KPA

KPA

KPA provides comprehensive Environmental Health and Safety (EHS) software, expert consulting, and award-winning training to help organizations improve safety, ensure compliance, and reduce risks across various industries.

Professional Services
251-1K
Founded 1986

Description

  • Own KPA's enterprise security platforms, including CrowdStrike, Rapid7, Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies.
  • Lead vulnerability management, remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives.
  • Lead security incident response, investigations, containment, remediation, and post-incident reviews.
  • Own SOC 2 controls, security audit requirements, and technical compliance initiatives.
  • Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity.
  • Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud-native workloads.
  • Administer and improve identity governance across SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture.
  • Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads.
  • Own and improve cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes.
  • Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI-assisted development.
  • Lead security assessments for new vendors, SaaS platforms, cloud services, and third-party integrations, and support vendor risk management.
  • Administer and improve the security awareness program, security policies, standards, and technical procedures.
  • Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies.
  • Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives.
  • Identify security gaps, technical debt, and opportunities to improve security through automation and modern engineering practices.

Requirements

  • 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role.
  • Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles.
  • Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux.
  • Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices.
  • Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies.
  • Experience supporting SOC 2 and NIST CSF or comparable security and compliance frameworks.
  • Relevant certifications such as CompTIA Security+, CISSP, CCSP, or AWS Certified Security are preferred.
  • Excellent communication, documentation, project leadership, and problem-solving skills.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or equivalent experience.

Benefits

  • Annual base salary range of $110,000-$150,000, commensurate with experience.
  • 10% annual bonus potential.
  • Full-time, exempt position.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Senior Detection Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring a Senior Detection Engineer to help build and operate detection engineering for its global cyber defense function across DoorDash, Deliveroo, and Wolt.

Go Python SIEM Snowflake SQL
1 hour, 8 minutes ago

Staff Security Engineer

Redox 51-250 Internet Software & Services

Redox is hiring a Staff Security Engineer to own cloud-native and application security for its remote healthcare data exchange platform, with a focus on hardening systems and driving secure-by-default engineering practices.

Argo CD AWS CI/CD CrowdStrike Docker GitHub Actions Go HashiCorp Vault Helm Kafka Kubernetes LLM Node.js PostgreSQL Python Redis Terraform TypeScript
1 hour, 23 minutes ago

IAM Architect - Saviynt

IDMWORKS 51-250 Professional Services

IDMWORKS is hiring an IAM Architect - Saviynt to design and deliver identity and access management solutions that strengthen security and support access control across enterprise environments.

Active Directory Cybersecurity OAuth SAML
1 hour, 23 minutes ago

Quantum Computing/Cryptography Engineer (R-00219)

True Zero Technologies 11-50 Internet Software & Services

True Zero Technologies is hiring a quantum security professional to assess, modernize, and implement post-quantum cryptography solutions for enterprise and government-scale systems.

C++ Encryption Java Python TLS
1 hour, 38 minutes ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers