Planet Technologies logo
Planet Technologies

For 24 years, we have built our reputation on establishing trust. Trust with our clients and among our team.

Security and Compliance Consultant

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 201-500Since 1999H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

2 days ago

Salary

$120K - $210K / year

Seniority

Senior

Bachelor Degree5 yrs expEnglishAzureCloud

Job Description

Security and Compliance Consultant

Planet Technologies

• Serve as a primary technical lead on client engagements involving Microsoft security, compliance, and data protection solutions • Design and implement data security, governance, and compliance strategies aligned with Microsoft 365 and Azure capabilities • Advise clients on secure adoption of Microsoft Copilot, including data exposure risks, governance controls, and compliance considerations • Architect and deploy solutions leveraging tools such as: Microsoft Purview, Microsoft Defender suite and Microsoft Sentinel • Translate regulatory and compliance requirements into actionable technical solutions (e.g., ISO frameworks, government regulations, internal controls) • Conduct data discovery, classification, and protection strategy design • Collaborate with project managers and stakeholders to deliver high-quality outcomes • Contribute to pre-sales efforts, including solution design, scoping, and level-of-effort estimates • Create technical documentation, implementation guides, and client training materials • Act as a subject matter expert (SME) and mentor to other engineers • Develop and refine repeatable offerings around data security, compliance, and Copilot readiness • Stay current on evolving Microsoft security, compliance, and AI governance capabilities

Job Requirements

  • Bachelor’s degree in technical field and/or equivalent experience
  • 5+ years of experience in Microsoft cloud security and compliance consulting
  • Relevant Microsoft certifications, such as:
  • SC-401 (Information Security Administrator Associate) - preferred
  • SC-400 (Information Protection & Compliance Administrator)
  • SC-200 (Security Operations Analyst)
  • SC-300 (Identity and Access Administrator)
  • Strong experience with Microsoft Security and Compliance ecosystem, including: Pruview, DLP, Records Management, Microsoft Defender Suite and Microsoft Sentinel
  • Deep understanding of data security concepts, including: DLP, Data Classification and labeling, and Insider risk and information governance
  • Experience advising on Microsoft 365 Copilot readiness, including: Data exposure risks, permission and access reviews, and governance and compliance controls.
  • Knowledge of identity and access management, including: Entra ID, Conditional Access and MFA and Identity governance
  • Ability to architect and communicate solutions to both technical and business stakeholders
  • Experience mapping compliance requirements to technical implementations
  • Strong consulting skills, including: Requirements gathering, solution design and client communication and presentation
  • Experience developing documentation and reusable frameworks
  • Familiarity with scripting (e.g., PowerShell)
  • Demonstrated commitment to continuous learning in security, compliance, and AI governance

Benefits

  • Details about our benefits can be found here Planet Technologies Benefits Guide 2024-2025.

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 10,001+Since 1993H1B Sponsor

• Define, analyze, and review secure software architectures for centralized automotive computing platforms • Perform threat modeling and security architecture analysis for mixed-criticality, multi-tenant automotive software systems • Partner with safety architects to reason about the interaction between security controls, safety mechanisms, failure modes, and recovery behavior • Define OS security policy, access control, isolation, and privilege models across Android, Linux, QNX, and virtualized environments • Build security systems that maintain integrity and availability for safety-critical vehicle software • Analyze security trade-offs involving performance, latency, memory footprint, boot time, diagnosability, and functional safety requirements • Guide engineering teams on secure build, secure coding, threat mitigation, and security review practices • Collaborate across software, hardware, safety, security, and systems teams to meet NVIDIA and automotive industry standards

California + 4 moreAll locations: California | New York | Michigan | Texas | Washington
$224K - $356.5K / year
Full TimeRemoteTeam 11-50

Role Description 10a Labs' Investigations Team is looking for a Senior Cyber Investigator to support critical safety incidents and conduct investigations across a range of cyber abuse areas. This role requires deep cybersecurity subject-matter expertise to detect and respond to malicious activity, assess threat actor behavior at the organizational level, and handle escalated cases requiring senior technical judgment. Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks. - Detect and investigate malicious uses and cyber abuse, including cases involving scaled data extraction, ransomware, and local and remote exploits. - Conduct org-level analysis of threat actor behavior, identifying patterns across cases to inform detection and mitigation strategies. - Handle escalated and technically complex cases, applying senior cybersecurity expertise to assess real-world harm potential. - Query internal data sources using SQL and Python and cross-reference open-source information (OSINT) to support investigations. - Document and share investigative findings and recommendations with internal stakeholders and client teams. - Support quality and consistency across the investigations team, providing guidance to junior investigators on ambiguous cases. - Respond to reactive escalations and on-call leads, including those not caught by existing safety systems. Qualifications - At least 5+ years of experience in cybersecurity, threat intelligence, Trust & Safety, national security, defense, intelligence, or law enforcement domains. - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - Familiarity with LLM systems and how AI technology can be misused for cyber operations. - Deep subject-matter expertise in one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations. - Strong ability to assess the real-world harm potential of technical content, distinguishing genuine offensive uplift from benign or educational security research. - Strong SQL and Python proficiency for querying data and supporting detection workflows. - Proven experience conducting org-level threat actor analysis across large datasets. - Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment. - Ability to clear an insider-threat background check. Preferred Qualifications - Experience with threat intelligence frameworks such as MITRE ATT&CK. - Background in dark web monitoring, OSINT, or cross-platform threat analysis. - Experience scaling and automating detection and mitigation processes. - Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish. - Relevant certifications such as OSCP, GREM, or GCTI. Benefits - Salary Range: $115K–$140K, depending on experience and location. - Work Environment: Fully remote, U.S.-based. - Health Benefits: Comprehensive health, dental, and vision coverage. - Time Off: Generous PTO and paid holiday schedule. - Retirement: 401(k) plan.

