Astreya provides IT support services with a special focus on increasing productivity and employee satisfaction for its business clients. The company was founded
Security Engineer III – Ransomware Governance
Location
California
Posted
16 days ago
Salary
$98.0K - $154.8K / year
Seniority
Senior
Job Description
Security Engineer III – Ransomware Governance
Astreya
• Support the maturation and day‑to‑day operationalization of the ransomware recovery governance program through hands‑on process execution, documentation updates, and technical validation activities. • Apply and enforce ransomware recovery maintenance policies by performing configuration checks, control verification, and operational compliance reviews. • Coordinate and execute testing for protected applications, including technical recovery validation, dependency mapping, and test result analysis. • Design and implement the application review and onboarding workflow, including technical assessments, readiness evaluations, and control implementation support. • Develop and document the decision authority framework by gathering requirements, validating operational roles, and ensuring alignment with technical processes. • Partner with incident response teams to build and refine the ransomware incident response plan, leading technical exercises, simulations, and tabletop scenarios. • Contribute technical insights to future‑state technology assessments, tool evaluations, and ransomware resilience capability improvements. • Review and enhance existing: Security policies and standards; Backup and recovery strategies; Risk management processes
Job Requirements
- Bachelor’s degree (B.S/B.A) from four-college or university
- 5 to 8 years’ related experience and/or training; or equivalent combination of education and experience
- Networks with senior internal and external personnel in own area of expertise
- Demonstrates good judgment in selecting methods and techniques for obtaining solutions
- System implementation, installation, and disaster preparedness experience
Benefits
- Medical provided through UHC (PPO, HSA, Surest options) / Medical provided through Kaiser (HMO option only) for California employees only
- Dental provided through UHC Nationwide
- Vision provided by UHC
- Flexible Spending Account for Health & Dependent Care
- Pre-Tax Account for Commuter Benefit/Parking & Transit (location-specific)
- Continuing Education and Professional Development via various integrated platforms, e.g. Udemy and Coursera
- Corporate Wellness Program provided by Goomi Group
- Employee Assistance Program
- Wellness Days
- 401k Plan
- Basic and Supplemental Life Insurance
- Short Term & Long Term Disability
- Critical Illness, Critical Hospital, and Voluntary Accident Insurance
- Tuition Reimbursement (available 6 months after start date, capped)
- Paid Time Off (accrued and prorated, maximum of 120 hours annually)
- Paid Holidays
- Any other statutory leaves, paid time, or other ancillary benefits required under state and federal law
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Build, operationalize, and scale the security engineering practices that protect the benefits platform • Work across application security, cloud security, security architecture, supply chain security, detection engineering, and vulnerability management • Partner deeply with the teams building web and mobile applications, backend services, system integrations, card and banking workflows, infrastructure as code, and data platforms • Turn risk reduction into scalable guardrails, automated controls, and clear engineering guidance • Help define secure AI tooling usage, LLM and code-assistant governance, and data protection practices for AI-enabled development workflows • Balance ideal security outcomes with engineering velocity and business priorities
• Lead Contribute to security requirements in designing, developing, and deploying large-scale services and platforms • Conducting security architecture reviews of the application stack, including applications built on cloud and emerging technologies • Design and develop platform-level solutions to promote security-related initiatives and improvements. - Review source code for potential security issues, recommend and implement fixes • Providing specific risk assessment and remediation guidelines for developers and business owners - Belief in automation and tooling as a critical part of the software lifecycle • Document and disseminate security guidelines for common security issues, remediation guidance, and security baselines • Contribute to SOC2 and ISO 27001/27701 audits as needed • Work with developers to provide security guidance • Actively promote improving the security culture and education within the organization • Eager to learn new technologies and solutions • Be curious about how systems work and how they fail, design them to be sustainable in the face of failures
Principal Business Information Security Officer
LastPassLastPass is a password and data management service headquartered in Boston, Massachusetts. Founded in 2008 by Joe Siegrist and Robert Billingslea, the company has continually worke
• Lead the continued evolution of LastPass's risk management framework to ensure it remains repeatable, scalable, and consistently applied • Design and scale the BISO-aligned advisory model, defining engagement patterns, communication flows, and partnership rhythms that embed GRC in business decisions • Provide just-in-time risk advisory for product development, engineering changes, supplier decisions, architecture reviews, and other high-impact initiatives, ensuring risks and tradeoffs are clearly understood • Build strong cross-functional partnerships, serving as a trusted advisor who translates complex technical and business risks into actionable, business-aligned recommendations • Coach GRC Analysts to adopt advisory behaviors, apply the risk framework consistently, and deliver high-quality just-in-time support across their aligned business areas • Partner with Governance and GRC Engineering to integrate risk insights with standards, continuous control monitoring signals, and assurance workflows • Lead technical and executive-level risk discussions through Risk Governance Committees, driving clarity, alignment to risk appetites, and accountable decisions • Produce clear, executive-ready risk narratives, reports, and dashboards that support leadership understanding, prioritization, and decision-making
Senior Developer, Product Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Work within a small team of developers who are specialists in Rust, Swift, Kotlin and Security Development • Implement new security features for the 1Password iOS and core hybrid applications • Assist in security design efforts or scoping initiatives for new features • Demonstrate leadership in security development • Collaborate with teams across our hybrid core architecture • Mentor junior and new team members • Review code for others to maintain high code quality • Stay informed about the latest industry trends, technologies, and best practices in security development




