: None/Not Required RTX Corporation is an Aerospace and Defense company that provides advanced systems and services for commercial, military and government customers worldwide. It comprises three industry-leading businesses – Collins Aerospace Systems, Pratt & Whitney, and Raytheon. Its 185,000 employees enable the company to operate at the edge of known science as they imagine and deliver solutions that push the boundaries in quantum physics, electric propulsion, directed energy, hypersonics, avionics and cybersecurity. The company, formed in 2020 through the combination of Raytheon Company and the United Technologies Corporation aerospace businesses, is headquartered in Arlington, VA. The following position is to join our RTX Enterprise Services team in Santa Isabel, Puerto Rico: What You Will Do - Collaborate with internal RTX business units to assess network security issues and develop effective design solutions. - Lead the implementation of new cloud firewall deployments, focusing on network and security policies. - Administer and manage Palo Alto and Checkpoint cloud firewalls to ensure robust security operations. - Contribute to network security efforts during acquisition and divestiture activities. Update and maintain information for DNS, DHCP, and IP Address Management systems. - Participate in rotational on-call duties. - This position will reference written work instructions for guidance with daily job activities. Work instructions are available in English only. - Travel approximately 10%. Qualifications You Must Have - A University Degree or equivalent experience and minimum 5 years prior relevant experience, or an Advanced Degree in a related field and minimum 3 years experience. - Minimum of 3+ years of experience with network security best practices, including evaluating and implementing security requests. - Proficiency in configuring and managing firewalls, NAT, and packet filtering. - 3+ years of hands-on experience with BGP routing in private and public cloud environments. - Demonstrated ability to design, implement, and support private and public peering for cloud exchanges with a focus on routing and firewall best practices. - Experience with common and industry-standard cloud authentication mechanisms and proficiency with scripting languages such as Perl, VBScript, PowerShell, or Terraform. - 3+ years of experience troubleshooting firewall and access issues using logging and monitoring tools. - Proven ability to maintain the stability of firewall environments, including product lifecycle management. - 3+ years of experience with DNS, DHCP, and IP address management systems. Qualifications We Prefer - Industry-recognized networking certifications (e.g., CCNA, CCNP, or equivalent) - Next-Generation Firewall (NGFW) certification (e.g., Palo Alto Networks certification) - Experience with Linux system administration - Information security certifications (e.g., CISSP, GIAC) What We Offer Whether you’re just starting out on your career journey or are an experienced professional, we offer a robust total rewards package with compensation; healthcare, wellness, retirement and work/life benefits; career development and recognition programs. Some of the benefits we offer include parental (including paternal) leave, flexible work schedules, achievement awards, educational assistance and child/adult backup care. Learn More & Apply Now! Location: This position is remote. However, the successful candidate must live in Puerto Rico. Please consider the following role type definition as you apply for this role: Remote: This position is currently designated as remote. Employees who are working in Remote roles will work primarily offsite (from home). The employee may be expected to travel to the Santa Isabel site location as needed. RTX is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or veteran status, or any other applicable state or federal protected class. RTX provides affirmative action in employment for qualified Individuals with a Disability and Protected Veterans in compliance with Section 503 of the Rehabilitation Act and the Vietnam Era Veterans’ Readjustment Assistance Act. Privacy Policy and Terms: Click on this link to read the Policy and Terms
AI Security Architect
CIVIECIVIE provides equal employment opportunity for all applicants and employees. All qualified applicants will be considered regardless of an individual’s race, color, sex, gender identity or expression, religion, age, national origin, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, military or veteran status, or any other basis protected by federal, state or local laws. If you cannot submit your application due to a disability, please email hr@civie.com; we will reasonably accommodate individuals with disabilities to the extent required by applicable law.
