
10,000+ employees
🏗️ Construction
🏭 Manufacturing
📦 Logistics
Construction • Manufacturing • Logistics
Ferguson is a leading supplier of plumbing and HVAC products for residential and commercial markets. The company offers a wide range of products including water heaters, plumbing parts, and HVAC systems, as well as various tools and cleaning supplies. Ferguson provides solutions for professionals in the plumbing and HVAC industries, ensuring they have access to the resources and expertise they need for both new construction and remodeling projects.
🔥 10 minutes ago
🇺🇸 United States – Remote
💵 $8.5k - $14.8k / month
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
Improve your chances of getting an interview by checking your resume score before you apply.

10,000+ employees
🏗️ Construction
🏭 Manufacturing
📦 Logistics
Construction • Manufacturing • Logistics
Ferguson is a leading supplier of plumbing and HVAC products for residential and commercial markets. The company offers a wide range of products including water heaters, plumbing parts, and HVAC systems, as well as various tools and cleaning supplies. Ferguson provides solutions for professionals in the plumbing and HVAC industries, ensuring they have access to the resources and expertise they need for both new construction and remodeling projects.
• Lead cybersecurity risk assessments and security maturity evaluations using industry frameworks, including NIST CSF, identifying control gaps, emerging risks, and opportunities to strengthen Ferguson's security posture. • Develop risk mitigation strategies, remediation plans, and governance recommendations, partnering with business and technology teams to drive sustainable risk reduction. • Support the development and continuous improvement of cybersecurity governance processes, security roadmaps, risk registers, and program performance metrics. • Coordinate and support internal and external audits, independent security assessments, regulatory reviews, and risk management initiatives. • Lead Ferguson's enterprise simulated phishing exercises and cybersecurity education program, developing risk-based campaigns and targeted training initiatives that improve employee awareness and cyber resilience. • Analyze phishing simulation results, reporting trends, and awareness metrics to identify risks, measure efficiency, and drive ongoing improvement of security culture. • Partner with business leaders, Human Resources, Corporate Communications, and Information Security teams to reduce phishing susceptibility and increase employee engagement in security procedures. • Conduct security assessments of vendors, suppliers, and technology partners as part of Ferguson's third-party risk management program. • Review security questionnaires, SOC reports, penetration test results, compliance certifications, and other security documentation to evaluate vendor risk. • Identify, assess, and communicate third-party security risks, providing recommendations to support informed business decisions and remediation efforts. • Collaborate with Procurement, Legal, and business customers to help ensure appropriate security requirements are incorporated into third-party engagements. • Develop and maintain cybersecurity dashboards, scorecards, important metrics, KRIs, and executive reporting that provide access to risk, compliance, and program performance. • Apply reporting and automation tools to improve the efficiency, effectiveness, and scalability of Governance, Risk, and Compliance (GRC) activities. • Translate technical risks into business-focused insights, helping leaders understand risk exposure, prioritize remediation efforts, and make informed decisions. • Serve as a trusted advisor on cybersecurity governance, risk management, and compliance matters, building strong partnerships across business and technology teams. • Communicate security risks, recommendations, and program outcomes effectively to both technical and non-technical audiences, including senior leadership.
• Bachelor's degree in Information Security, Cybersecurity, Information Systems, Computer Science, Business Administration, or a related field; equivalent combination of education and experience will be considered. • 5+ years of experience in Information Security, Cybersecurity, IT Risk Management, IT Audit, Governance, Risk & Compliance (GRC), or related disciplines. • Experience conducting security risk assessments and evaluating security controls across on-premises, cloud, and third-party environments. • Solid understanding of cybersecurity governance, risk management, compliance frameworks, and third-party risk management practices. • Extensive knowledge of industry frameworks and standards, including NIST CSF, ISO 27001, COBIT, COSO, and IT General Controls (ITGCs). • Experience developing and maintaining security policies, standards, controls, and governance processes. • Experience supporting audits, regulatory compliance initiatives, risk assessments, and remediation activities. • Ability to identify, assess, prioritize, and communicate risk across applications, infrastructure, cloud services, and vendors. • Strong analytical, problem-solving, and critical thinking skills, with the ability to translate sophisticated risks into actionable recommendations. • Excellent written, verbal, presentation, and customer management skills, with experience presenting findings and recommendations to technical and business leaders. • Experience working with Microsoft technologies, cloud platforms, and security governance or reporting tools preferred. • Proven ability to lead complex initiatives, influence interested parties, and drive outcomes through multi-functional collaboration. • Preferred Certifications: CISSP, CISM, CRISC, CISA, and/or ISO 27001 Lead Auditor/Lead Implementer certification.
• Health insurance • Dental insurance • Vision insurance • Paid time off • Life insurance • 401(k) with company match • Mental health coverage • Gender affirming benefits • Family building benefits • Paid parental leave • Associate discounts • Community involvement opportunities
Apply Now🔥 13 minutes ago
AI Security Engineer at Rimini Street focusing on secure AI technologies adoption and governance. Collaborating with IT and business teams to implement security controls and manage AI risks.
🇺🇸 United States – Remote
💵 $102k - $153k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🦅 H1B Visa Sponsor
🔥 1 hour ago
Cybersecurity Assessment & Authorization Subject Matter Expert supporting DLA Cybersecurity. Responsible for guidance on A&A of information systems, policy adherence, and risk assessment.
🔥 1 hour ago
Senior AI Security Architect at Paylocity, responsible for AI/ML security design and governance. Collaborating with cross-functional teams to ensure secure and compliant AI systems.
🇺🇸 United States – Remote
💵 $147.4k - $210.6k / year
⏰ Full Time
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🔥 1 hour ago
Learning Consultant at OCHIN leading learning strategies to enhance patient care access and improve health outcomes. Collaborating with health teams to develop scalable training solutions.
🇺🇸 United States – Remote
💵 $85.7k - $137.1k / year
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer
🔥 2 hours ago
Account Executive managing sales of AI-powered security platform and services at Binary Defense. Responsible for customer acquisition and developing relationships while driving value for clients.
🇺🇸 United States – Remote
💰 Private Equity Round on 2022-11
⏰ Full Time
🟡 Mid-level
🟠 Senior
👮♂️ Cybersecurity / Security Engineer