Expoint – all jobs in one place
Finding the best job has never been easier

Information Security Consultant jobs

With Expoint, the dream vaccancy is waiting for you around the corner. Jobs as Information Security Consultant, is this the job you are looking for? We definitely have a Information Security Consultant job with your name on it.
Company
Job type
Job categories
Job title (1)
United States
State
City
6,119 jobs found
Yesterday
PA

Palo Alto Principal Engineer Software Backend - AI Security Cloud United States, California

Limitless High-tech career opportunities - Expoint
Collaborate with product managers, cybersecurity researchers, AI application researchers and infrastructure software engineers. Design and build an innovative and solid products to ensure our customers can use AI service securely....
Description:

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Impact

  • Collaborate with product managers, cybersecurity researchers, AI application researchers and infrastructure software engineers
  • Design and build an innovative and solid products to ensure our customers can use AI service securely
  • Participate in all phases of the product development cycle, from definition, design, through implementation and test
  • Implement real-time security services to customers
  • Work with PLM on new feature requirement
  • Work with QA and DevOps on new release deployment

Your Experience

  • Solid golang/python programming skills
  • Solid knowledge on HTTP 1.1/HTTP2 protocols and gRPC
  • Profound knowledge on web service proxy technology especially on envoy and web assembly
  • Experience in designing large distributed system and web services in the cloud
  • Deep knowledge in GCP platform is a plus
  • Familiar with major CSP LLM foundation models is a plus
  • The candidate should be a good problem solver
  • Master's degree in computer science or equivalent or equivalent military experience required

We define the industry, instead of waiting for directions. We need individuals who feel comfortable in ambiguity, excited by the prospect of a challenge, and empowered by the unknown risks facing our everyday lives that are only enabled by a secure digital environment.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $0 - $0/YR. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

All your information will be kept confidential according to EEO guidelines.

Show more
Yesterday
PA

Palo Alto Solutions Consultant - Federal System Integrators United States, Virginia

Limitless High-tech career opportunities - Expoint
Set the strategic vision and direction for all post-sales technical service delivery in the US Public Sector, ensuring consistent and high-quality execution for Palo Alto Networks’ NetSec Products. Act as...
Description:

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Career

As the, you will be the, including full-time employees and/or assigned personnel. You will be responsible for driving leadership over the professional services business and providing strategic and operational oversight to the Senior Managers and regional delivery leaders who report to this role. You will be instrumental in defining thenecessary to scale technical services delivery across key U.S. Federal, State, and Local accounts. This role is highly integrated with the Service Sales, Product Sales, and other Support teams, focusing on building strong, trusted customer relationships and ensuring successful outcomes.


Your Impact

  • Set the strategic vision and direction for all post-sales technical service delivery in the US Public Sector, ensuring consistent and high-quality execution for Palo Alto Networks’ NetSec Products.

  • Act as the single point of accountability for technical services, interfacing with GCS, Sales, Product, Engineering, and Partner teams to ensure alignment and delivery of business outcomes.

  • Serve as the Executive Sponsor for strategic US Public Sector accounts, engaging with executive-level customer stakeholders (e.g., CIOs, CISOs) to provide value reviews and resolve high-stakes escalated issues.

  • Build and develop a high-performing team of technical professionals through hiring the best talent in the industry, mentoring/coaching, and performance management in line with the defined capability requirements for the team.

  • Drive and achieve the following business and operational objectives:

    • Maintain consistently high utilization of PS consultants through optimal planning and backlog management.

    • Design and maintain the best resource mix across FTEs and contractors, maximizing quality and agility.

    • Reduce Time to Value (TTV) by accelerating deployment and adoption timelines.

    • Contribute to Service Sales Growth by enabling scalable, value-driven technical offerings.

    • Achieve global target service margin ratios through delivery efficiency and cost control.

    • Build and sustain strong, strategic relationships with subcontractors and delivery partners.

    • Ensure high levels of customer satisfaction (CSAT) through proactive support and continuous improvement.

  • Drive continuous improvement across the delivery of Netsec Professional Services and Customer Success Engineering, through the use of Automation and AI to drive efficiency, quality, and scale.

  • Standardize and continuously optimize the NetSec operating rhythm and delivery practices to improve service health.

  • Represent US Public Sector region at a global level, sharing customer insights, local challenges, and opportunities for regional impact.

  • A significant portion of your impact is external: collaborating with the sales leadership team, product, portfolio, and support teams, where you will act as the Professional Services liaison to enable client success. You will build strong customer relationships and be the point of contact for successfully handling customer escalations to maintain high customer satisfaction.

Your Experience

  • 10+ years of experience in technical services, professional services, customer success, support or related functions within a high-growth SaaS/cloud enterprise environment.
  • 5+ years of experience in a leadership role managing regional teams, including direct and matrixed reporting lines.
  • Demonstrated success in managing performance against KPIs related to deployment, adoption, margin, utilization, and CSAT.
  • Strong foundational understanding of Internet security concepts and products, with a demonstrated knowledge of NGFW and SASE (Secure Access Service Edge) architecture and its components.
  • Demonstrated experience running a profitable Professional Services or Customer Success business , including achieving revenue/margin targets, managing backlog, health and optimizing project closure rates.
  • Skilled in key business systems, including:

    • Experience with Professional Services Automation (PSA) tools (e.g., Clarizen, Certina, Kantata) for tracking metrics like utilization, time-off, and backlog.
    • Experience with Sales Management tools (e.g., Salesforce) for revenue forecasting and pipeline review.
    • Experience with Business Intelligence (BI) tools (e.g., Tableau) for reporting on key operational metrics.
  • Demonstrated ability to manage critical customer escalations effectively and ensure prompt resolution for high-profile clients.
  • Excellent written and verbal communication skills with the ability to clearly articulate complex technical knowledge to non-technical individuals and leadership.
  • Undergraduate degree in a related field (CS, IS, EE, CE, IT, etc.) or commensurate experience.
  • US Government DoD Active Top Secret Clearance or higher.
  • Relevant industry certifications such as CISSP and/or PMP are highly desirable.
  • Background in cybersecurity or enterprise IT preferred.
  • Ability to travel up to 25%+ domestically to customer sites and internal business meetings.

As threats and technology evolve, we stay in step to accomplish our mission. You’ll be involved in implementing new products, transitioning from old products to new, and fixing integrations and critical issues as they are raised. But you won’t wait for them to be raised, you’ll seek them out, too. We fix and identify technical problems with a pointed focus of providing the best customer support in the industry.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $230000 - $268000/YR. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

All your information will be kept confidential according to EEO guidelines.

Show more

These jobs might be a good fit

Yesterday
PA

Palo Alto Consulting Director Cloud Security Proactive Services Unit - United States, California

Limitless High-tech career opportunities - Expoint
Serve as a key contributor to the development, maturation, and innovation of Unit 42’s cloud security consulting services. Lead and deliver complex cloud security assessments covering architecture, configuration, identity, monitoring,...
Description:

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Impact

  • Serve as a key contributor to the development, maturation, and innovation of Unit 42’s cloud security consulting services.

  • Lead and deliver complex cloud security assessments covering architecture, configuration, identity, monitoring, and threat detection across AWS, Azure, GCP, and hybrid/multi-cloud environments.

  • Evaluate cloud network architectures, including perimeter protections, VPC/VNet segmentation, API gateways, ingress/egress controls, and cloud-native security services.

  • Analyze cloud logging, telemetry, and monitoring coverage; identify gaps in detection and alerting; and provide actionable recommendations to improve visibility, SIEM/XDR integration, and threat-hunting effectiveness.

  • Assess cloud identity and access management (IAM) design, including federation, least privilege models, role delegation, conditional access, privilege escalation paths, and MFA enforcement across cloud providers.

  • Utilize cloud-native CLIs, SDKs, and APIs to perform deep technical validation of configurations, controls, and security posture.

  • Assess multi-cloud and hybrid-cloud deployments by reviewing interoperability, dependencies, and security impacts between cloud services and on-prem infrastructure.

  • Develop strategic cloud security roadmaps that align technical recommendations with a client’s broader business objectives, resource constraints, and long-term security transformation initiatives.

  • Integrate Palo Alto Networks cloud platforms (Prisma Cloud, Prisma SASE, Cortex XSIAM, and Precision AI) into consulting engagements to drive differentiated value and help customers enhance their security posture.

  • Engage with prospective clients in a pre-sales capacity to uncover cloud security pain points, evaluate architectural weaknesses, and position Unit 42 solutions to key outcomes.

  • Support delivery teams in overcoming technical objections and effectively tying cloud security recommendations to business risk, operational impact, and customer strategic goals.

  • Build and maintain long-term executive relationships, serving as a trusted strategic advisor for cloud security and Zero Trust transformation initiatives.

  • Lead the development and delivery of cloud security enablement content to elevate consulting capabilities across Unit 42.

  • Partner with Palo Alto Networks product development teams to provide structured feedback on features, customer patterns, and cloud security trends that influence the roadmap and delivery experience.

Your Experience

  • 4+ years of experience performing cloud security advisement and risk assessments based upon industry-accepted standards

  • 6+ years of professional services and consulting experience and 3+ years of Director (or and equivalent Senior Manager) experience leading consulting delivery teams is highly preferred

  • Experience managing a diverse team of business and technical consultants

  • Cloud Security-related certifications preferred

  • Hands-on experience with a cloud hosting provider (AWS, Azure, GCP, etc).

  • Deep experience within the cloud native application protection platform (CNAPP) technology or advisory/consulting space.

  • Strong fluency in the application of Virtual Machines, SaaS, IaaS, PaaS, FaaS and other public cloud technical infrastructure concepts.

  • Possess a deep technical knowledge in Cloud Platforms and the dependencies around such an environment (WAF, SSO, Cloud Threats, API Security, Cloud Security Posture Management)

  • Former experience with cloud migrations (cloud to cloud, or on-prem to cloud)

  • Knowledge of the technical nuances related to SD-WAN and SASE solutions and their application to Cloud Environment access solutions.

  • 10+ years in developing, strengthening and expanding client relationships

  • Knowledge of how to integrate command-line interfaces or scripting tools as a part of a risk assessment or remediation in cloud environments is a plus.

  • Rich understanding of how Enterprise’s use and struggle using infrastructure as code and continuous integration tools such as Ansible, Chef, Jenkins, Kubernetes, Packer, Pulumi, Puppet, Saltstack and Terraform or CSP tools such as CloudFormation, Resource Manager or Deployment Manager.

  • Ability to scope new opportunities with prospective clients, including drafting statements of work and proposals

  • Ability to perform travel requirements as needed to meet business demands (on average 25%)

  • Bachelor’s Degree in Information Security, Computer Science, Digital Forensics, Cyber Security OR equivalent years of professional experience to meet job requirements and expectations

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $183000/YR - $252000/YR. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

All your information will be kept confidential according to EEO guidelines.

Show more

These jobs might be a good fit

Yesterday
PA

Palo Alto Senior Product Marketing Manager - Data Security Platform United States, California

Limitless High-tech career opportunities - Expoint
Apply your data security knowledge to translate product capabilities into simple, compelling messages and tools that resonate with customers, with a clear understanding of the target markets and buyer personas....
Description:

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Career

As a Product Marketing Manager at Palo Alto Networks, you will play a key role in planning and executing the product marketing strategy for our data security offerings. You will be the expert, voice, and go-to-market driver for Palo Alto Networks’ data security capabilities. You will drive positioning, messaging, content creation, and sales enablement for the product line that you are responsible for. You will work closely with stakeholders from product management, sales, field marketing, and technology partners to develop and execute your strategy and advance our mission.

Your Impact

  • Apply your data security knowledge to translate product capabilities into simple, compelling messages and tools that resonate with customers, with a clear understanding of the target markets and buyer personas

  • Work closely with Product Management to build a shared market and product vision, and a cooperative relationship that forms the foundation of all product marketing activities

  • Author compelling, high-quality content, both at a business and a technical level, in a variety of formats including print, web, social media, and video. You like to write and present

  • Launch products and collaborate with field teams to execute marketing campaigns; be a subject matter expert and a go-to resource for the sales and field marketing teams

  • Effectively work at building and executing plans that cross different functional groups, including product management, business development, and sales

  • Represent the company in customer engagements and at events, to evangelize our point of view

  • Track the data security market and competitive landscape in collaboration with product, marketing, and sales leadership

Your Experience

  • 5+ years of product marketing experience ideally with 3+ years in data security or adjacent cybersecurity solutions..

  • An understanding of data security technologies, market trends, competitive landscape, and customer requirements is desirable

  • Outstanding verbal and written communication skills

  • Comfortable with creating and delivering presentations in a range of environments, from industry conferences to customer briefings

  • Demonstrated record of working cross-functionally to drive sales, demand generation, and overall organization and business success

  • Experience and innovative energy to champion successful market and competitive disruption initiatives

  • Bachelor’s degree required, Technical degree or equivalent background or equivalent military experience is desirable

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $131,000 - $212,500/YR. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

All your information will be kept confidential according to EEO guidelines.

Show more

These jobs might be a good fit

Yesterday
BOA

Bank Of America Identity Access management IAM Mainframe Security United States, Massachusetts, Boston

Limitless High-tech career opportunities - Expoint
Implement and maintain security administration and access policies using RACF, ACF2, or Top Secret. Enforce least privilege and role-based access control (RBAC). Ensure multi-factor authentication for privileged users. Ensure that...
Description:

LOB Overview:

Global Information Security (GIS) is responsible for protecting bank information systems, confidential and proprietary data, and customer information. GIS develops the bank’s Information Security strategy and policy, manages the Information Security program, identifies, and addresses vulnerabilities and operates global security operations centers that monitor, detect, and respond to cybersecurity incidents. Within GIS, Identity and Access Management (IAM) is a security discipline that enables the right individuals to access the right resources at the right times and in the right context. IAM addresses the mission-critical need to ensure appropriate access to the resources across increasingly heterogeneous technology environments, and to meet increasingly rigorous compliance requirements.

Role Description:

The Mainframe Security Administration Manager leads a team of analysts responsible for managing secure access to mainframe systems. This role requires a blend of technical acumen in mainframe security mechanisms (RACF, ACF2, Top Secret), strong governance expertise including knowledge of industry standards, and leadership of team members as a key stakeholder within Information Security and the broader IT organization.

Access Control Management

  • Implement and maintain security administration and access policies using RACF, ACF2, or Top Secret.

  • Enforce least privilege and role-based access control (RBAC).

  • Ensure multi-factor authentication for privileged users.

  • Ensure that privileged access and encryption policies are enforced.

Compliance & Auditing

  • Align security administration and access controls with regulatory frameworks (SOX, UCAL and PWC applications).

  • Maintain detailed logs and audit trails for all access request and administrators provisioning activities.

  • Utilize tools such as Vanguard Resource Administrator (VRA) for forensic analysis and Report Analyzer for reporting.

Security Governance

  • Monitor for unauthorized access and potential data leakage.

  • Conduct regular access reviews and security assessments.

  • Integrate with Identity and Access Management (IAM) systems for centralized governance.

Team Management

  • Lead and mentor a team of mainframe security analysts.

  • Ensure team proficiency in RACF, Top Secret, and z/OS environments, including by participating in learning opportunities and communicating with vendors

  • Promote automation of repetitive provisioning tasks to enhance efficiency.

  • Oversee ticketing systems integrated with IAM workflows for request tracking, Quality Assurance validation for efficiency and remediation.

Training & Development

  • Provide ongoing training on evolving security threats and compliance requirements, process changes.

  • Set Global Information Security goals and encourage professional certifications (e.g., CISSP, Certified RACF and Vanguard Specialist).

Operational Best Practices

  • Ensure 24/7 monitoring of access provisioning activities.

  • Establish and maintain incident response protocols for access-related events.

  • Design scalable provisioning processes to support organizational growth.

Required Qualifications:

  • 10+ years of progressive experience in Identity and Access Management, with a strong focus on access provisioning across enterprise environments.

  • 10+ Years of experience in RACF, ACF2 and zOS systems

  • Drives Mainframe Modernization and work in close partnership with the CTO Mainframe team to provide SME security leadership.

  • Deep technical expertise in Mainframe RACF, Vanguard and Microsoft Azure AWS, Databases DB2 and VMSecure and enterprise storage platforms.

  • Proven ability to design, implement, and manage access provisioning solutions that enforce least privileged access and align with regulatory and internal compliance requirements.

  • Strong understanding of IAM governance frameworks, platforms (e.g., ForgeRock Single Sign- On SSO, Adaptive Authentication) role-based access control (RBAC), group policy management, and privileged access management (PAM) tools, CyberArk, Hashi Corp and Beyond Trust.

  • Experience with automated provisioning/de-provisioning workflows, including integration with HR systems to demonstrated proficiency in scripting and automation (e.g., PowerShell, Python) to support scalable access provisioning and audit processes.

  • Familiarity with cloud infrastructure security and access controls in hybrid environments, particularly within Microsoft Azure AWS and Oracle Cloud.

  • Ability to conduct access reviews, entitlement audits, and risk assessments to identify and remediate access-related vulnerabilities.

  • Excellent analytical, problem-solving, and communication skills, with the ability to collaborate across technical and business teams.

  • Bachelor’s degree in computer science, Information Security, or a related field; advanced degree or certifications (e.g., CISSP, CISM, Microsoft Certified: Identity and Access Administrator Associate) preferred.

  • BS/BA Engineering degree or equivalent experience

Desired Skills:

  • Understanding or have experience with agile and lean philosophies.

  • Strong critical thinking and problem-solving skills with clear communication

  • Ability to collaborate with different roles to achieve common goals.

  • Ability to think critically and question the status quo.

  • Understand how to identify software security vulnerabilities and recognize and communicate their associated impact to the business.

  • Demonstrate awareness of secure software design principles such as least privilege, defense in depth, or designing secure user interfaces

1st shift (United States of America)

Show more

These jobs might be a good fit

Yesterday
EY

EY AI & Machine Learning Engineering Consultant United States, New York, New York

Limitless High-tech career opportunities - Expoint
Researching and implementing scalable AI systems that meet business requirements. Enhancing data pipelines and storage for optimal data accuracy and cleanliness. Monitoring and optimizing learning processes to improve high-performance models....
Description:


AI/Machine Learning Engineer, Senior Consultant


Our Artificial Intelligence and Data team helps apply cutting edge technology and techniques to bring solutions to our clients. As part of that, you'll sit side-by-side with clients and diverse teams from EY to create a well-rounded approach to advising and solving challenging problems, some of which have not been solved before. No two days will be the same, and with constant research and development, you'll find yourself building knowledge that can be applied across a wide range of projects now, and in the future. You'll need to have a passion for continuous learning, stay ahead of the trends, and influence new ways of working so you can position solutions in the most relevant and innovative way for our clients. You can expect heavy client interaction in a fast-paced environment and the opportunity to develop your own career path for your unique skills and ambitions.

As a Senior AI Native Engineer, you will be at the forefront of revolutionizing how businesses leverage artificial intelligence. Your role will involve researching, building, and implementing scalable AI systems that learn and make predictions tailored to diverse business environments, whether in the cloud or on-premises. You will enhance data pipelines to ensure data integrity and optimize learning processes, all while collaborating with a talented team of data and analytics professionals.

Your key responsibilities


In this role, you will contribute significantly to the delivery of innovative AI solutions. You will work with a wide variety of clients to deliver the latest data science and big data technologies. Your teams will design and build scalable solutions that unify, enrich, and derive insights from varied data sources across a broad technology landscape. You will help our clients navigate the complex world of modern data science, analytics, and software engineering. We'll look to you to provide guidance and perform technical development tasks to ensure data science solutions are properly engineered and maintained to support the ongoing business needs of our clients.

You will spend your time on key responsibilities that include:

  • Researching and implementing scalable AI systems that meet business requirements.
  • Enhancing data pipelines and storage for optimal data accuracy and cleanliness.
  • Monitoring and optimizing learning processes to improve high-performance models.
  • This position may have travel requirements as needed to engage with external clients regularly.

Skills and attributes for success


To excel in this role, you will need a blend of technical expertise and interpersonal skills. Your ability to navigate complex challenges and deliver impactful solutions will be essential.

This role will work to deliver tech at speed, innovate at scale and put humans at the center. Provide technical guidance and share knowledge with team members with diverse skills and backgrounds. Consistently deliver quality client services focusing on more complex, judgmental and/or specialized issues surrounding emerging technology. Demonstrate technical capabilities and professional knowledge. Learn about EY and its service lines and actively assess and present ways to apply knowledge and services.

  • Strong analytical and decision-making skills to guide project direction.
  • Proven experience in project management and tracking deliverable completion.
  • Ability to build and maintain relationships with clients and team members.
  • Excellent communication skills to convey complex ideas effectively.

qualify for the role, you must have

  • A Bachelor’s degree required (4-year degree).
  • 3-6 years of full-time working experience in AI and/or Machine Learning
  • Strong skills in Python
  • Ability to collaborate and communicate effectively with diverse, hybrid and global teams
  • Experience designing, building, and maintaining high-impact, high-value production AI/ML solutions on a major cloud platform
  • Proficient in Generative AI models and frameworks (e.g., OpenAI, Dall-e, Langchain, Retrieval Augmented Generation (RAG)) and experienced with ML packages like scikit-learn and PyTorch
  • Experience with natural language processing and deep learning
  • Extensive experience in DevOps tools (GIT, Azure DevOps), Agile methodologies (Jira), and CI/CD pipelines for developing, deploying, and scaling analytical solutions
  • Experience with MLOps and ML workflows, including data ingestion, transformation, and evaluation
  • Experience with model retraining and feedback loop methodologies
  • Experience with model and solution monitoring and reporting
  • Understanding of data structures, data modelling, and software engineering best practices
  • Strong foundation in mathematics, statistics, and operations research, with proficiency in data manipulation tools (SQL, Pandas, Spark) and deep learning techniques
  • Excellent communication skills for conveying findings and recommendations, with a willingness to travel for client engagements

