Search 4,053 Remote CISM Jobs

4,053 remote jobs

Senior Sales Engineer - Data & AI Security

Remote Germany

Veeam is the Data and AI Trust Company specializing in helping organizations ensure their data and AI are fully understood secured and resilient to enable the acceleration of safe AI at scale. As the market leader in both data resilience and data security posture management Veeam is built for the convergence of identity data security and AI risk. Headquartered in Seattle with offices in more than 30 countries Veeam protects over 550000 customers worldwide who trust Veeam to keep their businesses running. Join us as we go fearlessly forward together growing learning and making a real impact for some of the world's biggest brands. About the Role Veeam following its acquisition of Securiti AI - the leader in AI-powered data security posture management (DSPM) - is seeking a Senior Sales Engineer to drive technical leadership in our sales team focusing on the Securiti AI portfolio. You will partner with a Securiti Sales Specialist and support 3–5 Account Executives and Veeam Solution Engineers as the technical subject matter expert. You will guide customers from needs assessment to solution design delivering hands-on demos and proof-of-concepts to showcase value. Success in this role requires strong technical skills and the ability to build trust with clients. What You'll Do Act as the primary technical contact for Securiti AI solutions during the sales cycle Lead technical discussions and deliver customized security solutions Address customer needs in data discovery posture management and compliance Design and present product demonstrations and proof-of-concepts Collaborate with product engineering and customer success teams to ensure smooth transitions What You'll Bring Significant experience in pre-sales or sales engineering Strong understanding of data and/or cloud security Effective communicator with both technical and business stakeholders 10+ years technical sales experience in security 15+ years in Software/SaaS/Enterprise technical sales Hands-on experience with AWS Azure or GCP Knowledge of data privacy/security standards (e.g. GDPR NIST 800-53 ISO 27001) Experience with DSPM frameworks Linux Kubernetes or cloud data systems Relevant certifications (CISSP CISM or cloud-specific) What You'll Get Veeam offers benefits that support your whole self 30 paid vacation days plus 4 extra global VeeaMe Days for self-care and 24 paid volunteer hours annually through Veeam Cares Statutory public health insurance with employer and employee contributions Statutory pension scheme with employer and employee contributions Statutory accident insurance fully funded by Veeam Supplemental pension plan with employer match and salary sacrifice option Supplemental accident insurance with 24/7 worldwide coverage Opportunities to learn and grow through on-demand libraries (LinkedIn Learning O'Reilly) mentoring workshops and learning events like our annual Global Day of Learning Please note If an applicant is permanently located outside of Germany Veeam reserves the right to decline the application for this position. LI-DF1 LI-REMOTE Veeam Software is an equal opportunity employer and does not tolerate discrimination in any form on the basis of race color religion gender age national origin citizenship disability veteran status or any other classification protected by federal state or local law. All your information will be kept confidential. Personal data collected during the recruitment process will be processed in accordance with our Recruiting Privacy Notice which explains how your information is collected used and handled in connection with hiring activities. By applying for this position you consent to this processing. By submitting your application you confirm that the information provided including any supporting documents is complete and accurate to the best of your knowledge. Any misrepresentation omission or falsification may result in disqualification from consideration or if discovered after employment begins termination of employment.

