Find your dream job faster with JobLogr
AI-powered job search, resume help, and more.
Try for Free

Latest Jobs

These are the latest job openings our job search agents have found.

Modern Construction Services

IT Operations & Security Manager

Modern Construction Services•Charlotte, North Carolina•Full-time
View Job
Compensation$70K - 120K a year

Build and manage IT infrastructure, security governance, and operations including help desk, identity management, endpoint security, and vendor transitions. | Several years of hands-on IT support, systems administration, cybersecurity experience, proficiency in Microsoft 365 and Azure AD/Entra ID, and strong skills in scalable IT processes and documentation. | IT Operations & Security Manager Modern Construction Services • Charlotte, NC (Hybrid) $90,000 + annual performance bonus Modern Construction Services (MCS) is a certified WBENC women‑owned commercial construction and facilities maintenance company headquartered in Charlotte and serving clients nationwide. We’re bringing IT in‑house for the first time — and this role builds the entire foundation. If you want to own IT operations, identity & access, security governance, endpoint management, and the systems that keep a fast‑growing company running, this is your seat. You’re not maintaining someone else’s playbook. You’re building the function from the ground up. What You’ll Own IT Operations & Support Run day‑to‑day IT support for office + field teams Manage help desk, hardware/software issues, connectivity, and access Administer Microsoft 365 (Teams, SharePoint, Outlook, Office) Support VPN and remote access for a distributed workforce Take full ownership of company phone systems (first 30 days priority) Identity, Access & Security Governance Manage provisioning, deprovisioning, and role‑based access in Entra ID/Azure AD Review and right‑size software + SharePoint permissions Administer MFA, SSO, and secure access across platforms Endpoint, Hardware & Inventory Manage standard device builds and endpoint management Run new‑hire setups end‑to‑end Oversee equipment return, wipe, redeployment, and mobile plans Maintain IT asset records, licenses, purchasing, and budgeting Cybersecurity & Continuity Own endpoint protection, email security, patching, backups, and DR Build incident‑response capability and lead response Own business continuity and redundancy planning Systems, Migrations & Integrations Support new platforms and SSO rollout Bring systems‑integration literacy across Procore, Sage, Fexa Administer company website + careers page and ATS feed Policy & Governance Partner with HR + leadership on IT safety, security, and acceptable‑use policies Contribute technical guidance on AI/ML/LLM governance Keep policy practical, current, and enforceable Vendor Transition & Documentation Manage clean transition off external IT vendor Write SOPs and documentation for scalable IT processes Support remote + field workforce with mobile‑first tools What the Work Looks Like You’re the person the whole company relies on when technology must work You step into an environment with active change, not a quiet maintenance seat Hybrid role: onsite for onboarding + hands‑on work, remote‑eligible otherwise Mix of hands‑on (imaging laptops, issuing phones) and heads‑down (identity, security, governance) You support people wherever they are — VPN issues don’t wait You set the standard, build the systems, and create documentation that lasts Who You Are You take ownership and act in the company’s best interest You balance protection with enablement You see around corners on security and reduce risk early You build systems and documentation that scale You communicate clearly and explain the “why” You stay steady under load — migrations + full support board don’t rattle you What You Bring Several years of hands‑on IT across support, systems admin, and security Strong Entra ID/Azure AD identity & access management Cybersecurity fundamentals: endpoint protection, email security, DR, incident response Microsoft 365 experience (Teams, SharePoint, Outlook) VPN + remote‑access support for distributed teams Endpoint/device management + IT asset/license management Vendor/MSP management, ideally including bringing services in‑house Systems‑integration literacy + SSO experience Judgment to balance protection with enablement and build from scratch Nice to Have Experience with SSO implementations or cutovers Familiarity with Procore, Fexa, Sage Timberline, ProEst Exposure to AI/ML/LLM governance Business phone system administration Website/careers‑page + ATS feed administration (Workable) Certifications: Security+, Microsoft (Entra/Azure/M365), Cisco Experience supporting construction, facilities, or field‑based workforce What Sets a Strong Manager Apart Here Strong builds systems + documentation so the lights stay on without one person Strong grants the right access and reviews it regularly Strong protects the company while enabling people to work Strong prevents incidents with policies, backups, and controls Strong gets ahead of migrations and integrations Strong leads AI governance instead of ignoring it Why You’ll Want to Be Here At MCS, you join a women‑owned, Charlotte‑based company that’s growing fast and doing it on purpose. We’re big enough to offer a real career path and small enough that your work gets seen. Our culture runs on shared standards — we coach, we communicate clearly, we take safety seriously, and we do what we said we would do. This role sits at the front of something. You’re building the IT function with trust, ownership, and room to grow as we scale. Compensation & Benefits Competitive salary + training/professional development allowance Annual company performance bonus Medical, dental, vision, and full benefits package 401(k) with 3% match The chance to build a function from the ground up with room to grow Modern Construction Services is an equal opportunity employer. We evaluate every candidate on merit and do not discriminate on the basis of any protected status under applicable law.

Security Governance
Identity and Access Management
Incident Response
Direct Apply
Posted 25 days ago
Crisp

