Expoint – all jobs in one place
Finding the best job has never been easier

Information Security Manager jobs in United States, Virginia, Arlington

Unlock your potential in the high tech industry with Expoint. Search for job opportunities as a Information Security Manager in United States, Virginia, Arlington and join the network of leading companies. Start your journey today and find your dream job as a Information Security Manager with Expoint.
Company
Job type
Job categories
Job title (1)
United States
Virginia
Arlington
583 jobs found
09.12.2025
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
09.12.2025
EY

EY Government Public Sector - FAAS Senior Manager United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year. Direct field work, inform...
Description:

Our Government & Public Sector-Financial Accounting Advisory Services (GPS-FAAS) team is growing exponentially, and as a Senior Manager you'll play a key role in that growth. Working across all Federal GPS sector service lines, you'll develop your career by communicating creative, strategic goals both internally and externally. It's all about listening to and understanding our clients to give them a truly exceptional experience in a field where there really are no off-the-shelf recommendations.

Your key responsibilities

The nature of this role means no two projects will be the same. That means you'll need to think on your feet and challenge existing practices to develop answers to complex issues. You'll also be collaborating with colleagues across multiple service lines, so we'll look to you to build relationships and identify opportunities for our clients to benefit from our knowledge in other areas. Regular travel will be required as you will be meeting with key clients, some of those being the most respected in their fields.

Skills and attributes for success

  • Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Demonstrate a thorough understanding of complex accounting and auditing concepts and apply them to client situations
  • Develop people through effectively delegating audit tasks and providing guidance to assurance staff
  • Provide performance feedback, training and performance reviews for assurance staff
  • Contribute ideas/opinions to the assurance teams and listen/respond to other assurance team members' views
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Develop an understanding of EY's service lines and actively seek/encourage assurance team members to contribute ideas and identify opportunities to apply the firm's services

To qualify for the role you must have

  • A bachelor's degree in accounting, finance or business discipline, supported by 7 years of progressive post baccalaureate work experience with Federal US GAAP
  • U.S. CPA license in your work state
  • Excellent project management skills
  • Excellent communication and negotiation skills and a collaborative approach to management
  • A proven record of excellence when managing, mentoring and improving a team of high-performing colleagues
  • Dedication to teamwork and leadership
  • Integrity within a professional environment
  • The ability to obtain and maintain a security clearance
  • Due to the nature of our work in the Government and Public Sector, work may be required to be completed at client, EY and/or contractor sites. Our goal is to assign professionals to projects within a commutable distance of their work location office. In certain circumstances, travel may be required beyond your work location based on client and project needs. Candidates should be willing to travel on average 25% to 30% or more in a hybrid environment.

Ideally you’ll also have

  • CGFM and/or CDFM

What we look for

We're interested in versatile people with the ability to take on new responsibilities and listen to clients to get things done. We're not just looking for accounting and audit experience — we're after genuinely interesting people with the ability to build relationships, negotiate and think in unique and creative news ways. If you're a confident leader with a curious mind and the ability to solve complex issues, this role is for you.

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $145,200 to $331,800. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $174,300 to $337,000. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

08.12.2025
EY

EY Government Public Sector - Assurance Manager United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year. Direct field work, inform...
Description:

Our Government & Public Sector Assurance practice is growing exponentially, and as a manager, you'll play a key role in that growth. Together with our substantial investments in technology, knowledge, and learning resources on behalf of our audit professionals, this commitment will enable us to deliver quality assurance services to our clients and their stakeholders. While interacting with our clients, you'll develop your career by communicating and providing expertise around data integrity that can provide improved insight within the accounting, finance, governance, and regulatory space.

Your key responsibilities

The nature of this role means that you will be recognized as a primary day-to-day contact for our clients. That means you'll develop your knowledge by learning about current issues, profession, and business developments relevant to the client's industry, so we'll look to you to build relationships and manage teams.

Skills and attributes for success

  • Develop and maintain strong, productive working relationships with audit client personnel, assess audit clients' satisfaction and proactively maintain contact with the audit client throughout the year
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Demonstrate a thorough understanding of complex accounting and auditing concepts and apply them to client situations
  • Develop people through effectively delegating audit tasks and providing guidance to assurance staff
  • Provide performance feedback, training and performance reviews for assurance staff
  • Contribute ideas/opinions to the assurance teams and listen/respond to other assurance team members' views
  • Foster an efficient, innovative and team-oriented work environment
  • Use technology to continually learn, share knowledge with assurance team members and enhance service delivery
  • Direct field work, inform supervisors of the audit engagement status and manage assurance staff performance
  • Develop an understanding of EY's service lines and actively seek/encourage assurance team members to contribute ideas and identify opportunities to apply the firm's services

