Crux for technical talent

Build your career in cybersecurity -
your way

01.
Contract/ fractional
Want flexibility and variety? Indicate your target areas of work and your availability, and we will match you with opportunities
You name your own bill rate. You control what you make.
02.
Contract to hire
Sometimes it makes sense both ways to 'try before you buy.' We will match you up with opportunities that allow you to get to know a company and the people before committing to a full time role
03.
Full time
Get matched with full time job opportunities via our job board and proprietary roles that we are recruiting for

How it works‍

Cyber River
01.
Join Crux
Abstract Art
02.
Help us get to know you
Abstract Lightbulb
03.
Access jobs custom tailored to you
Cyber City
04.
Receive ongoing career resources and guidance
Abstract Heart
05.
Find work you love
05.
Find work you love

Recent Jobs

Director - Cybersecurity & CISO
Sempra Infrastructure
State
Texas
Remote Elig.
Hybrid
Seniority
Executive
Domain
Cross-domain
Salary ($K)
190.00
-
Not disclosed
284
Chief Information Security Officer
CalSTRS
State
California
Remote Elig.
Hybrid
Seniority
Executive
Domain
Cross-domain
Salary ($K)
12.00
-
Not disclosed
21
Director Deputy CISO
IDEXX
State
Remote
Remote Elig.
On-site
Seniority
Senior
Domain
Cross-domain
Salary ($K)
-
Not disclosed
Hybrid
State
California
Remote Elig.
Hybrid
Not disclosed
Seniority
Senior
Domain
GRC
Salary ($K)
-
Not disclosed
Oversee and Govern

Company Description

At Western Digital, we are on a mission to unlock the potential of data so people, companies and organizations everywhere can create what’s next. To fulfill our vision, we are always on the lookout for potential team members who share our passion for solving problems to empower others.

When you join Western Digital, you join a legacy more than 50 years in the making. Across our Western Digital®, SanDisk®, SanDisk® Professional, WD® and WD_BLACK™ brands, we have brought some of the most storied advancements in memory and data storage technology to market—and our best, most innovative work is yet to come.

From energizing gaming platforms, to enabling systems to make cities safer and cars smarter and more connected, to powering the data centers behind many of the world’s biggest companies and public cloud, Western Digital is fueling a brighter, smarter future.

Here’s how you can help.

  • Implement enterprise-wide risk management frameworks that aligns with industry standards (e.g. ISO27001, NIST, etc).
  • Lead technical and business process risk assessment activities to identify, evaluate, and prioritize information security risks across the organization, including threats, vulnerabilities, and potential impacts to information and technology assets.
  • Develop and drive implementation of effective risk management strategies to mitigate identified risks, ensuring alignment with industry best practices and regulatory requirements.
  • Collaborate across the organization to ensure the integration of risk management practices into organizational processes and projects.
  • Generate comprehensive reports and metrics to communicate the status of information security risks to stakeholders and leadership.
  • Analyze security data to identify trends, vulnerabilities, and areas for improvement.
  • Collaborate with internal and external auditors to facilitate security audits and assessments.
  • Stay current with industry trends, emerging threats, and best practices for information security and risk management.
  • Provide expert guidance and support in developing and maintaining information security policies, standards, and procedures.

REQUIRED:

  • Bachelor's degree in Information Security, Computer Science, or equivalent work experience.
  • 8+ years of experience in information security, including risk management, risk assessments, reporting, and metrics analysis, and hands-on with at least one of the following: security engineering, network security, identity and access management, security operations, and/or software development security.
  • 4+ years of experience in technical roles, or similar technical proficiency are highly desirable.
  • Proficiency in risk assessment methodologies, tools, and techniques.
  • Experience in conducting risk assessments, vulnerability assessments, and compliance audits.
  • Strong understanding of information security frameworks, standards, and best practices (e.g., ISO 27001, NIST, GDPR).
  • Experience in generating and interpreting information security metrics and reports.

SKILLS:

  • Excellent analytical and problem-solving skills with attention to detail.
  • Strong communication and interpersonal skills, with the ability to explain complex security concepts to non-technical stakeholders.
  • Ability to work independently and collaboratively in a fast-paced environment.
  • Experience in building and maturing information security risk management practices.

PREFERRED:

  • Relevant certifications such as CISSP, CISM, CRISC, GSNA or similar are highly desirable.
  • Technical certifications such as GCIH, GPEN, CEH, OSCP or similar are highly desirable.

