Jobbörse
Finde Jobs in deiner Nähe – ob vor Ort, hybrid oder remote.- Ähnliche Jobs zu: Director, Security Compliance
Senior Security Analyst, Compliance
OpenSesameNew YorkOpenSesame is the trusted partner for Workforce Reinvention in the age of AI. OpenSesame delivers integrated software, curated and customizable content, and expert services – embedded into existing le
IT Compliance & Product Security Analyst
01 & 04 Woodward, Inc.Fort CollinsKey Responsibilities Creates and updates IT compliance and product security policies to align with regulations and best practices. Leads the Review Board for open‑source compliance. Tracks and analyze
IT Compliance & Product Security Analyst
Woodward HRT/MPCFort CollinsWoodward supports our members' wellbeing and regularly benchmarks with other companies in our industry to offer an extensive Total Reward package for this position. Salary will be determined by the ap
Industrial Security Analyst: Secure Facilities & Compliance
Minnesota JobsMinneapolisNorthrop Grumman is looking for an Industrial Security Analyst based in Plymouth, MN. This role involves developing and managing physical security programs and ensuring compliance with federal regulat
Cyber-Compliance & Product Security Analyst
WoodwardNilesWoodward, Inc. is seeking a candidate for an IT compliance role that involves creating policies and ensuring adherence to regulations. This position entails audits of IT systems and advising on cyber-
Cyber-Compliance & Product Security Analyst
Woodward HRT/MPCRockfordWoodward HRT/MPC in Rockford, Illinois is looking for a qualified candidate to develop and manage IT compliance and product security policies. This role involves conducting audits, advising on securit
Cyber-Compliance & Product Security Analyst
WoodwardRockfordWoodward, Inc. is seeking a candidate for an IT compliance role in Rockford, Illinois. The position focuses on creating policies and ensuring product security compliance with regulations. Candidates s
Cyber-Compliance & Product Security Analyst
WoodwardFort CollinsWoodward, Inc. is seeking a compliance and product security expert to create policies and ensure regulatory adherence. This role involves auditing IT systems, advising on security development, and fac
Global Cyber Security & Compliance Manager
FikeBlue SpringsFike Corporation is seeking a Cyber Security Manager responsible for developing and administering the company's cyber security program. The role requires overseeing compliance with NIST standards and
RMF & Cyber Security Compliance Engineer
LaunchTechColorado SpringsLaunchTech, located at Schriever Space Force Base, is seeking a Cyber Security Compliance & Integration Engineer. This role focuses on supporting the Missile Defense Agency's needs while ensuring comp
Remote GRC Security Analyst - Risk & Compliance
LaunchDarkly GroupNew YorkLaunchDarkly Group is seeking a Security Analyst III for its Governance, Risk, and Compliance team. This remote role demands deep cybersecurity knowledge and excellent communication skills. You will c
Remote QA Tester - Compliance & Security Focus
kozmetickesluzby.vecnakraska.sk - JobboardNew YorkInformation Technology Strategies, Inc., a provider of IT solutions for government initiatives, is hiring a remote QA Tester. The chosen candidate will design and execute software tests ensuring compl
Security Analyst (CIP Compliance) Oaks, PA
JPC PartnersNew YorkJPC Partners is looking for a Security Analyst. The Security Analyst will work with the Critical Infrastructure Protection (CIP) Compliance Department that is responsible for assisting in the developm
Information Security Analyst - Cyber Defense & Compliance
The University of Texas Rio Grande ValleyEdinburgThe University of Texas Rio Grande Valley is seeking an Information Security Analyst to assist with the development and support of digital access control and data confidentiality measures. Candidates
Industrial Security Analyst I: Compliance & Audits
Huntington Ingalls IndustriesNewport NewsHuntington Ingalls Industries, Inc. in Newport News, Virginia, is seeking a security professional to develop and administer security programs for classified materials. The role also involves implement
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosHyattsvilleDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosLaurelDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosSpringfieldDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosAlexandriaDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosUpper MarlboroDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Systems Engineer – Microsoft 365 Security & Compliance / Endpoint Security Engineer (GCC)
LeidosRiverdaleDescription Leidos is seeking an experienced M365 Security and Compliance Administrator to join our Information Technology team. This role requires a seasoned professional who can strategically manag
Senior Windows Systems Administrator - Security & Compliance
Koitecc SolutionsDetroitKoitecc Solutions is seeking a Senior Windows System Administrator in Detroit, Michigan, to provide support and administration for the CAA and Army Contracting Command. The role requires expertise in
Security Analyst: Incident Response & Compliance Pro
VertilocityEnglewoodVertilocity, located in Englewood, CO, is looking for a Security Analyst to help protect our client's systems and data from cyber threats. The successful candidate will have a strong background in IT
Data Scientist, AWS Compliance & Security Assurance
AmazonUnited StatesThe AWS Compliance & Security Assurance Engineering team builds tools and services that scale AWS's ability to exceed security and compliance expectations for our regulators, auditors, and customers g
SaaS Security Analyst - Cloud, Risk & Compliance
Tata Consultancy Services LimitedPhoenixTata Consultancy Services Limited is looking for a professional in Phoenix, Arizona with a strong background in cloud security to drive risk assessments on Third-Party SaaS providers. The candidate wi
Senior Security Analyst, Compliance
- New York, New York, United States
- New York, New York, United States
Über
As a Senior Security Analyst on our Compliance team, you will play a key role in strengthening OpenSesame’s security posture in a fast-moving, high-growth environment. We’re looking for someone who brings deep technical security expertise, a proactive mindset, and the ability to turn complex risks into practical, scalable solutions.
This role spans vulnerability management, penetration testing, bug bounty operations, cloud and application security, and audit readiness. You’ll partner across Engineering, DevOps, IT, and Compliance to improve security processes, support compliance efforts, and help ensure security is built into how we work, especially as we continue evolving our approach to AI security. We’re looking for proven examples from your career that show you can do this job; that you’ve owned penetration testing programs, built vulnerability management systems, implemented security automation, and helped organizations adopt modern technologies (including AI) securely and responsibly.
You’ll be a strong fit if you’re detail-oriented, collaborative, and excited to build programs that reduce risk, improve visibility, and support safe innovation across the business.
Performance Objectives Establish Security Ownership & Technical Depth (0–6 Months)
Develop a comprehensive view of OpenSesame’s external attack surface, vulnerabilities, and threat landscape — integrating signals from CrowdStrike, cloud environments (AWS, GCP), and application security tooling.
Own external penetration testing engagements end-to-end — including vendor selection, scope design, execution oversight, remediation validation, and executive reporting.
Build and operationalize a structured vulnerability management program — partnering with DevOps, Engineering, and IT to prioritize and remediate risk effectively.
Stand up scalable evidence collection and control mapping workflows in Drata — improving audit readiness and reducing manual effort.
Establish strong cross-functional relationships to embed security into engineering, infrastructure, and IT workflows from the outset.
Operationalize Continuous & AI-Aware Security (6–12 Months)
Design and implement a continuous penetration testing program that complements annual third-party testing — leveraging automation, threat modeling, and targeted validation.
Own and mature the bug bounty program — improving signal quality, triage processes, researcher engagement, and remediation workflows.
Lead implementation of AI security practices across internal systems and product development:
Apply OWASP Top 10 for LLMs / AI systems to identify and mitigate emerging risks
Support adoption and operationalization of ISO 42001 controls
Define secure usage patterns for internal AI tools and third-party AI integrations
Partner with Product Engineering to define and enforce secure AI and application baseline requirements — ensuring security is built into system design, not retrofitted.
Develop automations and tooling (Python, APIs, Make) to continuously collect threat intelligence, validate security baselines, and detect drift across AWS, GCP, GitHub, and SaaS platforms.
Improve Jira and Confluence workflows to create visibility, accountability, and measurable progress across security findings and remediation.
Provide deep technical support during audits — translating real-world implementations into clear, defensible narratives aligned with ISO 27001, ISO 27701, and ISO 42001.
Drive Security Maturity & Compliance Integration (12+ Months)
Serve as a senior technical partner to Compliance — supporting vendor reviews, customer security questionnaires, and control design with practical, implementation-level expertise.
Continuously improve Drata automation and evidence pipelines — moving toward near real-time compliance visibility.
Partner with Engineering and DevOps leadership to evolve secure development practices, CI/CD security controls, and cloud security baselines.
Establish and refine AI security governance models — balancing innovation with risk management across internal and customer-facing use cases.
Identify systemic risks, recurring vulnerability patterns, and process inefficiencies — driving durable, organization-wide improvements.
Contribute to long‑term security strategy — aligning threat management, AI adoption, compliance requirements, and engineering velocity.
What Success Looks Like
Penetration testing (external and continuous) is predictable, effective, and drives measurable reductions in risk.
Vulnerabilities are prioritized intelligently and remediated within defined SLAs, with clear ownership across teams.
The bug bounty program consistently yields high‑quality findings with efficient triage and response.
AI systems and tools are deployed with clear security guardrails aligned to OWASP AI Top 10 and ISO 42001.
Engineering teams proactively incorporate security — including AI security — into design and development workflows.
Audit readiness becomes continuous rather than event-driven, with strong evidence pipelines in Drata.
Security is viewed as a strategic enabler of safe innovation, not a bottleneck.
We’re looking for proven examples from your career that show you can do this job — that you’ve owned penetration testing programs, built vulnerability management systems, implemented security automation, and helped organizations adopt modern technologies (including AI) securely and responsibly.
Location This position can be based anywhere in the US. We operate as a remote‑first company, and invest in mandatory all‑company meetings several times a year in addition to required team travel as necessary.
Performance Driven We're looking for self‑starters with a track record of delivering excellent results, but we're highly selective about who we hire. We don't focus on typical job requirements, instead, we're interested in specific examples from your past experiences. All positions can be based anywhere in the US, and require up to 15 days of travel per year, with senior management and leadership teams requiring up to 35 days.
Compensation The base salary for this position generally ranges between $130,000 and $160,000, depending on experience. At OpenSesame, we offer a comprehensive benefits package to employees upon hire, including professional development, ISOs, health insurance, 401(k) matching, and paid time off.
Equal Employment Opportunity OpenSesame is an Equal Employment Opportunity and affirmative action employer that values and welcomes diversity. We do not discriminate on the basis of various legally protected characteristics, including criminal history, and strive to provide reasonable accommodations to qualified individuals with disabilities. We prioritize safety and security and may use your information accordingly, and you can contact us for assistance or accommodations during the job application process.
Pay Transparency At OpenSesame, we prioritize pay transparency, fairness, and equity to create a positive and inclusive work environment, regularly reviewing our compensation practices to align with our values and goals. We provide competitive and fair compensation to our employees based on their skills, experience, and performance.
CPRA (California Candidates) When you submit your application, OpenSesame may collect and use your personal information in accordance with our privacy policy and the CPRA. This may include personal details and employment history, and will only be used for employment‑related purposes. If you have any questions or concerns, please contact us, and for more information on your rights under the CPRA, refer to our privacy policy or the California Attorney General's website.
#J-18808-Ljbffr
Sprachkenntnisse
- English
Dieses Stellenangebot stammt von einer Partnerplattform von TieTalent. Klick auf „Jetzt Bewerben”, um deine Bewerbung direkt auf deren Website einzureichen.