To qualify for the role you must have

  • A bachelor's degree an approximately 5 years of related work experience; or a graduate degree and approximately 4 years of related work experience, with approximately 2 years of audit experience with a public accounting firm
  • A degree in Accounting, Finance, or related field
  • U.S. CPA license
  • Must be able to obtain and maintain a secret clearance or higher.
  • Excellent project management skills; advanced written and verbal communication skills
  • Dedication to teamwork and leadership
  • Integrity within a processional environment
  • The EY Government and Public Sector Practice's staffing model is to assign resources to projects aligned to the office within the metropolitan area you have been hired; however, in certain circumstances, travel may be required within and/or beyond your geographic region based on client and project needs. For roles within the federal practice, the flexibility to travel up to approximately 30% is preferred. Within the state, local and education practice, the flexibility to travel up to approximately 80% is preferred.

Ideally you'll also have

  • CGFM and/or CDFM

What we look for

We're interested in versatile people with the ability to take on new responsibilities and listen to clients to get things done. We're not just looking for accounting and audit experience — we're after genuinely interesting people with the ability to build relationships, negotiate and think in unique and creative news ways. If you're a confident leader with a curious mind and the ability to solve complex issues, this role is for you.

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $97,200 to $178,200. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $116,700 to $202,500. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

08.12.2025
EY

EY GPS - Cyber Security Engineer Supervising Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Supporting the run state of our security technologies. Bringing operational expertise into efforts which introduce new technologies and upgrade current ones. Providing technical oversight of Information Security technologies that fall...
Description:

Our GPS Technology Organization is a structure within the US GPS practice that implements and maintains a new operate and technology model designed specifically to support U.S. defense and Government engagements.

As the Cyber Security Engineer, you’ll be part of our Security Engineering & Operations team. In this role you’ll be involved in leading and coordinating activities related to multi-functional security technologies for our US Government and Public Sector (GPS) Practice. You’ll also work with internal security teams including IAM and Cyber Defense to ensure the related systems are secure, robust and compliant. You’ll spend most of your time supporting the run state of our security technologies. The remainder of your time will be spent bringing operational expertise into efforts which introduce new technologies and upgrade current ones.

Your key responsibilities

  • Supporting the run state of our security technologies
  • Bringing operational expertise into efforts which introduce new technologies and upgrade current ones
  • Providing technical oversight of Information Security technologies that fall under the team’s responsibilities, confirming they are operating within agreed service levels, compliance specifications and at peak performance
  • Managing and coordinating planned maintenance activities as well as incidents for Information Security technologies
  • Representing the team in specific project activities, including leading projects and managing the activity of others towards successful completion
  • Articulating technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders
  • The role will likely be 100% remote and require <10% travel
  • Occasional weekend and off hours work to support the business. It will also require a rotational on-call schedule.

Skills and attributes for success

  • Operational experience in an environment of more than 3000 users
  • Perform detailed troubleshooting of issues, by using their analytical skills and collaborating with other technical teams, stakeholders and internal and external customers
  • Ability to work and solve issues independently, finding solutions to problems.
  • Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
  • Comfortable working remotely in a large, global virtual environment
  • Ability to react appropriately during stressful and ambiguous situations and communicate clearly to senior leadership when the situation requires
  • Strong problem solving, decision making and collaboration skills
  • Functional and/or technical experience in supporting security technologies including detailed knowledge of many of the following: Cloud Operations especially Azure, O365 Tenants, networking concepts & mechanisms, EDR, DLP, AV/AM, DNS, Encryption, E-Mail technologies including DMARC, DKIM, SMTP, TLS, EVM, SYSLOG, PKI, as well as a myriad of other related security and desktop technologies:
    • Azure networking and platform protection
    • Azure architectural design.
    • Diagnostic logging & log retention and complex logging solutions with varied vendors and environments.
    • Vulnerability and compliance scanning solutions and policies
    • Virtual networks and Network Security Groups
    • Application gateways and load balancing
    • Traffic Manager and Azure DDoS protection
    • Host Security and VM Hardening
    • Serverless Computing (Kubernetes)
    • Subscription security and policies
    • Azure resource policies and resource locks
    • Azure information protection
    • Access control and key management for storage accounts
  • Basic Scripting and Automation Skills
  • Experience with CI/CD pipelines deployment, DevSecOps and Policy as Code
  • Experience with Containers
  • Experience with WDAC

To qualify for the role, you must have

  • Bachelor’s degree in computer related field or equivalent work experience
  • At least 5 years of experience in managing Information Systems and Security, including demonstratable knowledge of the various platforms and interactions
  • Strong English language skills – written and verbal
  • Experience in training and coaching staff in technical processes and practices
  • Proven experience in configuration of the following Microsoft and Azure security services:
    • Microsoft Sentinel
    • Microsoft Defender XDR
      • Microsoft Defender for Endpoint
      • Microsoft Defender for O365
      • Microsoft Defender for Identity
      • Microsoft Defender for Cloud Apps
      • Microsoft Defender Vulnerability Management
      • Microsoft Defender for Cloud
      • Microsoft Entra ID Protection
      • Microsoft Data Loss Prevention (Purview)
      • App Governance
    • Microsoft O365 DLP
    • Microsoft Intune
    • Azure Monitor Log Analytics
    • Azure Firewall
    • Azure WAF
    • Azure EventHub
    • Azure Network Watcher
  • Eligible to obtain and maintain Top Secret Security Clearance

Ideally, you’ll also have

  • Experience with MS Exchange, O365,Azure, AWS, and GCP.
  • Advanced skills in troubleshooting cloud environments
  • General Knowledge of FedRAMP, NIST SP 800-53, and NIST SP 800-171 and other frameworks.
  • Federal Government experience, including CMMC Maturity Level 3
  • Strong ability to document processes, procedures and security controls clearly and accurately for distribution to internal teams and customers
  • GSEC/CISSP or other security related generalist certification from ISC2 or GIAC
  • Experience in incident, problem and change management
  • Certifications:
    • AZ-900: Azure Fundamentals
    • AZ-500: Azure Security Technologies
    • AZ-303: Azure Architect Technologies
    • SANS SEC401: Security Essentials - Network, Endpoint, and Cloud
    • SANS SEC 510, Public Cloud Security: AWS, Azure, and GCP
    • Sans SEC 540: Cloud Security and DevSecOps Automation

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $91,100 to $170,400. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $109,300 to $193,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

07.12.2025
EY

EY Manager - Tax Indirect Technology Platform Application Suppo... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Reproduce and resolve user-level defects in platform applications. Submit targeted hotfix pull requests (PRs) with appropriate test coverage. Coordinate with the Operations Lead Engineer to deploy releases and hotfixes. Debug...
Description:

Your key responsibilities

  • Reproduce and resolve user-level defects in platform applications.
  • Submit targeted hotfix pull requests (PRs) with appropriate test coverage.
  • Coordinate with the Operations Lead Engineer to deploy releases and hotfixes.
  • Debug application issues to identify root causes and prevent recurrence.
  • Act as a technical escalation point during high-pressure incidents.
  • Maintain close alignment with engineering teams to ensure support readiness and release quality.
  • Deliver high-quality work within expected timeframes and on budget.
  • Monitor progress, manage risk, and ensure key stakeholders are kept informed about progress and expected outcomes.
  • Work with various stakeholders to understand the business challenges and provide workarounds in case of challenges.

To qualify for this role, you must have

  • A bachelor's degree in technology, information systems, or computer science, and minimum of 6 years of related work experience; or a graduate degree and approximately 5 years of related work experience.
  • Approved certification
  • Strong hands-on technical skills equivalent to an Application Engineer.
  • Proven experience in debugging and resolving complex application issues.
  • Familiarity with release management and deployment coordination.
  • Ability to write and validate hotfix PRs with test cases.

Ideally, you will also have

  • Strong interest in learning generative AI and using AI technologies is preferred
  • Excellent prioritization, organizational, and stakeholder management skills.
  • Ability to manage pressure and respond effectively in high-stakes situations.
  • Strong communication skills, including the ability to interact with executive stakeholders.
  • Characteristics of a forward-thinker and self-motivator who adapts quickly to new challenges.
  • Experience working in hybrid environments and collaborating across distributed teams.
  • Experience managing personnel and participating in hiring processes.
  • Willingness to travel occasionally, as needed.

What we look for

  • We're interested in people who are ready to become part of a highly engaged, diverse, and dynamic team to help us continue to make a real difference to our clients. If you have an interest in leveraging technology to improve business processes and the ambition to go above and beyond expectations, this role is for you.

What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $86,600 to $197,800. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $103,900 to $224,700. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

18.11.2025
EY

EY GPS - Assistant Facility Security Officer Associate United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance. Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies,...
Description:

As Assistant Facility Security Officer (AFSO) you will be responsible for ensuring the protection of National Security Information in accordance with the National Industrial Security Program Operating Manual (NISPOM)/32 CFR Part 117. Responsibilities include program oversight, evaluations, and educating cleared employees on promulgated government and company initiatives, policies and procedures. The candidate will serve as the primary security liaison with government agencies, sponsor representatives and integrate security solutions across business portfolios.

