Cybersecurity Specialist
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+11 more
Job description
Be an Early Applicant In-Office Longmont, CO, USA Entry level In-Office Longmont, CO, USA Entry level Operate cybersecurity controls across corporate, cloud, and SaaS environments; support ISO 27001 and SOC 2 compliance, GRC administration, access reviews, incident response, vulnerability management, vendor risk, audit evidence, and security awareness programs. The summary above was generated by AI, * Operate and enforce Kraken’s day-to-day information security controls across corporate, cloud, and SaaS environments.
- Support Kraken’s ISO/IEC 27001 Information Security Management System (ISMS) by monitoring control operation, maintaining evidence, addressing control gaps, and updating risk register.
- Support SOC 2 Type II compliance by ensuring security and availability controls operate effectively and are supported by accurate, auditable evidence.
- Administer and maintain Kraken’s GRC platform (Vanta) to support control tracking, evidence collection, remediation management, and audit activities.
- Enforce access control processes, including user onboarding and offboarding, privileged access reviews, and periodic access recertification.
- Monitor and respond to security alerts and incidents in coordination with managed detection and response (MDR) and SOC providers.
- Support incident response activities, including investigation, documentation, corrective actions, and post-incident review.
- Validate operational security controls such as logging, monitoring, vulnerability management, backup verification, and configuration compliance.
- Support cybersecurity infrastructure and policy projects, including the implementation and rollout of new security tools, platforms, and control capabilities.
- Enforce secure system usage and data handling requirements, escalating non-compliance and control failures as appropriate.
- Support third-party security and vendor risk management activities, including review of ISO 27001 certifications, SOC 2 reports, and related assurance artifacts.
- Identify gaps between documented controls and operational practice and work with internal teams to drive remediation and continuous improvement.
- Provide guidance to users on secure system usage and data handling requirements in line with company policy.
- Support the delivery of the organization’s security awareness and phishing resistance program using KnowBe4, including administration of training campaigns, simulated phishing exercises, and post-email analysis workflows, and contributing to user remediation and reporting activities., Support a global 24x7x365 security operations team by monitoring systems and networks, investigating threats and incidents, responding to phishing, malware, breaches, and cyberattacks, deploying countermeasures, analyzing post-event activity, assessing vulnerabilities, and improving security protocols. The role requires familiarity with cloud security controls, network protocols, operating systems, scripting, web technologies, penetration testing tools, and threat intelligence. Top Skills: AspBashBurp SuiteChronicle DetectCloud ArmorData Security Posture ManagementGoogle Cloud Platform (Gcp)Google SecopsJavaKqlLinuxmacOSMetasploitNmapPHPPowershellSecurity Command CenterSQLWeb Security ScannerWindowsWiresharkYara Federal Reserve System
Requirements
- Post-secondary education in Cybersecurity, Information Technology, Computer Science, or a related field, or equivalent practical experience.
- Experience supporting operational cybersecurity, information security programs, or compliance initiatives.
- Working knowledge of ISO/IEC 27001, SOC 2 Trust Services Criteria, and common operational security controls.
- Experience collecting, maintaining, and validating audit-ready security evidence.
- Experience working with GRC platforms (e.g., Vanta or similar) is strongly preferred.
- Technical security knowledge across areas such as identity and access management, endpoint security, logging and monitoring, vulnerability management, and secure system configuration.
- Experience operating in regulated, customer-assessed, or compliance-driven environments is an asset.
PREFERRED SKILLS
- Strong written and verbal communication skills, with the ability to explain security requirements clearly to technical and non-technical audiences.
- High attention to detail and a disciplined, evidence-driven approach to security operations.
- Ability to translate security requirements into practical, enforceable operational controls.
- Strong organizational and time-management skills in a multi-priority environment.
- Self-motivated with a proactive mindset and a commitment to continuous improvement.
- Relevant certifications (e.g., Security+, SSCP, CISSP, ISO 27001 Lead Implementer/Auditor) are considered assets.
Benefits & conditions
In-Office or Remote 10 Locations 130K-179K Annually Senior level 130K-179K Annually Senior level Fintech * Payments * Financial Services This role involves leading red team cybersecurity efforts to evaluate and improve the security posture of the Federal Reserve System through advanced attack simulations and vulnerability assessments. Top Skills: C#GoPowershellPython Wipfli
Quality Assurance Lead
12 Minutes Ago Remote or Hybrid United States 97K-131K Annually Senior level 97K-131K Annually Senior level Cloud * Fintech * Software * Business Intelligence * Consulting * Financial Services Leads end-to-end quality assurance for Workday implementations, upgrades, and enhancements. Defines testing strategies, plans, frameworks, and risk mitigation; oversees functional, integration, regression, and UAT testing across Workday modules. Manages defects, test data, environments, release validation, reporting, and stakeholder sign-off. Coordinates QA activities among business teams, developers, system integrators, vendors, and delivery partners while ensuring adherence to quality standards and governance. Top Skills: Azure DevopsErpJIRAWorkday
What you need to know about the Colorado Tech Scene
With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Fully Remote Software Engineer Jobs
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
Dev Digest 134 - Where pixels sing?
Is Software Engineering Over-Saturated?