What You'll Be Doing - the day to day - Lead our team of Security Engineers - assisting with decision making and solution analysis, and enabling them to deliver security consulting to the wider business
- Work directly with, and provide escalated support and guidance to, our Product & Technology teams to assist in how our platform is built and how our applications behave; supporting everything from the security of our users inside our products to how our applications connect to the Internet.
- Have significant impact on the security of our systems that are used by thousands of fire fighters, paramedics and hospitals worldwide.
- Be a key part of our cyber security team, with demonstrable impact on the security of our systems and applications.
- Help our teams to model threats using the STRIDE model, against new designs, ensuring appropriate protection and controls are in place.
- Make a difference by mitigating vulnerabilities across our systems, helping developers to produce secure code and evaluating new next-gen security technologies.
- Respond to security and compliance issues generated via analysis or automated tools.
- Work collaboratively cross-team, to impart your expertise across the organisation.
- Be in the detail, working shoulder-to-shoulder with our technology teams.
Who You Are - some of the essential things required to be successful in the role - At least 5 years' experience in securing software or infrastructure in cloud platforms (e.g. Microsoft Azure, AWS, GCP)
- Your experience should include;
- Securing systems in line with 'Well Architected Frameworks' e.g. Azure Well Architected Framework
- Network experience - whether designing and building, managing or troubleshooting - you should have experience and confidence in your networking knowledge
- Applying security to networks, hosts, web applications and cloud native deployments
- Working with toolsets from one or more of: asset management, vulnerability management, firewalls, SIEM, PAM, IDS/IPS, EDR/XDR, DLP, SWG, WAF, CSPM, CNAPP
- A solid understanding and ideally experience in the design, implementation or run of one or more of: SAST / DAST / IAST / RASP
You should also:
- Having knowledge of Continuous Integration / Continuous Deployment best practices, and securing pipelines
- Understand current attack tactics, techniques and procedures along with the use of MITRE Attack framework and associated MITRE security research
- Be inquisitive, have a passion for what you do and understanding how your work impacts and contributes ESO's success
Who You Are - it's desirable if you have any of the following - Exposure to Infrastructure as Code and Azure native technologies
- Experience with threat modelling, NIST and CIS frameworks
- Knowledge of application security standards such as OWASP Top 10, SANS / CWE 25
Benefits & PerksESO offers a comprehensive suite of benefits to promote health and financial security for our employees and their families. For full-time employment this includes:
- Competitive health plan (medical, dental, & vision insurance)
- RRSP with company match
- Telemedicine service provided by ESO
- Front-loaded vacation and sick time
- Employee Assistance Program (EAP)
- Peace of mind benefits such as life insurance and disability insurance