Ideally, you’ll also have

  • Master's degree Computer Science, Mathematics, Physical Sciences, or another quantitative field
  • Experience in hybrid collaboration and emotional agility
  • A track record of working with diverse teams to drive outcomes through complex problem-solving
  • Knowledge of sustainability practices in technology
  • A deep understanding of and ability to teach concepts, tools, features, functions, and benefits of different approaches to apply them
  • Strong skills in languages beyond Python: R, JavaScript, Java, C++, C
  • Experience fine-tuning Generative AI models
  • Experience with image processing techniques and/or speech and audio processing and analysis

What we offer you
At EY, we’ll develop you with future-focused skills and equip you with world-class experiences. We’ll empower you in a flexible environment, and fuel you and your extraordinary talents in a diverse and inclusive culture of globally connected teams. Learn .

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $106,900 to $176,500. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $128,400 to $200,600. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

Yesterday
EY

EY Chief Information Security Officer CISO - US Government & Pu... United States, Virginia, Arlington

Limitless High-tech career opportunities - Expoint
The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across...
Description:

Responsibilities

  • The successful candidate will work with GPS engagement teams, supporting functions, and EY’s Client Technology and Global Information Security organizations to develop and maintain a security and compliance program across all environments, platforms and applications used or desired for use by GPS. Responsibilities include:
  • Strategy, Governance and Risk Management
  • Development and execution of a multiyear cybersecurity strategy and investment roadmap aligned to business objectives and federal contract requirements.
  • Development, management and maintenance of the GPS IT security risk management policy and/or procedural documentation mapped to NIST SP 800-37 (RMF), NIST SP 80053, NIST SP 800171, NIST SP 800161 (CSCRM), and NIST SP 800218 (SSDF)
  • Ownership of the enterprise risk assessment (ERA), business impact analysis (BIA), and security metrics; present posture and material risk to the COO on a recurring cadence.

Defense Industrial Base Compliance (Classified & Unclassified)

  • Manage GPS compliance with DFARS 252.204-7012, 252.204-7020, and 252.204-7021. This includes:
    • Leading DFARS/CMMC readiness and ongoing compliance.
    • Serving as the Affirming Official (AO) and maintaining an accurate SPRS selfassessment score with defensible Plans of Action and Milestones (POAMs).
    • Achieving and maintaining CMMC certification at level 2.
    • Overseeing management and maintenance of POAMs.
  • Ensure systems operated for the government are designed properly and assessed against the appropriate requirements such as FedRAMP, Cloud Computing Security Requirements Guide, IRS 1075, and MARS-E.
  • Ensure safeguarding and incident reporting obligations for CUI (e.g., DFARS 252.2047012 72hour reporting) are met; coordinate with DC3/DIBNet and affected customers when necessary.
  • Oversee NISPOM compliance for classified systems; partner with FSO to achieve and maintain Authorizations to Operate (ATOs).
  • Ensure proper handling of exportcontrolled data (ITAR/EAR).
  • Prepare for and lead Program through contractually required assessments and customer audits; keep evidence, policies, configurations, and logs auditready.
  • Respond to government inspections or audits in coordination with EY Information Security and Risk Management.

Secure Cloud, Identity & Enterprise Platforms

  • Own security architecture and controls for Azure Government (Azure Gov) and Microsoft 365 GCC High tenants, including Conditional Access, PIM/PAM, encryption, logging/retention, and data governance for CUI.
  • Implement Zero Trust principles across identity, endpoints, networks, and workloads; drive continuous verification and leastprivilege.
  • Deploy and operate EDR/XDR, SIEM/SOAR, DLP, CASB/SSE/SASE, MDM, key management/HSM, and vulnerability/configuration management at scale.
  • Oversee user authorization process and ongoing attestation of user authorization and access.
  • Assist to resolve GPS practitioners’ access or other issues with Enclave environments.
  • Ongoing development, coordination and sustainment of Information Security Continuous Monitoring (ISCM) Program across all applications within the environment.

