May The Best Drug Win
Information Security Lead
Location
United States
Posted
2 days ago
Salary
$150K - $200K / year
Seniority
Senior
Job Description
Information Security Lead
Alloy Therapeutics, Inc.
• Own Alloy's security program in its entirety • Design and implement IAM controls that enforce least-privilege • Run a structured vulnerability management program • Maintain Alloy's information security policy landscape • Own our SOC 2 type designations • Design and implement IAM controls • Own Alloy's approach to protecting proprietary scientific data • Maintain visibility across Alloy’s environment through logging, alerting, and monitoring tooling • Work closely with Alloy's AI teams to ensure security in AI-forward environment • Evaluate new SaaS applications and ensure software landscape doesn't introduce unacceptable risk • Design and operate elevated controls for sovereign and government-aligned engagements
Job Requirements
- Significant breadth across both technical security work and governance
- Hands-on experience with cloud security across Google Workspace and AWS (or GCP/Azure equivalent), including IAM design, cloud storage security, and logging and monitoring configuration
- Experience securing proprietary scientific or research data at massive scale
- Experience defending against advanced and nation-state-level threat actors
- Experience implementing MFA programs including FIDO2/hardware key standards (e.g., YubiKey)
- Demonstrated experience with backup architecture design
- Familiarity with compliance frameworks including SOC 2 Type 2 and/or ISO 27001
- Experience writing security policies and documentation that can withstand external scrutiny
Benefits
- Competitive base and equity compensation commensurate with level of experience and independence
- 401(k) company match
- Generous personal and family medical, dental and vision benefits with 100% of premiums and deductibles covered
- Company-paid disability (STD, LTD) and life insurance
- Paid parental leave
- Family planning support up to $45,000 (e.g., IVF/PGT, adoption, surrogacy, egg retrieval)
- Unlimited PTO (paid time off) and flexible schedules
- Annual stipend for continuing education with commitment to your career through individualized professional development plan
- Wellness and Extensive Employee Assistance Program (EAP) including resources for mental wellness
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Senior Staff Product Manager – Platform Security
CiscoWe securely connect everything to make anything possible.
• Develop and maintain a multi-year roadmap for Platform Security capabilities including certificate lifecycle management, PKI infrastructure, secrets management, token security, and cryptographic compliance (FIPS 140-3, TLS modernization) • Manage strategic decisions to ensure the highest impact from security engineering investments in a dynamic and fast-paced environment • Lead product strategy for secure-by-default foundation services • Drive security strategy for AI agent workloads and runtime environments • Partner closely with engineering, architecture, compliance, and product teams to deliver security-critical outcomes • Drive product development end-to-end • Influence direction and elevate standards through clear roadmap narratives, technical proposals, and risk-impact evaluations • Champion a platform-wide security culture focused on resilience, crypto-agility, and continuous improvement
Information Security Engineer
Dealer TireWe’re more than tires and parts. We’re a team on a mission to revolutionize the automobile dealer channel.
• Performing vendor risk assessments for new vendors and reviewing the risk of current vendors • Evaluating alerting processes and systems, developing security automation processes • Policy & Runbook development, incident reporting, pen testing analysis • Building new monitoring capabilities, developing alerts, integrating new feeds • Providing security guidance for compliance issues
Role Description Join our team as a Cybersecurity Engineer, where you will execute and/or lead advanced security assessments for client information systems. You will apply deep technical and compliance expertise to evaluate, advise, and guide clients through FedRAMP, FISMA, and NIST RMF requirements. You will also lead technical discussions, mentor team members, and support secure cloud architecture and risk mitigation activities, with a primary focus on FedRAMP. - Engage directly with clients through verbal communication to perform interviews, lead assessment discussions, and provide expert guidance and solutions. - Utilize expertise in security engineering, secure architecture design, system and network security, authentication protocols, applied cryptography, and application security. - Conduct comprehensive security assessments by analyzing cybersecurity documentation and performing evidence collection, interviews, and testing to evaluate compliance with relevant standards such as FISMA, NIST RMF, and FedRAMP. - Perform system and network vulnerability scanning and analysis using automated and manual techniques with tools such as Nessus, ACAS, DB Protect, WebInspect, NMAP, and DISA STIGs/STIG Viewer. - Perform identification and application of vulnerability remediations, fix procedures, and when necessary mitigation techniques. - Identify, recommend, and validate vulnerability remediation actions, fix procedures, and mitigation strategies. - Lead compliance-related and technical discussions, demonstrating expert understanding of security frameworks, architectures, and control requirements. - Coordinate and guide cross-functional teams, ensuring effective collaboration, delivery, and communication. - Prepare clear, accurate, and original reports, attestations, and customer-facing documentation. - Inform customers of cybersecurity issues and concerns that need to be resolved and explain how compliance to various standards and frameworks is achieved. - Work independently or as part of a client delivery team in a fast-paced, deadline-driven, remote environment. Qualifications - Bachelor's Degree or 5+ years equivalent experience. - 3+ years of experience in performing and/or participating in FISMA based security Assessment and Authorization (A&A) activities. - Must be a US Citizen and able to obtain an active SECRET Security Clearance. - Strong technical background in security engineering, secure architecture, system and network security, authentication protocols, applied cryptography, and application security. - Expert knowledge of Cloud Computing, FedRAMP, FISMA, NIST/DoD RMF, and NIST SP 800-series publications. - Intermediate experience with testing and assessment tools such as Nessus/ACAS, SCC, DISA