Chargement en cours

Cybersecurity Engineer

LES ULIS, 91
il y a 24 jours

Overview

Istari is a digital engineering software company enabling our customers to turn the physical world into the digital to accomplish their specific mission or business objectives. Istari was founded with the vision of making open, scalable digital engineering ecosystems a reality – where new technologies and systems are created digitally, free from the real-world constraints of costs and schedules. We are creating the world’s best engineering model sharing platform, allowing our customers to simply and securely integrate their models across different engineering disciplines, organizations, and security levels. At Istari, we are passionate about our mission of creating the world's first open and scalable industrial metaverse. Whether our customers are designing prototypes, performing virtual testing, or training AI and autonomy for complex systems, we know that going digital will save them time, resources, and reduce their environmental impact.

While we are a distributed team with most team-members working remotely, we place an emphasis on staying connected and collaborative, prioritizing in-person opportunities to build trust as a team. At Istari, we still believe that trust is best built in-person. To do this, we have an engineering headquarters in Cambridge, MA for focused technical development and several times per year we gather for an off-site that allows us to develop our professional skills and our team relationships.

Base pay range

$98,400.00/yr - $147,600.00/yr

Key Responsibilities

  • Lead security design and threat modeling for new and existing systems (cloud, application, data, network)
  • Implement and manage core controls: IAM/SSO, least privilege, network segmentation, encryption and key management, secrets management, endpoint and email security
  • Build and operate detection and response capabilities: SIEM/EDR/SOAR, log pipelines, alert tuning, use-case development, threat hunting
  • Own vulnerability remediation: scanning, triage, risk-based prioritization, remediation with product/IT teams, tracking to closure
  • Strengthen application and cloud security: SAST/DAST/SCA, secure SDLC, CI/CD guardrails, IaC scanning, container/Kubernetes runtime protections, CSPM/CIEM
  • Coordinate and support security testing: internal reviews, penetration tests, red/purple team, tabletop exercises; drive remediation and lessons learned
  • Lead/participate in incident response: triage, containment, eradication, recovery, forensics, root-cause analysis, post-incident reports and runbooks
  • Define and maintain security standards, baselines, hardening guides, and architecture diagrams
  • Monitor and report security metrics, KPIs/KRIs, and risk posture to stakeholders
  • Support audits and compliance efforts (e.g., SOC 2, ISO 27001, PCI DSS, HIPAA) and align controls to frameworks (NIST CSF, CIS Controls)
  • Conduct third‑party/vendor security reviews and support contract/security requirements
  • Drive security awareness initiatives and phishing simulations; mentor engineers on secure practices
  • Contribute to business continuity and disaster recovery planning and testing
  • Automate repetitive tasks and integrations to improve scale and reliability

Required Qualifications

  • Bachelor’s in Computer Science, Engineering, Information Security, or equivalent practical experience
  • 3+ years of hands-on cybersecurity engineering, blue team, or security operations experience (adjust years for your level)
  • Strong understanding of networks and protocols (TCP/IP, DNS, HTTP(S)/TLS, routing, VPN, firewalls, Zero Trust concepts)
  • Practical experience with two or more: SIEM, EDR, IDS/IPS, WAF, CSPM/CIEM, vulnerability scanners, SAST/DAST/SCA, PAM/IGA, PKI
  • Cloud security experience in at least one major cloud (AWS/Azure/GCP): IAM, network security, KMS, logging/monitoring, security services
  • Proficiency in scripting/automation (e.g., Python, Bash, PowerShell) and exposure to IaC/Config management (Terraform, CloudFormation, Ansible)
  • OS administration and hardening (Windows, Linux, macOS) and endpoint security fundamentals
  • Familiarity with MITRE ATT&CK, common attack techniques, and modern detection strategies
  • Experience participating in incident response and writing/runbook-level documentation
  • Knowledge of cryptography basics (encryption at rest/in transit, key rotation, cert management)
  • Clear communication skills and ability to partner with cross‑functional teams
  • Must be a US citizen living within the United States
  • Understanding of cybersecurity principles, practices, and frameworks, including JSIG, NIST 800-171, NIST 800-53, ITAR, and CMMC

Preferred Qualifications

  • DevSecOps experience embedding security into CI/CD, artifact signing, and SDLC governance
  • Container/Kubernetes security (admission controls, runtime policies, image scanning)
  • Data protection and privacy controls (DLP, tokenization, data classification)
  • Identity security (SSO/MFA, conditional access, PAM, IGA) and Zero Trust architectures
  • Threat intelligence integration and use-case development; basic digital forensics
  • SOAR playbook design and automation; custom detections and log enrichment
  • Experience with regulatory environments (e.g., healthcare, fintech, government)
  • Contributions to security architecture reviews and risk assessments at scale
  • Certifications a plus: Security+, GSEC, GCIH, GCIA, GCED, CISSP, CCSP, CCSK, OSCP, AZ‑500, SC‑100, AWS Security Specialty
  • Experience with tools such as Splunk/Microsoft Sentinel, CrowdStrike/Defender, Qualys/Nessus, Burp/ZAP, Prisma/Aqua/Twistlock, Trivy, Checkov/tfsec, Vault/KMS, Okta/Azure AD, Palo Alto/Fortinet, Elastic
  • Active TS Security Clearance

Benefits

We offer highly competitive benefits, including:

  • Medical/Dental/Vision
  • Employee Premiums are 100% Company Paid
  • Life Insurance
  • Flexible Work Hours
  • Unlimited Paid Time Off (PTO) with federal government holidays

Note - some benefits are not available to interns or contractors.

Thank you for your interest in Istari. Expect to hear back from us soon with next steps.

Job details

  • Seniority level: Not Applicable
  • Employment type: Full-time
  • Job function: Information Technology
  • Industries: Transportation, Logistics, Supply Chain and Storage

Referrals increase your chances of interviewing at Istari Digital by 2x

Linux Cryptography and Security Engineer

#J-18808-Ljbffr
Entreprise
Istari Digital
Plateforme de publication
WHATJOBS
Offres pouvant vous intéresser
PARIS, 75
il y a 23 jours
PARIS, 75
il y a 23 jours
PARIS, 75
il y a 23 jours
Soyez le premier à postuler aux nouvelles offres
Soyez le premier à postuler aux nouvelles offres
Créez gratuitement et simplement une alerte pour être averti de l’ajout de nouvelles offres correspondant à vos attentes.
* Champs obligatoires
Ex: boulanger, comptable ou infirmière
Alerte crée avec succès