Overstory logo
Overstory

Satellite vegetation intelligence for smarter infrastructure and safer communities.

Senior Security Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

Canada

Posted

25 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expEnglishAWSAzureCloudGoogle Cloud Platform

Job Description

Senior Security Engineer

Overstory

• Own and evolve Overstory’s compliance program, ensuring ongoing alignment with SOC 2, ISO 27001, and other relevant frameworks • Drive vulnerability management end-to-end, from detection to remediation, working closely with engineering teams to prioritize and resolve risks efficiently • Design and improve security processes and controls across infrastructure, applications, and internal systems • Lead security input in architecture and engineering decisions, helping teams build secure-by-design systems • Oversee and improve identity and access management, endpoint security, and core IT security practices • Own vendor security and third-party risk management, including assessments, risk evaluation, and mitigation strategies • Lead audit readiness and execution for SOC 2 and ISO 27001, including control design, evidence collection, and auditor coordination • Partner with customer-facing teams to handle security questionnaires and build scalable, high-quality response processes • Contribute to security awareness and culture, mentoring others and raising the security bar across the organization

Job Requirements

  • 5+ years of experience in security engineering, security operations, or a related field
  • Direct experience with security and compliance frameworks such as SOC 2 and/or ISO 27001, including audit processes
  • Deep experience with vulnerability management, including tooling, prioritization, and remediation workflows
  • Fluency working across cloud environments (AWS, GCP, or Azure) and modern SaaS ecosystems
  • Experience with identity and access management, endpoint security, and IT/security operations
  • Demonstrated ability to translate security risks into clear, actionable guidance for technical and non-technical stakeholders
  • Demonstrable experience (or at a minimum a serious interest in) leveraging AI tooling to accelerate business impact.
  • Strong written communication skills and are comfortable owning documentation and audit artifacts
  • Demonstrable proactive, pragmatic mindset as well as capacity for balancing security best practices with business needs
  • Experience working cross-functionally influencing without authority in a remote-first environment

Benefits

  • Competitive, location-specific compensation and benefits
  • Flexible, autonomous and collaborative working environment rooted in trust - we build our work days around our lives, not the other way around
  • Home office stipend, coworking and ongoing education budgets
  • A company culture that genuinely embodies each of our core values
  • To be part of truly mission-driven work that reduces wildfires, protects earth’s natural resources and helps solve our climate crisis

Related Categories

Related Job Pages

More Security Engineer Jobs

OtherRemoteTeam 51-200

Role Description Tier One Technologies has an immediate need for an Information System Security Officer to support our US Government client. This will be a 100% remote position. SELECTED CANDIDATES WITHOUT REQUIRED CLEARANCE WILL BE SUBJECT TO A FEDERAL GOVERNMENT BACKGROUND INVESTIGATION TO RECEIVE IT. - Conduct assessments of threats and vulnerabilities. - Determine deviations from acceptable configurations or enterprise or local policy. - Assess the level of risk and develop and/or recommend appropriate mitigation countermeasures in operational and non-operational situations. Qualifications - A degree from an accredited College/University in the applicable field of services is required. If an individual's degree is not in the applicable field, then 4 additional years of related experience is required. - 8+ years of overall cyber security-related experience. - Ability to manage responsibility for security assessments of a variety of applications or domains, including cloud computing, and to manage several project/initiatives of large size, complexity, and risk. - Proficiency in implementing security controls, conducting risk assessments, and documenting compliance measures based on NIST RMF and ISO standards to meet organizational and regulatory requirements. - Proficiency in successfully evaluating and supporting documentation, validation, and accreditation processes necessary to ensure that new and existing Information Technology systems meet the organization's Information Assurance and security requirements. - Proficiency in utilizing Governance, Risk, and Compliance (GRC) tools for managing Assessment & Authorization (A&A) processes. - Expertise in ensuring appropriate treatment of risk, compliance, and assurance from internal and external perspectives. - Demonstrated ability to support development of actionable security blueprints, principles, models, designs, standards, and guidelines to ensure enterprise IT architecture and support is consistent, usable, secure and adds value to the business. - Experience with network and vulnerability scanning tools and technologies to interrogate systems for configuration and status. - In-depth understanding of security architecture principles and best practices to design, implement, and maintain secure IT infrastructures in alignment with A&A policies. - Ability to serve as subject matter expert (SME) for the company’s A&A process, including providing guidance to stakeholders, business units, and new A&A resources as necessary. - Strong organizational skills and ability to build and maintain schedules and step-by-step action plans. - Effective communication and collaboration skills to work with cross-functional teams, business units, stakeholders, and IT professionals, and brief executives. Requirements - Must be able to obtain a Position of Public Trust Clearance. - Be able to pass a drug screening, criminal history, and credit checks. - Must be a US Citizen or have permanent residence status (Green Card). - Must have lived in the United States for the past 5 years. - Cannot have more than 6 months travel outside the United States within the last five years. Military Service excluded. (Exception does not include military family members.)

