FM

FM

3 open positions available

2 locations
1 employment type
Actively hiring
Full-time

Latest Positions

Showing 3 most recent jobs
FM

Senior Vendor Security Risk Management Analyst

FMAnywhereFull-time
View Job
Compensation$106K - 152K a year

Lead end-to-end third-party vendor security risk assessments and recommend mitigation strategies. | 5+ years cybersecurity experience with expertise in vendor security posture assessment, cloud security, and risk analysis. | Job Description Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection. Work Schedule This position requires on-site work one day per week at our Corporate Headquarters and flexibility to be on-site when needed based on the demands of the business Relocation is not offered for this position. Position Summary FM is seeking a Senior Information Security Analyst with deep expertise in Third-Party Risk Management (TPRM), you will play a critical role in protecting FM by assessing how external vendors, SaaS platforms, and cloud solutions interact with our systems and data. This high-impact role where your expertise in cyber risk, vendor security, and cloud architecture will help shape business decisions, strengthen our security posture, and support innovation in a secure way. This includes reviewing both the vendor’s security control environment and the specific solution being implemented, with a focus on data handling, storage, and integration with internal systems. You will partner closely with business, technology, and procurement teams to identify risks and recommend practical, business-aligned mitigation strategies. You will lead end-to-end cybersecurity risk assessments of third-party vendors and solutions—going beyond standard due diligence to evaluate real-world risk across systems, data, and integrations. Key Responsibilities • Lead end-to-end third-party solution risk assessments and vendor security reviews across the vendor lifecycle, including due diligence, onboarding, ongoing monitoring, and reassessments. • Evaluate vendor security programs, control effectiveness, and governance, along with deep-dive assessment of the specific product being implemented including solution architecture, data flows, and integration points. • Identify and communicate inherent and residual cyber risks related to data protection, privacy, IAM, privileged access, system connectivity, and external attack surface exposure. • Review and interpret security documentation, including SOC 1/SOC 2 reports, ISO 27001 certifications, audit reports, architecture diagrams, data flow diagrams, and technical configurations. • Recommend practical risk mitigation strategies, including compensating controls, secure design changes, and contractual safeguards to support risk-informed decisions. • Partner with business, technology, procurement, and legal teams to support risk acceptance, exception management, and third-party risk governance. • Contribute to the evolution of FM’s third-party risk management framework, methodology, and standards in alignment with NIST, ISO 27001, NYDFS, and other applicable regulatory expectations. Qualifications • 5+ years of experience in cybersecurity, information security, or cyber risk, with a background in third-party risk management (TPRM), IT risk, audit, incident response, or access management. • Experience assessing vendor security posture in cloud (SaaS/PaaS)and enterprise environments. Technical Expertise • Strong understanding of systems, networks, application architecture, cloud security, and secure system design across AWS, Azure, SaaS, PaaS, APIs, and enterprise integrations. • Experience evaluating data flows, data classification, data protection, data governance, and secure data handling practices. • Knowledge of IAM, SSO, federation, privileged access, cyber threats, vulnerabilities, and attack methodologies. • Ability to interpret SOC 1, SOC 2, ISO certifications, and other third-party assurance artifacts to identify control gaps and residual risk. Risk & Analysis • Ability to identify, assess, and clearly communicate complex cyber risks, trade-offs, and residual risk. • Experience recommending practical, business-aligned risk based mitigation strategies, including compensating controls and secure design changes. • Strong analytical judgment, attention to detail, and risk-based decision-making. Collaboration & Communication • Ability to translate technical findings into clear, business-relevant insights and recommendations. • Strong stakeholder management and partnership across business, technology, procurement, and legal teams. • Collaborative, solutions-focused mindset with strong influencing skills in a fast-paced assessment environment. • High degree of professional skepticism and curiosity when evaluating vendor claims and evidence • Ability to manage multiple priorities independently while maintaining quality and consistency of assessments Tools & Certifications • Proficiency with Microsoft Office tools. • Relevant certifications such as CISSP, CISA, CSA, CISM, Security+, GIAC, CEH, or similar are strongly desired. Education Bachelor's degree in information security, Computer Science, Information Technology, or a related field required. An equivalent of relevant work experience will also be considered. The hiring range for this position is $106,000- $152,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FM’s comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time. FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce. #FMG

Third-party risk management
Cybersecurity risk assessment
Cloud security (AWS, Azure)
Verified Source
Posted 25 days ago
FM

