Soteria - Security Solutions & Advisory logo
Soteria - Security Solutions & Advisory

Tailored Security Solutions Managed Detection and Response

Security Advisor – Control Assessor

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

South Carolina

Posted

8 days ago

Salary

0

Seniority

Senior

Bachelor Degree5 yrs expEnglishCyber Security

Job Description

Security Advisor – Control Assessor

Soteria - Security Solutions & Advisory

• Perform control gap assessments to help organizations understand where gaps exist within client security programs. • Provide project management tasks to ensure assessment delivery is on time and meets the client’s needs. • Identify gaps in desired control implements and determine appropriate recommendations for clients based on identified regulatory framework and desired controls. • Review information system security controls and evaluate efficacy. • Perform detailed audit-like assessments according to cybersecurity-related frameworks. • Analyze documentation and evidence provided to verify adherence to prescribed cybersecurity-related frameworks. • Develop and review policies, procedures, and other related documentation to ensure compliance with control frameworks. • Write clear and well-structured reporting to detail observations and strategic recommendations, at an appropriate level for the intended audience. • Identify cybersecurity-related regulatory requirements (e.g., PCI-DSS, HIPAA, CCPA, GDPR, NYDFS) as well as gaps in compliance, and develop strategic plans to achieve and maintain compliance. • Work closely with clients and the Soteria team to develop remediation plans to ensure clients achieve their desired outcomes. • Document and present findings and recommendations to clients, including C-Suite and board-level executives, in a professional manner. • Support project team with quality assurance review of deliverables. • Maintain relationships with clients post-assessment in order to assist and advise as they continue to build and improve their security. • Maintain competence in security trends, technologies, and practices through self-study and attendance of industry events. • Conduct interviews with clients and the Soteria team to evaluate a client’s IT environment and security practices. • Assess and research common business platforms and technologies to deliver recommendations for secure configurations. • Maintain integrity and confidentiality for sensitive client information.

Job Requirements

  • 5+ years of industry experience with an understanding of the cybersecurity space.
  • 2+ years of experience in a cybersecurity consulting role; specifically conducting IT audits or assessments.
  • Familiarity with cybersecurity frameworks such as NIST CSF, CMMC, ISO 27001, and CIS Controls.
  • Relevant certifications such as CISSP, CISM, CISA, etc.
  • Strong knowledge of Microsoft Suite, Advanced Excel skills a plus.
  • Candidates must be legally authorized to work full time within the United States and able to pass a background check.

Benefits

  • Soteria is an Equal Opportunity Employer.
  • Competitive salary with health insurance and retirement plans.
  • Professional development opportunities.

Related Categories

Related Job Pages

More Security Engineer Jobs

WBS Training logo

Learning Facilitator, Security and Property Protection

WBS Training

Serving the Global Quantitative Finance Community since 2000

Full TimeRemoteTeam 1-10Since 2000H1B No Sponsor

• As an employee of WBS TRAINING, you represent your field with passion and foresight. • In your role as a trainer, the primary focus is on developing the competencies of course participants. • In your lesson design you see yourself both as a provider of input and as a support in the role of a learning facilitator — Learning 4.0! • This includes: subject-specific teaching from the home office in the WBS LearnSpace 3D. • Use of a variety of teaching methods for lesson design. • Preparation and development of course-related learning materials according to the curriculum. • Conducting assessments to measure competency gains. • Excellent command of German as the language of instruction (C2 level).

Germany
Airwallex logo

Staff Corporate Security Engineer

Airwallex

Airwallex is a financial services company that has developed a “global financial platform for modern businesses.” As an employer, the company strives to cul