Senior Director, Information Security and Compliance

Remote Canada

A NOTE ON HOW TO REACH US We're truly grateful that so many people have Foundant on their radar — it means a lot that our work resonates with others. That said due to the high volume of direct messages and emails we receive cold outreach isn't the preferred way to be considered for a role and we're not able to prioritize applications submitted this way. To apply for open positions please visit our careers page which is the fastest and most effective route to being considered. About Foundant At Foundant we build mission-critical software for the social good ecosystem — helping foundations grantmakers nonprofits and community organizations streamline their work strengthen relationships and maximize their impact. We serve the giving community worldwide with a comprehensive suite of solutions spanning grant management community foundation software and giving analytics. We're a unified company shaped by strong roots across our product portfolio and we operate with intention and purpose. Our team of ~350 people across six countries is connected by a shared North Star to be the trusted partner and strategic advisor to the communities we serve. Where You’ll Work As a remote-first workplace we believe in offering flexibility and the freedom to work where it suits you best while staying connected through technology. Our global network of talent is supported by physical office hubs and virtual collaboration fostering a dynamic environment where innovation and growth thrive. With office locations in Bozeman MT Toronto Canada and Dublin Ireland you'll be part of a globally connected team. Whether you're working remotely or from one of our office locations you'll be contributing to a vibrant collaborative culture focused on driving meaningful impact across the world. WhatYou’llDo You'll own and drive the maturity of Foundant's information security and GRC program end to end — setting the strategic roadmap that protects the trust our clients place in us across five products and every region we serve. You'll lead and develop our Head of Technical Security and Head of GRC aligning both teams around a shared vision for reducing risk and building a security-first culture across the organization. You'll serve as Foundant's executive voice during security incidents communicating clearly and confidently with clients leadership and regulators — because how we show up when things go wrong says as much about who we are as how we operate day to day. You'll build and mature Foundant's GRC program — policies risk registers control frameworks and audits (e.g. SOC 2 ISO 27001) — ensuring compliance across US Canadian European UK and Australian regulatory requirements. You'll partner closely with Product and Engineering leaders to embed security and privacy by design into all five product lines. You'll develop and present security and compliance metrics to executive leadership and the Board translating technical risk into business impact and clear priorities. You'll own third-party and vendor risk management ensuring our extended ecosystem meets the same standard of care we hold ourselves to. You'll represent Foundant's security posture to clients and prospects during enterprise sales cycles security reviews and due-diligence questionnaires. Other duties as assigned. WhatYou’llNeed 8+ years of progressive leadership experience in information security and/or governance risk and compliance (GRC) including experience leading both technical security and compliance functions. Demonstrated experience building or maturing a security and compliance program for a multi-product SaaS company. Experience navigating international regulatory and compliance frameworks (e.g. GDPR UK GDPR Australian Privacy Act SOC 2 ISO 27001). Experience leading security incident response programs including experience serving as a public-facing or client-facing spokesperson during incidents. Experience managing and developing senior technical and compliance leaders. CISSP CISM or CRISC preferred but not required. No specific degree requirement — equivalent professional experience is accepted. Must be legally eligible to work in the United States. WhatYou’llBring to our Team Dynamics Strategic Thinking Translates Foundant's North Star into a multi-year security and compliance roadmap that scales across five product lines and every region we operate in adapting the plan as regulatory and threat landscapes shift. Decision-Making Makes fast values-aligned calls under pressure — especially during security incidents — using evidence and risk data to protect clients and the business while keeping leadership clearly informed. Change Management Leads with calm direct communication during incidents and organizational change alike serving as a steady and credible voice for clients regulators and internal teams when it matters most. Staff Development Coaches the Head of Technical Security and Head of GRC to grow as leaders in their own right giving them the feedback autonomy and visibility to build strong teams beneath them. Collaboration and Learning Builds trusted partnerships with Product Engineering and Legal leaders across a global organization and stays ahead of an evolving threat and regulatory landscape by continually learning and sharing insight with the team. Why You’ll Love Working at Foundant At the heart of everything we do is a commitment to innovation and making a positive impact. Whether you’re working on projects that empower not-for-profits community foundations or corporations your contributions will help drive real-world change. We offer competitive salary and benefits including tuition and lifestyle reimbursements and bespoke mindfulness and fitness initiatives. With our Flexible PTO policy you’ll have the freedom to manage your time in a way that supports your personal well-being and professional success. We’re committed to your professional and personal development. With our merger you'll have the chance to collaborate across teams giving you exposure to diverse ideas expertise and projects that span multiple industries. As part of a larger organization you’ll have even more opportunities to grow your career. Whether it’s exploring new roles leadership opportunities or shifting to a different department we support internal mobility to help you achieve your career goals You’ll enjoy autonomy and responsibility empowering you to approach your work creatively and independently fostering innovation and independent thought. Employee recognition is a core part of our culture. When you do a great job we make sure everyone knows about it! Foundant is an equal opportunity employer committed to building a diverse workforce that represents the communities we serve. We welcome and encourage applications from all qualified candidates and will consider all applicants without regard to race color citizenship religion sex marital/family status sexual orientation gender identity Indigenous status age disability or individuals who may require accommodation. Foundant is also committed to providing accommodations throughout the interview and employment process. Accommodations are available upon request for candidates participating in all aspects of the selection process. If you have accessibility requirements during the recruitment process and require accommodation please contact hr@smartsimple.com.

Executive Advisor - Governance, Risk & Compliance

Remote Canada

About Malleum - Malleum is at the forefront of next-generation cyber defense partnering with marquee clients across space aerospace defense government financial services and critical infrastructure. We're experiencing exceptional growth as demand accelerates for trusted advisors capable of delivering at the intersection of national security allied intelligence cooperation and enterprise resilience. Our advisors shape the governance risk and compliance programs that underpin cutting-edge defensive technologies sovereign space capabilities and allied programs with national security impact – from satellite and launch operations to next-generation defense platforms. If you take pride in shaping how the most consequential organizations govern cyber risk and want your counsel to influence sovereign and allied missions Malleum is where your leadership meets purpose.The Opportunity - We're seeking a very senior governance risk and compliance specialist to lead our most strategic GRC engagements and to help scale our advisory practice across the space aerospace and defense sectors. In this role you'll serve as a trusted counsel to CISOs CIOs CROs and boards – translating regulatory complexity into pragmatic mission-aligned programs. This is a remote position with travel to client sites – typically Ontario-based – as required. This is a senior leadership role for a recognized GRC practitioner who has stood up enterprise-grade cyber resilience programs navigated the most demanding compliance regimes and can mentor the next generation of Malleum advisors.What You'll Do Lead executive-level GRC advisory engagements for clients across space aerospace defense government and critical infrastructure Stand up and mature Cyber Resilience Programs at large enterprises integrating governance risk management business continuity third-party risk and incident readiness into a cohesive operating model Advise C-suite and board stakeholders on cyber risk posture regulatory exposure and strategic investment priorities Lead client journeys to CMMC (Cybersecurity Maturity Model Certification) readiness and certification including scoping gap assessments SSP/POAM development and assessor coordination Lead client adoption of the Canadian Program for Cyber Security Certification (CPCSC) for organizations supporting the Government of Canada defense supply chain Develop operationalize and audit programs aligned with NIST CSF 2.0 NIST 800-53/171 ISO 27001/27005 ITSG-33 SOC 2 and sector-specific frameworks Advise space-sector clients on emerging requirements such as Space ISAC guidance NIST IR 8401 (Satellite Ground Segment) and allied space defense expectations Define and implement enterprise risk management frameworks KRIs/KPIs risk appetite statements and board reporting cadences Lead third-party / supply-chain risk programs aligned with defense industrial base (DIB) and allied requirements Shape Malleum's GRC service offerings methodologies accelerators and intellectual property Mentor and develop senior managers managers and consultants — building bench strength and a strong delivery culture Drive business development trusted-advisor relationships account growth proposals and thought leadership across the space aerospace and defense ecosystem Represent Malleum in industry forums regulator engagements client briefings and executive roundtables What You Bring 15+ years of progressive cybersecurity and GRC experience including senior leadership roles in consulting industry or government Demonstrated track record standing up and scaling Cyber Resilience Programs for large complex enterprises — including governance structures risk frameworks control libraries metrics and operating cadences Deep expertise across CMMC (Levels 1–3) and emerging CPCSC requirements including how each maps to NIST 800-171 / 800-172 and supplier obligations Hands-on experience advising clients in space aerospace and defense — familiarity with ITAR CGP controlled goods export controls and allied compliance regimes Strong command of NIST CSF 2.0 NIST 800-53/171/172 ISO 27001/27005 ITSG-33 SOC 2 PCI DSS and relevant privacy regimes (PIPEDA Quebec Law 25 GDPR) Executive presence — proven ability to advise CISOs CIOs CFOs GCs audit committees and boards Strong commercial acumen — practice building account growth proposal leadership and revenue accountability Demonstrated leadership in mentoring coaching and developing high-performing GRC teams Certifications such as CISSP CISM CRISC CGEIT CISA ISO 27001 Lead Auditor/Implementer or CMMC Registered Practitioner (RP) strongly preferred Eligibility for Government of Canada security clearance (Secret or higher) existing clearance highly valued French fluency is an asset Bachelor's degree required advanced degree (MBA MS in Cybersecurity) preferred Why Malleum - Lead GRC programs with genuine national and allied security impact across space aerospace and defense Shape the strategy and growth of a rapidly scaling advisory practice with direct partner-level visibility Work alongside seasoned IR offensive security engineering and program leaders on the most consequential client missions Highly competitive executive compensation performance incentives and equity-style participation in practice growth Continuous learning budget certification sponsorship and a platform to publish speak and shape industry dialogue A flat high-trust culture that rewards judgment ownership and mission focus Malleum is an equal opportunity employer. We welcome applications from all qualified candidates and are committed to building a team that reflects the communities and missions we serve. We are committed to providing accommodations for individuals with disabilities throughout the recruitment process. Please let us know if you require accommodation at any stage. Gm1VJfwdua