Lead AI Security Engineer

FMJohnston, Rhode IslandFull-time
View Job
Compensation$90K - 150K a year

Lead design and implementation of security controls for enterprise AI capabilities and partner with engineering teams on threat modeling and security patterns. | 7+ years IT/cybersecurity experience including 5+ years in security engineering, knowledge of LLM systems, bachelor's degree, and preferred CISSP or CISM certifications. | Established nearly two centuries ago, FM is a leading mutual insurance company whose capital, scientific research capability and engineering expertise are solely dedicated to property risk management and the resilience of its policyholder-owners. These owners, who share the belief that the majority of property loss is preventable, represent many of the world’s largest organizations, including one of every four Fortune 500 companies. They work with FM to better understand the hazards that can impact their business continuity to make cost-effective risk management decisions, combining property loss prevention with insurance protection. Schedule & Location: This is an onsite position based at our corporate headquarters in Johnston, RI, with the flexibility to work from home two days per week, depending on business needs. Relocation is not offered for this position. Position Summary The Lead AI Security Engineer is a senior technical role responsible for enabling the secure adoption of AI capabilities across the organization. This role defines and evolves security and risk requirements for enterprise AI capabilities, in addition to designing and implementing the supporting controls. The role operates at the intersection of cybersecurity, platform engineering, and emerging AI technologies, supporting enterprise AI solutions such as Microsoft Copilot, Claude, and internally developed or platform-based agentic AI systems, including Azure AI Foundry. The role translates emerging AI risks, security expectations, and enterprise requirements into clear, actionable, and scalable security patterns that can be consistently applied across platforms. The incumbent serves as a hands-on technical leader and subject matter expert, partnering with platform, engineering, and product teams to design, evaluate, and implement security capabilities for AI systems, while establishing standards and guidance for ongoing operations. In areas where security owns and administers the relevant controls, this role leads tool selection, control design, and implementation, with other teams potentially supporting day-to-day operations. In areas where security is not the system owner, this role consults with platform teams to ensure systems are configured and administered appropriately and effective security guidance is defined and applied. Role Emphasis This is a hands-on leadership role for someone who can define the security model for enterprise AI, not just implementing requirements provided by others. The successful candidate should be able to identify AI-related security risks, develop clear requirements and guardrails, and help teams implement those controls in a practical and scalable way. The role requires strong security engineering judgment, practical AI understanding, and the ability to balance risk reduction with business enablement. Key Responsibilities Lead the definition, design, and implementation of security capabilities that enable secure enterprise AI adoption across platforms such as Microsoft Copilot, Claude, and agentic AI frameworks. Define security and risk requirements for enterprise AI platforms and agent-based systems. Translate security, risk, and regulatory expectations, including emerging AI risks, into clear technical controls, guardrails, and implementation patterns aligned to relevant industry frameworks and enterprise requirements. Partner with AI platform, engineering, and product teams to embed security requirements and controls into architecture, design, delivery, and operations. Conduct security reviews and threat modeling for AI use cases, agent workflows, integrations, and platform capabilities to identify required controls before production deployment. Define and guide implementation of controls related to AI agent identity, tool and API access, data usage constraints, auditability, and agent behavior in enterprise environments. Lead evaluation, proof-of-concept, and selection of activities for native and third-party capabilities that support AI security, governance, and control objectives. Assess integration requirements across enterprise identity, logging, monitoring, data protection, and security tooling. Drive cross-functional implementation efforts involving security, platform, engineering, and product teams to operationalize AI security capabilities and supporting processes. Maintain practical standards, guidance, and best practices for secure AI deployment, configuration, and ongoing platform administration. Provide consultation and technical direction where security is not the system owner, ensuring effective security requirements are defined and applied. Qualifications 7+ years of experience in information technology or cybersecurity, including at least five years in security engineering or a related technical area such as cloud security, identity and access management, data protection, application security, security operations, vulnerability management, incident response, or platform security. Hands-on experience designing and implementing security controls in modern environments, including cloud platforms, APIs, identity systems, data protection, and monitoring. Experience defining security requirements, standards, guardrails, or control frameworks in complex enterprise environments. Practical experience or strong working knowledge of AI or LLM-based systems, including their behavior, risks, and security implications. Experience partnering with engineering and platform teams to integrate security into architecture, design, delivery pipelines, and operations. Demonstrated ability to evaluate technologies and guide technical decision-making. Experience operating in complex, cross-functional environments and driving initiatives from concept through implementation. Familiarity with Azure-based platforms and services, including Azure AI Foundry or related capabilities, preferred. Exposure to enterprise AI platforms such as Microsoft Copilot, Claude, or similar platforms, preferred. Skills Strong technical knowledge of cybersecurity principles, including identity and access management, data protection, monitoring, secure architecture design, and security operations. Strong understanding of AI and LLM-related risks, including data exposure, prompt manipulation, unsafe tool use, misuse of agent capabilities, and auditability challenges. Ability to develop security and risk requirements from ambiguous or emerging technology risks. Ability to translate security requirements into practical engineering solutions, configurations, and implementation patterns. Familiarity with industry frameworks and guidance such as NIST Risk Management Framework, MITRE ATLAS, OWASP Top 10, and OWASP guidance for large language model applications. Strong analytical, problem-solving, and communication skills. Ability to work independently and collaboratively across teams. Education and Certifications Bachelor’s degree in information security, Computer Science, Information Technology, or related field (Equivalent experience may be considered) Relevant certifications, such as CISSP, CISM, Security+, GIAC, or cloud security certifications, preferred. The hiring range for this position is $121,000 - $173,000. The final salary offer will vary based on geographic location, individual education, skills, and experience. The position is eligible to participate in FM’s comprehensive Total Rewards program that includes an incentive plan, medical, dental and vision insurance, life and disability insurance, well-being programs, a 401(k) and pension plan, career development opportunities, tuition reimbursement, flexible work, and time off, including vacation and sick time. FM is an Equal Opportunity Employer and is committed to attracting, developing, and retaining a diverse workforce. #LI-NL1 #FMG

