Founders Founders logo
Founders Founders

A founder-led network for scaling startups in Portugal. Built by those who’ve raised, scaled, and exited. You're next.

IT Security Officer

Location

Oregon

Posted

21 hours ago

Salary

0

Seniority

Lead

Postgraduate Degree10 yrs expEnglishCyber Security

Job Description

IT Security Officer

Founders Founders

• Develop, implement, and maintain comprehensive security policies and procedures to protect organizational data and systems. • Monitor and assess system vulnerabilities, implementing corrective actions to mitigate risks. • Lead incident response efforts, including investigation, documentation, and resolution of security breaches. • Oversee the implementation of security technologies, tools, and best practices across the organization's infrastructure. • Conduct regular security audits and assessments to identify gaps and ensure compliance with industry standards and regulations. • Collaborate with cross-functional teams to educate staff on security best practices and promote a culture of cybersecurity awareness. • Stay current with the latest trends in cybersecurity and recommend proactive improvements to strengthen defenses.

Job Requirements

  • Minimum of 10 years of experience in cybersecurity or a related IT security field.
  • Current CISSP (Certified Information Systems Security Professional) certification.
  • Current CISM (Certified Information Security Manager) certification.
  • Strong knowledge of cybersecurity frameworks, risk assessment methodologies, and compliance standards.
  • Proven experience in handling security incidents and emergency response planning.
  • Excellent analytical and problem-solving skills with a meticulous attention to detail.
  • Exceptional written and verbal communication skills in English.

Related Categories

Related Job Pages

More Security Engineer Jobs

Electrosoft logo

Cybersecurity Assessment and Authorization SME

Electrosoft

A leader in cybersecurity services and solutions

Security Engineer21 hours ago
Full TimeRemoteTeam 51-200Since 2001

• Serve as a Cybersecurity Assessment & Authorization (A&A) Subject Matter Expert supporting enterprise Risk Management Framework (RMF) activities across customer Information Systems, Cloud Hosted Services, Operational Technology (OT), Platform Information Technology (PIT), Facility Related Control Systems (FRCS), and hybrid computing environments. • Lead and support all phases of the RMF lifecycle, including system categorization, security control selection, implementation, assessment, authorization, and continuous monitoring. • Develop, review, update, and maintain RMF artifacts including System Security Plans (SSPs), Security Assessment Plans (SAPs), Security Assessment Reports (SARs), Plans of Action & Milestones (POA&Ms), Continuous Monitoring Strategies, Privacy Impact Assessments (PIAs), Risk Assessment Memorandums (RAMs), Authorizing Official Risk Acceptance (AORA) documentation, and authorization packages. • Assess and validate security controls in accordance with DoDI 8510.01, NIST SP 800-53, DLA RMF guidance, and applicable Federal and DoD cybersecurity requirements. • Conduct security control assessments, vulnerability analyses, and compliance reviews to evaluate the effectiveness of implemented cybersecurity controls. • Support authorization decisions by identifying residual risk, evaluating compensating controls, and providing technical recommendations to Security Control Assessors (SCAs), Authorizing Officials (AOs), and senior Government leadership. • Perform cybersecurity assessments supporting enterprise IT infrastructure, Cloud environments, Operational Technology (OT), Facility Related Control Systems (FRCS), warehouse execution systems, and Platform IT (PIT) environments. • Support implementation and validation of Security Technical Implementation Guides (STIGs), Security Requirements Guides (SRGs), Assured Compliance Assessment Solution (ACAS) scans, IAVA compliance, vulnerability remediation, and continuous monitoring activities. • Utilize eMASS to manage authorization packages, track security control implementation, document vulnerabilities, and maintain authorization status throughout the system lifecycle. • Coordinate remediation efforts with ISSMs, System Owners, engineers, Information Owners, Program Managers, and Government stakeholders to resolve cybersecurity findings and maintain authorization. • Support cybersecurity inspections, audits, compliance assessments, incident response activities, and investigations involving potential cybersecurity events or unauthorized disclosures. • Prepare executive-level briefings, technical reports, dashboards, and risk assessments communicating authorization status, cybersecurity posture, and recommendations to Government leadership. • Monitor evolving cybersecurity threats, regulatory changes, and emerging technologies to ensure continued compliance and improve enterprise cybersecurity posture. • Provide technical mentorship and cybersecurity expertise to project teams while promoting continuous improvement, collaboration, and cybersecurity best practices.

United States
$115K - $125K / year
Kertos logo

Senior Professional Services Consultant – Information Security

Kertos

All-in-one compliance solution for GDPR, ISO27001, SOC2, NIS2, TISAX®, ISO27701, AI Act or ISO42001

Security Engineer21 hours ago
Full TimeRemoteTeam 51-200Since 2021H1B No Sponsor

• You support Kertos customers end-to-end in the implementation, operation, and continuous development of information security frameworks, helping them sustainably meet regulatory and organizational requirements. • With your expertise in information security (ISO 27001, SOC2, TISAX, NIS2), you act as a trusted advisor for our clients and provide subject-matter support to our product and sales teams. • As the bridge between our customers and our product team, you use direct customer feedback to continuously identify product improvements and new features. • You help shape our internal processes so they can grow with the company and meet customer needs.

Germany
Mozilla logo

Senior Security Engineer, Bug Bounty

Mozilla

Feel good about your work again.

Security Engineer21 hours ago
Full TimeRemoteTeam 501-1,000Since 1998H1B Sponsor

• Own and scale Mozilla’s web bug bounty program, including strategy, prioritization, KPIs, and continuous improvement • Act as the primary interface with external researchers and platforms (e.g., HackerOne), fostering a high-quality and trusted research community • Lead triage and technical validation of incoming reports across multiple intake channels (HackerOne, Bugzilla, email) • Drive end-to-end vulnerability remediation, partnering with engineering teams to ensure timely, effective fixes • Identify root causes and systemic issues, and influence long-term improvements in secure development practices • Collaborate with the Security Incident Response Team (SIRT) on active incidents and post-incident reviews • Perform targeted code reviews (primarily JavaScript and Python) during investigations and high-risk changes • Develop or leverage tooling to improve triage efficiency, signal quality, and program insights

Germany
€68K - €91K / year
Ionic Partners logo

Group Security & Compliance Manager

Ionic Partners

Helping companies overcome the second chasm

Security Engineer22 hours ago
Full TimeRemoteTeam 11-50H1B No Sponsor

• Lead customer security reviews, RFPs, RFIs, and questionnaires, turning around accurate, complete responses fast enough to keep deals moving • Stand up and maintain a customer-facing trust portal (SafeBase / Vanta / Drata or equivalent), including a dedicated AI/ML section • Own SOC 2 Type II program management, driving audits across portfolio companies (including Sparkrock's Type II conversion and CXT scoping), coordinating evidence with the Senior Group Security Engineer, and managing auditor relationships • Author and maintain security policies and documentation, including DPAs, sub-processor lists, and incident-communication templates • Own AI compliance and trust, including AI questionnaire responses, AI sub-processor management, framework tracking (EU AI Act, ISO 42001, NIST AI RMF), AI use disclosure, AI acceptable-use policy, and AI incident-comms playbooks • Run third-party vendor security reviews and renewals • Build and deliver internal security awareness training, and onboard customers through the required security setup • Draft and coordinate customer-facing incident communications, including breach/incident notifications with legal and engineering

Serbia
$60K / year