About the Role We’re looking for an AI Security Architect to define and own the security architecture for a modern platform that combines cloud infrastructure, large language models, and autonomous agents. In this role, you will establish secure-by-design patterns across Azure, AI/LLM systems, and regulated data environments, helping the company scale securely as products and capabilities evolve. This role is ideal for someone who can think across systems, set architectural direction, and partner with engineering and leadership to translate emerging risks into practical, scalable controls. What You’ll Do - Define end-to-end security architecture for cloud infrastructure, AI/LLM systems, APIs, and internal platforms - Establish security standards, reference architectures, and design patterns for engineering teams - Lead architecture reviews for new products, services, and major platform changes - Own threat modeling frameworks and guide teams in identifying and mitigating design-level risks - Design secure AI/LLM usage patterns, including model access controls, prompt handling, tool-use restrictions, agent isolation, and memory boundaries - Define zero trust architectures across identity, network, service-to-service communication, and privileged access - Architect data protection strategies including classification, encryption, tokenization, retention, and isolation - Partner with engineering leadership to embed security architecture into SDLC, CI/CD, and platform design decisions - Guide compliance architecture for regulated environments, including HIPAA, SOC 2, and related frameworks - Evaluate and recommend security platforms and controls across cloud, endpoint, identity, application, and AI layers - Drive secure multi-tenant and environment isolation strategies where applicable - Support leadership on risk strategy, prioritization, and tradeoff decisions across security and product velocity Required Expertise - 6+ years of experience in security, cloud security, platform security, or related roles, including significant architecture experience - Proven experience designing and reviewing cloud-native security architectures in Microsoft Azure - Deep understanding of identity-first security, zero trust principles, and secure distributed systems design - Experience designing security controls for AI/ML or LLM-based systems, or equivalent experience securing emerging technologies at scale - Strong expertise in threat modeling, security design reviews, and architecture governance - Experience defining security standards and scalable patterns across engineering organizations - Strong understanding of networking, IAM, encryption, secrets management, and secure application architecture - Ability to communicate risk, tradeoffs, and design decisions clearly to both technical and non-technical stakeholders Preferred Qualifications - Experience working in HIPAA-regulated environments - Experience with infrastructure as code (Terraform, ARM, or similar) - Experience securing LLM-based products, agent frameworks, or autonomous systems - Familiarity with red teaming AI systems, adversarial testing, or AI abuse scenarios - Knowledge of data security practices such as DLP, tokenization, and data governance - Experience with container, Kubernetes, and platform security - Experience with security architecture reviews at scale in high-growth or enterprise environments - Certifications such as CISSP, CCSP, Azure Security Engineer Associate, Azure Solutions Architect Expert, or similar What We’re Looking For - A systems thinker who can see across the full platform and design durable security patterns - Someone who can make high-impact design decisions under ambiguity - Strong influence and collaboration skills across engineering, product, and leadership - The ability to balance security rigor with business velocity at a strategic level - Curiosity about emerging AI threats and a practical mindset for turning risk into architecture Why Join Us - Shape the security architecture of cutting-edge AI systems and agent platforms - Drive foundational security decisions with high visibility and ownership - Work closely with engineering and leadership on meaningful platform and product challenges - Help define how secure AI systems are built in a fast-moving environment We Offer - Paid vacation, sick time, and personal days - 11 company paid holidays - Quarterly UberEats voucher - Monthly Fringe benefits - Flexible work schedules - Education and professional development stipend - Health, dental, and vision benefits, with employer HSA contribution - Long-term, short-term, and life insurances - 401(k) with company match & profit sharing The typical base salary range for this position is $150,000 - $185,000. CIVIE provides equal employment opportunity for all applicants and employees. All qualified applicants will be considered regardless of an individual’s race, color, sex, gender identity or expression, religion, age, national origin, citizenship, physical or mental disability, medical condition, family care status, marital status, domestic partner status, sexual orientation, military or veteran status, or any other basis protected by federal, state or local laws. If you cannot submit your application due to a disability, please email hr@civie.com; we will reasonably accommodate individuals with disabilities to the extent required by applicable law.
Position Summary: The Senior Identity and Access Management (IAM) Analyst is responsible for advanced operational support, analysis, and continuous improvement of identity and access controls within the Cybersecurity IAM team. This role serves as a senior individual contributor, providing subject matter expertise across IAM processes and tooling while supporting secure, compliant, and efficient access to Guthrie systems and information. The Senior IAM Analyst performs complex access analysis, troubleshooting, and workflow optimization; leads IAM operational initiatives; supports audits and compliance efforts; and partners with IT, clinical, and business stakeholders to ensure least‑privilege access aligned with healthcare workflows. Core responsibilities include Identity Governance and Administration (IGA), Privileged Access Management (PAM), Single Sign‑On (SSO), Multi‑Factor Authentication (MFA), federation, and access lifecycle management across Azure AD, Active Directory, LDAP, and Epic EMR. This role operates with a high degree of autonomy and may mentor