> Markdown version of [/jobs/ext/547191-information-security-engineer-iii](https://www.wearedevelopers.com/jobs/ext/547191-information-security-engineer-iii). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Information Security Engineer III - **Company:** Conduent, Inc. - **Location:** United States (Remote available) - **Experience:** Experienced - **Salary:** $91,438.0 - $118,750.0 - **Contract:** Permanent contract - **Skills:** Microsoft Word, Microsoft Excel, Application Firewall, Software System Penetration Testing, User Authentication, Collaborative Software, Cyber Security, Disaster Recovery, Identity and Access Management, Information Technology Audit, Intrusion Detection Systems, Network Security, Microsoft Project, Microsoft Visio, Network Architecture, PCI Data Security Standards, Microsoft PowerPoint, Information Technology Security Auditing, Service Pack, Microsoft SharePoint, Data Streaming, Software Vulnerability Management, Wireless Networks, Nessus, Splunk, Servicenow, Vulnerability Analysis - **Published:** June 5, 2026 - **Apply:** https://dejobs.org/x/x/B67071AF7D9545069EDE4F84F6D2CC84/job/ ## About the Role * CIPP, CRISC, CISA, CISSP, CISM, ISO or any security/IT audit certification is a plus. * Minimum of Five (4 to 5) Years of experience in IT Security, or Security Auditing is required. * Knowledge and understanding of security controls across all security domains, such as access management, encryption, vulnerability management, authentication, authorization, network security, physical security, etc. * Ability to identify security risks in application, system, and network architecture, data flow, and processes or procedures * Ability to assess the organizational impact of identified security risks and recommend solutions or mitigating controls. * Knowledge of security technologies, devices, and countermeasures, as well as the threats they are designed to counter. * Experience with developing security reports, recommendations, policies, and procedures that are meaningful, defensible, and actionable for a variety of audiences. * Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). * Experience in PowerPoint, Word, Excel; experience with Visio and MS Project. * Communication skills (interpersonal, verbal, presentation written, email). Experience to write report segments and to participate in presentations. * Familiarity with security, workflow, and collaboration tools such Nessus Tenable, Splunk, SharePoint and ServiceNow (Snow) is a plus * Positive attitude, team player, self-starter; takes initiative, ability to work independently and effectively with all levels of staff and management both internally and externally, * Familiarity with more than one framework (NIST 800-series, ISO 27000-series, PCI DSS and ISO, HIPAA, HITRUST, FISMA, FedRAMP other common security control frameworks). ## Description The Information Security Engineer III serves as a member of the NIST CISO Audit & Assurance team and will assist in the performance of internal audits, ensuring they comply with applicable Conduent and ISO security standards, regulations, and policies. The internal auditor will be professional, independent, impartial, and fair in all interactions. * The NIST security resource is accountable for procedures and processes that ensure the integrity, confidentiality, and availability of assigned Business units' information, applications, and infrastructure. * The resource will perform routine risk assessments, security audits, and vulnerability scans to identify, evaluate, document, and remediate organization risk, control gaps and vulnerabilities. * This position will be responsible for developing security reports, security recommendations, and security policies and procedures that are meaningful, defensible, and actionable for a variety of audiences as pertained to assigned business units. * Perform log collection, correlation, reviews, archival, retention, and monitoring of automated alerts for items such as, and not limited to: * IPS/IDS alerts; change detection (FIM) alerts * application firewall alerts; malware alerts * rogue wireless network alerts * security system health alerts; exploit attempt alerts * Participate and be an integral component of audit, compliance, and regulatory functions, including and not limited to: * audits of system security to ensure compliance with Corporate security framework * NIST 800-53, ISO 27001/2, PCI-DSS * emerging country, state, and Federal privacy laws * Primary POC in a vulnerability management program of the account that includes: * external and internal vulnerability scans of applications and systems * external and internal penetration tests of applications and systems * documentation and remediation of identified vulnerabilities and exploits * routinely monitoring various communication avenues for security vulnerabilities and security patches * taking a risk-based approach comparing those security vulnerabilities and security patches across the operating environments * making recommendations to various IT teams on the mitigation process for those identified security vulnerabilities * Coordinate with business units, operations, and technology teams for incident response, remediation, and improvement * Acts as the initial point of contact to facilitate the handling of security audits and client requests * Supports the creation of business continuity/disaster recovery plans, to include conducting disaster recovery tests, publishing test results, and making changes necessary to address deficiencies * Maintain documentation that supports the annual Security compliance attestation as it is relevant to the assigned Business units, * Creating and Maintaining NIST 800-53-rev5 based SSP and POAM ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Robots are coming into the wild! Full-Stack Robotics Engineers, be ready!](https://www.wearedevelopers.com/videos/479-robots-are-coming-into-the-wild-full-stack-robotics-engineers-be-ready) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Top-Paying Tech Jobs (with Salaries)](https://www.wearedevelopers.com/magazine/372-top-paying-tech-jobs-with-salaries)