67 security risk jobs at 46 companies in Denver, CO
4w
Save
Mark Applied
Hide
4w
Lead Security Governance & Risk Engineer
Boston or Denver
$156k-$234k/yrOnsiteFull Time
KlaviyoNYSE: KVYO: Software platform for automated e-commerce marketing and customer data.
7+ YOE7+ years in information/technology/cyber risk with hands-on risk engineering, cyber risk quantification, SQL and Python skills, API integration, knowledge of security/AI frameworks and risk tooling.
5+ YOEBachelor's in related field (or equivalent), 5+ years resilience/risk experience, financial services preferred, pursuing or holding CISM/CISSP/CRISC/CISA, working knowledge of NIST CSF and NIST Privacy Framework, strong documentation and communication skills.
CrocsNASDAQ: CROX: Design and distribution of casual foam footwear and accessories.
4+ YOE4+ years in governance, risk, compliance, audit, or information security; working familiarity with AI/ML and LLMs; strong SOX and privacy awareness; excellent policy, risk assessment, and documentation skills.
Washington or Boston or Dallas or Chicago or Miami or Denver or Orange or Los Angeles or Las Vegas or Sacramento or Phoenix or San Diego or United States
$130k-$160k/yrRemoteFull Time
DanaherNYSE: DHR: Develops scientific instruments and diagnostic tools for healthcare markets.
7+ YOE7+ years in third-party/vendor risk, enterprise risk, or vendor security; experience administering vendor questionnaires, reviewing SOC 2/ISO 27001 evidence, scoring at scale, reviewing cybersecurity contract provisions, and operating enterprise risk registers.
Lone Tree or Austin or Westlake or Southlake or Omaha or Orlando
$120k-$170k/yrOnsiteFull Time
Charles SchwabNYSE: SCHW: Financial services, brokerage, and investment management provider.
5+ YOEBachelor’s degree in information security, computer science, or related field; 5+ years in technology or cybersecurity risk, audit, oversight, or controls; strong analytical, communication, and stakeholder influence skills.
Burns & McDonnell: Engineering, construction, and architectural firm for critical infrastructure.
8+ YOEBachelor's degree in criminal justice, security management, or related field and 8 years of relevant experience. Requires risk assessment, security analysis, leadership, software, and integrated security systems expertise.
Microsoft Word, Microsoft Excel, Microsoft PowerPoint, Access Control, CCTV, Intrusion Detection, Everbridge, Critical Event Management (CEM)
1+ YOERequires a four-year degree plus 1–2 years of experience, a two-year degree with equivalent experience, or equivalent work experience; knowledge of LLM architectures, prompt engineering, and AI security risks.
Large Language Model (LLM), OWASP, NIST AI RMF, MITRE ATLAS
Peachtree Group: Invests in and manages hospitality and commercial real estate assets.
Responsibilities include patrolling hotel property, identifying safety and security risks, responding to emergencies, investigating incidents, writing reports, and resolving guest issues.
Bank of AmericaNYSE: BAC: Provides global banking, investing, and financial risk management services.
5+ YOERequires 5+ years in information security, 2–5 years in technology and application development or security, cloud experience with Azure, AWS, and Google Cloud Platform, risk management, and strong communication skills.
Microsoft Azure, Amazon Web Services, Google Cloud Platform, PaaS, SDLC
Bank of AmericaNYSE: BAC: Provides banking, investment, and financial risk management services.
5+ YOERequires 5+ years in information security, technology and application security experience, cloud experience with Microsoft Azure, Amazon Web Services and Google Cloud Platform, risk management, and strong communication skills.
Microsoft Azure, Amazon Web Services, Google Cloud Platform, PaaS, SDLC
Pittsburgh or Cleveland or Dallas or Denver or Chicago
$133k-$247k/yrOnsiteFull Time
PNC Financial ServicesNYSE: PNC: Provides banking, lending, and investment services to customers.
8+ YOEProvide independent risk oversight for swap dealer and broker-dealer businesses; assess capital markets risk, interpret U.S. securities and swap regulations (Dodd-Frank, FINRA, CFTC, SEC), and translate regulatory requirements into sustainable controls.
Cornerstone Capital Bank: Provides residential mortgage financing and retail banking services.