United States
Home Depot logo

Cybersecurity Senior Analyst - Disaster Recovery

Home Depot

Home Depot is a Fortune 500 company and the world's largest specialty retailer of home-improvement products. Founded in 1978 with its first two stores in Atlanta, Georgia, Home Dep

Cybersecurity Senior Analyst | Disaster Recovery (Remote) Remote/Virtual GEORGIA - VIRTUAL - GA01 Full time Req177729 With a career at The Home Depot, you can be yourself and also be part of something bigger. Position Purpose:  The Cybersecurity team at Home Depot protects the organization’s systems, data, and technology assets through proactive risk management, strong operational controls, and rapid incident response. This role supports core security functions by ensuring the resilience of critical systems and maintaining accurate oversight of technology assets across the enterprise.  Key Focus Areas:  Disaster Recovery:  - Support planning, execution, and testing of disaster recovery procedures to ensure business continuity.  - Partner cybersecurity teams to validate recovery readiness and close any identified gaps.  Technology Asset Management:  - Maintain visibility of hardware and software assets across the enterprise to reduce security risk.  - Ensure assets are properly tracked, compliant, and aligned with lifecycle and vulnerability management processes.  Protecting what matters most to our associates and consumers by securing our sensitive data and critical assets from current and emerging threats. At The Home Depot Cybersecurity consists of Architecture, Governance, Identity & Access Management, Internal Threat Operations, Issue and Compliance Management, Risk Assessment/Advisory, Security Consulting, Security Operations and Strategic Planning.   Sr. Analysts perform data gathering, analysis, synthesis and develop solutions to support THD Cybersecurity practices.  Key Responsibilities: - 50% Analysis - Synthesize data to develop a solution, communicate the solutions, present the solution to teams/stakeholders - 20% Collaborate - Partner cross-functionally to identify trends and resolve issues - 20% Drive Execution - Implement solutions to meet customer expectations; Ensure initiative/project goals are met in a timely manner - 10% Support and Enable - Mentor junior level Analyst Direct Manager/Direct Reports: - This Position typically reports to Manager or Sr. Manager - This Position has 0 Direct Reports Travel Requirements: - Typically requires overnight travel less than 10% of the time. Physical Requirements: - Most of the time is spent sitting in a comfortable position and there is frequent opportunity to move about. On rare occasions there may be a need to move or lift light articles. Working Conditions: - Located in a comfortable indoor area. Any unpleasant conditions would be infrequent and not objectionable. Minimum Qualifications: - Must be eighteen years of age or older. - Must be legally permitted to work in the United States. Preferred Qualifications: - IT Infrastructure Fundamentals – A solid, working understanding of enterprise IT environments (e.g. networking, databases, storage, virtualization, basic cloud concepts) to effectively communicate with engineers and understand recovery dependencies.  - Cybersecurity Awareness – Foundational understanding of current cybersecurity threats and the role of disaster recovery in the broader incident response strategy.  - Workshop Facilitation – Strong ability to lead meetings and facilitate workshops with both technical subject matter experts and non-technical business stakeholders.  - Documentation & Reporting – Excellent technical writing skills required to draft disaster recovery plans, test summary reports, and executive summaries.  - Project Management – Solid organizational and project management skills, with the ability to manage multiple workstreams and drive DR initiatives to completion across teams.  - BIA Execution – Experience planning, scheduling, and participating in Business Impact Analysis to identify critical business processes and establish RTO and RPOs.  - DR Planning and Validation – Experience coordinating, facilitating, and documenting IT disaster recovery plans and recovery testing (tabletops, application failovers).  - Experience in IT Disaster Recovery, Risk Management, Cybersecurity, or a closely related technical infrastructure/security role.   Minimum Education: - The knowledge, skills and abilities typically acquired through the completion of a bachelor's degree program or equivalent degree in a field of study related to the job. Preferred Education: - No additional education Minimum Years of Work Experience: - 5 Preferred Years of Work Experience: - No additional years of experience Minimum Leadership Experience: - None Preferred Leadership Experience: - None Certifications: - None Competencies: - Action Oriented - Collaborates - Communicates Effectively - Customer Focus - Drives Results For California, Colorado, Connecticut, Rhode Island, Nevada, New York City, Ithaca (NY), Westchester County (NY), and Washington residents: The pay range for this position is between $100,000.00 - $180,000.00