Security Engineering
Incident Response
Threat Modeling
Direct Apply
Posted about 1 month ago
FM

Consultant Engineer I -San Francisco

FMAnywhereFull-time
View Job
Compensation$50K - 70K a year

Perform hands-on site assessments of physical properties, evaluate risks, ensure engineering standards compliance, and communicate recommendations to clients while traveling frequently. | Bachelor’s degree in engineering, 0-5 years industry experience, strong communication and organizational skills, ability to work independently from home office, physical ability for site visits, valid driver’s license. | FM is one of the world’s largest risk management and industrial property insurance organizations. With 76 office locations in over 60 countries worldwide, FM provides specialized property protection to over one third of the FORTUNE 1000 companies as well as leading international corporations. A new Field Engineer at FM will learn to engineer risk management solutions from experienced mentors and a community-based work culture. The network of 1,900 loss prevention engineers, with backgrounds in physical engineering and fire protection, provide their clients with the benefit of FM's superior financial strength, policy coverage, and data-driven consulting. At FM you have the power to influence outcomes and make a difference in the future of your clients. When you join our team at FM, you can leverage your engineering background to help clients neutralize potential disaster such as fires, explosions, earthquakes, floods, and many others. What makes FM unique is our culture of camaraderie with colleagues and clients, the challenging work, and the excitement of being part of a successful organization. We believe in a supportive work/life environment and encourage our employees to participate in our total rewards benefit program, including a pension program. As a San Francisco Consultant Engineer, you will have opportunities to travel to the following states: California, Oregon, Washington, Utah, Nevada, Montana, Idaho, Wyoming, and Alaska. If you enjoy variety, put your time-management and organizational skills to use handling field visits, office work, and projects for large commercial occupancies and hazards. You will work with minimal supervision and must be capable of working independently. You will also have the resources to build a rewarding career at FM including a structured hands-on training program. Initially, assignments will be of limited scope and complexity giving you the opportunity to learn. You will gradually begin assessing risks at larger complex commercial properties by visiting client facilities and performing evaluations that accurately quantify foreseeable physical and human element exposures while working with client on-site risk management. Responsibilities Will Include • Perform hands-on site assessments of the physical property, including roofs • Conduct evaluations which include, but are not limited to, site water supplies, dust hazards, chemical storage, and rack storage arrangements for client products • Ensure that FM Engineering Standards are followed and, as necessary communicate the appropriate recommendations and/or engineering solutions to clients • Working from a home office and travel to clients' facilities daily (overnight travel is expected approximately 30% of the time) Qualifications Based on a candidate’s previous experience, this role can be for either a Consultant Engineer I or Consultant Engineer II. Successful Consultant Engineer candidates have the following qualifications: • Minimum of a bachelor’s degree in engineering (various specialties considered) • Zero to five years of industry experience • Strong verbal and written communication skills • Good analytical, organizational, problem solving, and interpersonal skills • Efficient time management ability with minimal supervision • Solid technical aptitude including diverse knowledge of engineering principles • Ability to stay focused from a home office environment • Authorization to work in the country you are applying to work in • Physical ability to lift 25 pounds, able to climb ladders, balance, and deal with heights • Proficiency in MS Office products • A valid driver’s license

Engineering principles
Site assessments
Risk management
Client communication
Time management
MS Office proficiency
Physical ability for site work
Verified Source
Posted 11 months ago

Ready to join FM?

Create tailored applications specifically for FM with our AI-powered resume builder

Get Started for Free

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt