Job Closed
This listing is no longer active.
Dayforce is a global HCM platform offering a comprehensive array of services encompassing payroll, HR, benefits, workforce management, talent, and analytics. With the mission of "m
Cybersecurity Risk and Compliance Analyst
Location
United States
Posted
32 days ago
Salary
$67K - $119.6K / year
Seniority
Mid Level
Job Description
Cybersecurity Risk and Compliance Analyst
Dayforce
Role Description We’re looking for a GRC Analyst to help ensure our cloud services meet key public sector security and compliance standards (including FedRAMP and PBMM). In this role, you’ll play a critical part in enabling government customers to securely and confidently use our platform. You’ll work across engineering, security, and compliance teams to support audits, maintain authorization status, and continuously improve our security posture. What you’ll get to do - Support FedRAMP & NIST Compliance - Support authorization, compliance, and continuous monitoring activities - Interpret and apply security controls and control enhancements - Keep key documentation up to date, including system security plans, policies, and control descriptions - Track compliance against established baselines (Low / Moderate / High) - Partner on audits and assessments - Work cross-functionally to ensure we’re always audit-ready: - Coordinate and support third-party audits (including 3PAO assessments) - Gather and review evidence from engineering, infrastructure, and operations teams - Respond to auditor questions and information requests - Help track remediation efforts and support closure of identified gaps - Contribute to annual assessments, penetration test reviews, and vulnerability reporting - Contribute to continuous monitoring - Help maintain a strong and consistent compliance posture by: - Supporting monthly FedRAMP continuous monitoring activities - Reviewing vulnerability scans and tracking remediation progress - Coordinating incident reporting and change management impacts - Ensuring changes follow approved compliance processes - Identifying and escalating potential compliance risks - Collaborate across teams - You’ll act as a bridge between technical and non-technical stakeholders: - Partner with Cloud Engineering, DevOps, Security Operations, Legal, and Product teams - Translate technical controls into clear, audit-ready documentation - Support internal reporting and briefings on compliance status and risk - Support governance and documentation - Maintain organized compliance evidence repositories - Assist with internal audits and readiness assessments - Contribute to updates of policies and standards aligned to federal requirements - Support responses to customer and government security questionnaires Qualifications - Experience in GRC, cybersecurity compliance, or audit support (typically 2+ years) - Familiarity with frameworks such as FedRAMP, NIST SP 800-53, or similar compliance programs - Experience working with auditors or assessment organizations (e.g., 3PAOs) is a plus - Exposure to cloud environments such as AWS or Azure Requirements - The FedRAMP lifecycle and continuous monitoring processes - NIST 800-53 control families - POA&M management and risk tracking - Analyzing technical controls and clearly documenting compliance - Working with compliance or GRC tools, ticketing systems, or evidence repositories Benefits - Excellent time away from work programs - Comprehensive wellness initiatives - Recognition through competitive pay and benefits - Opportunities for personal and professional growth - Commitment to community impact, including volunteer days and charity initiatives
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Role Description As a Lead Security Engineer (Consultant) in Kainos, you will be responsible for leading our security engineering and security testing efforts across Kainos Platforms and Services. Your responsibilities will include: - Setting direction on our security testing methodology, engagement scoping, outputs, and tool/technology selections. - Developing junior security engineers. - Working with agile delivery teams to promote good security practices throughout the software development journey. - Sharing knowledge and educating customers and Kainos team members on good security practices. - Managing, coaching, and developing a small number of staff, focusing on performance management and career development. - Providing direction and leadership for your team while solving challenging problems together. Qualifications - Expertise in securing Web Applications and Cloud Platforms (e.g. AWS/Azure). - Expertise in testing software and infrastructure security using existing manual or automated security tools. - Expertise in assessing software and infrastructure source code from a security standpoint. - Expertise in Continuous Security, Continuous Integration, and Continuous Delivery techniques. - Knowledge of international security standards and regulations such as NCSC, NIST, CIS, PCI, GDPR, OWASP ASVS, HIPPA, SOC2, etc. - Knowledge of typical cyber security attack vectors (e.g. OWASP Top 10, SQL, XSS, XXE, MITM, etc.) and ability to articulate threats and risks via threat modelling exercises/workshops. - Excellent communication skills, with the ability to convey security complexities to audiences of various technical abilities. - Demonstrated ability in managing, mentoring, and coaching team members and the wider community. - Good programming or scripting experience across Windows/Linux/MacOS. - Stays up to date with new threats and attack types. Requirements - Penetration testing qualifications (e.g. OSCP, CREST, TIGER or equivalent). - Experience of working with external penetration test companies to translate report findings into actionable tasks. - Experience with security tools (e.g. Burp Suite, OWASP-ZAP, NMAP, Nessus, Kali, Metasploit, etc.). - Knowledge about main cyber security areas (e.g. OSINT, network scanning, enumeration, sniffing, session hijacking, social engineering, firewalls, honeypots, IDS/IPS/WAF/AV/DLP, Cryptography/PKI, IoT threats, trojans/viruses/worms/backdoors/ransomware, etc.). - Active participation in knowledge sharing activities, both within the team and at a wider level. - Active involvement in the security community – conference speaking, sharing knowledge externally. - Experience of working in an Agile environment. Benefits - People-first culture where ideas are valued and growth is supported. - Opportunity to be part of a diverse, ambitious team that celebrates creativity and collaboration.
Principal Security Engineer – Threat Intelligence
SnowflakeSnowflake delivers the AI Data Cloud to help organizations share data, build apps and power their business with AI.
• Help define and mature the strategy for Threat Intelligence at Snowflake, including where the program should invest in people, processes, engineering, and AI-enabled capabilities. • Identify, profile, and track threat actors targeting Snowflake, our customers, partners, and ecosystem, and translate that intelligence into relevant, actionable outcomes. • Operationalize threat intelligence to help prioritize security initiatives and drive action with the relevant security teams and stakeholders. • Produce high-quality intelligence reports, assessments, briefs, and leadership-ready communications based on external events, internal requirements, and proactive research. • Engineer solutions that improve the efficiency, scale, and impact of the Threat Intelligence program, including automations, collection pipelines, enrichment workflows, and analyst tooling. • Build and improve AI-assisted intelligence workflows for tasks such as report triage, signal enrichment, summarization, vendor/customer monitoring, and threat-informed hunts, with strong measurement and quality. • Partner closely with Threat Detection, Incident Response, and other security teams to convert intelligence into detections, threat hunts, investigative pivots, and control recommendations. • Monitor alerts, intelligence feeds, vendor reporting, and external developments for threat events that may affect Snowflake. • Drive standards for how intelligence is curated, evaluated, delivered, and measured so the program remains high-signal, timely, and scalable. • Mentor other engineers and analysts by raising the team’s technical depth, analytic rigor, and operational maturity.
Senior Security Engineer - Kubernetes Security & AI Automation
Axos BankBank, borrow, invest & plan – manage your financial life with Axos. Our team is the secret to our success. Join us!