DevSecOps & Secure SDLC

  • Establish a software security program aligned to NIST SSDF (SP 800218) and EO 14028 expectations; integrate security into SDLC across GitHub and Azure DevOps.
  • Govern AppSec tooling and policy: SAST (e.g., Checkmarx), DAST (e.g., Qualys/AppScan), SCA/OSS (e.g., Mend), IaC/container/K8s scanning, and Wiz/Wiz Code; enforce buildtime gates and remediation SLAs.
  • Require SBOM generation, artifact signing/provenance (e.g., SLSA targets), and secrets management across all repositories and pipelines.

Detection, Response & Resilience

  • Develop, manage and maintain GPS incident response program.
  • Lead SOC and CSIRT functions: 24×7 monitoring, threat intelligence, purple/redteam exercises, and executive tabletop drills.
  • Maintain and test the Incident Response Plan and Cyber Crisis Playbook, including regulatory/customer communications and forensics preservation.

Effective Business Integration

  • Ensure development of fit-for-purpose solutions that support the business activities.
  • Manage integration of Firm applications into the GPS Enclave environment.
  • Understand and facilitate communication of EY’s IT disaster recovery and business continuity plans to GPS clients, potential clients and engagement teams (including engagement team responsibilities).
  • Augment existing Client Security Assurance reviews of data protection requirements contained in RFPs/RFQs to adequately respond, and assist in development of GPS client security and data protection (confidentiality) plans.
  • Monitor regulatory or other developments in INFOSEC principles, regulatory requirements and leading practices.

Leadership, Team and Budget

  • Role model a leadership style that brings infrastructure, application and cybersecurity professionals together to collaborate constructively on the design, implementation and operation of controls.
  • Build and mentor a highperforming organization spanning Policy/GRC, AppSec/DevSecOps, Security Engineering/Architecture, SOC/IR, and ThirdParty & SupplyChain Risk.
  • Own the cybersecurity budget and vendor portfolio; rationalize tools and services for value, performance, and compliance.
  • Participate in purchasing and enhancement of third-party tools for GPS.
  • Augment and potentially streamline existing Vendor Supplier Risk Assurance Program during evaluation of subcontractor compliance with applicable cybersecurity and data protection clauses.
  • Drive a securityfirst culture: ongoing training, phishing simulations, secure coding education, and leadership engagement including data protection and awareness and role-based training programs.
  • Coordinate and respond to annual (or more frequent) independent risk assessments and cyber security reviews.

Qualifications:

  • 12+ years of progressive cybersecurity leadership, including 5+ years at the enterprise or businessunit executive level.
  • 5+ years FISMA related experience
  • Bachelor’s degree in IT-related field or bachelor’s degree in non-IT related field with a total of 10 years of information security experience
  • Master’s degree preferred
  • Ability to obtain and maintain Top Secret clearance
  • US citizenship required
  • Clearance: The ability to obtain and maintain top secret required
  • Thorough knowledge and understanding of:
    • FAR 52.204-21 Basic Safeguarding of Covered Contractor Information Systems
    • DFARS 252.204-7012, Safeguarding Covered Defense Information and Cyber Incident Reporting
    • NIST SP 800-171, Protecting Controlled Unclassified Information in Nonfederal Systems and Organizations
    • NIST SP 800-53, Security and Privacy Controls for Federal Information Systems and Organizations
    • GSAM 552.239-70, Information Technology Security Plan and Security Authorization, 552.239-71, Security Requirements for Unclassified Information Technology Resources and similar clauses in agency FAR supplements
    • FISMA
  • Specialized knowledge and experience with the implementation of the NIST Special Publication (SP) 800 family of publications, particularly those associated with the Risk Management Framework
  • Proven experience in the Defense Industrial Base with DFARS/CMMC and NIST SP 800171 implementation and audits (including POA&M and SPRS management).
  • Experience with FEDRAMP compliance authorization and monitoring
  • Deep expertise securing Azure Government and Microsoft 365 GCC High environments
  • Experience working with other Government cloud communities, including AWS
  • Experience working with classified environments, achieving/maintaining ATOs, overseeing classified systems under NISPOM and DoD RMF, and working understanding of SCIF operations
  • Knowledge and experience with vulnerability scanning execution, assessment, and analysis
  • Knowledge and experience of networks, including LAN and WAN
  • Knowledge and experience with application security, database security, and network security
  • Experience with evaluating system, network, or infrastructure security controls against requirements such as FISMA, FIPS, and NIST guidelines
  • Handson leadership of DevSecOps and software security programs covering GitHub/Azure DevOps/Jenkins with SAST/DAST/SCA, IaC/container security, SBOMs, and supplychain controls.
  • Demonstrated analytical, problem-solving, organizational, interpersonal and communication skills required.
  • The ability to collaborate effectively with diverse stakeholders, including client-facing, legal, finance and contracting teams, executives, engineers, customers and assessors on a wide variety of tasks, as needed.
  • Ability to foster professionalism and demonstrate integrity and confidentiality in all actions.
  • Ability to demonstrate flexibility when required, sense urgency, organize and prioritize work, and achieve against tight deadlines.
  • The ability to interpret and communicate regulatory requirements related to cybersecurity and data protection.
  • Possession of excellent written/verbal communications skills.
  • Possession of excellent analytical skills, including strict attention to detail.
  • Ability to assess and weigh current and evolving security threats in an operational environment
  • Possession of Information Systems Security Professional certification (CISSP)
  • Certifications such as CISSP, CISM, CCISO, CCSP, CRISC, CISA, PMP, and relevant GIAC credentials preferred

What we offer you

  • We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $235,700 to $466,700. The base salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $282,900 to $530,400. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options.
  • Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year.
  • Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.


Show more

These jobs might be a good fit

Limitless High-tech career opportunities - Expoint
Collaborate with product managers, cybersecurity researchers, AI application researchers and infrastructure software engineers. Design and build an innovative and solid products to ensure our customers can use AI service securely....
Description:

Being the cybersecurity partner of choice, protecting our digital way of life.

Your Impact

  • Collaborate with product managers, cybersecurity researchers, AI application researchers and infrastructure software engineers
  • Design and build an innovative and solid products to ensure our customers can use AI service securely
  • Participate in all phases of the product development cycle, from definition, design, through implementation and test
  • Implement real-time security services to customers
  • Work with PLM on new feature requirement
  • Work with QA and DevOps on new release deployment

Your Experience

  • Solid golang/python programming skills
  • Solid knowledge on HTTP 1.1/HTTP2 protocols and gRPC
  • Profound knowledge on web service proxy technology especially on envoy and web assembly
  • Experience in designing large distributed system and web services in the cloud
  • Deep knowledge in GCP platform is a plus
  • Familiar with major CSP LLM foundation models is a plus
  • The candidate should be a good problem solver
  • Master's degree in computer science or equivalent or equivalent military experience required

We define the industry, instead of waiting for directions. We need individuals who feel comfortable in ambiguity, excited by the prospect of a challenge, and empowered by the unknown risks facing our everyday lives that are only enabled by a secure digital environment.

Compensation Disclosure

The compensation offered for this position will depend on qualifications, experience, and work location. For candidates who receive an offer at the posted level, the starting base salary (for non-sales roles) or base salary + commission target (for sales/commissioned roles) is expected to be between $0 - $0/YR. The offered compensation may also include restricted stock units and a bonus. A description of our employee benefits may be found .

All your information will be kept confidential according to EEO guidelines.

Show more
A great career opportunity awaits those who have a passion for the tech industry and a keen eye for details in IT security. As an Information Security Consultant at Expoint, you will be a go-to expert in all things information security. You will be required to develop, manage, and implement secure enterprise architecture and security policies. You will be charged with identifying and evaluating existing risk factors, then proposing and implementing adequate countermeasures to reduce the associated risks. This may include developing security guidelines, establishing secure access controls, engaging in risk assessments, computer forensics and incident response, and other areas related to IT security and privacy. As the security consultant, you must ensure that the company’s IT systems remain secure and adhere to the highest safety standards. You must also stay on top of the latest threats and trends in the industry, as well as any shifts in regulations that could affect the company’s security posture. Your organizational skills and technical competency will be put to the test on a daily basis. You must be able to handle multiple tasks and deadlines, and have a strong attention to detail. The Information Security Consultant position at Expoint is the perfect opportunity for someone who is passionate about the tech industry and its security. As the security consultant, you will have the chance to make a real difference in the company, knowing that your efforts help make a secure environment in which individuals can safely store, share, and access data.