12 hours ago
Base Salary
$180k - $216k/yr
Responsibilities
- Act as the hands-on security lead across IT and engineering and prioritize security projects across global operations.
- Develop, enforce, and maintain security policies, standards, governance, runbooks, and repeatable processes.
- Investigate security incidents, coordinate response activities, perform root-cause analysis, and serve as an escalation point for complex issues.
- Secure physical networking and cloud infrastructure, including firewalls, segmentation, cloud workloads, IAM, security groups, and permission policies.
- Design and manage least-privilege roles, RBAC, application permissions, user groups, and identity lifecycle access.
- Run user access audits, access reviews, compliance checks, security scans, monitoring, alerting, and reporting.
- Administer enterprise AI tools such as Claude and evaluate new AI capabilities, integrations, guardrails, and local MCP servers.
- Review systems, code, third-party components, and open-source components for security risks and secure integration practices.
- Gather and maintain audit evidence and validate controls for J-SOX, NIST, CMMC 2.0, and SOC 2.
- Automate manual security work and keep security documentation and internal knowledge bases current.
Requirements
- Senior-level expertise across identity and access management, infrastructure and cloud security, governance and compliance, incident response, application and integration security, and AI/LLM security.
- Hands-on incident investigation experience and the judgment to handle phishing, spam, and other user-facing threats.
- Hands-on experience securing networking and cloud infrastructure, including firewalls, segmentation, IAM, security groups, permission policies, and application permissions.
- Cloud security experience with AWS, Azure, or similar platforms and experience designing roles and RBAC with Microsoft Entra ID, Okta, or AWS IAM.
- Familiarity with security monitoring and detection tools and experience conducting user access audits, access reviews, and compliance checks.
- Experience supporting SOC 2, NIST 800-53/800-171, CMMC 2.0, and J-SOX programs through evidence gathering and control validation.
- Application security experience including automation tooling, code review for security issues, and secure integration practices.
- Working knowledge of AI and LLM security, including AI tool administration, risk evaluation, and MCP server integrations.
- Ability to make independent security decisions, prioritize competing initiatives, automate manual processes, and communicate across a global multi-site organization.
- Preferred certifications include CISSP, CISM, Security+, or GIAC certifications such as GSEC or GCIH.
- Preferred experience includes CMMC 2.0 assessments, global Japanese-owned company audit and controls work, and scripting with Bash, Python, or PowerShell.
Benefits
- Oakland, California location with 0–10% travel expected.
- Applicants must be U.S. citizens or Green Card holders.
- The role involves primarily computer-based work with extended periods of sitting.
About Fictiv
Fictiv builds a digital platform for on-demand manufacturing of custom parts, offering CNC machining, 3D printing, and urethane casting from prototype through low-volume production. Companies use its global manufacturing network and hubs in the U.S., China, India, and Mexico to source parts and manage supply chains. Founded in 2013 and headquartered in the San Francisco Bay Area, Fictiv was acquired by Misumi Group and has delivered over 35 million parts.