Georgia
$100K - $180K / year
Eliassen Group logo

Operational Technology Security Engineer

Eliassen Group

Founded in 1989, Eliassen Group is an award-winning consulting, staffing, and recruiting company. In 2018, Eliassen Group merged with Principle Solutions Group to move forward as o

Job Description: Anywhere Type: Permanent Category: Security Industry: Government Workplace Type: Remote Reference ID: JN -042026-106569 Date Posted: 04/26/2026 Shortcut: http://careers.eliassen.com/EYewvM - Description - Recommended Jobs Description: Description: Remote Our client seeks an Operational Technology Security Engineer to secure industrial and OT environments through the design, implementation, and monitoring of controls aligned to DoD and industry standards. The engineer will assess risk, harden architectures, and integrate cybersecurity across the OT system lifecycle. The role will bridge IT and OT practices, support inspections and incident response, and deliver analytics to inform leadership decisions. Salary: $110,000 - $135,000/ yr. w2 Responsibilities: - Support planning, design, development, testing, integration, and security of OT systems. - Analyze and implement OT cybersecurity requirements and controls. - Conduct vulnerability assessments across OT and IT systems, networks, applications, and databases. - Develop, maintain, and validate cybersecurity documentation and artifacts. - Manage and track POA&M entries, including remediation actions and timelines. - Perform OT-specific risk assessments and recommend mitigation strategies. - Support DoD cybersecurity inspections and ensure environment readiness. - Deploy and tune OT security monitoring solutions including IDS, IPS, and anomaly detection. - Develop and implement OT-specific incident response plans. - Manage software and firmware updates while minimizing operational disruption. - Generate cybersecurity reports, analytics, and trend analysis for leadership. - Bridge IT and OT cybersecurity practices to ensure aligned protections. - Provide technical recommendations to engineers, operators, and leadership. - Support compliance with industry and regulatory cybersecurity standards. - Build automated workflows for vulnerability management and reporting. Experience Requirements: - Minimum seven years of experience in OT cybersecurity or a related field. - Experience supporting DoD or federal cybersecurity environments (preferred). - Hands-on experience with industrial control systems and OT environments. - Strong knowledge of OT systems including SCADA, ICS, DCS, PLCs, HMIs, RTUs, and field devices. - Experience with OT communication protocols such as Modbus/TCP, DNP3, BACnet, and IEC 61850. - Understanding of secure OT network architectures including segmentation, firewalls, and IDS/IPS. - Knowledge of secure remote access solutions for OT environments. - Experience with vulnerability scanning tools such as ACAS, Nessus, Qualys, Forescout, and EyeInspect. - Familiarity with cybersecurity frameworks including NIST CSF, ISA/IEC 62443, and NERC CIP. - Understanding of DoD cybersecurity requirements including STIGs, IAVMs, and configuration guides. - Experience with patch management and change management processes. - Ability to conduct forensic analysis within OT environments. - Proficiency with Microsoft Excel, Access, Power BI, and Power Platform. - Strong analytical, problem-solving, and research skills. - Excellent written and verbal communication skills. - Ability to work independently and in team environments. - Active DoD Secret Clearance. - Training module or course completion in Forescout. Education Requirements: - One of the following certifications: 300 - ICS Cybersecurity; AWS Certified Solutions Architect - Associate; GIAC Certified Windows Security Administrator (GCWN); Infoblox Core DDI Configuration and Administration; ISA Certified Control System; Microsoft Certified: Azure Administrator Associate; Microsoft Certified Solutions Associate Windows Server 2016; Microsoft 365 Certified: Messaging Administrator Associate; MS 2016 Active Directory Identity and Networking; Oracle Cloud Infrastructure Foundations 2020 Certified Associate; OCI Cloud Infrastructure Foundations Associate 2025 Exam. - And one of the following certifications: CCNA Security; CompTIA CySA+; GICSP; CompTIA Security+ CE; CND; SSCP. Recruitment Transparency Notice Eliassen Group values transparency in our recruitment practices. Please be advised that Eliassen