Full TimeRemoteTeam 2,200Since 2015

About Airwallex Airwallex is the only unified payments and financial platform for global businesses. Powered by our unique combination of proprietary infrastructure and software, we empower over 200,000 businesses worldwide - including Brex, Rippling, Navan, Qantas, SHEIN and many more - with fully integrated solutions to manage everything from business accounts, payments, spend management and treasury, to embedded finance at a global scale. Proudly founded in Melbourne, we have a team of over 2,200 of the brightest and most innovative people in tech across 26 offices around the globe. Valued at US$8 billion and backed by world-leading investors including T. Rowe Price, Visa, Mastercard, Robinhood Ventures, Sequoia, Salesforce Ventures, DST Global, and Lone Pine Capital, Airwallex is leading the charge in building the global payments and financial platform of the future. If you're ready to do the most ambitious work of your career, join us. Attributes We Value We hire successful builders with founder-like energy who want real impact, accelerated learning, and true ownership. You bring strong role-related expertise and sharp thinking, and you're motivated by our mission and operating principles. You move fast with good judgment, dig deep with curiosity, and make decisions from first principles, balancing speed and rigor. You're humble and collaborative; turn zero-to-one ideas into real products, and you "get stuff done" end-to-end. You use AI to work smarter and solve problems faster. Here, you'll tackle complex, high-visibility problems with exceptional teammates and grow your career as we build the future of global banking. If that sounds like you, let's build what's next. Your role As a Staff Corporate Security Engineer, you will be a critical part of defending Airwallex's enterprise systems and employees from threats such as malware, phishing and unauthorised access. This role is a highly technical opportunity to detect, investigate and prevent security issues across a modern corporate environment. You will work on digital forensics, incident response and tool development and deployment, protecting a range of corporate IT platforms from endpoints to identity providers. What you'll be doing - Contribute to incident response for malware, phishing, digital forensics. - Design, develop, test, and evaluate new corporate security controls for a rapidly growing business. - Perform incident response and hunt through log sources to identify new threats. - Design and implement security alerts and workflows to support the incident response lifecycle. - Secure corporate IT infrastructure and remediate issues across identity providers, endpoints, corporate networks and other platforms. - Deploy, configure and operate security tooling with a laser focus on impact. What you'll bring - A passion for solving the complex challenges of high-growth startups. - Self motivation and drive to learn new skills, or dive deeper into existing skills. - Bachelor's degree in Computer Science, Cybersecurity or similar. - 7+ years working in a security engineering or incident response role within a tech company. - Strong experience with Crowdstrike, Splunk or other common security monitoring tools. - In depth understanding of common attacker tools and techniques, how they can be detected and prevented, and ability to respond to incidents with high depth and quality of investigation. - Experience with GCP, Alibaba Cloud or other cloud platforms is preferred. - Experience with Okta, Google Workspace and cloud-based VPN services is preferred. - Experience securing endpoints, including with MDM tooling such as Kandji, Intune - Strong communication skills with the ability to explain technical security and software concepts to a non-technical audience. - Scripting experience such as with Python, Bash, Powershell. Applicant Safety Policy: Fraud and Third-Party Recruiters To protect you from recruitment scams, please be aware that Airwallex will not ask for bank details, sensitive ID numbers (i.e. passport), or any form of payment during the application or interview process. All official communication will come from an @airwallex.com email address. Please apply only through careers.airwallex.com or our official LinkedIn page. Airwallex does not accept unsolicited resumes from search firms/recruiters. Airwallex will not pay any fees to search firms/recruiters if a candidate is submitted by a search firm/recruiter unless an agreement has been entered into with respect to specific open position(s). Search firms/recruiters submitting resumes to Airwallex on an unsolicited basis shall be deemed to accept this condition, regardless of any other provision to the contrary. Equal opportunity Airwallex is proud to be an equal opportunity employer. We value diversity and anyone seeking employment at Airwallex is considered based on merit, qualifications, competence and talent. We don't regard color, religion, race, national origin, sexual orientation, ancestry, citizenship, sex, marital or family status, disability, gender, or any other legally protected status when making our hiring decisions. If you have a disability or special need that requires accommodation, please let us know.

Singapore
Cohere logo

Infrastructure Security Engineer, Secret Clearance

Cohere

At Cohere, our mission is to build machines that understand the world, and to make them safely accessible to all.

Full TimeRemoteTeam 11-50H1B Sponsor

• Deploy, and manage infrastructure for Protected B classified environments, ensuring compliance with ITSG-33 and Canadian government standards • Design and implement security controls for cloud (AWS, GCP, Azure) and hybrid/multi-cloud deployments • Evaluate, implement, and manage security tools and technologies for training cluster and inference infrastructure hardening • Implement security best practices including IAM, encryption, logging, and monitoring • Participate in security incident response activities, including detection, analysis, containment, and remediation • Conduct regular vulnerability assessments and penetration testing of infrastructure components • Maintain comprehensive security documentation, procedures, and configurations for classified environments • Maintain active Secret+ security clearance and adhere to all Canadian government security protocols

Canada
Full TimeRemoteTeam 10,001+Since 1961H1B Sponsor

• Administer, configure, and maintain HashiCorp Vault for secure secrets management across Azure and Google Cloud Platform (GCP) environments. • Integrate Vault with enterprise cloud workloads, ensuring robust access control and compliance with Humana's security standards. • Develop and implement automation scripts and tools to support infrastructure management and operational efficiency, using PowerShell, Python, Ruby, or Bash. • Support installation, configuration, and maintenance of cloud-based servers and services, ensuring reliability and scalability in multi-cloud settings. • Collaborate with cross-functional teams to design and enhance secure cloud architectures, contributing to continuous improvement initiatives. • Monitor, identify, and remediate cybersecurity issues and opportunities, in alignment with Humana's IT/Cyber IOP policies. • Ensure accurate documentation and compliance for technology lifecycle management, including decommission requests as required. • Provide regular updates, evidence of remediation, and participate in closure reviews of IT/Cyber IOPs.

Florida + 8 moreAll locations: Florida | Illinois | Kentucky | New York | North Carolina | Massachusetts | Tennessee | Texas | Virginia
$117.6K - $161.7K / year