Director, Growth Marketing

Crisp•Anywhere•Full-time
View Job
Compensation$90K - 140K a year

Define and scale product-led growth strategies including virality, referral programs, organic discoverability, lifecycle marketing, activation journeys, and community building to drive user acquisition and expansion. | Extensive experience building growth programs at B2B SaaS companies with strong analytical skills, expertise in SEO/GEO/AEO, and ability to bridge product, marketing, and sales teams. | WHY THIS ROLE EXISTS The best B2B products grow because they are designed to. Figma spread because every file shared pulled in a new user. Slack spread because every invitation to a channel was a growth loop. Notion spread because every published page was a billboard. Crisp has the same opportunity in the CPG and retail ecosystem. This role exists to find those product-driven acquisition moments, design them intentionally, and scale them. It combines product-led growth strategy, lifecycle and activation marketing, community building, organic search presence, and growth experimentation — including a sales-assisted PLG motion that hands warm, behavior-triggered signals to sales — into a single function that makes Crisp the platform CPG and retail practitioners reach for first and talk about most. KEY OUTCOMES & ACCOUNTABILITIES Growth & Virality Platform virality: The number of new users and accounts generated through in-product sharing, network invitations, and referrals grows quarter-over-quarter, measured by platform-driven new user activations Referral pipeline: New pipeline attributed to referral and community programs grows as a percentage of total pipeline each quarter Organic discoverability: Crisp appears in the top results for the queries CPG and retail practitioners are asking across traditional search and AI answer engines, tracked by share of search and AI citation rate Sales-assisted pipeline: Product-qualified leads handed to sales convert at a measurable rate and grow as a share of total pipeline each quarter Marketing Operations Funnel efficiency: Conversion rates at each funnel stage improve quarter-over-quarter; primary metric is meetings booked Data quality: Marketing automation data is clean, complete, and trusted by the team for decision-making CORE RESPONSIBILITIES Growth Strategy & Product-Led Motion Define and own Crisp's growth model: identify and build the in-product sharing and referral mechanisms native to the CPG and retail ecosystem: the moments when a Crisp user naturally pulls in a new user or account through their everyday workflow. For example: a CPG brand shares a Crisp insights report in a retailer meeting and that retailer wants access; a user invites a trading partner to collaborate on shared data and that partner activates on the platform. Build and scale a self-serve motion that lets CPG brands, retailers, and distributors discover, trial, and activate on Crisp with minimal friction. Partner with Product to embed referral mechanisms, shareable artifacts, network invitations, and activation triggers directly into the product, so that everyday Crisp usage pulls in new users organically. Design and run a structured experimentation program: test acquisition channels, onboarding flows, referral incentives, and activation triggers with clear hypotheses and fast iteration cycles. Own the full growth funnel from first touch to activation: reduce time-to-value for new users and improve conversion at every stage. Identify and develop Crisp's network effect opportunity. Map that motion and build the programs that activate it. Build and manage a referral program that turns Crisp's most successful customers into its most effective growth channel. Own Crisp's organic discoverability strategy across SEO, GEO (Generative Engine Optimization), and AEO (Answer Engine Optimization): ensure Crisp appears where CPG and retail practitioners are searching, whether that is a Google results page, a ChatGPT response, or a Perplexity answer. This includes structured content strategy, entity optimization, and authoritative sourcing that AI systems surface and cite. Lifecycle & Activation Own the onboarding and activation journey: design the email and in-product messaging sequences that move new users from signup to activation, define what "activated" means for Crisp, and build automated triggers around the moments that correlate with long-term retention and expansion. Define the product-qualified lead (PQL) model: identify the in-product behaviors that signal a user or account is ready for a commercial conversation, and partner with Product and RevOps to surface those signals in real time. Design and own the sales-assisted PLG motion: when a self-serve user or trial account hits a PQL threshold, the handoff to sales should feel warm and well-timed, not cold and interruptive. Partner with Sales and RevOps to ensure the right rep gets the right context at the right moment. Own expansion triggers: identify the in-product signals that indicate an existing account is ready to grow, and build automated and human-assisted programs that accelerate expansion before a formal renewal conversation begins. Community Build and own Crisp's practitioner community: a destination for CPG brand managers, retail buyers, category managers, and supply chain leaders to share benchmarks, learn from peers, and talk about what works. Develop a content and events strategy that makes Crisp synonymous with the conversations already happening in the CPG and retail industry. Identify and cultivate Crisp's most influential customers and advocates, and build structured programs that amplify their voices in the market. Partner with Commercial Enablement and Content to ensure community-generated insights and stories flow back into sales conversations and marketing programs. Build Crisp's presence in the communities, Slack groups, LinkedIn networks, and industry associations where CPG and retail practitioners already gather. Marketing Operations Oversee Marketing Operations to ensure the team has the infrastructure, data quality, and attribution accuracy needed to measure growth experiments and report on pipeline impact. Ensure the marketing technology stack supports the growth motion: self-serve tracking, referral attribution, community engagement metrics, and experiment reporting. Partner with RevOps to close the loop between growth programs and revenue outcomes. WORKING WITH AI Use AI to accelerate growth experimentation: generate hypotheses, analyze test results, and identify patterns across acquisition channels and onboarding flows faster than any manual process would allow. Leverage AI tools to personalize self-serve onboarding experiences at scale, adapting messaging and product guidance based on user segment and behavior signals. Use AI to power lifecycle sequences: generate personalized onboarding messaging, predict which users are at risk of dropping off before activation, and identify the in-product signals that most reliably predict long-term retention and expansion. Use AI to synthesize community signals: surface emerging themes, identify high-influence members, and spot the conversations worth amplifying before they go mainstream. Use AI to analyze product usage data and identify the behaviors that correlate with expansion, referral activity, and long-term retention, then build programs around those signals. Use AI-powered tools to research and execute SEO, GEO, and AEO strategies: identify the queries CPG and retail practitioners are asking across traditional search and AI answer engines, optimize Crisp's content and entity presence to appear in those results, and track how Crisp is being cited and represented in AI-generated responses. WHO THIS PERSON IS They have built growth programs at a B2B SaaS company where the product had natural viral potential and they figured out how to unlock it. They think in product-driven acquisition loops, not campaigns. They understand that growth does not end at acquisition - they think equally hard about activation, expansion, and the handoff between product motion and sales. They are as comfortable in a product roadmap conversation as they are presenting a community growth strategy to a leadership team. They have run experiments at scale, know how to read the results honestly, and know when to kill an idea and when to double down. They are obsessed with how information spreads in professional communities, stay current on the latest in SEO, GEO, and AEO, and they understand the CPG and retail ecosystem well enough to know where Crisp fits in that conversation. What Makes a Great Fit at Crisp Collaboration: You believe the best results come from working together. You share ideas, pitch in, and elevate those around you. Grit: You’re curious, self-driven, and unafraid to roll up your sleeves. You get the job done even when the path isn’t clear and adapt quickly when things change. People: You stay close to those we serve. Listening, learning, and building what matters most. Feedback: You see it as fuel. You give it with care, take it with humility, and use it to level up. Ingenuity: You solve problems with creativity and speed. You look for ways to streamline, automate, or improve without being asked. We are committed to transparency, diversity, and meritocracy, fostering an environment where every team member is empowered to make an impact, grow personally, and advance in their career. We invite you to join us — not just to take on a role, but to help shape a company you’re proud to be part of. Compensation & Eligibility Compensation for this role is determined based on a variety of factors, including individual qualifications, professional experience, skill set, and geographic location. Crisp is committed to providing fair and competitive pay. Specific compensation details will be discussed with candidates throughout the hiring process. Applicants must be authorized to work for any employer in the United States. At this time, Crisp is unable to sponsor or assume sponsorship of employment visas. Background Verification In accordance with company policy, Crisp conducts background checks that may include verification of identity, education, and criminal history. Any falsification or misrepresentation in an application will result in disqualification from consideration.

Product-led growth
SEO
Lifecycle marketing
Marketing operations
Data analysis
AI tools
Leadership
Direct Apply
Posted 25 days ago
DoorDash USA

