Security Engineer Remote Jobs in New Mexico (US)
This page tracks remote security engineer openings that are location-eligible for New Mexico.
This page tracks remote security engineer openings that are location-eligible for New Mexico.
Open jobs
3,396
Hiring companies this week
10
Salary sample
$68,000 - $190,000
Jobs added last hour
0
3396 Jobs
1765 Companies
Data & Society studies the social implications of data-centric technologies and automation.
Role Description Data & Society is seeking a post-doctoral research fellow for our AI-Enabled Scams as a Systemic Security Challenge project, housed under our AI & Democracy initiative and led by Director of Research Dr. Alice Marwick. This position will report to the Director of Research, Alice Marwick, and will not have people manager responsibilities. This position is fully remote and will begin in September 2026 with an end date of May 31, 2028. The overall AI Scams project looks at how artificial intelligence is supercharging scams, frauds, and hoaxes. This specific project examines young people’s (Gen A/Z) susceptibility to scams, and how trust, legitimacy, and risk are constructed in online interactions. We are particularly interested in youth financial cultures, such as: - Cryptocurrency - Multi-level marketing schemes - Sports betting - Influencers - Prediction markets - Retail arbitrage - Memestocks - Drop-shipping - “Hustle and grind” culture The post-doctoral fellow will be working on a qualitative research project with two components: - Conducting interviews and focus groups with: - Individuals who have encountered or been harmed by AI-enabled scams - Youth involved in risky financial subcultures - Qualitative discourse and/or content analysis of scam materials, workflows, and use of generative tools. The end goal of this project is to translate our findings into bipartisan policy and governance recommendations, and to bring together consumer protection and cybersecurity perspectives on scams. Qualifications - PhD in any number of disciplines, with a strong background conducting empirical, qualitative research - Interest in questions related to youth, finance, risk, and emerging technology - Experience recruiting and working with populations for qualitative interview studies - Experience with discourse or content analysis (ideally) - Self-motivated and ambitious, with a collaborative spirit - Strong desire to understand how technology and power shape society - Able to write for multiple audiences Requirements - Excellent research, writing, and communication skills supported by a strong empirical foundation - Ability to independently conduct high-level qualitative research, including interviews, focus groups, content/discourse analysis, and other research methods - Experience with study recruitment - Expertise/interest in financial cultures, scams, generative AI, youth studies, economic sociology, or other relevant topics - Ability to work independently in a remote environment - Collaborative and generous intellectual partner - A strong history of work demonstrating a desire to understand how technology and power shape our sociotechnical society - Ability to translate research for non-academic audiences - A deep commitment to social change and the practical applications of research - Must be able to travel for conferences, workshops, or team meetings during the appointment Benefits - Salary range: $68,000 to $80,000 annually, commensurate with experience - Generous benefits package including medical, dental, and vision insurance - Access to a range of opt-in products and services including additional insurance and 401k management - Paid time off and paid federal holidays To Apply Please submit the following items by July 15, 2026: - A cover letter explaining your interest in this role and the research topic - An academic CV - The names, affiliations, and contact information for three (3) references - A 2-page research statement describing your research accomplishments and future trajectory - Two writing samples: one for an academic audience and one for a broad audience Applications will be reviewed beginning July 16, 2026. Please feel free to contact us at jobs@datasociety.net with any questions. Practical Considerations Data & Society has committed to safety requirements to protect our staff from the COVID-19 pandemic. We require that prospective employees are fully vaccinated against COVID-19 before joining our organization. This is currently a full-time, remote position in the AI & Democracy program with an expected start date in September 2026 and an end date of May 31, 2028. You must be living and authorized to work in the United States; we are unable to sponsor visas.
