Halcyon Logo

Halcyon

Senior Information Security Specialist

Posted 8 Days Ago
Remote
Hiring Remotely in US
120K-160K Annually
Senior level
Remote
Hiring Remotely in US
120K-160K Annually
Senior level
Supports enterprise cybersecurity and GRC programs through third-party risk assessments, security testing coordination, corrective action tracking, policy development, compliance support, incident response planning, disaster recovery exercises, and enforcement of technical and administrative controls. Partners with engineering, operations, managed security providers, and internal stakeholders to strengthen security posture across cloud and hybrid environments.
The summary above was generated by AI

What we do:
Halcyon is the industry’s first dedicated, adaptive security platform that combines multiple proprietary advanced prevention engines along with AI models focused specifically on stopping ransomware.

Who we are:
Halcyon was formed in 2021 by a team of cyber industry veterans after battling the scourge of ransomware (and advanced threats) for years at some of the largest global security vendors. Comprised of leaders from Cylance (now Blackberry), Accuvant (now Optiv), Fireye and ISS X-Force (now IBM), Halcyon is focused on building products and solutions for mid-market and enterprise customers.

As a remote-native, completely distributed global team, we recognize great talent can exist anywhere. We invite you to apply to a job you’re interested in and we'll work a plan to meet your needs.

The Role:

Halcyon is seeking a seasoned and collaborative Senior Information Security Specialist to support the advancement of our cybersecurity and GRC (Governance, Risk, and Compliance) programs. In this role, you will play a critical part in strengthening our enterprise-wide security posture by coordinating across teams, managing third-party risk, supporting compliance initiatives, and maturing internal security processes and documentation. Your responsibilities will span operational security, risk assessment, policy development, and incident response preparedness.

Responsibilities:

  • Perform and maintain third-party risk assessments and track vendor remediation activities.
  • Support coordination and analysis of internal and external security testing, including vulnerability scans and penetration tests.
  • Develop, track, and follow up on corrective action plans for identified security gaps or audit findings.
  • Collaborate with managed security service providers and internal stakeholders to monitor and manage security events and escalations.
  • Partner with engineering and operations teams to ensure implementation of security and compliance requirements across the organization.
  • Assist in developing, maintaining, and communicating information security policies, standards, and procedures.
  • Coordinate security incident response planning, disaster recovery testing, and business continuity exercises.
  • Monitor and support enforcement of technical and administrative security controls across the enterprise.
  • Stay current with evolving security and privacy regulations and frameworks (e.g., SOC 2, ISO 27001, TX-RAMP, FedRAMP).

Skills and Qualifications:

  • 5+ years of experience in information security, GRC, or IT risk management.
  • Strong understanding of cybersecurity concepts, controls, and risk frameworks.
  • Demonstrated experience with third-party risk management processes and tooling.
  • Proven ability to coordinate security testing and vulnerability management efforts.
  • Excellent communication, documentation, and cross-functional collaboration skills.
  • Ability to assess and implement technical and administrative controls across cloud and hybrid environments.
  • Experience with regulatory compliance and audit support in fast-paced environments.
  • Hands-on participation in incident response or disaster recovery exercises is a plus.

Bonus Skills and Qualifications:

  • Experience with compliance platforms (e.g., Drata, Vanta).
  • Knowledge of security frameworks beyond SOC 2 and ISO 27001, such as NIST 800-53 or CIS Controls.
  • Familiarity with secure software development practices or DevSecOps principles.
  • Background in auditing or supporting third-party security assessments.
  • Experience with Microsoft 365 and/or Google Workspace security configuration.
  • Exposure to regulatory environments such as HIPAA, GDPR, or CCPA.
  • Certifications such as CISSP, CISA, CISM, Security+, or similar are a plus.

Benefits: 

Halcyon offers the following benefits to eligible employees: 

  • Comprehensive healthcare (medical, dental, and vision) with premiums paid in full for employees and dependents. 
  • Short and long-term disability coverage, basic life and AD&D insurance plans. 
  • Medical and dependent care FSA options. 
  • 401k plan with a generous employer contribution. 
  • Flexible PTO policy. 
  • Parental leave. 
  • Generous equity offerings. 

The Company reserves the right to modify or change these benefits programs at any time, with or without notice. 

The expected base salary range for this position is $120,000 - $160,000. Compensation varies based on a variety of factors which include (but are not limited to) role level, skills and competencies, qualifications, knowledge, location, and experience. In addition to base pay, certain roles are eligible to participate in our bonus or commission plans, as well as our benefits offers, and equity awards. 