10+ YOE10+ years information and physical security experience in the financial sector, 5+ years mid-to-large bank security experience preferred; bachelor’s degree preferred; CISSP/CRISC/CPP/PSP preferred; strong risk management and communication skills; Microsoft Office proficiency.
Microsoft Word, Microsoft Excel, Microsoft Outlook
Westlake or Greenwood Village or Albuquerque or Covington or Jacksonville or Salt Lake City or Durham or Jersey City or Merrimack or Smithfield
$130k-$264k/yrOnsiteFull Time
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
15+ YOEBachelor’s degree and 15+ years in risk management, insider risk, technology, security, cybersecurity, audit, or related fields; proven leadership of large firmwide programs and executive communication skills.
Breakthru Beverage Group: Distributes alcoholic and non-alcoholic beverages to North American businesses.
7+ YOE7+ years IT security experience, CISSP required; expertise in networking, Windows and Linux administration, AWS/Azure, IaC (HCL/YAML/JSON), scripting (PowerShell, Python, Go, Shell), incident response, risk management, and security tooling.
York Space SystemsNYSE: YSS: Designs and manufactures modular spacecraft platforms and mission solutions.
3+ YOE3+ years cybersecurity/GRC experience; familiarity with NIST SP 800-171, CMMC, RMF, ISO 27001, SOC 2; experience with GRC platforms (Hyperproof); strong documentation and communication; US citizenship and ability to obtain a security clearance; onsite Greenwood Village, CO.
Hyperproof, Microsoft GCC High, NIST SP 800-171, NIST CSF, CMMC, RMF, ISO 27001, SOC 2
Jeppesen ForeFlight: Provides integrated software and data solutions for aviation flight planning.
10+ YOE10+ years in security engineering or architecture with 3+ years as a principal/staff-level IC; hands-on with cloud (AWS, Microsoft Azure), IAM, VPC, Okta/Entra ID/Azure AD, EDR/XDR, SIEM, SOAR; knowledge of NIST CSF, ISO 27001, SOC 2; strong communication and risk-to-engineering delivery.
Okta, Microsoft Entra ID, Microsoft Azure AD, AWS, Microsoft Azure, IAM, VPC, EDR, XDR, SIEM, SOAR, NIST CSF, ISO 27001, SOC 2, FAA, EASA, DoD, CMMC
McLean or Beavercreek or Austin or Denver or Tampa or Rome or Detroit or Sargodha or United States
$55k-$126k/yrFieldFull Time
Booz Allen HamiltonNYSE: BAH: Provides technology and management consulting services to diverse organizations.
Perform industrial security functions including COMSEC handling, inventory and accountability of classified assets, security risk assessments, incident reporting, and travel to austere South Asia locations (up to 90%); Secret clearance and HS diploma/GED required.
Westlake or Merrimack or Covington or Durham or Jersey City or Salt Lake City or Jacksonville or Albuquerque or Greenwood Village or Smithfield
$130k-$264k/yrOnsiteFull Time
Fidelity Investments: Provides investment management, retirement planning, and brokerage services.
15+ YOEBachelor's degree and 15+ years in risk management, insider risk, technology, security, cybersecurity, audit, or related fields. Requires firmwide program leadership, data protection knowledge, strategic thinking, executive communication, and reporting skills.
Seattle or Arlington or New York or Denver or Chicago or San Francisco or Dallas or Los Angeles County
$131k-$204k/yrOnsiteFull Time
AmazonNASDAQ: AMZN: Global online retail and cloud computing technology provider.
3+ YOERequires a bachelor's degree or equivalent, 3+ years in cloud architecture, security and risk management, and integration, testing, and automation. Strong AWS, communication, and technical problem-solving skills required.
Tract Capital: Alternative asset manager focused on digital infrastructure and data centers.
10+ YOE5+ Mgmt10+ years information security experience with 5+ years in CISO-level roles; expertise in ISO/NIST/SOC2, Microsoft 365 security stack, third-party risk, incident response, and investor-facing communications.
ISO/IEC 27001, NIST 800-53, SOC 2 Type II, GDPR, CCPA, Microsoft Purview Compliance Manager, Microsoft Entra ID, Defender XDR, Microsoft Purview, Intune, Microsoft 365, KnowBe4, Glean, OWASP, MITRE ATT&CK, NIST 800-115