Role Description Axos is building an AI-native security organization that moves at the speed of the business. Our Kubernetes footprint is expanding to support rapid innovation, continuous deployment, and faster time to market across every line of business. We are looking for a Kubernetes Security & AI Automation Engineer who will own the security posture of our container and orchestration infrastructure while pioneering AI-driven automation to detect, investigate, and remediate threats at machine speed. This is not a compliance checkbox role. You will build things: policy-as-code pipelines, AI-powered detection logic, and automated response workflows that keep Kubernetes clusters hardened without slowing engineering velocity. Responsibilities - Kubernetes & Container Security - Design, implement, and maintain security controls across Kubernetes clusters (EKS, AKS, or GKE), including network policies, RBAC, admission controllers, pod security standards, and secrets management. - Build and enforce policy-as-code guardrails that prevent misconfigurations from reaching production without creating developer friction. - Manage runtime security tooling (Falco, Isovalent, or equivalent) to detect anomalous container behavior, lateral movement, and privilege escalation in real time. - AI-Driven Security Automation - Build AI/LLM-powered automation pipelines that triage, investigate, and enrich Kubernetes security alerts, reducing mean time to respond and analyst toil. - Develop prompt-engineered investigation workflows that correlate container telemetry (audit logs, Isovalent alerts, network flows) with broader SIEM data to produce analyst-ready investigation reports. - Create automated remediation playbooks that can quarantine pods, revoke credentials, or roll back deployments in response to confirmed threats, with appropriate human-in-the-loop controls. - Continuously tune detection logic and AI investigation prompts based on false-positive analysis, emerging threat patterns, and feedback from SOC analysts. - Evaluate and integrate AI/ML-based anomaly detection for container workloads, API traffic, and cluster resource behavior. - Security Engineering & Operations - Instrument Kubernetes environments for comprehensive security observability: audit logs, runtime telemetry, and network flow data piped into Splunk or equivalent SIEM. - Partner with platform engineering and application teams to embed security into deployment pipelines without becoming a bottleneck. - Serve as the subject-matter expert on Kubernetes threat modeling, advising teams on attack surfaces unique to containerized and orchestrated environments. - Maintain runbooks, architecture diagrams, and operational documentation that enable the broader security team to support container security operations. - Track the Kubernetes security landscape (CVEs, CIS benchmarks, CNCF projects) and translate emerging risks into actionable hardening initiatives. Qualifications - 5+ years in security engineering, DevSecOps, or infrastructure security with meaningful hands-on Kubernetes experience in production. - Deep, practical knowledge of Kubernetes internals: API server, etcd, kubelet, networking (CNI), storage, and the admission control chain. - Demonstrated experience building security automation with Python (strongly preferred), Bash, or Go. - Hands-on experience with at least two of: OPA/Gatekeeper, Kyverno, Falco, Trivy, Cosign, KubeArmor, or Aqua. - Strong working knowledge of cloud platforms (AWS EKS, Azure AKS, or GCP GKE) and associated IAM, networking, and security services. - Experience integrating container security telemetry into SIEM platforms (Splunk preferred) for alerting and investigation. - Solid understanding of CI/CD pipelines (GitHub Actions, GitLab CI, or similar) and how to embed security gates without breaking developer flow. Requirements - Experience building or integrating LLM/AI-driven workflows for security operations (alert triage, investigation enrichment, automated remediation). - Familiarity with prompt engineering, LLM orchestration frameworks (LangChain, Kindo, or similar), and vector databases for security use cases. - CKS (Certified Kubernetes Security Specialist) or CKA certification. Benefits - You will build, not just govern. This team ships security tooling and automation, not slide decks. - AI-first security organization: our autonomous SOC pipeline is live and you will extend it into the Kubernetes domain. - Direct impact at a federally chartered digital bank where security decisions are consequential and visible to leadership. - Work alongside senior practitioners who value intellectual honesty, hands-on craft, and enforceable security over compliance theater.
• Responsible for targeting and influencing end users, dealers, integrators, and VARs in the West Region of the US. • Builds, expands, and maintains a network of relationships at all levels of each organization. • Coordinates the involvement of all Teledyne FLIR personnel and partners within the account. • Leverages account presence to up-sell/cross-sell, provides market intelligence. • Works to educate, collaborate, and persuade customers to engage in deeper, sustainable relationships across multiple business imperatives. • Actively prospect for new opportunities and grow the Security base business in the entire territory. • Establishes and maintains accurate sales pipeline and forecasts through CRM utilization. • Develops and maintains a broad understanding of all Teledyne FLIR Security products, services, and solutions including their value proposition, target market applications and pricing structures and discounts. • Conducts or coordinates product training and demonstrations as needed.