Group utilizes artificial intelligence (AI) tools as part of its initial application screening and hiring process. You may receive email and SMS notifications from the Eliassen Virtual Recruiting Team (noreply@eliassen.com, 781-808-2924) inviting you to complete a brief voice screening as part of your application process. These tools assist our hiring teams in different ways, including but not limited to, assistance in reviewing application materials to help identify candidates whose qualifications most closely match the requirements of the position. All AI-assisted evaluations and responses are reviewed by human recruiters before any hiring decisions are made. The use of AI in our process is intended to support fairness, efficiency, and consistency, and Eliassen Group takes measures to prevent bias or discrimination in connection with its hiring practices. By proceeding, you acknowledge, agree, and consent to Eliassen Group’s use of these tools, including AI tools, as part of the application and hiring process. Skills, experience, and other compensable factors will be considered when determining pay rate. The pay range provided in this posting reflects a W2 hourly rate; other employment options may be available that may result in pay outside of the provided range. W2 employees of Eliassen Group who are regularly scheduled to work 30 or more hours per week are eligible for the following benefits: medical (choice of 3 plans), dental, vision, pre-tax accounts, other voluntary benefits including life and disability insurance, 401(k) with match, and sick time if required by law in the worked-in state/locality. If anyone reaches out to you about an open position connected with Eliassen Group, please ensure that you are working directly with us by confirming the following: · When you work with Eliassen Group, all email communication will come from an Eliassen.com address, never Gmail, Yahoo, etc. · Eliassen Group will never ask you for personal information (home address, bank account, or check routing number) until you have worked with someone clearly associated with Eliassen Group. If you have any indication of fraudulent activity, please contact fraud@eliassen.com. About Eliassen Group: Eliassen Group is a strategic consulting firm that helps organizations reach further and achieve more through our technology, business advisory, and life sciences solutions. For nearly 40 years, we have combined exceptional people, deep domain expertise, and intelligent capabilities to expand our clients’ capacity and accelerate meaningful outcomes. We are driven by a purpose to positively impact the lives of our employees, clients, consultants, and the communities we serve. Eliassen is committed to building a diverse and inclusive team from a variety of backgrounds, perspectives, and skills. We are an Equal Opportunity and Affirmative Action Employer and all employment decisions are based on merit, performance, and business needs. Eliassen does not discriminate on the basis of race, color, gender identity or expression, sexual preference or orientation, sex (including pregnancy, childbirth, and related medical conditions), marital status, creed, religion, physical or mental disability, genetic information, military or veteran status, age, ancestry, national origin, citizenship status, prohibited criminal record inquiries of applicants and employees, or any other category protected by federal, state, or local laws. Don’t miss out on our referral program! If we hire a candidate that you refer us to then you can be eligible for a $1,000 referral check!

Worldwide
$110K - $135K / year
InternshipRemoteTeam 1,001-5,000Since 1972H1B No Sponsor

• Assist with monitoring alerts and logging to identify potential threats • Support threat intelligence collection and analysis to help detect emerging cyber risks • Participate in incident triage and response activities, including evidence collection and documentation • Assist with vulnerability scanning, reporting, and remediation tracking across enterprise systems • Explore the use of generative AI tools for cyber defense, automation, documentation enhancement, or workflow enhancements • Participate in team meetings, training, and assist with documentation/process updates • Assist with system hardening, patch validation, account reviews, and CMMC related artifact gathering • Participate in cross-departmental projects and process improvement initiatives as available

New York
Job Closed