Engineering Manager, Proactive Security - Platform

DoorDash USA•Anywhere•Full-time
View Job
Compensation$120K - 160K a year

Lead platform security hardening and manage tier-0 security services with technical leadership and cross-functional collaboration. | 12+ years in security or infrastructure platform engineering with 3+ years technical leadership and deep AWS/GCP hardening expertise. | About the Team At DoorDash we’re building the industry’s most scalable and reliable delivery network to support our three-sided marketplace of Consumers, Merchants, and Dashers. Security is paramount to the success of our business, and DoorDash Security aspires to be one the world’s most admired security team. We are committed to building the world's most trusted on-demand, logistics engine for delivery! We're expanding our team of great minds to help us secure and maintain a 24x7, no downtime, global infrastructure system that powers DoorDash’s multi-sided marketplace of Consumers, Merchants, and Dashers. About the Role Our Security Engineering team is looking for an Engineering Manager, Proactive Security to set and lead the technical direction for platform hardening at DoorDash, Wolt and Deliveroo globally. You will be a part of our inclusive, collaborative global team responsible for building “paved road” Platform Security controls to harden our compute and storage platforms and provide for a safe, secure and resilient delivery network. This is a US remote position reporting directly to the Director of our Security Engineering team. You’re excited about this opportunity because you will… Set and execute the technical vision for the Security Engineering Platform team, spanning AWS and GCP account/workload hardening, and vital tier-0 services (Access, Identity, Teleport, HashiCorp Vault, Tokenization and others). Influence and drive improvements to engineering standards, leverage advancements and LLMs to improve productivity and velocity. Own the hardening roadmap for tier-0 cloud infrastructure and access services, backed by rigorous, follow-the-sun on-call. Success is measured in eliminating classes of misconfiguration and exposure at the platform layer, not in shipping code for its own sake. Coach and mentor highly skilled tech leads and engineers as a "player-coach," leaning in at the lowest technical level on cloud hardening, identity, and secrets management problems, and lead the team to build the right durable controls. Partner cross-functionally with Core Infrastructure, Compute, Data, and other engineering platform teams to harden the shared cloud and access substrate that all of DoorDash, Wolt, and Deliveroo build on, and deliver bespoke, in-house services where vendored platform controls don't fit. Build and maintain high Operational Excellence (OE) practices for tier-0 security platforms with rigorous on-call rotations, clear escalation paths, and minimal downtime, since these systems are load-bearing for every other team's ability to ship and operate safely. Drive continuous hardening of AWS and GCP environments so insecure defaults are annihilated and prevented before they ever reach production. Influence and enable the secure and responsible adoption of AI tooling and agentic workflows from a platform hardening and access-control perspective. We’re excited about you because… 12+ years of experience as a Security or Infrastructure Platform Engineer at an internet-scale organization, with 3+ years of demonstrated technical leadership leading teams building outcomes at global scale. Deep hands-on expertise hardening AWS and/or GCP at scale, including account structure, guardrails, workload and network posture, and golden image pipelines. Demonstrated technical leadership operating access and secrets infrastructure such as Teleport, HashiCorp Vault, or equivalent PAM/secrets-management platforms, including the on-call rigor required to run them as tier-0 services. Track record of building and running highly available, no-downtime platform services with mature on-call practices, incident response, and root cause analysis. Master's degree in Computer Science, Security Engineering, a related field, or equivalent work experience. Demonstrated technical leadership designing scalable security platform controls and processes that meet required regulatory requirements. Exceptional problem solving of complex, systemic infrastructure issues that require audacious thinking, rigor, and creativity. Exceptional verbal and written communication skills - you will confidently shape and lead the Security Engineering Platform function globally and influence stakeholders across core infrastructure, product, and other engineering teams toward hardened, secure-by-default outcomes. Why You’ll Love Working at DoorDash We are leaders - Leadership is not limited to our management team. It’s something everyone at DoorDash embraces and embodies. We are doers - We believe the only way to predict the future is to build it. Creating solutions that will lead our company and our industry is what we do -- on every project, every day. We are learners - We’re not afraid to dig in and uncover the truth, even if it’s scary or inconvenient. Everyone here is continually learning on the job, no matter if we’ve been in a role for one year or one minute. We are customer-obsessed - Our mission is to grow and empower local economies. We are committed to our customers, merchants, and dashers and believe in connecting people with possibility. We are all DoorDash - The magic of DoorDash is our people, together making our inspiring goals attainable and driving us to greater heights. We offer exceptional compensation packages and comprehensive health benefits. Compensation The successful candidate’s starting pay will fall within the pay range listed below and is determined based on job-related factors including, but not limited to, skills, experience, qualifications, work location, and market conditions. Base salary is localized according to an employee’s work location. Ranges are market-dependent and may be modified in the future. In addition to base salary, the compensation for this role includes opportunities for equity grants. Talk to your recruiter for more information. DoorDash cares about you and your overall well-being. That’s why we offer a comprehensive benefits package to all regular employees, which includes a 401(k) plan with employer matching, 16 weeks of paid parental leave, wellness benefits, commuter benefits match, paid time off and paid sick leave in compliance with applicable laws (e.g. Colorado Healthy Families and Workplaces Act). DoorDash also offers medical, dental, and vision benefits, 11 paid holidays, disability and basic life insurance, family-forming assistance, and a mental health program, among others. To learn more about our benefits, visit our careers page here. See below for paid time off details: For salaried roles: flexible paid time off/vacation, plus 80 hours of paid sick time per year. For hourly roles: vacation accrued at about 1 hour for every 25.97 hours worked (e.g. about 6.7 hours/month if working 40 hours/week; about 3.4 hours/month if working 20 hours/week), and paid sick time accrued at 1 hour for every 30 hours worked (e.g. about 5.8 hours/month if working 40 hours/week; about 2.9 hours/month if working 20 hours/week). The national base pay range for this position within the United States, including Illinois and Colorado. $193,800—$285,000 USD About DoorDash At DoorDash, our mission to empower local economies shapes how our team members move quickly, learn, and reiterate in order to make impactful decisions that display empathy for our range of users—from Dashers to merchant partners to consumers. We are a technology and logistics company that started by enabling door-to-door delivery, and we are looking for team members who can help us go from a company that is known as the place you order food to a company that people turn to for any and all goods. DoorDash is growing rapidly and changing constantly, which gives our team members the opportunity to share their unique perspectives, solve new challenges, and own their careers. We're committed to supporting employees’ happiness, healthiness, and overall well-being by providing comprehensive benefits and perks including premium healthcare, wellness expense reimbursement, paid parental leave and more. Our Commitment to Diversity and Inclusion We’re committed to growing and empowering a more inclusive community within our company, industry, and cities. That’s why we hire and cultivate diverse teams of people from all backgrounds, experiences, and perspectives. We believe that true innovation happens when everyone has room at the table and the tools, resources, and opportunity to excel. Statement of Non-Discrimination: In keeping with our beliefs and goals, no employee or applicant will face discrimination or harassment based on: race, color, ancestry, national origin, religion, age, gender, marital/domestic partner status, sexual orientation, gender identity or expression, disability status, or veteran status. Above and beyond discrimination and harassment based on “protected categories,” we also strive to prevent other subtler forms of inappropriate behavior (i.e., stereotyping) from ever gaining a foothold in our office. Whether blatant or hidden, barriers to success have no place at DoorDash. We value a diverse workforce – people who identify as women, non-binary or gender non-conforming, LGBTQIA+, American Indian or Native Alaskan, Black or African American, Hispanic or Latinx, Native Hawaiian or Other Pacific Islander, differently-abled, caretakers and parents, and veterans are strongly encouraged to apply. Thank you to the Level Playing Field Institute for this statement of non-discrimination. Pursuant to the San Francisco Fair Chance Ordinance, Los Angeles Fair Chance Initiative for Hiring Ordinance, and any other state or local hiring regulations, we will consider for employment any qualified applicant, including those with arrest and conviction records, in a manner consistent with the applicable regulation. If you need any accommodations, please inform your recruiting contact upon initial connection. Notice to Applicants for Jobs Located in NYC or Remote Jobs Associated With Office in NYC Only We used Covey as part of our hiring and/or promotional process for jobs in NYC and certain features may qualify it as an AEDT in NYC. As part of the hiring and/or promotion process, we provided Covey with job requirements and candidate submitted applications. We began using Covey Scout for Inbound from August 21, 2023, through December 21, 2023. We resumed using Covey Scout for Inbound again on June 29, 2024, and ceased using Covey Scout for Inbound on April 30, 2026. The Covey tool has been reviewed by an independent auditor. Results of the audit may be viewed here: https://getcovey.com/nyc-local-law-144.

Security Engineering
Cloud Security
Identity and Access Management
Direct Apply
Posted 25 days ago
Health Insurance Alliance LLC

Healthcare Compliance Manager (Hybrid - Fort Lauderdale, FL)

Health Insurance Alliance LLC•Fort Lauderdale, Florida•Full-time
View Job
Compensation$70K - 90K a year