Western Digital is committed to providing equal opportunities to all applicants and employees and will not discriminate against any applicant or employee based on their race, color, ancestry, religion (including religious dress and grooming standards), sex (including pregnancy, childbirth or related medical conditions, breastfeeding or related medical conditions), gender (including a person’s gender identity, gender expression, and gender-related appearance and behavior, whether or not stereotypically associated with the person’s assigned sex at birth), age, national origin, sexual orientation, medical condition, marital status (including domestic partnership status), physical disability, mental disability, medical condition, genetic information, protected medical and family care leave, Civil Air Patrol status, military and veteran status, or other legally protected characteristics. We also prohibit harassment of any individual on any of the characteristics listed above. Our non-discrimination policy applies to all aspects of employment. We comply with the laws and regulations set forth in the “Know Your Rights: Workplace Discrimination is Illegal” poster. Our pay transparency policy is available here: Pay Transparency Nondiscrimination Provision (dol.gov)

Western Digital thrives on the power and potential of diversity. As a global company, we believe the most effective way to embrace the diversity of our customers and communities is to mirror it from within. We believe the fusion of various perspectives results in the best outcomes for our employees, our company, our customers, and the world around us. We are committed to an inclusive environment where every individual can thrive through a sense of belonging, respect and contribution.

Western Digital is committed to offering opportunities to applicants with disabilities and ensuring all candidates can successfully navigate our careers website and our hiring process. Please contact us at [email protected] to advise us of your accommodation request. In your email, please include a description of the specific accommodation you are requesting as well as the job title and requisition number of the position for which you are applying.

Based on our experience, we anticipate that the application deadline will be 01/08/2025 (3 months from posting), although we reserve the right to close the application process sooner if we hire an applicant for this position before the application deadline. If we are not able to hire someone from this role before the application deadline, we will update this posting with a new anticipated application deadline.

#LI-AS1

Compensation & Benefits Details

  • An employee’s pay position within the salary range may be based on several factors including but not limited to (1) relevant education; qualifications; certifications; and experience; (2) skills, ability, knowledge of the job; (3) performance, contribution and results; (4) geographic location; (5) shift; (6) internal and external equity; and (7) business and organizational needs.
  • The salary range is what we believe to be the range of possible compensation for this role at the time of this posting. We may ultimately pay more or less than the posted range and this range is only applicable for jobs to be performed in California, Colorado, New York or remote jobs that can be performed in California, Colorado and New York. This range may be modified in the future.
  • You will be eligible to participate in Western Digital’s Short-Term Incentive (STI) Plan, which provides incentive awards based on Company and individual performance. Depending on your role and your performance, you may be eligible to participate in our annual Long-Term Incentive (LTI) program, which consists of restricted stock units (RSUs) or cash equivalents, pursuant to the terms of the LTI plan. Please note that not all roles are eligible to participate in the LTI program, and not all roles are eligible for equity under the LTI plan. RSU awards are also available to eligible new hires, subject to Western Digital’s Standard Terms and Conditions for Restricted Stock Unit Awards.
  • We offer a comprehensive package of benefits including paid vacation time; paid sick leave; medical/dental/vision insurance; life, accident and disability insurance; tax-advantaged flexible spending and health savings accounts; employee assistance program; other voluntary benefit programs such as supplemental life and AD&D, legal plan, pet insurance, critical illness, accident and hospital indemnity; tuition reimbursement; transit; the Applause Program, employee stock purchase plan, and the Western Digital Savings 401(k) Plan.
  • Note: No amount of pay is considered to be wages or compensation until such amount is earned, vested, and determinable. The amount and availability of any bonus, commission, benefits, or any other form of compensation and benefits that are allocable to a particular employee remains in the Company's sole discretion unless and until paid and may be modified at the Company’s sole discretion, consistent with the law.
No items found.
On-site
State
New York
Remote Elig.
On-site
Not disclosed
Seniority
Entry
Domain
GRC
Salary ($K)
-
Not disclosed
Oversee and Govern

Company Description

Wavestone is a global consulting powerhouse dedicated to empowering businesses to navigate today's dynamic and competitive landscape. With a presence in 17 countries and a team of over 5,500 experts, we combine first-class sector expertise with a 360° transformation portfolio of high-value consulting services.

At Wavestone, we go beyond simply offering solutions – we strive to build lasting partnerships with our clients. Our collaborative approach ensures we understand your unique challenges and tailor our strategies to achieve your specific goals. We are passionate about fostering a culture of positive transformation – empowering businesses to not only survive but thrive in the ever-evolving world of technology, digitalization, and artificial intelligence.

