IT Security Principal Engineer -NATIONWIDE_

GlobalXperts, Inc.

• $120K — $145K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree required in computer science or information systems
  • 5+ years leading penetration testing and red team engagements
  • 10+ years in Information Technology focused on Security and Compliance
  • Proficiency with security tools like Nmap, Metasploit, and Burp Suite Pro
  • Experience with scripting languages (Python, Ruby) and programming languages (C/C++, Java, PHP)
  • Strong grasp of web protocols and technologies
  • Excellent technical communication skills to explain concepts to non-technical stakeholders

Responsibilities

  • Drive secure development lifecycle (SDL) for internal and external applications
  • Perform source code analysis and remediation using Fortify
  • Conduct network security assessments across diverse environments
  • Evaluate, review, and design firewall policies
  • Ensure compliance with security standards like PCI, HIPAA, and SOX
  • Provide security training covering Threat Modeling and Penetration Testing
  • Conduct code security reviews to enhance software security

Benefits

  • Opportunity for extensive technical consulting across diverse IT sectors
  • Engagement with cutting-edge technologies and security methodologies
  • Chance to influence security practices within the organization
  • Collaboration with executive stakeholders on security strategies
Full Job Description
Job Description

The IT Security Principal Engineer will deliver security technical consulting to internal organizations and Information Technology Services (ITS). The IT Security Principal Engineer will evaluate needs of key stakeholders to find solutions to challenging situations. Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.).

Responsibilities:
• Drive SDL across ITS and business segments, for internal and externally facing applications, including Ecommerce sites, Mobility (Android, Apple IOS), and legacy applications;
• Source code analysis and remediation using Fortify; Network security assessments and analysis for corporate and non-corporate network environments;
• Firewall policy evaluation, review, and design;
• Ensure compliance across applications and networks for PCI, HIPAA, and SOX;
• Provide training and guidance for security including Threat Modeling, Penetration Testing, SDL, and Code Security Reviews.

Qualifications
• Bachelor's degree required, preferably in computer science or information systems
• 5+ years of experience leading penetration testing, application testing, and red team engagements
• 10+ years of Information Technology, with a background in Security and Compliance experience

Additional Requirements:
• Experience with security tools such as - Nmap, Metasploit, Kali Linux, Burp Suite Pro, etc., as well as other various commercial and self-developed testing tools
• Experience with scripting languages such as python, ruby, POSIX shell, as well as familiarity with programming languages such as: C/C++/ObjC/C#, Java, PHP, or .NET
• Understanding of:
- Web protocols (e.g., HTTP, HTTPS, and SOAP)
- Web technologies (e.g., HTML, JavaScript, XML, AJAX, JSON, and REST)
• Experience with WLAN security concepts and testing
• Strong technical communication skills, both written and verbal; ability to explain technical security concepts to executive stakeholders in business language
• While experience in a number of IT disciplines may provide a solid framework for this position, hands-on results from performing IT risk assessments, information security consulting or IT audits are most beneficial.
• Experience in the following regulations and Frameworks: PCI, ISO 27001/2, HIPAA, GLBA, NIST

Additional Information

Similar Jobs

More Jobs at GlobalXperts, Inc.

More Information Technology Jobs

Find similar IT Security Principal Engineer -NATIONWIDE_ jobs: