Information Systems Security Manager – ISSM

🕒 il y a 1 mois

🗣️🇺🇸🇬🇧 Anglais requis

Postuler Maintenant
Trouver des Emplois à Distance Similaires

📊 Vérifiez votre score de CV pour ce poste

Améliorez vos chances d'obtenir un entretien en vérifiant votre score de CV avant de postuler.

Logo of Oklo Inc

Oklo Inc

51 - 200 employés

Fondée en 2013

⚡ Énergie

💰 Venture Round en 2021-11

Energy • Technology

Oklo Inc. est une entreprise de technologies de l’énergie spécialisée dans la conception et le déploiement de centrales à fission avancées. Son approche innovante s’appuie sur des réactions de fission nucléaire, similaires à celles des centrales existantes, mais optimisées pour renforcer la sûreté et l’efficacité. La technologie d’Oklo peut utiliser des déchets nucléaires comme combustible, offrant une solution énergétique propre, fiable et abordable. La mission de l’entreprise est de tirer parti de la fission nucléaire pour fournir une énergie durable tout en s’attaquant aux enjeux liés aux déchets nucléaires.

Description

• Serve as the primary authority for the security posture of Oklo’s information systems. • Implement, maintain, and continuously improve information system security controls in alignment with NIST 800-53 and NIST 800-171. • Ensure security requirements are embedded into system design, configuration, and operations across on-premises and cloud environments. • Implement, assess, and remediate system configurations against security baselines and hardening standards, including DISA STIGs and CIS Benchmarks, ensuring secure and compliant system configurations across servers, endpoints, and cloud resources. • Partner with IT and engineering teams to ensure secure architectures, access controls, encryption, and monitoring. • Oversee system-level security monitoring, logging, and alerting to detect and respond to security events. • Lead incident response activities, including investigation, containment, remediation, and post-incident reviews. • Coordinate vulnerability management activities, including scanning, remediation tracking, and validation. • Ensure timely application of security patches and configuration hardening across systems and platforms. • Own execution of security compliance activities related to various standards and contract requirements such as SOX, NIST and CMMC. • Build, Create and Maintain System Security Plans (SSPs), policies, procedures, and supporting security artifacts. • Conduct system risk assessments and track risks through mitigation, acceptance, or remediation. • Support internal and external audits and assessments, ensuring evidence readiness and corrective action tracking. • Enforce controls related to export-controlled data (DOE ECI), including access restrictions, segmentation, and secure data handling. • Develop, maintain, and enforce information security policies, standards, and procedures. • Ensure security documentation is accurate, current, and aligned with operational reality. • Provide clear, actionable guidance to system owners and users regarding security responsibilities and expectations. • Act as a trusted advisor to the Senior Manager of IT and Cyber on system security risks, gaps, and improvement opportunities • Partner with engineering, operations, and compliance teams to balance security, usability, and innovation • Communicate security risks, decisions, and requirements effectively to both technical and non-technical stakeholders

🎯 Exigences

• 6+ years of experience in information security or cybersecurity, with 3+ years in a system security, security engineering, or compliance-focused role. • Proven experience applying, remediating, and maintaining compliance with security configuration frameworks such as DISA STIGs and CIS Benchmarks. • Proven operational experience securing and maintaining systems across Linux, macOS, and Windows environments, with Linux as the primary operating system. • Demonstrated experience implementing or operating security controls under NIST frameworks. • Experience using automated or semi-automated compliance tooling to assess and remediate STIG or CIS controls (e.g., SCAP, OpenSCAP, compliance-as-code, or equivalent). • Prior experience supporting federally regulated environments, including DOE, NRC, DoD, or similar regulatory bodies. • Active certification meeting DoD 8570 / DoD 8140 baseline requirements for Information Assurance / Cybersecurity roles, including one or more of the following: • CISSP • CISM • CASP+ • GSLC • Security+ • Must be considered a “U.S. Person” under 8 U.S.C. 1324b(a)(3).

🏖️ Avantages

• flexible time off • equity • competitive pay • 401k • health insurance • FSA • flexible work hours

Postuler Maintenant

Emplois Similaires

🕒 il y a 1 mois

PlanetScale

51 - 200

☁️ SaaS

🏢 Entreprise

Software Engineer focusing on security for PlanetScale's cloud-native database platform. Collaborating with teams to design security controls and handle incidents while maintaining a great developer experience.

🇺🇸 États-Unis – Télétravail

💵 $140 000 - $320 000 / an

💰 €50 000 000 Series C en 2021-11

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Ledgebrook

51 - 200

💸 Finance

💳 Fintech

Cloud Security Engineer focused on AWS cloud security practices and architectures at Ledgebrook. Designing secure systems and collaborating with DevOps for enhanced security measures.

🇺🇸 États-Unis – Télétravail

💰 Series B en 2024-09

⏰ Temps Plein

🟡 Intermédiaire

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

MagicSchool AI

11 - 50

📚 Éducation

🤖 Intelligence artificielle

Senior Security Engineer specializing in application and cloud security for AI-powered education platform. Collaborating with engineering and compliance teams to ensure security practices are integrated.

🇺🇸 États-Unis – Télétravail

💵 $150 000 - $170 000 / an

💰 €2 400 000 Pre Seed Round en 2023-08

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

FullStory

501 - 1000

🛍️ eCommerce

☁️ SaaS

Lead Security Engineering team at Fullstory to enable secure software design and development. Focus on continuous improvement and stakeholder collaboration for security initiatives.

🇺🇸 États-Unis – Télétravail

💵 $230 000 - $240 000 / an

💰 €25 000 000 Venture Round en 2022-08

⏰ Temps Plein

🟠 Senior

👮‍♂️ Cybersécurité / Ingénieur Sécurité

🦅 Parrain de Visa H1B

info

🗣️🇺🇸🇬🇧 Anglais requis

🕒 il y a 1 mois

Inova Health

10 000+ employés

Oracle Security Administrator responsible for Oracle Security design and compliance for Inova's HR, Finance, and Supply Chain functions. The role involves enhancing the Oracle Security Architecture and supporting business customer objectives.

🗣️🇺🇸🇬🇧 Anglais requis