Senior Corporate Security Specialist II

ActBlue

Standort: Remote, United States (Remote)

WHO WE ARE ActBlue is a nonprofit organization dedicated to creating cutting-edge technology that fuels Democratic victories and enables progressive causes to thrive. Our vision is simple: building change through the power of people. Since our founding, we’ve been building innovative solutions to revolutionize grassroots fundraising – if you’ve donated to a Democratic campaign or a progressive organization online, you’ve probably used our platform! We believe in putting power in the hands of small-dollar donors by helping thousands of groups — from local candidates to national movements — mobilize their communities and create a lasting impact. Every member of our team is deeply committed to advancing our shared mission and core values. Together, we are shaping the future of democracy. THE OPPORTUNITY The Security Team at ActBlue works to protect ActBlue from threat actors that might target ActBlue, our donors, our employees, and the campaigns and organizations that fundraise on our platform. Our security program is anchored in empathy for our stakeholders, which is a primary value for our team. Corporate Security is the function responsible for safeguarding ActBlue’s people and information. We run security operations and incident response — including the on-call rotation — own and operate ActBlue’s SIEM and detection stack, secure our email and endpoints, deliver workforce security training and tabletop exercises, produce threat intelligence, and conduct employee investigations and sensitive matter reviews. Employee investigations and reviews of sensitive matters are core to this function. This is senior-level work requiring independence, discretion, and strict confidentiality, as well as prior experience leading investigations. The role also touches related domains such as AI security, identity, and audit support, in coordination with other security teams. The Senior Corporate Security Specialist II is an experienced individual contributor who builds and tunes detections that protect ActBlue, independently leads complex security reviews, and serves as a trusted resource for the Security team and its partners. You will report to the Sr. Manager of Security, who sets the direction of the function. Discretion is a core competency for this role. Sensitive matter reviews are conducted with forensically sound evidence handling, chain-of-custody discipline, and a confidentiality-by-default posture. WHAT YOU WILL DO Security Operations & Detection Author, tune, and maintain detections as code in our SIEM/SOAR pipeline — version-controlled, peer-reviewed, tested, and deployed through the detection pipeline Identify detection and tooling gaps and propose architecture improvements Serve on the on-call rotation and coordinate day-to-day escalations with our third-party managed SOC, maintaining the detection feedback loop Operate email security, endpoint security, and DLP controls; investigate and resolve high-sensitivity signals and tune controls based on what investigations surface Run tabletop exercises, deliver workforce security training, and produce threat intelligence that shapes team priorities Restrict, suspend, or revoke an employee's system access when a review identifies active risk, pending completion of that review Define security requirements and detection coverage for identity and audit collection across corporate systems Sensitive Matter Reviews Conduct investigations and sensitive matter reviews with forensically sound evidence handling, chain-of-custody discipline, and confidentiality by default Lead complex reviews independently — employee conduct, insider risk, access misuse, data exfiltration — co-leading or escalating the most sensitive matters Conduct forensic analysis across endpoint, identity, email, cloud, and SaaS sources Produce findings, evidence summaries, technical analyses, and timelines for key stakeholders Preserve evidence for legal holds and formal proceedings Interpret findings in context and recommend resolutions, rather than providing raw technical output alone Standards and Practice Apply and improve Corporate Security methodology, evidence standards, and reporting standards; Manage the SOC relationship and coordinate forensic vendors and external specialists, treating both as extensions of the team's capacity Exercise independent judgment over review methodology and evidence handling within established standards Maintain the chain-of-custody, evidence-handling, and confidentiality controls used by Corporate Security WHAT YOU BRING 5 to 7 years of security experience, including hands-on experience leading complex corporate-security and workplace investigations Hands-on experience conducting forensic investigations across endpoint, identity, email, cloud, and SaaS data sources Practical fluency with detection engineering as code, including authoring, testing, and tuning detections in a version-controlled pipeline Working experience with forensically sound evidence collection and preservation — including chain-of-custody discipline, hashing, custodian-based collection, and eDiscovery / legal-hold workflows Sound judgment about what evidence to collect, how to preserve it, and what to share with whom A track record of producing review findings and recommendations that have held up to scrutiny Comfort working with internal or external counsel, and directing forensic vendors on assigned engagements Understanding of the legal context in which corporate-security matters arise, including the limits and obligations that apply to management-side reviews Strong written and verbal communication, including the ability to explain technical findings to non-technical audiences Experience working alongside a managed SOC or MSSP, including escalation management Experience with infrastructure-as-code workflows in Terraform and Python for logging, alerting, and security automation Experience securing Google Workspace, Okta, GitHub, and Atlassian environments Experience supporting PCI evidence collection and response WORK & BENEFITS SNAPSHOT This posting is for a full-time, remote, salaried position. Travel may be required to attend all-staff, departmental retreats, or select meetings. Additional travel may be required for select positions. Registered States*: Arizona, California, Colorado, Connecticut, Florida, Georgia, Hawaii, Illinois, Indiana, Iowa, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, New Hampshire, New Jersey, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, Wyoming, and Washington D.C. *While ActBlue is currently registered to support remote work in the states listed above, we possess the ability to register in additional states as needed. If you are located in a state not listed, we may still be able to proceed with your application, but please note that the offer process may take longer to accommodate registration requirements. Work Schedule: This role requires availability during established, regular business hours (Mon-Fri) and is expected to be a part of an on-call rotation which will result in working nontraditional hours as needed. Work Environment: Employees can expect to work with distributed teams across all U.S. time zones. Our roles require extended technology usage, and proficiency with virtual communication tools such as Zoom and Slack. Regular attendance in virtual meetings is inherent to every position. Salary Range Details: Salary Range: $173,676 - $192,209 - $210,741 ActBlue is committed to consistent compensation practices across our organization. Final salary offers will take into account factors such as candidate experience, interview performance and current team salary parity. Benefits: Flexible work schedules and an unlimited time-off policy Fully paid and trans-inclusive health, dental

Ähnliche Stellen in Remote

Diese Stelle ansehen und bewerben auf PublicJobs