As a leading global consulting firm, Wavestone is deeply rooted in the vibrant business landscapes of the United States. With offices in New York City and Dallas, we leverage the innovation and entrepreneurial spirit of these cities to deliver exceptional consulting services. With a deep understanding of industries like Financial Services, Energy, Life Sciences, Healthcare, Transportation, and Retail, we offer a comprehensive range of IT transformation and business consulting services. From Cybersecurity and Operational Resilience to Data Strategy and Artificial Intelligence, Wavestone is a trusted partner in driving positive outcomes and setting new standards of excellence. We support CEOs and tech leaders (CDO, CTO, CISO, etc.) in crafting their IT strategy and optimizing their sourcing models to maximize the value of IT services and business processes.

Our 3 Business Circles and areas of expertise:

  • Digital and Artificial Intelligence Transformation (DAT) – GenAI adoption, maturity benchmarking, cloud strategy, data strategy, service provider & solution selection, IT governance design & implementation
  • Cybersecurity (CYB) - Identity and access management, regulatory remediation, incident response, resilience & crisis management, Strategy & roadmap, 360 OpRes Maturity Assessments
  • Sourcing & Service Optimization (SSO) - Resource model strategy​, vendor rationalization​, go-to-market strategy​, performance delivery valuation​, services continuity strategy​, functional sourcing strategy​

Join us for a rewarding career in management consulting, offering competitive compensation, continuous learning, and many opportunities for professional growth. Shape the future of consulting and make a lasting impact - Apply now to join our team!

Read more at www.wavestone.com

  • Deliver engagements managed by more experienced consultants from whom you will learn the basics of consulting core competencies.
  • Work with teams on projects for the business lines, functional teams, and technology departments of our clients from strategy definition to implementation
  • Bring strong learning abilities and be proactive to better develop consulting skills and become more autonomous.
  • Perform accurate assessments and analysis of client activities, manage day-to-day client relationships at peer client levels and assist clients in the effective use of management systems, tools, techniques, group problem-solving, and team building.
  • Structure, write, and deliver quality work documents with oversight from others, ensure all information related to the assignments is circulated correctly, and alert colleagues/superiors of any difficulties.
  • Collaborate/Coordinate across the different Wavestone teams to participate in local and global firm development.
  • Continue to up-skill and stay current with the market, through our apprenticeship style coaching and our learning and development programs.
  • Contribute to the firm’s development activities such as business development (i.e. proposals, market offers, white papers, etc.) and/or team development activities (i.e. recruitment, training, social events, office culture, etc.)

Required Qualifications:

  • Bachelor’s degree in business management, engineering, economics, or other analytical major
  • Strong interest in Management Consulting and digital technologies
  • Analytical mindset with a developing business acumen

Preferred Qualifications:

  • Strong entrepreneurial mindset, with a passion for innovation and driving growth
  • Exceptional teamwork skills, with a collaborative and supportive approach to working with colleague
  • Ability to complete structured problem solving with senior management support
  • Ability to learn quickly and work through critical business and/or technology challenges
  • Customer centric mindset and excellent interpersonal and communication skills
  • Strong Microsoft Office skills

Our Commitment

Wavestone values and Positive Way

At Wavestone, we believe our employees are our greatest ambassadors. By embodying our shared values, vision, mission, and corporate brand, you'll become a powerful force for positive change. We are united by a shared commitment to making a positive impact, no matter where we are. This is better defined by our value base, "The Positive Way," which serves as the glue that binds us together:

  • Energetic - A positive attitude gives energy to lead projects to success. While we may not control the circumstances, we can always choose how we respond to them.
  • Responsible - We act with integrity and take ownership of our decisions and actions, considering their impact around us.
  • Together - We want to be a great team, not a team of greats. The team's strength is each individual member, each member's strength is the team.

We are Energetic, Responsible and Together!

Benefits

  • 25 PTO / 6 Federal Holidays / 4 Floating Holidays
  • Great parental leave (birthing parent: 4 months | supporting parent: 2 months)
  • Medical / Dental / Vision coverage
  • 401K Savings Plan with Company Match
  • HSA/FSA
  • Up to 4% bonus based on personal and company performance with room to grow as you progress in your career
  • Regular Compensation increases based on performance
  • Employee Stock Options Plan (ESPP)

Travel and Location

This full-time position is based in our New York office. You must reside or be willing to relocate within commutable distance to the office.

Travel requirements tend to fluctuate depends on your projects and client needs.

Diversity and Inclusion

Wavestone seeks diversity among our team members and is an Equal Opportunity Employer.

At Wavestone, we celebrate diversity and inclusion. We have a strong global CSR agenda and an active Diversity & Inclusion committee with Gender Equality, LGBTQ+, Disability Inclusion and Anti-Racism networks.

If you need flexibility, assistance, or an adjustment to our recruitment process due to a disability or impairment, you may reach out to us to discuss this.

Go see our Wavestone website, our US specific page and LinkedIn page to see our most trending insights!

Also, check our Introduction Booklet to read more about Wavestone; and get a feel of our culture hearing what Wavestone employees have to say in our video testimonials!

No items found.
On-site
State
Florida
Remote Elig.
On-site
Not disclosed
Seniority
Experienced
Domain
Application security
Salary ($K)
-
Not disclosed
Protect and Defend

The Application Security Engineer will play a critical role in ensuring the security of our software applications and systems. The primary function of this role is to collaborate with development teams to address security configuration and vulnerability issues, perform in-depth code reviews, and analyze open-source libraries for potential security risks. The successful candidate will have a strong background in application security and secure coding practices, with the ability to work effectively in a fast-paced, agile environment.

<i>The Best Players Need the Best People.</i>

  • Security Configuration & Vulnerability Management:
  • Collaborate with development teams to identify, prioritize, understand, and remediate security configuration issues in applications.
  • Conduct vulnerability assessments on applications and systems, using both automated tools and manual techniques.
  • Provide recommendations and support for fixing identified vulnerabilities, ensuring they are addressed in a timely manner.
  • Code Reviews & Secure Coding Practices:
  • Perform thorough code reviews on internally developed applications, focusing on security vulnerabilities and coding best practices.
  • Review and assess third-party and open-source libraries for security risks and provide guidance on their safe integration into our applications.
  • Work with development teams to integrate security controls and best practices into the software development lifecycle (SDLC).
  • Security Tools & Automation:
  • Utilize and manage security tools and platforms, such as static and dynamic application security testing (SAST/DAST) tools, to enhance the security of our applications.
  • Collaborate with DevOps teams to automate security processes within CI/CD pipelines.
  • Manage and maintain the cybersecurity team’s internally built tools and pipelines.
  • Security Awareness & Training:
  • Assist in developing and delivering secure coding training and awareness programs for developers.
  • Act as a security advocate within the organization, promoting a culture of security awareness and continuous improvement.
  • Documentation & Reporting:
  • Document security vulnerabilities, their remediation plans, and progress, ensuring all stakeholders are kept informed.
  • Prepare reports and metrics on the state of application security, vulnerability management, and code review activities.
  • Special projects or work as assigned.

Required Qualifications:

  • Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent experience.
  • A minimum of 5 years related experience, inclusive of 3+ years of experience in application security, including hands-on experience with code reviews, vulnerability management, and security testing.
  • Strong knowledge of secure coding practices and experience in reviewing code written in languages such as Java, Python, JavaScript, or C#.
  • Familiarity with common security vulnerabilities (e.g., OWASP Top 10) and experience in applying security controls in a development environment.
  • Experience with security tools such as SAST/DAST, dependency checkers, and security monitoring tools.
  • Strong understanding of open-source libraries and the associated security risks.
  • Excellent communication skills with the ability to explain complex security issues to both technical and non-technical audiences.
  • Certifications such as CISSP, CEH, CSSLP, or OSCP are a plus.

Preferred Skills:

  • Experience with cloud security, particularly in AWS environments.
  • Knowledge of DevSecOps practices and experience integrating security into CI/CD pipelines.
  • Understanding of containerization and microservices architecture and associated security considerations.

In order to be considered for this role, after clicking "Apply Now" above and being redirected, you must fully complete the application process on the follow-up screen.

No items found.
Director - Cybersecurity & CISO
Sempra Infrastructure
State
Texas
Remote Elig.
Hybrid
Seniority
Executive
Domain
Cross-domain
Salary ($K)
190.00
-
Not disclosed
284
Chief Information Security Officer
CalSTRS
State
California
Remote Elig.
Hybrid
Seniority
Executive
Domain
Cross-domain
Salary ($K)
12.00
-
Not disclosed
21
Director Deputy CISO
IDEXX
State
Remote
Remote Elig.
On-site
Seniority
Senior
Domain
Cross-domain
Salary ($K)
-
Not disclosed