Senior Corporate Security Specialist

ActBlue

United States

Remote

USD 174,000 - 211,000

Full time

12 days ago
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Benefits offered by this job

Flexible work schedules
Comprehensive health benefits
401K with company match
Home office stipend
Unlimited time off

Job summary

ActBlue’s Security Team is hiring a Senior Corporate Security Specialist II to lead investigations, build detections, and guide forensic reviews for enterprise protection. This role handles on‑call rotations, threat intelligence, and escalation with a managed SOC, while ensuring strict confidentiality and chain‑of‑custody discipline.

You will collaborate across security domains, coordinate with counsel, and apply a robust, evidence‑driven approach to security operations, identity auditing, and

Qualifications

  • 5 to 7 years of security experience, including hands‑on experience leading complex corporate‑security and workplace investigations.
  • Hands‑on experience conducting forensic investigations across endpoint, identity, email, cloud, and SaaS data sources.
  • Practical fluency with detection engineering as code, including authoring, testing, and tuning detections in a version‑controlled pipeline.
  • Working experience with forensically sound evidence collection and preservation — including chain‑of‑custody discipline, hashing, custodian‑based collection, and eDiscovery / legal‑hold workflows.
  • Sound judgment about what evidence to collect, how to preserve it, and what to share with whom.
  • A track record of producing review findings and recommendations that have held up to scrutiny.
  • Comfort working with internal or external counsel, and directing forensic vendors on assigned engagements.
  • Understanding of the legal context in which corporate‑security matters arise, including the limits and obligations that apply to management‑side reviews.
  • Strong written and verbal communication, including the ability to explain technical findings to non‑technical audiences.
  • Experience with infrastructure‑as‑code workflows in Terraform and Python for logging, alerting, and security automation.
  • Experience securing Google Workspace, Okta, GitHub, and Atlassian environments.
  • Experience supporting PCI evidence collection and response.

Responsibilities

  • Author, tune, and maintain detections as code in our SIEM/SOAR pipeline — version-controlled, peer-reviewed, tested, and deployed through the detection pipeline.
  • Identify detection and tooling gaps and propose architecture improvements.
  • Serve on the on-call rotation and coordinate day-to-day escalations with our third‑party managed SOC, maintaining the detection feedback loop.
  • Operate email security, endpoint security, and DLP controls; investigate and resolve high‑sensitivity signals and tune controls based on what investigations surface.
  • Run tabletop exercises, deliver workforce security training, and produce threat intelligence that shapes team priorities.
  • Restrict, suspend, or revoke an employee’s system access when a review identifies active risk, pending completion of that review.
  • Define security requirements and detection coverage for identity and audit collection across corporate systems.
  • Conduct investigations and sensitive matter reviews with forensically sound evidence handling, chain‑of‑custody discipline, and confidentiality by default.
  • Lead complex reviews independently — employee conduct, insider risk, access misuse, data exfiltration — co‑leading or escalating the most sensitive matters.
  • Conduct forensic analysis across endpoint, identity, email, cloud, and SaaS sources.
  • Produce findings, evidence summaries, technical analyses, and timelines for key stakeholders.
  • Preserve evidence for legal holds and formal proceedings.
  • Interpret findings in context and recommend resolutions, rather than providing raw technical output alone.

Skills

Security investigations
Forensic investigations
Detection engineering as code
Terraform
Python
Google Workspace
Okta
GitHub
Atlassian environments
MSSP
Incident response
On-call rotation

Tools

SIEM/SOAR pipeline

Job description

WHO WE ARE

ActBlue is a nonprofit organization dedicated to creating cutting-edge technology that fuels Democratic victories and enables progressive causes to thrive.

Our vision is simple: building change through the power of people. Since our founding, we’ve been building innovative solutions to revolutionize grassroots fundraising – if you’ve donated to a Democratic campaign or a progressive organization online, you’ve probably used our platform! We believe in putting power in the hands of small-dollar donors by helping thousands of groups — from local candidates to national movements — mobilize their communities and create a lasting impact. Every member of our team is deeply committed to advancing our shared mission and core values. Together, we are shaping the future of democracy.

THE OPPORTUNITY

The Security Team at ActBlue works to protect ActBlue from threat actors that might target ActBlue, our donors, our employees, and the campaigns and organizations that fundraise on our platform. Our security program is anchored in empathy for our stakeholders, which is a primary value for our team.

Corporate Security is the function responsible for safeguarding ActBlue’s people and information. We run security operations and incident response — including the on-call rotation — own and operate ActBlue’s SIEM and detection stack, secure our email and endpoints, deliver workforce security training and tabletop exercises, produce threat intelligence, and conduct employee investigations and sensitive matter reviews.