Senior Application Specialist – OKTA Build Out

Remote Brazil

What we are looking for At Insi we are seeking a visionary and highly skilled Senior Application Specialist to lead the end-to-end design implementation integration optimization and governance of our enterprise-wide Identity and Access Management (IAM) solutions. In this strategic role you will champion the Okta Build Out across a multinational environment driving our global IAM strategy security compliance and automation efforts. You will collaborate closely with cross-functional teams and key stakeholders to deliver operational excellence ensuring a secure seamless and highly resilient identity infrastructure that supports our business growth and digital transformation. Main responsibilities Lead the end-to-end implementation configuration and global expansion of the Okta Workforce Identity Cloud at an enterprise level. Design architect and deploy robust Single Sign-On (SSO) Multi-Factor Authentication (MFA) Adaptive Authentication Lifecycle Management and Identity Governance solutions. Seamlessly integrate diverse applications—including SaaS on-premises legacy and custom-built systems—with Okta leveraging standards such as SAML OAuth OIDC and SCIM. Architect and automate complex Joiner-Mover-Leaver (JML) lifecycles and provisioning workflows using REST APIs PowerShell Python and Infrastructure as Code (Terraform Ansible). Act as the technical lead for complex IAM incident resolution performing thorough root cause analysis to prevent recurring issues and optimize platform reliability. Establish and enforce robust security governance policies supporting cybersecurity compliance initiatives risk assessments and internal/external audits (e.g. NIST ISO 27001 CIS). Partner with executive and technical stakeholders to align the IAM roadmap with overall business objectives driving automation operational excellence and a zero-trust security posture. Requirements Extensive hands-on experience designing building and managing Okta Workforce Identity Cloud solutions (including Universal Directory Lifecycle Management and API Access Management) in multinational environments. Deep expertise in federated identity standards and protocols including SAML 2.0 OAuth 2.0 OpenID Connect (OIDC) SCIM and LDAP. Proven experience integrating Okta with core enterprise platforms and ecosystems such as SAP Workday ServiceNow Microsoft 365 and hybrid directories. Strong scripting and automation skills using PowerShell Python and REST APIs alongside practical experience with Infrastructure as Code (IaC) tools like Terraform and Ansible. Solid understanding of multi-cloud security environments including Azure AD / Microsoft Entra ID AWS IAM and Google Cloud IAM. Comprehensive knowledge of cybersecurity frameworks compliance requirements and standards such as NIST ISO 27001 and CIS Controls. Native or fluent English communication skills (both written and verbal) with the ability to deliver executive-level presentations and highly technical documentation. Strategic thinker with outstanding analytical and problem-solving skills capable of translating complex business requirements into robust IAM architectures. Proven technical leadership stakeholder management and decision-making capabilities with a strong ability to collaborate build trust and influence without direct authority. A continuous improvement mindset results-oriented focus and commitment to driving operational excellence. Nice to have Official Okta certifications such as Okta Certified Professional Administrator or Consultant. Recognized cybersecurity credentials such as CISSP CISM CCSP or equivalent IAM-specific certifications. Experience with advanced Identity Governance and Administration (IGA) tools and modern DevSecOps pipeline integrations. Location Remote Who is Insi? We are a consulting firm specialized in digital evolution. But above all we are a company of people. People who listen before proposing. Who get to the core before offering a solution. Who measure success by what truly changed not by what was simply implemented. With over three decades of history and a global presence we believe that true transformation begins from within within people teams and organizations. And it is this conviction that guides every choice we make every project we deliver and every person we develop. Why build your career at Insi? Because here you think decide and create together. We offer autonomy clear goals and an environment where Insiders have the space to interact with different technologies participate in challenging projects bring new ideas and work from anywhere in Brazil and (why not?) the world. We are one of the best companies to work for in Brazil according to Great Place to Work and are among the top 10 best employers in Brazil according to TIME magazine. What are our values? We are people serving people We think and act like owners We hunger for performance We grow and learn together We seek excellence and simplicity We have innovation and creativity in our DNA Everyone is welcome regardless of background disability ethnicity religious belief sexual orientation appearance age or any other status. We want you to grow with us in a welcoming environment filled with opportunities. Did you identify with this? Then VemSerInsi

IT Security Analyst II

Careers at IT Security Analyst II VC3 an innovative and growing IT services solution provider headquartered in Columbia SC is seeking to fill a Senior Cybersecurity Analyst role. They will be responsible for helping organizations to protect their infrastructure data people and customers and will work with the existing management and technical teams to be successful. Our People Our team members are collaborative positive and dedicated to mutual success. Transparency isn't just a buzzword here it's a commitment to open communication ensuring every voice is heard and valued. Guided by our core values — Passionately Curious Own It Go Beyond and Serve as One — we’re here to create something extraordinary together. Our Core Focus Our team members play a pivotal role in our focus Serving those who serve with technologies for today and tomorrow that make life safe and simple. With nearly 30 years of specialized expertise our team goes beyond conventional boundaries delivering tailored managed services and cybersecurity solutions to our clients. Your Growth We are a growth minded organization that prioritizes development offering numerous opportunities for career advancement. Rooted in our core value of being Passionately Curious VC3 offers a dynamic learning environment emphasizing hands-on experiences and formal development programs that celebrate continuous learning to propel your career forward. Department Technology Operations Employment Type Full Time Location Canada - Remote Workplace type Fully remote Key Responsibilities Understand and follow “The VC3 Way”. This is our set of standards and processes that produce a predictable result for the client. You must be aware of and maintain our standards Translate complex Cyber Security concepts into actionable insights for clients ensuring alignment with their business priorities and enhancing their understanding of strategic security decisions. Oversee and prioritize security event monitoring and incident response queues ensuring swift and accurate triage to meet or exceed established SLAs/objectives. Develop and implement strategies to streamline incident response processes and improve resolution times. Conduct comprehensive analysis of system security and application logs to diagnose intricate faults identify subtle abnormal behaviors and refine false positive reduction techniques. Leverage advanced tools and techniques for sophisticated threat detection and analysis. Utilize and optimize a broad range of VC3 and client toolsets including advanced End Detection and Response (EDR) tools for in-depth investigation of alerts anomalies and building accurate timelines related to potential security compromises. Formulate and execute strategic approaches for investigating escalating containing and eradicating sophisticated malicious activities. Develop deliver and present detailed written and oral reports to clients teammates and management focusing on security trends metrics and strategic recommendations. Provide strategic input and recommendations for improving internal processes procedures and security practices based on industry trends and operational experience. Lead threat hunting activities and oversee special projects employing advanced methodologies to proactively identify and mitigate potential threats. Additional Responsibilities Advocate for and lead the adoption of innovative security solutions and methodologies within the organization. Collaborate with internal stakeholders to address changes in technologies practices and business activities that may impact security. Facilitate cross-departmental initiatives to enhance client security and mitigate threats. Maintain and update comprehensive documentation related to security operations threat analysis and incident management. Ensure timely and accurate communication with clients and internal teams reflecting changes and new findings effectively. Mentor and guide Security Analyst I team members providing support and sharing expertise to enhance their skills and knowledge. Lead by example in adhering to security best practices and take ownership of complex security issues leading escalation efforts to senior resources or specialized teams. Engage actively in team huddles L10 meetings and other collaboratively structured meetings. Review Tickets with Manager Attend company-based meetings as required Participate in the on-call rotation (1 week every ~ 1.5-2 months) Additional duties as required Skills Knowledge and Expertise Five or more years of work experience in information security risk management or related fields. One of the following certifications preferred CompTIA Security+ CompTIA CySA+ CCNA CEH SSCP or equivalent Advanced certifications such as Certified Information Systems Security Professional (CISSP) Certified Ethical Hacker (CEH) Certified Information Security Manager (CISM) Certified Information Systems Auditor (CISA) or Certified Risk & Information Security Controls (CRISC) are highly desirable. Practical knowledge of security technologies and tools including Firewalls IDS/IPS SIEM Identity and Access Management (IAM) remote working solutions and cloud technologies. Understanding of current and emerging threats countermeasures and organizational challenges in addressing these threats. Awareness of information security management frameworks and industry regulations (e.g. NIST ISO 27001 GDPR). Strong problem-solving and decision-making abilities with a capacity to analyze complex issues and develop effective solutions. Excellent verbal and written communication skills with the ability to present complex technical issues in a clear and simple format. Self-motivated detail orientated highly organized and able to handle a variety of tasks and responsibilities in an efficient manner with a high level of quality Demonstrates effective communication skills both written and verbal Shows the ability to adapt and thrive in ambiguous or uncertain situations quickly assessing and navigating challenges. Additional Information You Will Want To Know Applicant selected will be subject to a criminal and department of motor vehicles background checks and must meet Criminal Justice Information Systems (CJIS) requirements post-employment Minimal travel required VC3 offers a comprehensive benefit package and 401K/RRSP company matching Thank you for your interest in VC3. We appreciate all applications however only those candidates selected for an interview will be contacted. About VC3 Inc. VC3 offers Managed IT Services Private Cloud Services Hosted VoIP Custom Web Applications SharePoint Consulting and Website Design & Hosting. VC3 has more than 25 years of experience providing a full range of Information Technology Solutions and Services to hundreds of municipalities and organizations throughout the United States and Canada. The technologies needed by our customers have changed many times over the years but our focus has always stayed the same connect the best technologies with our experienced and talented engineers programmers web designers and support specialists to deliver solutions that take our customers to the next level of productivity and results. We pride ourselves on making IT personal making IT easy and getting IT right. And it all starts with our talented team that is committed to raising the bar. Apply Now Not quite right? Register your interest to be notified of any roles that come along that meet your criteria. Register Your Interest Apply Now Department Technology Operations Employment Type Full Time Location Canada - Remote Workplace type Fully remote View all opportunities at VC3 Inc. Apply Now

GRC – ITGC(General Control) SME

New York, NY

Cybersecurity Audit & Compliance Specialist About The Role As a Cybersecurity Audit & Compliance Specialist you will make an impact by supporting global cybersecurity audit compliance certification and governance initiatives across the organization. You will be a valued member of the Cybersecurity and Risk Management team and work collaboratively with Information Security Legal Vendor Management IT Internal Audit and business stakeholders to ensure compliance with industry standards regulatory requirements and corporate security policies. In this role you will help strengthen the organization's security posture through audit readiness certification management compliance monitoring and continuous improvement initiatives while supporting global information security frameworks and standards. In This Role You Will Support cybersecurity audit and compliance initiatives including ISO 27001 certification ENS certification and other global information security standards and regulatory requirements. Prepare the organization for internal and external security audits by coordinating audit activities tracking deliverables and ensuring timely completion of remediation efforts. Partner with cross-functional teams external auditors advisors and vendors to collect validate organize and present audit evidence and compliance documentation. Conduct compliance reviews gap assessments and remediation tracking to identify and address deficiencies against applicable security frameworks and policies. Review information security requirements within vendor and customer contracts and provide guidance to ensure alignment with corporate cybersecurity standards and controls. Work Model We strive to provide flexibility wherever possible. Based on this role's business requirements this is a remote position open to qualified applicants in the United States . Regardless of your working arrangement we are here to support a healthy work-life balance through our various wellbeing programs. The working arrangements for this role are accurate as of the date of posting. This may change based on the project you're engaged in as well as business and client requirements. Rest assured we will always be clear about role expectations. What You Need to Have to Be Considered Bachelor's degree in Cybersecurity Information Technology Information Systems Business Administration Risk Management or a related field or equivalent professional experience. Experience supporting cybersecurity audits compliance programs regulatory assessments or certification initiatives. Knowledge of ISO 27001 requirements controls risk management principles and certification processes. Experience conducting compliance assessments gap analyses evidence collection and remediation tracking activities. Strong understanding of information security governance policies standards and audit methodologies. Experience managing audit documentation compliance records and evidence repositories. Ability to coordinate multiple projects and compliance initiatives while meeting deadlines. Strong stakeholder management skills with experience collaborating across technical and business teams. Excellent written and verbal communication skills with exceptional attention to detail. Strong analytical organizational and problem-solving abilities. These Will Help You Stand Out Experience supporting ISO 27001 certification or recertification efforts. Knowledge of ENS (Esquema Nacional de Seguridad) requirements and other global cybersecurity compliance frameworks. Experience working with third-party risk management vendor security reviews and contract security assessments. Familiarity with NIST Cybersecurity Framework SOC 2 CIS Controls GDPR or other regulatory and security frameworks. Experience managing corrective action plans and compliance remediation programs. Professional certifications such as CISA CRISC CISM ISO 27001 Lead Implementer ISO 27001 Lead Auditor or similar credentials. Knowledge of cybersecurity risk assessments security governance and control testing methodologies. Experience supporting global audit and compliance programs within large enterprise environments. We're excited to meet people who share our mission and can make an impact in a variety of ways. Don't hesitate to apply even if you only meet the minimum requirements listed. Think about your transferable experiences and unique skills that make you stand out as someone who can bring new and exciting things to this role. Salary And Other Compensation The annual salary for this position is anticipated to be between $95000 and $135000 depending on experience qualifications geographic location skills and other job-related factors. This position is also eligible for Cognizant's discretionary annual incentive program based on performance and subject to the terms of Cognizant's applicable plans. Benefits Cognizant offers a comprehensive and competitive benefits package designed to support the health wellbeing and financial security of our associates and their families including Medical dental and vision insurance Health Savings Account (HSA) and Flexible Spending Accounts (FSA) where applicable Company-paid life insurance and disability coverage 401(k) retirement savings plan with company contributions subject to plan provisions Paid time off company holidays and leave programs Employee Assistance Program (EAP) Wellbeing and mental health resources Professional development training and certification opportunities Career growth and internal mobility programs Associate recognition and reward programs Benefits may vary by location and employment status and are subject to change. Application Deadline Applications will be accepted until September 30 2026 . Cognizant reserves the right to close this posting earlier based on application volume business needs or hiring timelines.

Security Operations & GRC Lead

Founding Security Operations & GRC Lead A newly established fintech and trust bank focused on digital payments and digital asset infrastructure. Location Remote U.S.-Based Employment Type Full-Time Compensation $150000–$200000 Base Salary (Depending on Experience) Position Overview The Founding Security Operations & GRC Lead will serve as the internal owner of security operations execution and governance activities across cloud infrastructure enterprise technology product platforms and third-party vendors. The organization leverages specialized security infrastructure compliance and advisory partners for implementation and monitoring activities however internal ownership of security findings remediation tracking risk management control evidence and examination readiness remains critical. This role is ideal for someone with experience in security operations cloud security security governance technology risk management audit support or security compliance within regulated industries. Key Responsibilities Security Operations Manage day-to-day security operations across cloud product vendor and enterprise technology environments. Monitor and coordinate remediation of security findings from security tools cloud monitoring services and third-party assessments. Review triage prioritize track and escalate security alerts and security-related issues. Coordinate security incident response activities including investigation support escalation evidence preservation communications and post-incident review. Cloud Security Support cloud-security posture management within AWS environments. Oversee security controls related to IAM CloudTrail AWS Config Security Hub GuardDuty Inspector Macie KMS Secrets Manager WAF Backup and recovery controls Maintain cloud-security documentation and evidence for audits and examinations. Governance Risk & Compliance (GRC) Maintain security control documentation audit evidence risk registers and security exception records. Support access governance activities including user access reviews privileged access certifications and joiner/mover/leaver processes. Prepare and organize security evidence for internal audits external audits regulatory examinations and third-party reviews. Assist with ongoing compliance and examination-readiness initiatives. Vendor Risk & Oversight Coordinate security oversight activities involving critical third-party providers and security partners. Review vendor security documentation assessment results penetration-test reports and remediation plans. Track vendor-related security issues and follow up on corrective actions. Secure Development & Vulnerability Management Partner with engineering and platform teams to support secure SDLC controls. Coordinate remediation activities for findings from Vulnerability assessments Penetration tests Code reviews SAST tools Dependency scans Secrets scanning Container security reviews Track remediation progress and ensure timely closure of identified risks. Regulatory & Examination Readiness Maintain organized accurate and examination-ready security evidence. Support regulatory readiness activities and ensure security controls remain properly documented and defensible. Provide regular updates to leadership regarding security risks incidents remediation efforts and control effectiveness. Qualifications Required 7 + years of experience in one or more of the following areas Security Operations Cloud Security Information Security Technology Risk Incident Response Vulnerability Management GRC / Security Compliance Experience supporting security programs in regulated or audit-sensitive environments. Strong understanding of Incident response Alert triage Access reviews Vulnerability management Risk remediation Security control documentation Hands-on experience with AWS security services and cloud-security operations. Experience working with SIEM MDR EDR vulnerability management identity management and ticketing platforms. Ability to coordinate effectively across technical teams business stakeholders and external partners. Strong documentation communication and organizational skills. Preferred Experience within Banking Fintech Payments Trust companies Financial services Digital asset or custody environments Familiarity with OCC examination readiness FFIEC guidance NIST CSF NIST 800-53 SOC 2 GLBA CIS Controls Experience supporting AWS multi-account cloud environments. Exposure to digital assets blockchain stablecoins wallets custody platforms or regulated payment systems. Experience supporting Microsoft 365 endpoint security identity governance EDR or SASE technologies. Professional certifications such as CISSP CISM CISA CCSP AWS Security Specialty GIAC Security+ What Makes This Opportunity Unique Founding-level security leadership role with significant visibility and impact Opportunity to help build security operations and governance programs from the ground up Direct interaction with executive leadership including CTO/CISO Exposure to regulatory cloud-security vendor-risk and audit-readiness initiatives Collaborative environment supported by specialized security and compliance partners Remote work flexibility within the United States Interested candidates should possess a hands-on approach strong ownership mentality and the ability to thrive in a fast-paced high-growth environment where security compliance and operational excellence are critical to success. To apply please email your resume to xjiang@pasona.com

Technical Security Risk Consultant

Senior Technical Security Risk Consultant Location Remote with occasional UK travel Contract Type Permanent & Full-time Security Clearance Active SC clearance required Salary Competitive + Benefits About the Role As a Technical Cyber Risk Consultant you will work closely with clients across government defence and regulated sectors. You will operate as a trusted advisor working alongside senior stakeholders and technical teams to deliver pragmatic risk-led outcomes. Key Responsibilities Provide expert advice on cyber risk management frameworks including ISO 27005 and NIST RMF Lead risk identification assessment and treatment across applications infrastructure and digital services Facilitate structured risk workshops and threat modelling sessions Assess solution architectures to identify security risks and control gaps Review and interpret IT Health Check outputs and define clear remediation plans Produce concise reporting on risks vulnerabilities and treatment options Maintain and manage risk registers including residual risk position Conduct gap analysis against recognised security frameworks Evaluate third party suppliers and assess control effectiveness Produce audit reports controls assessments and security briefings Work with delivery teams to ensure security is embedded throughout Experience Required This role is aligned to a technically credible and delivery focused consultant / cyber risk practioner with an emphasis on real world risk assessment not theory. Success will come from strong judgement hands-on experience and the ability to operate effectively in a clearance constrained stakeholder heavy environment. Proven experience as a technical cyber risk practitioner not purely advisory Strong technical background with hands-on delivery of system level risk assessments across infrastructure applications and cloud environments Demonstrable experience identifying assessing and treating risk within live systems not just framework alignment Experience operating in secure and regulated environments ideally government or defence Proven ability to engage senior stakeholders and influence decisions Ability to translate technical findings into clear actionable risk outcomes Confident leading risk workshops threat modelling and control assessments Experience working within Agile delivery environments Strong analytical capability and sound judgement Any candidates must have an active SC level of security clearance to be considered. Technical Knowledge Security frameworks including ISO 27001 NIST CSF CIS and NCSC guidance Regulatory landscape including GDPR and PCI DSS Familiarity with HMG and NCSC standards Modern technology environments Cloud platforms such as Azure AWS and Google Cloud Microsoft 365 Infrastructure and network security Zero Trust principles Understanding of security architecture concepts Certifications Relevant industry certifications such as CISSP CISM CRISC or equivalent. Candidates should either hold or be working towards Full Membership of CIISEC and professional registration with the UK Cyber Security Council at Chartered or Principal level in Cyber Security Governance and Risk Management. What’s in it for You Exposure to complex high impact work in high trust environments Direct engagement with senior client stakeholders Opportunity to shape risk led security decisions Ongoing professional development Flexible working / Remote first Interested? Submit your application to learn more about this exciting opportunity.

Cybersecurity Program Manager - Remote

Halifax, Nova Scotia, Canada

Req ID 387731 NTT DATA strives to hire exceptional innovative and passionate individuals who want to grow with us. If you want to be part of an inclusive adaptable and forward-thinking organization apply now. We are currently seeking a Cybersecurity Program Manager - Remote to join our team in Halifax Nova Scotia (CA-NS) Canada (CA). Cybersecurity Program Manager Position Overview We are seeking an experienced Cybersecurity Program Manager to lead complex security transformation initiatives across a large enterprise environment. This role will oversee cross-functional cybersecurity programs coordinate multiple Agile teams and ensure security initiatives are delivered against business priorities risk objectives and enterprise security standards. The ideal candidate combines strong program management experience with hands-on cybersecurity delivery expertise and is comfortable working across security technology product risk compliance and executive stakeholders. This is an opportunity to lead high-visibility cybersecurity initiatives in a scaled Agile environment using tools such as Jira and Jira Align and applying frameworks including NIST ISO 27001 CIS Controls and Lean Portfolio Management. What You’ll Do Lead Cybersecurity Programs Lead end-to-end delivery of complex cybersecurity programs and strategic security initiatives. Manage cross-functional teams across cybersecurity infrastructure cloud applications risk compliance and business functions. Ensure programs are aligned with enterprise security strategy business objectives risk priorities and regulatory requirements. Manage program scope timelines dependencies budgets risks issues and delivery outcomes. Drive accountability across teams and ensure commitments are met. Drive Agile & Scaled Delivery Lead cybersecurity initiatives using Agile methodologies including Scrum SAFe and Kanban. Coordinate delivery across multiple Agile teams and where applicable Agile Release Trains. Use Jira and Jira Align to manage roadmaps backlogs dependencies milestones and program reporting. Partner with Product Owners Scrum Masters architects and technical leads to prioritize work and remove delivery impediments. Apply Lean Portfolio Management (LPM) principles to connect cybersecurity investments with measurable business and risk outcomes. Drive value-stream identification mapping optimization and continuous improvement. Lead Security Transformation Initiatives Manage large-scale cybersecurity programs such as + Identity & Access Management (IAM) + Zero Trust + Security Operations / SOC modernization + Cloud security + DevSecOps + Secure SDLC + Vulnerability and risk management + Security compliance and continuous monitoring Develop and maintain a forward-looking cybersecurity roadmap aligned with enterprise strategy. Identify opportunities to improve security capabilities processes technology and operational maturity. Ensure security initiatives deliver measurable risk reduction and business value. Risk Compliance & Governance Ensure program delivery aligns with enterprise security policies standards and regulatory requirements. Apply cybersecurity frameworks and standards such as NIST CSF CIS Controls and ISO 27001. Support compliance requirements including HIPAA PCI-DSS SOX and other applicable regulations. Identify track and escalate cybersecurity risks issues dependencies and control gaps. Establish effective governance and reporting mechanisms across programs. Executive & Stakeholder Management Provide clear program status KPI risk financial and roadmap reporting to senior leadership and steering committees. Translate complex cybersecurity issues into clear business impacts and actionable recommendations. Build strong relationships with security leaders technology executives business stakeholders product teams and third-party partners. Facilitate program governance meetings executive reviews planning sessions and strategic roadmap discussions. Proactively identify issues and drive resolution before they impact business outcomes. Vendor & Third-Party Management Manage cybersecurity vendors and third-party delivery partners. Coordinate third-party risk management activities and ensure vendor commitments align with program objectives. Track vendor performance dependencies deliverables risks and escalations. Required Qualifications 7+ years of experience in program or project management. 3+ years of cybersecurity program delivery experience. 3+ years managing large-scale cybersecurity initiatives such as IAM Zero Trust SOC modernization cloud security DevSecOps or similar programs. 3+ years of experience working in Agile environments including Scrum SAFe and/or Kanban. 2+ years of hands-on experience with Jira and Jira Align for program planning tracking dependency management and reporting. 3+ years of experience with value-stream management or scaled Agile delivery. Strong understanding of cybersecurity frameworks including NIST CSF CIS Controls and ISO 27001. Experience managing complex cross-functional programs involving multiple technology and business teams. Strong understanding of cybersecurity risk governance compliance and enterprise security practices. Excellent communication leadership facilitation and stakeholder management skills. Ability to communicate effectively with both technical teams and senior executives. Education Bachelor’s degree in Computer Science Cybersecurity Information Security or a related discipline or equivalent professional experience. Preferred Qualifications Certifications such as PMP SAFe SPC CSM CISSP or CISM. Experience with DevSecOps secure SDLC continuous compliance or security automation. Experience working in regulated industries such as financial services healthcare government or other highly regulated environments. Consulting or professional services experience with strong client-facing and executive stakeholder engagement. Experience managing enterprise security technology implementations across cloud infrastructure applications and identity environments. Strong understanding of networking and network security concepts. Experience applying globally recognized cybersecurity standards and frameworks. Experience with cybersecurity transformation maturity improvement or enterprise security roadmap development. Why This Role? This is an opportunity to lead high-impact cybersecurity transformation programs in a complex enterprise environment. You’ll work across security technology product risk and business teams while helping shape the organization’s security roadmap and delivery model. The successful candidate will bring a combination of program leadership cybersecurity expertise Agile delivery experience and executive communication skills to drive measurable improvements in security risk reduction compliance and business resilience. Pay Transparency Where required by law NTT DATA provides a reasonable range of compensation for specific roles. The starting pay range for this remote role is $95910 -$146905. This range reflects the minimum and maximum target compensation for the position across all US locations. Actual compensation will depend on a number of factors including the candidate’s actual work location relevant experience technical skills and other qualifications. This position is eligible for company benefits including medical dental and vision insurance with an employer contribution flexible spending or health savings account life and AD&D insurance short- and long-term disability coverage paid time off employee assistance participation in a 401k program with company match and additional voluntary or legally-required benefits. About NTT DATA NTT DATA is a $30+ billion business and technology services leader serving 75% of the Fortune Global 100. We are committed to accelerating client success and positively impacting society through responsible innovation. We are one of the world’s leading AI and digital infrastructure providers with unmatched capabilities in enterprise-scale AI cloud security connectivity data centers and application services. Our consulting and industry solutions help organizations and society move confidently and sustainably into the digital future. As a Global Top Employer we have experts in more than 50 countries. We also offer clients access to a robust ecosystem of innovation centers as well as established and start-up partners. NTT DATA is part of NTT Group which invests over $3 billion each year in R&D. Whenever possible we hire locally to NTT DATA offices or client sites. This ensures we can provide timely and effective support tailored to each client’s needs. While many positions offer remote or hybrid work options these arrangements are subject to change based on client requirements. For employees near an NTT DATA office or client site in-office attendance may be required for meetings or events depending on business needs. At NTT DATA we are committed to staying flexible and meeting the evolving needs of both our clients and employees. NTT DATA recruiters will never ask for payment or banking information and will only use @nttdata.com and @talent.nttdataservices.com email addresses. If you are requested to provide payment or disclose banking information please submit a contact us form https//us.nttdata.com/en/contact-us. NTT DATA endeavors to make https//us.nttdata.com accessible to any and all users. If you would like to contact us regarding the accessibility of our website or need assistance completing the application process please contact us at https//us.nttdata.com/en/contact-us . This contact information is for accommodation requests only and cannot be used to inquire about the status of applications. NTT DATA is an equal opportunity employer. Qualified applicants will receive consideration for employment without regard to race color religion sex sexual orientation gender identity national origin disability or protected veteran status. For our EEO Policy Statement please click here . If you'd like more information on your EEO rights under the law please click here . For Pay Transparency information please click here .

Presales Solutions Engineer - Endpoint Security

Texas, United States

About Us Since 1989 SHI International Corp. has helped organizations change the world through technology. We’ve grown every year since and today we’re proud to be a $16 billion global provider of IT solutions and services. Over 17000 Organizations Worldwide Rely On SHI’s Concierge Approach To Help Them Solve What’s Next. But The Heartbeat Of SHI Is Our Employees – All 7000 Of Them. If You Join Our Team You’ll Enjoy Our commitment to diversity as the largest minority- and woman-owned enterprise in the U.S. Continuous professional growth and leadership opportunities. Health wellness and financial benefits to offer peace of mind to you and your family. World-class facilities and the technology you need to thrive – in our offices or yours. Job Summary The Presales Solutions Engineer – Security will be a customer-facing endpoint security expert. They will take a consultative approach to security projects and have a holistic understanding of how security technology enables business.  The Solutions Engineer will also develop and deliver new security services offerings to address customer requests/opportunities. This remote position may be required to report to the office in Austin Texas as required for business needs and as determined by SHI management. Role Description Collaboration  with multiple layers of contacts within client organizations including but not limited to CIO CSO CISO Security Engineers and procurement to strengthen our overall customer relationship and better understand the goals and objectives they are trying to achieve Understand the company’s service offerings in all solution practice areas by attending company training and expanding knowledge through self-study Educate sales teams on cybersecurity solution selling and key technologies through 1x1 team and company training Staying current on new technology trends and market behavior by studying market trends and the industry landscape Engaging in self-study and independent work in lab facilities to increase job-related knowledge and skills Developing collateral to assist with cybersecurity sales engagements Developing use cases in the SHI lab to support sales engagements Behaviors and Competencies Presenting Can design and deliver engaging presentations adapting the content and style to suit the audience context and medium. Negotiation Can proactively seek out negotiation opportunities initiate discussions and contribute to conflict resolution. Communication Can effectively communicate complex ideas and information to diverse audiences and can facilitate effective communication between others. Detail-Oriented Can manage complex tasks or projects identifying errors or inconsistencies and ensuring all details are addressed necessary corrections are made and quality is maintained. Organization Can effectively coordinate multiple projects delegate tasks where appropriate and employ advanced organizational tools and methods. Follow-Up Can proactively identify tasks that require follow-up initiate necessary actions and contribute to efficient workflow management. Problem-Solving Can proactively identify potential problems initiate preventive measures and propose and contribute to innovative solutions. Relationship Building Can proactively seek out opportunities to expand networks initiate collaborations and contribute to team cohesion. Documentation Can develop comprehensive documentation standards implement best practices and ensure documentation supports operational efficiency. Results Orientation Can set challenging goals for their team and lead them to achieve these goals demonstrating a consistent track record of results. Skill Level Requirements Experience and understanding of security frameworks such as NIST HITRUST CIS etc. - Intermediate Strong technical endpoint security knowledge including but not limited to EDR EPP XDR and other endpoint-related security controls. - Intermediate Ability to effectively communicate and sell complex technical products or services by understanding customer needs articulating the value proposition and providing technical expertise to support the sales process - Intermediate Other Requirements Completed Bachelor’s Degree or relevant work experience required 5+ years experience in a technical cybersecurity role 3+ years experience in Security Pre-Sales Consulting Advanced certification in one or more of the following mainstream technologies preferred CISSP Relevant GIAC Cert SSCP CISM CCSP CEH CPT CWSP CCNP Security CCIE Security or Relevant Professional certifications in Cyber Security OEMs Travel to client locations required up to 20% for customer meetings internal meetings or engagements travel to customer or partner sites conferences and SHI offices Extended hours are required to complete some special projects The estimated annual pay range for this position is $120000 - $230000 which includes a base salary and bonus. The compensation for this position is dependent on job-related knowledge skills experience and market location and therefore will vary from individual to individual. Benefits may include but are not limited to medical vision dental 401K and flexible spending. Equal Employment Opportunity – M/F/Disability/Protected Veteran Status

unlock: sign-up for free / login and use the searches from your home page
🔥 job listings updated in real time


For the 10 positions listed above we've analyzed the salary ranges, where available, and the resulting overall salary range is: 95.91K - 230K USD.

For 56 similar CISM position(s) we've listed yesterday we've checked the salary ranges, as posted, and the resulting overall range is: 87.12K - 432K USD.

For 1,503 similar CISM position(s) we've listed in the previous 30 days we've processed the salary ranges data as posted by employers in job descriptions and the resulting overall range is: 40K - 650K USD.

View highest-paying job

Note: If any discrepancies or 'wild' numbers appear this could be because of: typos in job postings, data source errors, ghost jobs, etc. We do not modify salary data inserted in JDs by employers nor use estimates.


Login & search by other job titles, a specific location or any keyword.
Additional custom search filters are available once you login.