Partnership for Supply Chain Management: Procures health products and manages global medical supply chains.
10+ YOE10+ years IT strategy/operations; Bachelor’s in information systems; Master’s preferred; ISO27001 knowledge a plus; willingness to travel; strong English communication.
Cloud computing, Information security, ISO27001, Data governance, Project management tools
Pennsylvania or Maryland or Washington or North Carolina or Louisiana or Kentucky or Kansas or Indiana or Illinois or Georgia or Iowa or Florida or Colorado or California or Delaware or Connecticut or Arkansas or Arizona or Alabama or Alaska or Nevada or Vermont or Tennessee or Idaho or Oklahoma or Hawaii or Mississippi or Utah or New Hampshire or New Mexico or Wyoming or North Dakota or South Dakota or Rhode Island or West Virginia or Montana or Texas or District of Columbia or Ohio or New Jersey or Oregon or South Carolina or Missouri or Virginia or Massachusetts or Nebraska or Minnesota or Michigan or Wisconsin or New York or Maine
$79k-$127k/yrRemoteFull Time
Highmark Health: Provides health insurance and integrated medical care services.
3+ YOEPerform information risk assessments, score and document risks, support compliance (PCI-DSS,HITRUST,ISO27001), present findings, and partner on security architecture and remediation.
ARCHER, IPS, firewalls, endpoint protection, web/email filtering, Data Loss Prevention (DLP), digital rights management, encryption, Security Event and Incident Management (SEIM), virtualization platforms, HITRUST CSF, NIST 800-83, PCI, HIPAA, HITECH, COBIT, ISO 27001/2, ITIL 3, NIST AI RMF, ISO/IEC 42001
Beusa Energy: Provides oil exploration, fracturing, and power generation services.
3+ YOE3-6 years in cybersecurity GRC/risk, bachelor’s in cybersecurity or related field, strong knowledge of CSF/ISO27001/SOC2, controls design and risk management.
NIST CSF, ISO 27001, SOC 2, GRC tools (e.g., Drata)
Nordic: Provides global healthcare IT consulting and managed services.
15+ YOE15+ years audit/cybersecurity experience, bachelor's or equivalent, experience performing IT and cybersecurity audits across ISO27001,HITRUST,NIST,SOC2; strong communication, analytical, and remediation tracking skills.
Ironsite: AI-powered wearable cameras for construction safety and productivity.
4+ YOE4+ years in IT engineering/systems administration. Experience with IAM/SSO, MDM/EDR, IaC (Terraform), Python/Bash scripting, VPN/ZTNA, corporate networking, and SOC2/ISO27001 compliance.
Boom: Fintech building rental financial services for renters and property managers.
5+ YOE5+ years security engineering with hands-on web development; AWS preferred; strong SOC2/ISO27001 awareness; knowledge of OWASP; Ruby and React stack experience; ability to own security program.
Bentley SystemsNASDAQ: BSY: Software for designing, building, and operating global infrastructure.
3+ YOEBachelor's degree, 3+ years communications experience (security/IT preferred), experience with ISMS documentation, security compliance (ISO27001,SOC2,FedRAMP), training program development, strong writing and project management skills.
ISO 27001, NIST, CIS Controls, SOC2, FedRAMP, ISMS, QMS
BlackRockNYSE: BLK: Provides investment management and financial technology services globally.
Deep technology risk and controls experience, framework knowledge (NIST/COBIT/ITIL/ISO27001/CSA CCM), policy and metrics development, strong stakeholder and program management, excellent communication and change leadership.
WHSmithLondon Stock Exchange: SMWH: Global travel retailer operating stores in airports and resorts.
1+ YOEBachelor's in cybersecurity or equivalent experience,1+ years cybersecurity/GRC/IT experience,knowledge of NIST CSF/CIS/ISO27001/PCI DSS,EDR exposure,vulnerability and access management,training and communication skills.
ToyotaNYSE: TM: Designs and manufactures vehicles and provides automotive financial services.
4+ YOEBachelor's in CS/IT,4+ years IT audit or cybersecurity experience,knowledge of NIST CSF/ISO27001/PCI DSS and regulations,experience with risk assessments,project management and stakeholder influence;US work authorization required.
NIST CSF, ISO 27001, PCI DSS, Sarbanes-Oxley, FFIEC
WHSmith North AmericaLondon Stock Exchange: SMWH: Specialty travel retailer operating stores in airports and resorts.
1+ YOEBachelor's in cybersecurity or equivalent experience,1+ year cybersecurity/GRC/IT experience,knowledge of NIST CSF/CIS/ISO27001/PCI DSS,EDR and vulnerability concepts,strong communication and training skills,English fluency.
VeSync: Designs and sells smart home appliances and wellness products.
8+ YOE8+ years information security experience, bachelor’s in related field, hands-on cloud security (AWS/Azure/GCP), SIEM and incident response, familiarity with NIST CSF/ISO27001/CIS, Mandarin bilingual required.
Temporal: Platform for building and running reliable distributed applications.
8+ YOE8+ years in GRC or information security compliance; hands-on with SOC2/ISO27001/HIPAA or similar; experienced managing SIG/CAIQ questionnaires; scripting/automation with Python or Bash; strong customer-facing and risk assessment skills.
Hyundai America Technical CenterKorea Exchange: 005380: Designs and engineers vehicles for the North American market.
Lead enterprise IT strategic planning, governance, vendor and budget management; experience with IT audits, risk and compliance (SOX, ISO27001, COBIT); preferred PMP or ITIL v4; bachelor\u0002s degree preferred; senior-level IT strategy experience.
SOX, ISO27001, COBIT, Business Management System (BMS), Environmental Management System (EMS), Safety Management System (SMS), ITIL v4
US Signal: Provider of data center, cloud, and fiber network services.
4+ YOE4+ years internal audit/risk/compliance experience in tech, CISA or CIA preferred,Bachelor's degree or 4+ years IT experience, familiarity with ISO27001/PCI/HIPAA/GDPR/NIST/SOC1/SOC2,valid driver’s license.