Employee investigations and reviews of sensitive matters are core to this function. This is senior-level work requiring independence, discretion, and strict confidentiality, as well as prior experience leading investigations. The role also touches related domains such as AI security, identity, and audit support, in coordination with other security teams.

The Senior Corporate Security Specialist II is an experienced individual contributor who builds and tunes detections that protect ActBlue, independently leads complex security reviews, and serves as a trusted resource for the Security team and its partners. You will report to the Sr. Manager of Security, who sets the direction of the function.

Discretion is a core competency for this role. Sensitive matter reviews are conducted with forensically sound evidence handling, chain-of-custody discipline, and a confidentiality-by-default posture.

WHAT YOU WILL DO
Security Operations & Detection
  • Author, tune, and maintain detections as code in our SIEM/SOAR pipeline — version-controlled, peer-reviewed, tested, and deployed through the detection pipeline
  • Identify detection and tooling gaps and propose architecture improvements
  • Serve on the on-call rotation and coordinate day-to-day escalations with our third‑party managed SOC, maintaining the detection feedback loop
  • Operate email security, endpoint security, and DLP controls; investigate and resolve high‑sensitivity signals and tune controls based on what investigations surface
  • Run tabletop exercises, deliver workforce security training, and produce threat intelligence that shapes team priorities
  • Restrict, suspend, or revoke an employee’s system access when a review identifies active risk, pending completion of that review
  • Define security requirements and detection coverage for identity and audit collection across corporate systems
Sensitive Matter Reviews
  • Conduct investigations and sensitive matter reviews with forensically sound evidence handling, chain‑of‑custody discipline, and confidentiality by default
  • Lead complex reviews independently — employee conduct, insider risk, access misuse, data exfiltration — co‑leading or escalating the most sensitive matters
  • Conduct forensic analysis across endpoint, identity, email, cloud, and SaaS sources
  • Produce findings, evidence summaries, technical analyses, and timelines for key stakeholders
  • Preserve evidence for legal holds and formal proceedings
  • Interpret findings in context and recommend resolutions, rather than providing raw technical output alone
Standards and Practice
  • Apply and improve Corporate Security methodology, evidence standards, and reporting standards;
  • Manage the SOC relationship and coordinate forensic vendors and external specialists, treating both as extensions of the team’s capacity
  • Exercise independent judgment over review methodology and evidence handling within established standards
  • Maintain the chain‑of‑custody, evidence‑handling, and confidentiality controls used by Corporate Security
WHAT YOU BRING
  • 5 to 7 years of security experience, including hands‑on experience leading complex corporate‑security and workplace investigations
  • Hands‑on experience conducting forensic investigations across endpoint, identity, email, cloud, and SaaS data sources
  • Practical fluency with detection engineering as code, including authoring, testing, and tuning detections in a version‑controlled pipeline
  • Working experience with forensically sound evidence collection and preservation — including chain‑of‑custody discipline, hashing, custodian‑based collection, and eDiscovery / legal‑hold workflows
  • Sound judgment about what evidence to collect, how to preserve it, and what to share with whom
  • A track record of producing review findings and recommendations that have held up to scrutiny
  • Comfort working with internal or external counsel, and directing forensic vendors on assigned engagements
  • Understanding of the legal context in which corporate‑security matters arise, including the limits and obligations that apply to management‑side reviews
  • Strong written and verbal communication, including the ability to explain technical findings to non‑technical audiences
  • Experience working alongside a managed SOC or MSSP, including escalation management
  • Experience with infrastructure‑as‑code workflows in Terraform and Python for logging, alerting, and security automation
  • Experience securing Google Workspace, Okta, GitHub, and Atlassian environments
  • Experience supporting PCI evidence collection and response
WORK & BENEFITS SNAPSHOT

This posting is for a full‑time, remote, salaried position. Travel may be required to attend all‑staff, departmental retreats, or select meetings. Additional travel may be required for select positions.

Registered States*

Arizona, California, Colorado, Connecticut, Florida, Georgia, Hawaii, Illinois, Indiana, Iowa, Kentucky, Maine, Maryland, Massachusetts, Michigan, Minnesota, Missouri, Montana, Nebraska, New Hampshire, New Jersey, New York, North Carolina, Ohio, Oregon, Pennsylvania, Rhode Island, South Dakota, Tennessee, Texas, Utah, Vermont, Virginia, Washington, Wisconsin, Wyoming, and Washington D.C.