STIGs/STIG Viewer, NMAP, and Acunetix. - Self-motivated and able to operate independently or as part of a team. - Ability to author original assessment reports, attestations, and compliance documentation. - Strong verbal communication, organizational, planning, and attention to detail skills. - Successful completion of the FedRAMP Baltimore Cyber Range. - Knowledge of the Software Development Lifecycle (SDLC) as it relates to Information Security and Information Assurance. - Able to travel up to 25% as required for various client engagements. - Must hold one other advanced certification such as CISA, CISM, etc. in accordance with the A2LA R311. - The candidate must have at least one industry certification from the following list: - Cisco Certified Network Associate Security (CCNA Security) - Cisco Certified Network Associate Cyber Security Operations (CCNA Cyber Ops) - Cybersecurity Analyst (CySA+) - GIAC Certified Incident Handler (GCIH) - GIAC Systems and Network Auditor (GSNA) - GIAC Certified Intrusion Analyst (GCIA) - Certified Information Systems Auditor (CISA) - Certified Information System Security Professional or Associate (CISSP or Associate) - Certified Secure Software Lifecycle Professional (CSSLP) - Certified Information Systems Security Officer (CISSO) - CyberSec First Responder (CFR) - CompTIA Advanced Security Practitioner Continuing Education (CASP+) Continuing Education (CE) - CompTIA Cloud+ (Cloud+) - Global Industrial Cyber Security Professional (GICSP) - Securing Cisco® Networks with Threat Detection Analysis (SCYBER) Requirements - High School diploma, Bachelor's Degree in Computer Science, Engineering, Information Systems, or Technology required. - Must be a U.S. citizen with the ability to obtain a necessary security clearance as required by our government customers. - Legal authorization to work in the U.S. indefinitely is required. Employer work permit sponsorship is not available for this position. Benefits - Incentive Bonus Plans - Medical, Dental, Vision benefits - 401K with Company Match - 10 Paid Holidays - Generous Paid Time Off Packages - Employee Stock Purchase Plan - Paid Parental & Family Leave - and more!
Information System Security Officer
KBR, Inc.We deliver science, technology and engineering solutions to governments and companies around the world.
Role Description The successful candidate will provide support to the Test Resource Management Center’s (TRMC) All Domain Test Range (ADTR) and INDOPACOM Pacific-Rim Multi-Domain Training and Experimentation Capability Team, Joint Mission Environment Test Capability (JMETC) Secret Network (JSN) Node, JMETC Multiple Independent Levels of Security Network (JMN) Node, Secret Defense Research and Engineering Network (SDREN), Defense Research and Engineering Network (DREN). In this role, you will be a critical part of our team responsible for evaluating customer requirements pertaining to complex technical challenges. The successful candidate will assist with providing solutions to complex problems in a manner which meets both functional and security requirements. You will be responsible for keeping the team’s computing environment operational and in compliance with all TRMC directives and applicable RMF requirements. To do this you will frequently collaborate with other distributed team members to discuss current system status and plan desired future enhancements. The candidate will have a blended skill set with a strong background in both systems administration and cybersecurity. This individual will possess experience in: - Windows and Linux server management - Active Directory - Security Technical Implementation Guides (STIGs) - Virtualization technologies This role is critical in ensuring the integrity, confidentiality, and availability of our information systems within a Department of Defense (DoD) environment. Qualifications - Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field - Active TS/SCI security clearance - Minimum 10 years of system administration or cybersecurity-related experience, specifically within DoD environment - Proficient in Windows server and Linux server management, including installation, security policies, configuration, and troubleshooting Requirements - Develop, implement, and maintain security policies, procedures, and standards to safeguard organizational information systems - Conduct regular security assessments, vulnerability scans, and penetration testing to identify and mitigate potential threats - Monitor security alerts and logs to respond to incidents in a timely manner, ensuring compliance with DoD regulations - Manage Privileged Access Management (PAM) solutions to ensure secure access control for sensitive systems and data - Filter and generate reports from Security Information and Event Management (SIEM) tools to provide insights into security incidents and trends - Respond to JFHQ-DODIN issued orders, such as Cyber Task Orders (CTO) - Participate in DoD mandated Zero Trust efforts (initiatives, planning, testing and implementation) - Administer Windows and Linux servers, ensuring optimal performance, security and uptime - Manage Active Directory for user account provisioning, authentication, and access control, ensuring compliance with organizational security policies - Implement and maintain STIGs to harden system configurations and reduce vulnerabilities across all server environments - Oversee the virtualization of servers using VMware, Hyper-V, or similar technologies, ensuring secure and efficient resource allocation - Manage cloud-based services and applications, ensuring they adhere to security policies and best practices - Apply RMF principles to assess and manage risk associated with information systems, including categorization, selection of security controls, implementation, assessment, authorization, and continuous monitoring - Collaborate with stakeholders to ensure all systems are RMF-compliant and maintain relevant documentation - Develop and conduct security training programs for staff to enhance awareness of information security best practices and organizational policies - Function as a security advisor to other departments, providing guidance on secure system design and implementation - Maintain comprehensive documentation of security processes, incidents, and remediation efforts - Prepare and present reports on security posture, vulnerabilities, and incident response efforts to senior management and other stakeholders Benefits - 401K plan with company match - Medical, dental, vision, life insurance, AD&D - Flexible spending account - Disability - Paid time off - Flexible work schedule - Support for career advancement through professional training and development