Execute compliance plans, perform control testing, and drive remediation in healthcare compliance. | 5+ years in health insurance compliance with knowledge of ACA, CMS Medicare, and automation tools. | Position: Compliance Manager Location: Hybrid with office located in Fort Lauderdale, FL, 33334 Status: Full Time, W2 Dress code: Business Casual, Casual Fridays ABOUT US We are looking for a highly experienced Compliance Manager to join our dynamic team at Health Insurance Alliance, LLC.  We are a rapidly growing technology focused Insurance sales company whose employees maintain a competitive nature and a desire to succeed above all. Our philosophy is to provide a quality service to our clients, offering an easy and seamless experience from start to finish. We compassionately strive to take all of our client’s needs into consideration, which helps lead us to having a well-rounded understanding of who they are and what they want, so we can offer them the highest level of quality healthcare products out there. At HIA, we recognize that our most valuable asset is our people. We prioritize creating an inclusive and diverse workforce, where every individual feels valued, respected, and empowered.  What You’ll Do The program * The annual compliance work plan. You execute it, and you're accountable for whether it lands. * Control testing and internal reviews across sales, marketing, and licensing. You design the tests, run them, and act on what they show. * Designing and documenting controls where they're missing or immature, and driving remediation of the gaps monitoring surfaces. * Remediation itself. When testing finds a problem, closing it is yours — including the uncomfortable conversations that come with it. * The reporting rhythm to leadership: work plan status, testing results, open items, and trend lines. * Compliance documentation, audit trails, and records, maintained against retention requirements. The front line * Partner due diligence in both directions — the lead and call vendors we buy from, and the parties we sell to. Intake, questionnaires, documentation, ongoing monitoring, and the recommendation to walk away when a file doesn't hold up. * Marketing review — materials, scripts, and disclosures — against applicable federal and state requirements, including CMS Medicare marketing rules. * Carrier, consumer, and regulatory inquiries, including complaints routed through third parties such as the Better Business Bureau. * Regulatory change monitoring, translated into decisions rather than summaries: what changed, what it means for us, what we're doing about it, and by when. * Do-Not-Call and opt-out handling, OIG/SAM exclusion screening, and background check, licensing, and appointment eligibility — run as systems with documented evidence, not as a queue of tickets. The operating layer * Building compliance monitoring on top of the systems we already run. The raw material is there; the coverage isn't. Closing that gap is a large part of this job. * Replacing manual spot-checks with systematic coverage — script and call review at scale, exception-based sampling, and evidence collected as a byproduct of the work rather than assembled after the fact. * Using automation and AI tools where they genuinely extend coverage, and knowing where they don't belong. Some of this work needs a defensible human decision and an auditable trail. Drawing that line well matters more than how much you automate. * Compliance reporting that updates itself, so leadership can see the state of the program without anyone assembling a deck. * Deciding what we should buy, build, or consolidate. You'll evaluate, recommend, and have real budget influence. If a tool is the wrong tool, say so. What Success Looks Like * In your first 90 days, you'll have mapped what the compliance program actually covers against what it should, gotten current on the regulatory requirements that apply to our distribution model, and shipped at least one change that permanently removes manual work. * By the end of your first year, control testing runs on a defined schedule with documented evidence. Monitoring covers meaningfully more than a hand-pulled sample. Leadership has a view of the program they trust without asking anyone to build it. Vendor files are current on both sides of the business and actively monitored. And when a carrier or a regulator asks us a question, we answer it from records rather than from memory. What You’ll Bring Required * 5+ years in compliance within health insurance distribution — agency, brokerage, or carrier. * Demonstrated experience executing a compliance program, not only advising on one. You've run the tests, found the problems, and closed them. * Command of the regulatory environment for health insurance sales: ACA and marketplace requirements, CMS Medicare marketing rules, state licensing and appointments, and the telemarketing and consent rules that govern a lead-driven operation. * Evidence that you own technology rather than tolerate it. You've automated a workflow, built reporting that runs without you, administered a system end to end, put AI tools to substantive use, or queried a database yourself. Be ready to walk us through a specific example. * Strong analytical judgment — you can look at a process, find where it breaks, and recommend a fix supported by data. * Writing clear enough that a sales manager reads your guidance once and knows exactly what to do. You'll do well here if * You've built compliance coverage out of systems that weren't designed for it, and made it stick. * You've used AI tools on real work and can describe both where they helped and where you stopped trusting them. * You'd rather prototype something in a week and learn from it than scope it for a quarter. * You've had to hold a line with a revenue team and found a way to do it that kept the relationship intact. * You're comfortable being the most technical person in the room on compliance, and the most compliance-literate person in the room on technology. * You're happy owning scope rather than headcount. This role has no direct reports — its weight comes from what you control, not who reports to you. Useful, not required SQL, Python, or a low-code automation platform such as Power Automate, Zapier, or Airtable. Experience with speech analytics or conversation intelligence tooling. Exposure to GRC platforms. Prior work in a lead-generation or performance-marketing regulatory environment. Location & Hours * Our office is located in Fort Lauderdale, Florida.  We are looking for someone who can work remotely or hybrid within Florida. * Hours of operation will be from 9 AM-5 PM Monday-Friday. * Mandatory Department meetings on Monday & Friday at 12:30PM. Compensation Range: $100- 120K USD Annually Benefits * Competitive Compensation * 20 PTO days accrued per calendar year after 3 months of employment. * Health, Dental, Vision Group Insurance after 3 month Probationary Period (Optional) * 401K + Matching program after 3 month Probationary Period (Optional) * Great Career development opportunities * Biannual Company Events & Weekly Team Lunches The Interview Process Round 1: Video Interview with HR. Round 2: Video Interview with Hiring Manager. Round 3: In Person (or Video) Interview with Hiring Panel. > Conduct references and background check > Offer  How We Hire Health Insurance Alliance (HIA) is committed to a fair and equitable hiring process for all candidates. To ensure that each candidate’s journey is consistent and the selection process is unbiased, the team at HIA will not be responding to any personal messages regarding this role or other opportunities. HIA is a proud equal opportunity workplace that is committed to equal employment opportunity regardless of race, color, ancestry, religion, sex, national origin, sexual orientation, age, citizenship, marital status, disability, gender identity or Veteran status.  HIA is committed to developing an inclusive, barrier-free recruitment process and work environment. Should you require any accommodation, please inform us and we will work with you to meet your accessibility needs. For any accessibility-related assistance, requests for information in accessible alternative formats or to report any accessibility problems, please share in your application.

Compliance Management
Regulatory Compliance
Project Management
Direct Apply
Posted 25 days ago
SECURA Insurance

Information Security Engineer

SECURA Insurance•Neenah, Wisconsin•Full-time
View Job
Compensation$85K - 120K a year

Design, implement, and maintain technical safeguards to protect systems, collaborate with teams for secure architecture, respond to incidents, and enhance security posture. | At least five years in IT security or ten years in AppDev/Infrastructure engineering, bachelor's degree, and relevant security certifications preferred. | The Information Security Engineer is responsible for designing, implementing, and maintaining the technical safeguards that protect the organization’s systems, networks, and data. This role involves evaluating security technologies, responding to incidents, and collaborating with IT and business teams to ensure secure architecture and operations. The engineer plays a key role in proactively enhancing the organization’s overall security posture. This is a hybrid role, with the associate required to be in the office 3 days per week.   RESPONSIBILITIES: * Configure, implement, monitor, and support security software/systems that will help ensure compliance with policies and procedures. This may include but is not limited to SIEM, Next Gen Firewall Management, Multi-Factor Authentication, Identity Management, Internal/External Certificate Authority, Network Access Control, Cloud access controls, Vulnerability Management, AppDev security and monitoring, etc * Assists with the definition of requirements for security technologies to application/data security, encryption, authentication systems, identity management, and access control * Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks * Document security procedures and contribute to policy development * Assists in the development, execution and/or coordination of Security Architecture Reviews, Secure Network Design, Threat & Risk Investigations, Incident Response and Documentation, DNS, Registrar Management, etc * Assist in the identification, response, investigation, and remediation of potential breaches of and issues surrounding data security * Collaborate with infrastructure and application teams to embed security into system designs and DevOps pipelines * Proactively identifies security problems, monitors performance trends, performs upgrades, and makes recommendations for security hardware and software as required * Maintain job knowledge by tracking and understanding emerging security practices and standards; participating in educational opportunities; reading professional publications; and participating in professional organizations * Responsible for providing off hours support for security as needed * Act as project lead for security tools implementations, which may include cross-functional teams * Provide education to teammates, interns, and other teams regarding specific initiatives or * InfoSec areas of importance * Other duties as assigned QUALIFICATIONS: ESSENTIAL: * Five or more years of experience working in an Information Technology security capacity or ten or more years working in AppDev or Infrastructure engineering role. * Demonstrate the ability to maintain strict confidentiality of SECURAs internal affairs PREFERRED: * A college degree (i.e. B.A. Information Systems or B.S. Computer Science) * One or more information security certifications (i.e. CISSP, GIAC, CEH, OSCP) * Understanding of ISO27001/NIST principles * Experience administering Identity and Access Management solutions * Knowledge of cloud security * Understanding of the current security threat landscape and ability to demonstrate a strong willingness to stay at the forefront of security developments * Experience with vulnerability assessment, scanning, and ethical penetration testing * Knowledge of multiple operating system internals and hardening * Experience with security policies and procedures, awareness programs, and IT audits * Highly motivated and dependable self-starter * Coding or scripting ability At SECURA, we are transforming the insurance experience by putting authenticity at the forefront of everything we do. Our mission is clear: we’re making insurance genuine. We recognize that our associates are our greatest assets, and we invest in their well-being and professional growth. We offer opportunities for continuous learning and career advancement, competitive benefits [https://youtu.be/3gzY_57b4kM], and a culture [https://youtu.be/pXAqGwTpSno] that champions work-life balance. Joining SECURA means becoming part of a dynamic team that values everyone's contribution and fosters a collaborative atmosphere. Here, you’ll not only find a fulfilling career but also a place where you can make a positive impact every day. SECURA Insurance strives to provide equal opportunity for all employees and is committed to fostering an inclusive work environment. We welcome applicants from all backgrounds and walks of life.