* While ActBlue is currently registered to support remote work in the states listed above, we possess the ability to register in additional states as needed. If you are located in a state not listed, we may still be able to proceed with your application, but please note that the offer process may take longer to accommodate registration requirements.

Work Schedule:

This role requires availability during established, regular business hours (Mon‑Fri) and is expected to be a part of an on‑call rotation which will result in working nontraditional hours as needed.

Work Environment:

Employees can expect to work with distributed teams across all U.S. time zones. Our roles require extended technology usage, and proficiency with virtual communication tools such as Zoom and Slack. Regular attendance in virtual meetings is inherent to every position.

Salary Range Details:

Salary Range: $173,676 - $192,209 - $210,741

ActBlue is committed to consistent compensation practices across our organization. Final salary offers will take into account factors such as candidate experience, interview performance and current team salary parity.

Benefits:
  • Flexible work schedules and an unlimited time‑off policy
  • Fully paid and trans‑inclusive health, dental, and vision insurance for employees and their families; plus fully‑paid health reimbursement arrangement to use for out of pocket expenses and fully‑paid short‑ and long‑term disability
  • Fully paid basic and AD&D life insurance and a voluntary supplemental life insurance option
  • Dependent and health care flexible spending account options
  • Employee Assistance Program (EAP) benefits for employees
  • Automatic 2% Employer‑paid 401K contribution, plus up to an additional 6% match on employee contributions
  • A minimum of three months paid medical, family and parental leave (for all new parents, adoptions included)
  • Commuter or home‑office benefits, including a $1,000 home‑office setup allowance for all new full‑time remote employees
  • Additional perks including quarterly snack deliveries and digital subscriptions to the Boston Globe & New York Times

ActBlue is unable to sponsor work visas at this time.

UNION INFORMATION

This position is excluded from the Bargaining Unit as a supervisory and/or confidential employee; if this role has direct reports, certain employees reporting to this position may be covered by a collective bargaining agreement.

BACKGROUND CHECKS

As part of our hiring process, ActBlue will conduct a background check at the time of offer. This will be completed in compliance with applicable laws and will not be initiated without your consent.

INCLUSION STATEMENT FROM ACTBLUE

ActBlue is committed to equal employment opportunities and fostering a diverse, inclusive workplace. We celebrate unique perspectives, honor the dignity of all individuals, and recognize that diverse backgrounds and identities strengthen our mission.

We also provide reasonable accommodations for individuals with disabilities throughout the hiring process and employment. To request an accommodation, email recruitment@actblue.com.

*ActBlue will never ask candidates to buy equipment, nor will we email from anything other than an actblue.com or actbluetech.com email address.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Staff Software Engineer, Extensibility and Integration
Staff Software Engineer, Extensibility and Integration

ActBlue Charities Inc. • Northern (KY)

On-site
USD 192,000 - 241,000
Flexible time off
Health, dental, vision insurance
Life insurance & Disability
+2
Software Engineer at ActBlue
Software Engineer at ActBlue

Feedinkoo • United States

On-site
USD 137,000 - 166,000
Unlimited time off
Health insurance
401(k) with match
+3
Senior Corporate Security Specialist II
Senior Corporate Security Specialist II

Actblue • Somerville (MA)

On-site
USD 120,000 - 160,000
Analytics Manager I
Analytics Manager I

BlueLabs, Inc. • United States

Hybrid
USD 77,000 - 94,000
Health insurance
401K matching
Unlimited PTO
+3
Cyber Defense Analyst
Cyber Defense Analyst

Blue Origin LLC • Denver (CO)

On-site
USD 75,000 - 104,000
Medical insurance
Dental insurance
Vision insurance
+5
Cyber Defense Analyst II
Cyber Defense Analyst II

Blue Origin LLC • Denver (CO)

On-site
USD 91,000 - 127,000
Medical insurance
Dental insurance
Vision insurance
+6
Associate Director, Program Management
Associate Director, Program Management

Bluelabsanalyticsinc • Washington

On-site
USD 125,000 - 140,000
Health insurance
401K matching
Unlimited PTO
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Blue Origin LLC • Denver (CO)

On-site
USD 134,000 - 187,000
Medical insurance
Dental insurance
Vision insurance
+5
Cyber Security Engineer III
Cyber Security Engineer III

Blue Origin LLC • Denver (CO), Northern (KY)

On-site
USD 111,000 - 155,000
Medical, dental, vision insurance
401(k) with company match
Stock options
+2
Cyber Defense Analyst II
Cyber Defense Analyst II

Blue Origin • Seattle (WA)

On-site
USD 105,000 - 160,000
Medical, dental, vision
401(k) with company match
Paid time off
+1