• Lead and manage the GRC and Security Engineering teams, including strategy, objectives, staffing, coaching, and performance management. • Own governance, risk, and compliance programs. Maintain ISO 27001 and related controls. Drive audit readiness for HIPAA and other frameworks. Coordinate policy lifecycle management and control testing. • Run vendor assessment and qualification program. Oversee third party risk management, due diligence, contractual security requirements, and continuous monitoring. • Provide AI related security assessments and guidance. Establish acceptable use guardrails for AI, assess model and data risks, and advise on controls for AI enabled solutions. • Oversee security architecture for cloud environments and enterprise platforms. Partner with engineering on secure design for AWS, Azure, identity, network, and data protection. • Direct security engineering operations. Manage EDR and threat detection with CrowdStrike, SIEM operations, CSPM posture management, vulnerability management, and SOAR automation. • Lead incident response readiness and execution. Run tabletop exercises, coordinate investigations, and deliver root cause and lessons learned. • Own and manage security budgets, multiyear planning, vendor contracts, and cost optimization while meeting control objectives. • Report program status and risk posture to executives and the board. Define and track KPIs and KRIs. Communicate clearly with technical and non technical stakeholders. • Establish and enforce secure software development practices and SDLC controls with engineering leadership. • Maintain a current security roadmap and maturity plan aligned to business priorities. • Oversee metrics, dashboards, and reporting for program performance and risk reduction. • Coordinate with Legal, Privacy, and Compliance on regulatory obligations and customer security assessments. • Champion security awareness training and culture, sponsor targeted training for engineering and high risk roles. • Evaluate, select, and manage strategic security vendors and platforms, drive successful implementations and integrations. • Represent security in customer meetings and due diligence, provide credible technical and compliance answers.
Role Description The Senior Consultant, Application Security is a senior technical practitioner in IOActive's Application Security practice, with secure code review as the central specialty. The role centers on deep manual code audit work across web and systems languages, paired with application penetration testing, threat modeling, and Secure Development Lifecycle (SDLC) advisory engagements. - Code review engagements span the full landscape: - Source code reviews on production codebases for enterprise web applications, mobile backends, embedded systems, and cryptographic implementations - Application penetration testing against web, API, and mobile targets - Threat modeling for new product designs - SDLC advisory work helping clients integrate security into their development processes - The Senior Consultant brings particular depth in code review and broad competence across the adjacent work. Qualifications - 5+ years in offensive security services, with at least 2–3 years focused on application security and source code review - Hands-on engagement delivery across multiple AppSec disciplines — code review, application penetration testing, threat modeling, or SDLC consulting - Deep code review expertise in at least two of: - JavaScript / TypeScript (Node.js, modern frontends) - Python (Django, Flask, FastAPI) - Java (Spring, J2EE) - C# / .NET (ASP.NET, Core) - C / C++, Rust, GoLang - Working knowledge of common framework patterns, ORM behavior, authentication and authorization libraries, cryptographic libraries, and the security pitfalls particular to each - Familiarity with vulnerability classes - Nice to have - Familiarity with relevant standards and frameworks: OWASP ASVS, NIST SSDF, BSIMM, SAMM Requirements - Strong technical credibility and the comfort to operate as the senior voice on engagements - Excellent written communication — producing actionable reports for developers - Strong verbal communication, capable of presenting complex concepts to diverse audiences - Comfort moving between languages and stacks - Collaborative mindset — close coordination with delivery teams and client developers - Genuine curiosity about how systems work, and patience for reading code carefully Benefits - A chance to work with an industry leader in cyber security - Access to world-class technical teams and research - A high-energy, collaborative team that values innovation - Flexibility—work remotely or from the office as needed - Opportunities for travel - Competitive compensation and performance-based incentives - US base salary range $75,000 - $175,000, depending on experience level, background and location.
• Design, develop, and implement automations and workflows to improve security processes within security-oriented platforms and other IT platforms. • Build and optimize integrations between security tools/platforms. • Develop dashboards, reports, and technical documentation for stakeholders to track security operations deliverables, trends, and progress on security posture. • Support incident response and other security operations tasks through automation and orchestration. • Contribute to continuous improvement initiatives by applying DevOps and agile principles to security engineering tasks. • Collaborate with global teams to ensure alignment on security engineering, standards, and best practices.
Role Description Reporting to the Global CTO/CISO, the Head of Security owns the full security program across Ignyte and its operating companies: engineering, operations, governance/risk/compliance, and incident response. You will run day-to-day security operations and detection & response, own and rationalize the security technology stack, lead the GRC and regulatory agenda, drive cyber due diligence and post-close security integration for acquisitions, and own incident response end to end. You will lead a direct team of four and manage key security vendors, partners, and budget. Key Responsibilities - Security Engineering & Operations: - Own day-to-day security operations: detection & response, EDR/XDR, email security, endpoint management, SIEM/log management, and vulnerability management. - Drive measurable gains in detection coverage, mean time to detect/respond, and operational maturity. - Manage MDR/MSSP and tooling vendor relationships. - Cloud & Identity Security: - Lead security posture across Microsoft Azure and Microsoft 365 / Entra ID (Microsoft Defender suite, conditional access, identity governance, and privileged access). - Operate cloud security posture management and drive remediation to closure. - M&A Cyber Due Diligence & Integration: - Lead pre-acquisition cyber due diligence: external attack surface mapping, gap assessment, etc. - Own post-close security integration (onboarding acquired entities onto the common baseline, rationalizing overlapping tooling, and supporting TSA stand-up and exit). - Incident Response: - Own the incident response program (playbooks, tabletop exercises, forensics/vendor coordination, and executive communication during incidents). - Governance, Risk & Compliance: - Own the GRC function: security risk management, the risk register, policy and standards, and control-framework alignment (NIST CSF / CIS Controls). - Run the security exception, remediation, and risk-acceptance process and surface residual risk to executive leadership. - Leadership: - Lead, mentor, and grow the security team. - Build global relationships within a matrixed organization. - Own the security operations budget and roadmap; report posture and risk to the CISO and leadership. Qualifications - 10+ years in information security, including 4+ years in security leadership. - Experience owning aspects of a security program end to end: engineering, operations, GRC, and incident response (not just a single function). - Deep, hands-on expertise with the CrowdStrike suite of tools, including Falcon (EDR/XDR, threat hunting, response, Spotlight). - Strong Microsoft Azure and Microsoft 365 / Entra ID security expertise (Defender, conditional access, identity governance). - Hands-on incident response leadership and modern SecOps practices (detection engineering, vulnerability management). - Experience in a regulated industry (insurance or financial services), with working knowledge of NYDFS 23 NYCRR 500 or a comparable regime. - Demonstrable experience with email threat detection and endpoint management, log management/detection (SIEM), and external attack surface management. Preferred Qualifications - Previous MSP/MSSP experience highly desired. - Experience in a highly acquisitive, multi-entity environment. - Insurance, MGA/MGU, or brokerage industry background. - Relevant certifications (e.g., CISSP, CCSP, Azure Security Engineer, GIAC). - Track record standing up or maturing a security program through rapid inorganic growth. - Demonstrated M&A cyber due diligence and integration experience, assessing and onboarding acquired companies onto a common security baseline. Benefits - Competitive benefits offering including medical, dental, vision, and supplemental benefits. - Company-paid life insurance, long-term and short-term disability policies. - 14 annual paid holidays and generous PTO plan. - 401(k) with annual Safe Harbor and profit share contributions. - Open to remote work environment.
• Experience conducting vulnerability assessments, system audits, and risk analysis using industry-standard scanning tools (e.g., Nessus, Azure security tools, Tenable, Burpsuite, etc…) to support a proactive security posture. • Manage and implement continuous monitoring processes to ensure the organization maintains compliance with a variety of information security frameworks, including ISO 27001:2022 and SOC 2 Type II. Experience with government compliance standards such as FedRAMP (NIST SP 800-53) and CMMC is preferred. This role focuses on ensuring robust security practices and adapting to evolving compliance requirements. • Collaborate closely with IT, DevOps, Engineering, and Compliance teams to enforce security policies, procedures, and best practices. • Actively monitor, analyze, and respond to security alerts and incidents, performing investigations, incident handling, and recommending corrective actions. • Provide expert guidance on security matters to support secure development and operations.
Driving Customer Success Through Finance Transformation: Advanced Processes, Analytics, & AI.
• Design and implement SAP security and authorization frameworks for SAP S/4HANA Public Cloud. • Define role-based access control (RBAC) models aligned with business processes. • Configure and maintain: Business Roles Business Catalogs Business Spaces Authorization Assignments Fiori Launchpad Access User Access Controls • Ensure secure access to SAP applications and business processes. • Support security design during Fit-to-Standard workshops. • Define authorization concepts aligned with SAP Best Practices. • Support SAP Central Business Configuration (CBC) security requirements. • Perform Segregation of Duties (SoD) assessments. • Identify and mitigate security and compliance risks. • Develop security documentation and access control procedures. • Manage user provisioning, deprovisioning, and access reviews. • Troubleshoot authorization and access-related issues. • Provide post-go-live support and hypercare.
• Support Principal and Senior Consultants in the delivery of cybersecurity and compliance engagements • Conduct gap analyses against frameworks and requirements such as NIST CSF 2.0, SOC 2, ISO 27001, PCI DSS, HIPAA, and CMMC - crosswalking when applicable • Assist in identifying, assessing, and documenting security and compliance risks • Contribute to the preparation of client-facing materials, helping communicate compliance requirements and risk findings to technical and non-technical stakeholders • Support the development of strategic, operational, and tactical recommendations to remediate identified risks and improve the client’s security posture and compliance position • Deliver tasks and projects on time and within budget while meeting critical success metrics to maintain high client satisfaction
Booz Allen Hamilton is an award-winning provider of strategic innovation, management consulting, technology, and engineering services. Founded in 1914, the comp
Information Systems Security Officer locations Kirtland AFB, NM Full time job requisition id R0239642 The Opportunity: Cyber threats are everywhere, and the constantly evolving nature of these threats can make understanding them seem overwhelming to Department of War (DoW) agencies and related components. In all of this "cyber noise," how can these organizations understand their risks and how to mitigate them? The answer is an Information Systems Security Officer (ISSO) like you who will break down complex threats into manageable plans of action. As an ISSO on our team, you will use your experience to work with government stakeholders to identify cyber risks, understand applicable policies, and develop a mitigation plan. You'll work closely with the Information System Security Manager to monitor the information systems and their environment, including developing and updating the authorization documentation and implement configuration management across authorization boundaries. You will work with your client to conduct risk assessments, considering data confidentiality, integrity, and availability. You will be involved in organized Incident Response actions such as guiding and reporting back to key stakeholders. You will support the team in meeting authorization timelines and coordinating communications with external entities in support of that objective. Join us. The world can't wait. You Have: - Experience with control implementations associated with RMF, FedRAMP, ICD 503, and DoD information levels, including applying them to the design and implementation of IT solutions to achieve system authorizations - Experience developing and reviewing ATO authorization packages in Xacta or eMASS - Experience analyzing compliance and vulnerability scan results, and implementing appropriate mitigations - Experience with DoD security technical implementation guides (STIGs), checklists, and testing tools, including STIG Viewer, SCAP, and ACAS scanning tools - Experience performing audit log reviews to detect anomalous behavior in information systems and networks, and overseeing continuous monitoring activities - Active TS/SCI clearance; willingness to take a polygraph exam - Bachelor's degree in a Cybersecurity field and 2+ years of experience providing cybersecurity leadership, including interfacing with internal and external SMEs such as PMs, Cyber Assessors, and AOs, or 5+ years of experience providing cybersecurity leadership, including interfacing with internal and external SMEs such as PMs, Cyber Assessors, and AOs, in lieu of a degree - DoD Directive 8140 Qual Matrix for Information Assurance Technician Level II or Information Assurance Manager II Certification Nice If You Have: - Ability to work through challenging security requirements to maintain compliance - Possession of excellent written, presentation, and verbal communication skills - Possession of excellent organizational skills - TS/SCI clearance with a polygraph - Bachelor's degree in IT, Cybersecurity, Data Science, Information Systems, or CS - CGRC, CCNA-Security, CASP+, CISSP, or Security+ Certification - AWS Solutions Architect or Certified Security - Specialty Certification Clearance: Applicants selected will be subject to a security investigation and may need to meet eligibility requirements for access to classified information; TS/SCI clearance is required. Compensation At Booz Allen, we celebrate your contributions, provide you with opportunities and choices, and support your total well-being. Our offerings include health, life, disability, financial, and retirement benefits, as well as paid leave, professional development, tuition assistance, work-life programs, and dependent care. Our recognition awards program acknowledges employees for exceptional performance and superior demonstration of our values. Full-time and part-time employees working at least 20 hours a week on a regular basis are eligible to participate in Booz Allen's benefit programs. Individuals that do not meet the threshold are only eligible for select offerings, not inclusive of health benefits. We encourage you to learn more about our total benefits by visiting the Resource page on our Careers site and reviewing Our Employee Benefits page. Salary at Booz Allen is determined by various factors, including but not limited to location, the individual's particular combination of education, knowledge, skills, competencies, and experience, as well as contract-specific affordability and organizational requirements. The projected compensation range for this position is $99,000.00 to $225,000.00 (annualized USD). The estimate displayed represents the typical salary range for this position and is just one component of Booz Allen's total compensation package for employees. This posting will close within 90 days from the Posting Date. Identity Statement As part of the hiring process, we will ask you to complete an identity verification process that leverages advanced biometrics and artificial intelligence to ensure authenticity and protect against identity fraud. You are expected to be on camera during interviews and assessments. We reserve the right to take your picture to verify your identity and prevent fraud. Candidate AI Usage Policy AI is a part of our daily work at Booz Allen, and we are committed to the responsible and ethical use of AI tools. However, we want to ensure a fair candidate process based on your own skills and knowledge. As part of this commitment, the use of artificial intelligence (AI) or other tools to assist with responses during interviews (whether in-person or virtual) is prohibited unless permission is explicitly provided. Work Model Our people-first culture prioritizes the benefits of collaboration, whether it occurs in person or virtually. To support engagement and effective communication, employees working virtually are generally expected to have their cameras on during meetings. - Remote: If this position is listed as remote, there may still be occasions when you are required to work in person at a Booz Allen or customer facility. - Hybrid: If this position is listed as hybrid, you will be expected to work from a Booz Allen facility frequently, in alignment with leadership expectations and the needs of the role. You may also be required to work from or visit a customer facility. - Onsite: If this position is listed as onsite, work will primarily be performed at a Booz Allen office or customer facility, where employees will collaborate directly with colleagues and customers as required by the role. Commitment to Non-Discrimination All qualified applicants will receive consideration for employment without regard to disability, status as a protected veteran or any other status protected by applicable federal, state, local, or international law.
Leidos is an innovation company rapidly addressing the world’s most vexing challenges in national security and health.
• Operate and maintain secure network solutions operated as a centralized enterprise capability for the United States Army • Partner with key stakeholders and technical experts to perform legacy environment discovery, assessing current capabilities, configurations, and requirements to provide network firewall migration support for the Army global network • Analyze and understand complex firewall security zones and policies with the ability to transform policies between multiple vendor firewall devices while meeting mission requirements • Support secure access solutions leveraging zero trust network access (ZTNA) including support for creation of new access policies and maintenance of existing policies • Integrate capacity planning and scaling of network and security stack environments into the overall operational support processes and staff • Collect, investigate, and identify network resource management strategies and techniques to meet capacity and performance requirements • Work with information assurance teams and the AGUN cybersecurity service provider (CSSP) to ensure compliance to DoD standards to assist with maintenance of the network security posture • Document designs, diagrams, drawings, and technical narratives using wiki technologies and common diagram and drawing tools
3,386more opportunities are still waiting for you.Log in now and take your next shot before someone else does.
AWS, Cyber Security, Azure, Cloud, Python, AI