Your key responsibilities

  • Oversee daily security operations and NISP/32 CFR Part 117 NISPOM compliance.
  • Maintain and mature the facility’s industrial security program for Department of Defense (DoD) elements in compliance with applicable policies, and established regulations.
  • Enforce procedures for accounting, controlling, transmitting, safeguarding, and destroying classified information.
  • Support a security education, training, and awareness program.
  • Support the FSO with preparing reports and presentations for all levels of Management.
  • Maintains data compliance in DISS, NISS, NBIS, SWFT and other system of records.
  • Maintain and update Standard Practices and Procedures (SPP) documentation.
  • Support and mature the NISP annual security self-inspection, coordinating with internal stakeholders and DCSA representatives.
  • Provide support for classified meetings, including coordination and visitor management (e.g., processing Visitor Approval Requests (VARs)).
  • Lead security incident investigations in accordance with EY policy, NISPOM/32 CFR Part 117, and DCSA guidelines, collaborating with internal and external stakeholders.
  • Analyze and validate security processes, procedures, and standards to ensure compliance, identify trends and root-causes and facilitate multi-disciplinary teams to address gaps.
  • Prepare, track, and maintain Prime and Subcontractor DD-254s forms to ensure accuracy of security requirements. Coordinate with applicable stakeholders to facilitate actions necessary to execute and update such documentation.
  • Demonstrate professionalism, independent engagement, and collaboration with peers and external personnel to ensure adherence to regulations and guidelines.
  • Exhibit strong decision-making, individual initiative, organizational skills, and the ability to function with minimal supervision.

Skills and attributes for success

  • The AFSO must be a strategic thinker who can exercise independent judgment and knowledge to manage risks, deliver Industrial security support and align security solutions with business needs.
  • Candidate will collaborate with Senior security staff, employees and government clients to meet objectives while ensuring EY security program remains effective, compliant with Defense Counterintelligence and Security Agency (DCSA) standards, and aligned with corporate security requirements
  • In addition to technical expertise and independent initiative, the ideal AFSO will demonstrate a collaborative spirit and the ability to work seamlessly within multidisciplinary teams. Strong interpersonal skills are essential, enabling the candidate to foster open communication, support colleagues in joint problem solving, and cultivate an environment of mutual respect and shared accountability. A commitment to partnership—both within the security staff and across business units—ensures robust information exchange, effective coordination, and unified progress toward security and organizational objectives.

To qualify for the role you must have

  • Bachelor’s degree (Criminal Justice preferred) or equivalent experience
  • Strong organizational and communications skills, and the ability to effectively interact with staff and customers at all levels.
  • Proficiency in Microsoft Office products is required, with particular emphasis on Microsoft Access for database management and Microsoft Copilot for workflow optimization and automation.
  • DCSA Center for Development of Security Excellence (CDSE) FSO Program Management for Possessing Facilities courses.
  • Ability to obtain and maintain a TS/SCI Fullscope polygraph clearance
  • This position has an on-site requirement of 5 days a week on-site in the Tysons, VA and Arlington, VA office locations

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $57,400 to $104,100. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $68,800 to $118,300. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

08.10.2025
EY

EY EY Parthenon - Deals Manager Multiple Positions United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next. Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful...
Description:

Full time employment, Monday – Friday, 40 hours per week, 8:30 am – 5:30 pm.

MINIMUM REQUIREMENTS:

Must have a Bachelor's degree in Accounting, Business, Finance or related field plus 5 years of progressive post-baccalaureate related work experience. Alternatively, will accept a Master’s degree in Accounting, Business, Finance or related field plus 3 years of related work experience.

Must have 3 years of combined experience conducting external audits, financial due diligence and/or tax due diligence experience with a public accounting or professional services firm.

Must have 2 years of combined experience supervising the planning, execution, reporting on audits and/or other due diligence of financial statements or taxes prepared in accordance with U.S. GAAS, U.S. GAAP and/or another foreign equivalent accepted accounting standard, such as IFRS.

Must have 2 years of combined experience supervising audit, financial due diligence and/or tax due diligence teams consisting of two or more staff members.

Requires domestic travel up to 50% in order to serve client needs.

Employer will accept any suitable combination of education, training, or experience.

What we offer

We offer a comprehensive compensation and benefits package where you’ll be rewarded based on yourperformance and recognized for the value you bring to the business. The base salary for this job is $138,120.00 per year. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


• Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
• Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
• Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
• Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
EY exists to build a better working world, helping to create long-term value for clients, people and society and build trust in the capital markets.


This particular position at Ernst & Young in the United States requires the qualified candidate to be a "United States worker" as defined by the U.S. Department of Labor regulations at 20 CFR 656.3. You can review this definition at at the bottom of page 750. Please feel free to apply to other positions that do not require you to be a "U.S. worker".

Show more

These jobs might be a good fit

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Must have government sector experience
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more
Find your next career move in the high tech industry with Expoint. Our platform offers a wide range of Information Security Manager job opportunities in the United States, Virginia, Arlington area, giving you access to the best companies in the field. Whether you're looking for a new challenge or a change of scenery, Expoint makes it easy to find your perfect job match. With our easy-to-use search engine, you can quickly find job opportunities in your desired location and connect with top companies. Sign up today and take the next step in your high tech career with Expoint.