junior analysts and support engineers. Required Education and Experience: - High school diploma required; - 5+ years of experience in Identity and Access Management, information security, or related IT roles - 3+ years of hands‑on experience with IAM, PAM, MFA, and access lifecycle management processes - Experience supporting IAM in a regulated environment - Obtain one relevant professional security certification within 6 months of hire/in role - Obtain the Epic security certification within 6 months of hire/in role Preferred Qualifications - Bachelor’s degree in a relevant field preferred - Experience supporting Epic EMR security and clinical access workflows - 7+ years of experience in Identity and Access Management, information security, or related IT roles - 5+ years of hands‑on experience with IAM, PAM, MFA, and access lifecycle management processes - Healthcare experience strongly preferred - Familiarity with healthcare regulations and security frameworks (HIPAA, NYSDOH, HITRUST CSF, NIST CSF) - Experience with scripting or automation (PowerShell or similar) to improve IAM workflows - Relevant Professional certification such as CompTIA Security+, ISC2 SSCP, or equivalent - Epic Security certification Core Competencies & Skills - Advanced understanding of IAM operational processes and controls - Strong analytical and troubleshooting skills for complex identity‑based access issues - Ability to independently manage workload and prioritize competing requests - Strong written and verbal communication skills for documentation, training, and stakeholder engagement - Experience documenting standards, procedures, and control evidence - Ability to translate business and clinical requirements into effective access controls - Familiarity with emerging technology such as AI to support improvements to IAM services Essential Functions: Identity & Access Management Operations - Perform advanced provisioning and deprovisioning of regular, privileged, and Epic EMR user access - Administer and support IAM platforms including Azure AD, Active Directory, PAM, MFA, SSO, and federation - Identify, analyze, and resolve complex IAM and access workflow issues; recommend process improvements - Support and execute account lifecycle management processes to ensure appropriate access is granted and removed - Participate in IAM tool integrations, upgrades, testing, and operational enhancements - Adoption and utilization of AI to increase operational efficiencies Governance, Risk, and Compliance - Participate in periodic user access reviews and entitlement certifications across the organization - Support audits, regulatory reviews, and risk assessments by gathering and validating IAM control evidence - Ensure IAM controls operate effectively to support HIPAA Security and Privacy Rule compliance - Assist with documenting IAM control gaps, risks, and remediation recommendations - Support efforts to acquire and sustain HITRUST CSF certification Process Improvement & Collaboration - Develop and maintain IAM playbooks, procedures, and standards documentation - Establish and track operational IAM metrics and reporting for management - Partner with IT, clinical, and business stakeholders to align access controls with workflows - Provide guidance and informal mentoring to IAM Analysts and junior team members - Participate in project work to ensure IAM requirements are addressed in system designs and operating procedures Working Conditions & Expectations - Full Remote with monthly on‑call - Requires attention to detail, independent judgment, and ability to manage multiple priorities - Frequent interaction with IT, clinical staff, vendors, and auditors - No direct people management responsibility Joining the Guthrie team allows you to become a part of a tradition of excellence in health care. In all areas and at all levels of Guthrie, you’ll find staff members who have committed themselves to serving the community. The Guthrie Clinic is an Equal Opportunity Employer. The Guthrie Clinic is a non-profit, integrated, practicing physician-led organization in the Twin Tiers of New York and Pennsylvania. Our multi-specialty group practice of more than 500 physicians and 302 advanced practice providers offers 47 specialties through a regional office network providing primary and specialty care in 22 communities. Guthrie Medical Education Programs include General Surgery, Internal Medicine, Emergency Medicine, Family Medicine, Anesthesiology and Orthopedic Surgery Residency, as well as Cardiovascular, Gastroenterology and Pulmonary Critical Care Fellowship programs. Guthrie is also a clinical campus for the Geisinger Commonwealth School of Medicine.
Manager, Application Security – APAC
GitLabGitLab, founded in 2011 and based in San Francisco, California, maintains a distributed team of professionals that work remotely across multiple continents. GitLab advocates for pr
• Lead, develop, and mentor a team of Application Security Engineers focused on clearing roadblocks, career growth and development, coaching and mentoring. • Own the team’s operational cadence end to end: triage rotations, Application Security review queues, milestone planning. • Drive tactical execution of the Application Security program: scaling the team for non linear security gains, security reviews enhancements and secure design consultations for high-risk changes. • Lead AI adoption within the Application Security team: leverage AI-assisted/automated workflows for review triage, threat model generation, code analysis, and operational toil reduction. Champion practical AI use without losing critical thinking rigor. • Recommend and drive security-related technical and process improvements. • Author and execute project plans for security initiatives. Set schedules and assignments, anticipate roadblocks, and measure performance against goals. • Provide input on security architecture, features, and issues. Serve as a partner and enabler to Product and Engineering teams on application security decisions. • Partner with Security Architecture, Infrastructure Security, Security Research, and Security Operations on end-to-end risk reduction, aligning Application Security work with broader Product Security objectives. • Prepare and deliver meaningful, actionable metrics to Product Security leadership. • Hire and build a world-class team. Train team members to screen candidates and conduct structured interviews. Build the team’s ability to grow itself.