Information security
SIEM
Firewall management
Multi-factor authentication
Identity management
Direct Apply
Posted 25 days ago
Aleut Federal

Compliance, Asset, Security, & Configuration Management (CASC) Manager

Aleut Federal•Colorado Springs, Colorado, Arlington County, Virginia, Fairfax County, Virginia•Full-time
View Job
Compensation$85K - 120K a year

Manage and mature compliance posture, IT asset lifecycle, and security configuration standards while supporting daily operations and process improvements. | Bachelor's degree with strong cybersecurity, cloud platform, and compliance framework experience, including IT asset management and federal contractor security knowledge. | About Aleut Federal At Aleut Federal, we believe the company and its mission is just as important as the job you are applying for. Aleut Federal is an Alaskan Native-owned enterprise whose purpose is to support our "Shareholders," the Unangax, the indigenous people of the Aleutian Islands of Alaska. People are at the core of everything we do. We support our Shareholders by providing excellent service and quality results to our Clients, the various branches of the federal government. We engage in our local markets, so community service is embedded into our process. Our culture nurtures the strength of our workforce through mentorship and coaching, providing opportunities for growth, and competitive benefits. We support and encourage diversity, inclusion, and accountability at every level. The Aleut Federal motto is "We are One" because we truly believe that with one heart, one mind, and one purpose, we can accomplish our mission and be an organization anyone would be proud to be a part of. Position Overview Aleut Federal is seeking a Compliance, Asset, Security, & Configuration Management (CASC) Manager to own and mature the organization's compliance posture, IT asset lifecycle, security configuration standards, and change/configuration management practices. This is a full product-ownership role: the CASC Manager owns these areas end-to-end, from working day-to-day support tickets through to driving continuous improvement and maturity of the underlying processes. This is an individual-contributor role (no direct reports) requiring detailed, results-focused execution in a fully cloud-native, CMMC Level 2-obligated enterprise environment. The ideal candidate is highly organized, technically fluent across cyber, cloud, and compliance domains, and comfortable owning outcomes independently, from triaging a single ticket to redesigning a process. Key Responsibilities: Compliance * Own and maintain the organization's compliance posture against CMMC Level 2, NIST 800-171, and related federal contractor security requirements. * Maintain and continuously improve the System Security Plan (SSP), policies, and control narratives, ensuring evidence and documentation stay audit-ready. * Support C3PAO assessments and any follow-on assessments, coordinating evidence collection and remediation of findings. * Track and manage POA&Ms (Plans of Action & Milestones) through closure. * Monitor regulatory and contractual compliance changes and translate them into actionable internal requirements. Asset Management * Own the IT asset inventory (hardware, software, cloud resources) across commercial and GCC High environments, ensuring accuracy and completeness. * Establish and maintain asset lifecycle processes: procurement, provisioning, tracking, and decommissioning/disposal. * Conduct software inventory triage and licensing reviews to identify unauthorized or high-risk tools and reduce audit risk. * Maintain shredding/disposal standards and documentation in accordance with applicable requirements (e.g., NSA/CSS EPL). Security & Configuration Management * Own baseline security configuration standards across endpoints, servers, and cloud environments, and monitor for drift. * Manage the Change Control Board (CCB) process and associated risk-tiered change management framework. * Partner with the Cloud Architect/Engineer and IT team on configuration hardening, sensitivity labeling, and access control alignment with compliance requirements. * Support security incident response efforts by providing configuration, asset, and compliance context. * Maintain Confluence/KB documentation for CASC processes, optimized for both human use and internal AI/RAG retrieval. Ticket Ownership & Continuous Improvement * Serve as the primary owner for compliance, asset, security configuration, and change management tickets in the IT service desk queue, from intake through resolution. * Triage and resolve day-to-day requests (asset requests, access/configuration questions, compliance inquiries, change requests) within established SLAs. * Use recurring ticket patterns and root-cause analysis to identify opportunities for process improvement, automation, and documentation. * Own the full lifecycle of each CASC function as a "product" — from reactive ticket support up through proactive roadmap and maturity planning. Cross-Functional * Report on compliance, asset, and configuration risk posture to IT leadership on a regular cadence. * Collaborate with Cloud Architecture and Program teams to ensure CASC practices are embedded in ongoing initiatives (e.g., dual-tenant M365 architecture, AI tooling governance). * Drive process discipline and documentation rigor across all CASC areas. Required Qualifications: * Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field. * Strong technical proficiency across cybersecurity, cloud platforms (Microsoft Azure/M365 preferred), and compliance frameworks. * Working knowledge of CMMC Level 2 / NIST 800-171 requirements and audit/assessment processes. * Experience with IT asset management and lifecycle tracking. * Experience with configuration/change management processes and tooling (e.g., Jira, ServiceNow, or similar). * Highly detail-oriented, organized, and results-focused, with the ability to independently drive initiatives to completion. * Strong written and verbal communication skills, including documentation and audit-facing materials. * Comfortable working a service desk/ticket queue directly and balancing reactive support work with longer-term process ownership. Preferred Qualifications: * Master's degree in Information Technology, Cybersecurity, or related field. * Relevant IT/security certifications (e.g., CISSP, CISM, Security+, CySA+, CMMC-related certifications such as CCP/CCA, ITIL, or similar). * Experience supporting a federal contractor or Alaska Native Corporation (ANC)/8(a) environment. * Experience with dual-tenant Microsoft 365 environments (Commercial + GCC High). * Familiarity with Microsoft Purview, Defender for Cloud, or similar governance/security tooling. Location Hybrid with in person reporting at Colorado Springs CO, Reston VA, or Arlington VA We will be accepting applications for this position until 4 September 2026. Salary Range: $155 - $170 annually (final rate based on experience and location) Aleut offers the following benefits to eligible employees: * Health insurance * Dental/Vision Insurance * Paid Time Off * Short- and Long-Term Disability * Life insurance * 401k, and match Aleut Federal, LLC provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, sex, national origin, age, disability, sexual orientation, gender identity, or genetics. In addition to federal law requirements, AF complies with applicable state and local laws governing nondiscrimination in employment in every location where the company has facilities. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation, and training. AF prohibits workplace harassment based on race, color, sex, religion, sexual orientation, gender identity or expression, national origin, age, genetic information, disability, or veteran status. #AF

Compliance management
Security configuration
Cloud security
Direct Apply
Posted 25 days ago
The New York Times