In accordance with applicable state and federal laws, the range provided is Halcyon’s reasonable estimate of the base compensation for this role. The actual amount may differ based on non-discriminatory factors such as experience, knowledge, skills, abilities, and location. Base pay is one part of the total package that is provided to compensate and recognize employees for their work, and this role may be eligible for additional discretionary bonuses/incentives, and equity in the Company.

We understand it takes a diverse team of highly intelligent, passionate, curious, and creative people to develop the exceptional product we are building. Our dynamic team has incredible perspectives to share, just as we know you do, and we take great pride in being an equal opportunity employer.

HQ

Halcyon Austin, Texas, USA Office

Austin, Texas, United States, 73301

Similar Jobs

4 Days Ago
Remote
MD, USA
150K-200K Annually
Senior level
150K-200K Annually
Senior level
Information Technology
Monitors and analyzes cybersecurity events, supports incident response and continuous monitoring, and manages DoD authorization-to-operate activities. Designs secure architectures, maintains RMF documentation, POA&Ms, STIGs, vulnerability assessments, system inventories, and authorization records. Audits security logs, coordinates risk mitigation and recovery, supports system accreditation and decommissioning, and advises government, engineering, operations, and system-owner stakeholders on security posture and compliance.
Top Skills: AppdynamicsAto Lifecycle ManagementCnssi 1253Disa StigsDod Risk Management FrameworkDodi 8510.01FismaIcd 503Nist Sp 800-30Nist Sp 800-37Nist Sp 800-39Nist Sp 800-53Poa&MScomScorchSecurity MonitoringSolarwindsSplunkVulnerability ScanningXacta
11 Days Ago
Remote
USA
57K-63K Annually
Senior level
57K-63K Annually
Senior level
Social Impact
Monitors and triages security alerts, investigates and documents incidents, supports identity and access management, vulnerability remediation, security awareness, phishing simulations, incident response, and security control checks. Collaborates with IT teams and an MSSP to resolve security issues, tune security tools, maintain documentation, and escalate threats. Requires availability for identity and access management, incident response, and escalation outside standard business hours.
Top Skills: AzureContent FilteringDns SecurityEdr/XdrEmail SecurityFirewallsIdentity And Access ManagementMfaMicrosoft 365Phishing ProtectionSIEMSsoVulnerability Scanning
Senior level
Information Technology • Professional Services • Defense • Manufacturing
Leads federal cybersecurity program management and ISSO activities for FHWA systems. Manages plans, schedules, risks, deliverables, staffing, reporting, audits, contingency testing, authorization documentation, vulnerability remediation, security assessments, cloud controls, DevSecOps, incident support, and compliance with FISMA, NIST, FIPS, and FedRAMP requirements. Advises system owners, developers, infrastructure teams, and government stakeholders on cybersecurity risk and information assurance.
Top Skills: Active DirectoryBigfixCsamData-Loss-Prevention TechnologiesDevsecopsDynamic Application Security Testing ToolsElasticsearchFirewallsIntrusion-Detection SystemsIntrusion-Prevention SystemsJcamLinuxAzureExcelMicrosoft PowerpointMicrosoft TeamsMicrosoft VisioMicrosoft WordNetsparkerSharepointSplunkStatic Application Security ScannersSynackTableauTenable NessusWindows Server

What you need to know about the Austin Tech Scene

Austin has a diverse and thriving tech ecosystem thanks to home-grown companies like Dell and major campuses for IBM, AMD and Apple. The state’s flagship university, the University of Texas at Austin, is known for its engineering school, and the city is known for its annual South by Southwest tech and media conference. Austin’s tech scene spans many verticals, but it’s particularly known for hardware, including semiconductors, as well as AI, biotechnology and cloud computing. And its food and music scene, low taxes and favorable climate has made the city a destination for tech workers from across the country.

Key Facts About Austin Tech

  • Number of Tech Workers: 180,500; 13.7% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Dell, IBM, AMD, Apple, Alphabet
  • Key Industries: Artificial intelligence, hardware, cloud computing, software, healthtech
  • Funding Landscape: $4.5 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Live Oak Ventures, Austin Ventures, Hinge Capital, Gigafund, KdT Ventures, Next Coast Ventures, Silverton Partners
  • Research Centers and Universities: University of Texas, Southwestern University, Texas State University, Center for Complex Quantum Systems, Oden Institute for Computational Engineering and Sciences, Texas Advanced Computing Center

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account