United States
$115K - $140K / year
Full TimeRemoteTeam 11-50

Role Description 10a Labs' Investigations Team is looking for a Cyber Investigator to support high-volume exchange labeling and investigations across a range of cyber abuse areas. This role requires a solid foundation in cybersecurity and a keen ability to assess whether technical content poses real-world harm. Investigations may involve exposure to harmful or disturbing content, including malicious code, exploit development, and content designed to facilitate cyberattacks. In this role, you will: - Review and label AI-generated exchanges to assess whether content provides meaningful offensive cyber uplift, distinguishing it from legitimate security research. - Investigate potentially policy-violating activity by querying internal data sources using SQL and Python and cross-referencing open-source information (OSINT). - Document and share investigative findings with internal stakeholders. - Respond to reactive escalations and on-call leads, including those not caught by existing safety systems. Qualifications - At least 1–3 years of experience in cybersecurity, Trust & Safety, national security, defense, intelligence, or law enforcement domains. - Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. - Foundational knowledge of cyber threat concepts, including one or more of the following: scaled data extraction, ransomware, local and remote exploits, or offensive security operations. - Familiarity with LLM systems and how AI technology can be misused for cyber operations. - Ability to assess the real-world harm potential of technical content, distinguishing offensive uplift from benign or educational security research. - Strong SQL and Python proficiency for querying data and supporting investigations. - Ability to rapidly context-switch across domains, modalities, and abuse areas in a fast-paced, ambiguous environment. - Ability to clear an insider-threat background check. Requirements - Experience with threat intelligence frameworks such as MITRE ATT&CK. - Background in dark web monitoring, OSINT, or cross-platform threat analysis. - Full professional proficiency in Arabic, Chinese, Farsi, Portuguese, Russian, or Spanish. - Relevant certifications such as CompTIA Security+, CEH, or OSCP. Benefits - Salary Range: $80K–$105K, depending on experience and location. - Work Environment: Fully remote, U.S.-based. - Health Benefits: Comprehensive health, dental, and vision coverage. - Time Off: Generous PTO and paid holiday schedule. - Retirement: 401(k) plan.

United States
$80K - $105K / year
Full TimeRemoteTeam 11-50

Role Description You’ll help build Clearwing: an AI-native cybersecurity system for autonomous vulnerability discovery, exploit validation, pen-testing, reverse engineering, and security reporting. You’ll combine hands-on offensive security work with LLM agent development, eval design, and product engineering. The ideal candidate can chase real bugs, validate exploitability, write production-quality Python, and turn exploratory research into repeatable security capabilities. - Develop AI-assisted vulnerability discovery workflows for source code, binaries, networks, and live systems. - Build and improve Clearwing’s source-code hunting, network pen-testing, N-day exploit, reverse engineering, and validation pipelines. - Design agentic workflows for reconnaissance, static analysis, dynamic testing, exploit development, patch validation, and reporting. - Perform static analysis to identify vulnerable patterns, reachable attack surfaces, and exploitability conditions. - Conduct authorized live testing against networks, services, containers, lab targets, and operational environments. - Develop and validate proof-of-concept exploits in controlled, authorized settings. - Build evaluation harnesses for vulnerability discovery quality, false positives, exploitability, reproducibility, and model/tool performance. - Improve safety, authorization, auditability, guardrails, and human-in-the-loop controls for dual-use cybersecurity capabilities. - Work with AI researchers and engineers to improve prompts, tools, agent loops, memory systems, scoring systems, and model-routing strategies. - Produce clear technical reports with evidence, reproduction steps, impact analysis, and remediation guidance. Qualifications - 3+ years of hands-on cybersecurity experience in vulnerability research, penetration testing, exploit development, reverse engineering, or security engineering. - Practical experience with at least two of: - Static analysis - Dynamic analysis - Binary exploitation - Web application security - Network penetration testing - Cloud/container security - Malware analysis or reverse engineering - Detection engineering - Strong Python skills and comfort building automation around security tools. - Familiarity with Linux, Docker, Kali/security tooling, Git, CI, and shell workflows. - Ability to reason from vulnerability signal to exploitability, impact, evidence quality, and remediation. - Experience working with LLMs, agents, prompt engineering, evals, or AI-assisted security workflows. - Strong written communication skills for technical findings, customer-facing reports, and internal research notes. - Clear judgment around authorization, responsible disclosure, and dual-use security tooling. Requirements - Experience with Ghidra, IDA, Binary Ninja, angr, Semgrep, CodeQL, Joern, AFL++, libFuzzer, ASan/UBSan, or OSS-Fuzz. - Experience developing exploits for memory corruption, deserialization, auth bypass, SSRF, RCE, sandbox escape, or supply-chain vulnerabilities. - Experience with CVE reproduction, N-day analysis, patch diffing, or exploit validation. - Experience building LLM agents, tool-using systems, ReAct loops, eval harnesses, or synthetic-data pipelines. - Familiarity with SARIF, CVSS, CWE, MITRE ATT&CK, MITRE CVE workflows, HackerOne/Bugcrowd-style disclosure, or government security reporting. - Experience with Rust, Go, C/C++, or systems programming. - Prior work with security products, autonomous agents, fuzzing infrastructure, or government/security customers. Benefits - Comprehensive benefits package, including health, dental, and vision insurance, as well as retirement savings plans. - Opportunities for growth and professional development. - A collaborative and supportive company culture that values diversity and inclusion. - Access to cutting-edge technology and resources for research and development. - Compensation (commensurate with experience): $180,000 - $200,000 (base salary) + equity.

United States
$180K - $200K / year