Vice President, Cybersecurity and Deputy Chief Information Security Officer

The New York Times•New York, New York•Full-time
View Job
Compensation$150K - 250K a year

Lead cybersecurity functions and manage program execution including incident response and risk management. | Requires 12+ years progressive cybersecurity experience with senior leadership and expertise in security architectures and incident response. | The mission [https://www.nytco.com/mission-and-values/] of The New York Times is to seek the truth and help people understand the world. That means independent journalism is at the heart of all we do as a company. It’s why we have a world-renowned newsroom that sends journalists to report on the ground from nearly 160 countries. It’s why we focus deeply on how our readers will experience our journalism, from print to audio to a world-class digital and app destination. And it’s why our business strategy centers on making journalism so good that it’s worth paying for.  About the Role: As Vice President, Cybersecurity and Deputy CISO, you will translate our cybersecurity strategy into operational reality. You will: * Lead and integrate core security functions, including security architecture and engineering, threat detection and incident response, security operations, identity and access management, and risk and compliance. * Own day-to-day cybersecurity program execution, including annual planning, roadmap delivery, operational reviews and metrics. * Serve as the primary operational escalation point for significant security risks and incidents, partnering closely with Global Security, Legal, Communications, Enterprise Technology and business leaders. * Act as a visible security leader with executives, senior editors and technology leaders, helping them understand risk, tradeoffs and priorities in practical terms. * Serve as acting CISO when needed, including during executive forums, audits and key stakeholder meetings. This is a hybrid role based in our New York City headquarters, reporting to the CISO and Head of Enterprise Technology. You can typically expect to come into the office 3+ days per week. Responsibilities: Program leadership and strategy execution * Own the day-to-day execution of the cybersecurity strategy and roadmap, ensuring alignment with company and Technology priorities * Translate high-level risk and board-level objectives into concrete programs, projects and measurable outcomes * Strategically manage the Cybersecurity budget, including coordinating with finance, setting multi-year forecasts, and managing billing workflows for Cybersecurity vendors * Establish and run operating rhythms for Cybersecurity, including staff meetings, portfolio reviews, operational reviews, OKRs and metrics * Partner with the CISO on multi-year planning, budget development and investment prioritization across tools, people and services * Drive continuous improvement using internal metrics, external benchmarks and findings from assessments, incidents and exercises Security architecture, engineering and operations * Provide senior leadership across security engineering, architecture and operations, ensuring our security stack is robust, observable and well-integrated with Enterprise Technology and Developer Platforms * Guide the evolution of core controls such as endpoint protection, EDR, SIEM, email security, web security, vulnerability management, secrets management, MDM and identity governance * Partner with Enterprise Technology, Developer Platforms and product engineering to embed secure-by-design patterns, guardrails and self-service controls into platforms and workflows * Provide oversight and strategic direction for identity and access management, including identity platforms, access orchestration and privileged access * Ensure operational excellence for security tooling, including lifecycle management, vendor relationships and integration with incident response and monitoring workflows Detection, incident response and resilience * Oversee threat detection, monitoring and incident response programs, including a modern, automation-forward SOC capability. * Serve as senior escalation leader for high-severity incidents, driving real-time decision-making, cross-functional coordination and executive communications * Ensure playbooks, tabletop exercises, red/purple team activities and crisis management plans are in place, tested and regularly updated. * Partner with Global Security, Business Continuity and Enterprise Technology on integrated resilience programs, including disaster recovery, crisis response and resilience exercises * Ensure post-incident reviews lead to durable improvements in controls, processes and architecture Governance, risk, compliance and security education * Lead cybersecurity governance and risk management frameworks in alignment with NIST CSF 2.0 and other relevant standards * Drive the development and use of risk metrics, control health indicators and dashboards to communicate security posture to executives, Audit Committee and other stakeholders * Strategically support security education programs to ensure a metrics-driven approach to providing relevant training and resources to our staff Newsroom and high-risk user security * Partner with newsroom teams to support the unique threat models of journalists and other high-risk users. * Ensure security measures and controls enable, rather than impede, high-stakes newsgathering, international reporting and sensitive investigative work * Support programs that protect journalists and high-risk staff across travel, field operations, online harassment and digital threats People leadership and culture * Lead, mentor and develop senior managers and staff across multiple security disciplines, building a high-performing, inclusive and collaborative team * Foster a growth-minded, metrics-driven, blameless culture focused on learning and continuous improvement * Support career paths, succession planning and leadership development across Cybersecurity, including preparing future CISO-level leaders * Help champion security awareness and education programs that engage staff at all levels in shared security ownership * Engage in cross-industry collaboration and knowledge sharing to ensure that The New York Times is up-to-date on latest security events, techniques, and industry norms * Demonstrate support and understanding of our value of journalistic independence [https://www.nytco.com/company/mission-and-values/] and a strong commitment to our mission to seek the truth and help people understand the world Basic Qualifications: * 12+ years of progressive experience in cybersecurity or information security, including leadership of large, complex security programs * Experience leading multiple security domains, such as security engineering, security operations, incident response, cloud security, identity, application security or GRC * Prior experience in a VP, Head of Security, Deputy CISO or similar senior leadership role with accountability for both strategy and execution * Deep technical understanding of modern security architectures, including cloud (AWS, GCP or similar), network, endpoint, identity and application security * Proven track record leading major incident response efforts and security crisis management, including communication with executives and external stakeholders * Strong familiarity with industry frameworks and standards such as NIST CSF, ISO 27001, SOC 2, PCI, HIPAA and data protection regulations * Experience working in close partnership with teams across Legal, Privacy, HR, Finance, Internal Audit and external regulators or auditors * Expertise building and leading diverse teams, including developing senior managers and cross-functional leaders Preferred Qualifications: * Experience securing media, news, technology or similarly fast-paced, high-profile environments with unique threat models * Background working directly with or supporting newsroom, high-risk user or investigative teams * Experience presenting to boards or audit committees and supporting public-company security and risk disclosures * Experience operating in a global context, including international offices, complex regulatory environments and cross-border data considerations * Prior experience shaping AI governance, AI security or emerging-technology security programs #LI-Hybrid REQ-020259   Additional Compensation and Benefits For roles in the U.S., dependent on your role, you may be eligible for variable pay, such as an annual bonus and restricted stock. Benefits may include medical, dental and vision benefits, Flexible Spending Accounts (F.S.A.s), a company-matching 401(k) plan, employee stock purchase plan, paid vacation, paid sick days, paid parental leave, tuition reimbursement and professional development programs. For roles outside of the U.S., information on benefits will be provided during the interview process. The annual base pay range for this role is between: $275,000—$290,000 USD Candidate Use of GenAI Tools: We’re excited to learn more about you and your experience. To keep our hiring process as fair and authentic as possible, we ask that you submit your own work and not use GenAI tools to generate substantive content during the application and interview process. If you’re an engineering candidate, we’ll let you know what specific GenAI tools you are permitted to use for your technical assessment. --------------------------------------------------------------------------------   The New York Times Company is committed to being the world’s best source of independent, reliable and quality journalism. To do so, we embrace a diverse workforce that has a broad range of backgrounds and experiences across our ranks, at all levels of the organization. We encourage people from all backgrounds to apply. We are an Equal Opportunity Employer and do not discriminate on the basis of an individual's sex, age, race, color, creed, national origin, alienage, religion, marital status, pregnancy, sexual orientation or affectional preference, gender identity and expression, disability, genetic trait or predisposition, carrier status, citizenship, veteran or military status and other personal characteristics protected by law. All applications will receive consideration for employment without regard to legally protected characteristics. The U.S. Equal Employment Opportunity Commission (EEOC)’s Know Your Rights Poster is available here [https://www.eeoc.gov/know-your-rights-workplace-discrimination-illegal].  The New York Times Company will provide reasonable accommodations as required by applicable federal, state, and/or local laws. Individuals seeking an accommodation for the application or interview process should email reasonable.accommodations@nytimes.com. Emails sent for unrelated issues, such as following up on an application, will not receive a response. For information about The New York Times' privacy practices for job applicants, click here [https://nytco-assets.nytimes.com/2020/06/NYT_Applicant_Privacy_Policy.pdf]. Please beware of fraudulent job postings. Scammers may post fraudulent job opportunities, and they may even make fraudulent employment offers. This is done by bad actors to collect personal information and money from victims. All legitimate job opportunities from The New York Times will be accessible through The New York Times careers site [https://www.nytco.com/careers/]. The New York Times will not ask job applicants for financial information or for payment, and will not refer you to a third party to do so. You should never send money to anyone who suggests they can provide employment with The New York Times. If you see a fake or fraudulent job posting, or if you suspect you have received a fraudulent offer, you can report it to The New York Times at NYTapplicants@nytimes.com. You can also file a report with the Federal Trade Commission [https://reportfraud.ftc.gov/#/] or your state attorney general [https://www.consumerresources.org/file-a-complaint/].

Cybersecurity Strategy
Incident Response
Risk And Compliance
Direct Apply
Posted 25 days ago
CR

Information Systems Security Officer (ISSO)

Credence•Arlington, Virginia•Full-time
View Job
Compensation$85K - 120K a year

Manage federal cybersecurity compliance, risk management, and authorization activities including security documentation and validation of NIST controls. | Bachelor's degree, 3-5 years cybersecurity experience, active Secret clearance, knowledge of RMF and federal compliance. | Overview Join a team where innovation meets mission. Our AI, cloud, cyber, and modernization solutions save agencies thousands of hours, safeguard national security, and strengthen health and humanitarian missions worldwide. With 1,700+ team members, 1,500+ AI/data experts, and 100+ prime contracts, we deliver at scale and with purpose. We’ve been recognized as a Top Workplace by the Washington Post for six straight years and named to the Inc. 5000 Fastest Growing Private Companies 13 of the past 14 years. Credence is a welcoming home for those looking to grow and contribute to positive change. We encourage all employees to expand beyond their boundaries, dive into important world-changing Federal challenges. Position Summary Credence has an immediate need for an Information Systems Security Officer (ISSO) to support federal cybersecurity compliance, risk management, and authorization activities within a complex government environment. The ISSO will serve as a key security and compliance resource, supporting Authority to Operate (ATO) efforts, continuous monitoring activities, security documentation, risk assessments, and implementation validation of NIST security controls. The successful candidate will work closely with government stakeholders, technical teams, and compliance personnel to ensure systems remain secure, compliant, and operationally effective. Responsibilities include, but are not limited to the duties listed below Serve as the primary point of contact (POC) to Lead Security Impact Analysis (SIA) and NOC packages Serve as the primary point of contact (POC) for compliance-related questions by client, RPC, and other stakeholders (except RSCs) Serve as the primary point of contact (POC) for ATO efforts for RPC systems: Privacy Impact Assessment (PIA);Perform risk analysis and risk assessments on proposed changes Information System Contingency Plan (ISCP) - will maintain and coordinate updates annually Contingency Plan Testing – conducted and documented annually SSP updates Cyber Table Top/Testing requirements – Support conducting and documenting annually to meet requirements POA&M management Serve as the primary point of contact (POC) for ISSO Checklist (monthly, quarterly, annual) Support compliance-based data call requests where necessary Participate in IRB, CCB, A&A, M21-31, and other policy meetings Ensure security controls are being met (NIST 800-53 control implementation validation) Keep ArchAngel updated with system changes (boundary diagrams, connection table, POCs...) Participate on IIS daily calls (once a week) Support Compliance meetings with client(s): currently bi-weekly Government Sync with ISO and Monthly AODR Check-in Monthly continuous monitoring deliverables (ISSO checklist, and recurring account validation) Customer responsibility matrix maintenance Evaluate security tools and verify that all have obtained required FedRAMP and TRB approvals prior to integration into the environment Active Secret security clearance required. Bachelor's degree in Cybersecurity, Information Assurance, Information Systems, Computer Science, Computer Engineering, Mathematics, or a related field. Three (3) to five (5) years of relevant professional experience supporting information security, cybersecurity compliance, risk management, or related IT security functions. Experience supporting security authorization and compliance activities within federal, government, or highly regulated environments. Knowledge of Risk Management Framework (RMF) principles and NIST SP 800-53 security controls. Experience developing or maintaining security documentation, including System Security Plans (SSPs), Plans of Action and Milestones (POA&Ms), risk assessments, and contingency plans. Experience supporting continuous monitoring and security compliance activities. Strong analytical, organizational, documentation, and communication skills. Preferred Qualifications Security+, CAP, CISSP, CISM, or other relevant cybersecurity certifications. Experience supporting Assessment and Authorization (A&A) or Authority to Operate (ATO) activities. Familiarity with FedRAMP, cloud security, and federal cybersecurity compliance requirements. Experience supporting government customers and stakeholders. Salary Range: $95,000 - $132,000 annually. Actual compensation will be determined based on factors such as experience, education, certifications, security clearance status, and internal equity. Health Care Plan (Medical, Dental & Vision) Retirement Plan (401k, IRA) Life Insurance (Basic, Voluntary & AD&D) Paid Time Off (Vacation, Sick & Public Holidays) Family Leave (Maternity, Paternity) Short Term & Long Term Disability Training & Development Wellness Resources

Cybersecurity
Risk Management Framework
NIST SP 800-53
Compliance
Security Documentation
Direct Apply
Posted 25 days ago
North American Electric Reliability Corporation

Compliance Assurance Manager

View Job
Compensation$70K - 120K a year

Lead a team overseeing risk-based compliance monitoring and certification programs and manage policy development and industry outreach. | Bachelor's degree and 7+ years of progressive project and team leadership experience in complex organizations with strong regulatory compliance knowledge. | Our Company  The North American Electric Reliability Corporation (NERC) is a not-for-profit international regulatory authority whose mission is to assure the effective and efficient reduction of risks to the reliability and security of the grid. NERC develops and enforces Reliability Standards; annually assesses seasonal and long-term reliability; monitors the bulk power system through system awareness; and educates, trains, and certifies industry personnel. NERC’s area of responsibility spans the continental United States, Canada, and the northern portion of Baja California, Mexico. NERC is the Electric Reliability Organization (ERO) for North America, subject to oversight by the Federal Energy Regulatory Commission (FERC) and Provincial authorities in Canada. NERC's jurisdiction includes users, owners, and operators of the bulk power system, which serves nearly 400 million people. Our Mission  The vision for the ERO Enterprise, which is comprised of NERC and the six Regional Entities, is a highly reliable and secure North American bulk power system. Our mission is to assure the effective and efficient reduction of risks to the reliability and security of the grid. Your Impact  Reporting to the Director, Compliance Assurance and Certification, the Compliance Assurance Manager leads a team of professionals responsible for overseeing, monitoring, reviewing, and evaluating program effectiveness of the ERO Enterprise’s implementation of risk-based compliance monitoring and certification. In addition, the Compliance Assurance Manager, and team, is responsible for overseeing Regional Entities and assessing adherence to the NERC Rules of Procedure, Compliance Monitoring and Enforcement Program (CMEP), and approved delegation agreements. This role requires a highly organized, collaborative, and solutions-oriented CMEP professional who can balance strategic partnership with operational excellence, while contributing to the successful execution of NERC’s Regional Entity oversight strategy. Your Responsibilities and Qualifications Responsibilities  * Manage Compliance Assurance staff responsible for ERO Enterprise compliance assurance activities and oversight supporting NERC’s risk-based CMEP. * Develop, execute, and proactively manage project schedules, including risk identification, risk mitigation, and change management. * Coordinate with Compliance Assurance staff, other NERC departments, and Regional Entity staff to facilitate ERO Enterprise compliance engagement oversight. * Develop and execute oversight programs/processes/activities to evaluate Regional Entity adherence to the NERC Rules of Procedure, CMEP, and delegation agreements. * Manage identification, development, and effective delivery of regional and industry Operations and Planning outreach and/or training. * Provide cyber technical expertise on Risk and Operations and Planning in support of other NERC departments. * Manage the ongoing development and improvement of NERC CMEP policies, procedures, rules, and other activities. * Facilitate industry stakeholder Operations and Planning outreach through presentations, briefings, seminars, news articles, and workshops. * Interface with NERC committees, subcommittees, working groups, and industry stakeholder groups as necessary. * Ensure that Compliance Assurance activities are conducted in adherence with NERC Rules of Procedure. * Communicate job expectations to the team and provide feedback to employees as needed. * Motivate and inspire staff while facilitating personal growth. * Strategize, set goals, and monitor employees’ progress towards completion. * Other duties as assigned. Qualifications   The successful candidate will have:  * A Bachelor’s Degree from an accredited four-year college or university, or equivalent experience. * Ability to lead a team of subject-matter-experts and effectively contribute to the Compliance oversight program. * At least seven years of progressive and successful experience leading projects, teams, and initiatives in a technically and operationally complex business/organization. * Progressive knowledge of Bulk Electric System Operations and Planning. * Strong experience in evaluating and analyzing risk. * Advanced project management and analytical experience. * Demonstrated group facilitation skills. * Ability to manage multiple projects and accept shifting priorities. * Ability to work independently in a fast-paced environment with minimal direct supervision. * Strong leadership, interpersonal, problem-solving, with the ability to interact diplomatically with people from many levels of industry and government. * Excellent oral and written communication skills, including editing and proofreading skills. * Proficiency using Microsoft Office tools including Word, Outlook, Excel, and PowerPoint. * Ability and willingness to travel regularly. Additional Desirable Qualities * Familiarity with the application of NERC standards, specifically the Operations and Planning standards. * Knowledge of COSO, GAGAS, and/or IIA. * One or more of the following professional certifications: PE, CIA, CISA, CISSP. * Prior experience in regulatory compliance oversight and/or enforcement within a recognized industry, government, or government-authorized agency, especially in conducting performance audits or analysis of program effectiveness of government agency operations (e.g., GAO or other federal or state-level equivalent experience). * A master’s degree in a related field. * At least five years of experience in the energy sector. * Demonstrated experience with public policy or regulatory affairs. Other * Background check will be conducted prior to employment. * In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification document form upon hire. * Travel necessary: Passport required for North American travel. * This position has been classified as exempt. * This position is classified as a remote/virtual. Our Culture Declarations * Everyone at NERC is a leader. * We are accountable personally and organizationally to deliver on commitments. * We develop ourselves and people in the organization to ensure that NERC realizes its strategic objectives. * We are resilient and adaptable to the challenges and needs of the business/people. * We exude a growth mindset and empower teams to take risks. * Build collaborative relationships within NERC, the ERO, and the stakeholders of NERC. * We exemplify NERC cultural behaviors: * Reward, high-quality, creative, and innovative work; * Attract, engage, and retain top talent; * Value and respect diverse perspectives; * Provide a safe, inclusive, and collaborative work environment; and * Form strong relationships within the company, and with the ERO Enterprise. * We demonstrate curiosity in a wide variety of areas and are open to exploring new situations, knowledge and opportunities for growth and development. * We demonstrate an anticipatory mindset; preventing problems, and building contingencies where appropriate. * We are champions for diversity and inclusion. Seeks out and values diverse perspectives.

Compliance management
Project management
Risk assessment
Direct Apply
Posted 25 days ago
North Point Technology

Software Engineer: Full Stack - Python, Java or JavaScript/TypeScript (TS/SCI Clearance Required)

North Point Technology•Gaithersburg, Maryland•Full-time
View Job
Compensation$70K - 120K a year

Design, develop, and deploy secure cloud-native software solutions and support DevSecOps pipelines. | Bachelor's degree, active TS/SCI clearance, proficiency in full-stack development and secure coding practices. | ***This job requires active TS/SCI clearance. Please apply only if you have an active TS/SCI clearance. *** North Point Technology is looking to hire a Full Stack Software Engineer to support a mission-critical GEOINT program for an Intelligence Community customer. The qualified candidate must have an active Top Secret/SCI security clearance and will design, develop, and deliver modern, cloud-native software solutions that enable national security missions. The ideal candidate has an excellent understanding of the full software development lifecycle and exceptional coding skills across front-end interfaces, backend services, and secure cloud integrations in support of the mission. Responsibilities: This position spans the full software development lifecycle, building and delivering innovative capabilities that support GEOINT data access, visualization, and dissemination. Duties include designing, developing, testing, and deploying software solutions; building and maintaining secure, containerized microservices and RESTful APIs with tools such as Docker, Kubernetes, AWS, React, Node.js, and Spring Boot; participating in Agile sprints, daily stand-ups, sprint planning, and retrospectives; supporting DevSecOps pipelines while meeting security and accreditation standards; collaborating with mission users and product managers to refine requirements; performing code reviews and mentoring fellow developers; and resolving prioritized tasks alongside internal teams at North Point Technology. Required Skills/Experience: Proficiency in Python, Java, or JavaScript/TypeScript Web development with HTML, CSS, JSON, AJAX, and REST APIs Modern front-end and back-end frameworks (React, Angular, Vue.js, Node.js, Spring Boot, Django, or Flask) Cloud development on AWS or Azure Relational databases (MySQL, PostgreSQL, or SQL Server) Linux and Windows operating systems Version control with Git CI/CD pipelines (GitLab CI or Jenkins) Agile collaboration tools (JIRA, Confluence) Containerization with Docker and Kubernetes Secure coding practices and government accreditation processes (RMF, STIGs) Preferred Skills/Experience: Go programming Front-end UI/UX design NoSQL databases (OpenSearch/Elasticsearch) Specific AWS services (S3, EC2, SQS, SNS, RDS, CloudFormation) Multi-cloud environments (AWS, Azure, Google Cloud, IBM, or Oracle) Infrastructure-as-Code (Terraform, Ansible) Geospatial tools and standards (GeoServer, PostGIS, OGC APIs, ESRI ArcGIS) Familiarity with modern software design patterns and secure coding standards Experience delivering complex software systems into production Experience supporting a customer contract or the Intelligence Community Certifications such as AWS Certified Developer, Security+, or SAFe Practitioner Qualifications: Active TS/SCI security clearance with the ability to obtain a polygraph Bachelor's degree in Computer Science, Software Engineering, or a related field North Point Technology is THE BEST place to work for curious-minded engineers motivated to support our country’s most crucial missions! We focus on long term projects, leveraging the latest technology in support of innovative solutions to solve our customer’s most difficult problems. At North Point Technology, EMPLOYEES come first! We value our employees by providing excellent compensation, benefits, and a flexible work-life balance. We strive for a close-knit and open atmosphere where the owners are always directly available to our team members. Come join us! Apply with North Point Technology today! For positions requiring a federal security clearance, your clearance level must be clearly identified on your resume.

Python
Java
JavaScript
TypeScript
Docker
Kubernetes
Direct Apply
Posted 25 days ago
Showing 5541-5550 of 23,537 jobs

Ready to have AI work for you in your job search?

Sign-up for free and start using JobLogr today!

Get Started »
JobLogr badgeTinyLaunch BadgeJobLogr - AI Job Search Tools to Land Your Next Job Faster than Ever | Product Hunt