Job Description
Guides the creation of testing tools and facilitates their integration into engineering workflows, ensuring team is equipped to identify and address security-related weaknesses efficiently. Establishes protocols for security violation escalation, managing communication with senior leadership and stakeholders. Conducts compliance assessments and coaches employees providing compliance assessments. Guides employees on using advanced tools and techniques for data security such as encryption, hashing, masking, and access management to ensure the confidentiality and integrity of sensitive information.
Responsibilities
KeyResponsibilities
SecurityMonitoring - Security Tool Design and Development:
- Drivessecurity strategy, ensuring that organizational goals are met.
- Overseesemployees working on security assessments across a wide range of complexproducts and services.
- Guidesthe creation of testing tools and facilitates their integration intoengineering workflows, ensuring the team is equipped to identify and addresssecurity-related weaknesses efficiently.
- Chairssecurity design and evaluation (e.g., traffic capturing, alerts), ensuringadherence to internal and external obligations, and strengthening securityposturing.
EventResponse:
- Establishesprotocols for security violation escalation, managing communication with seniorleadership and stakeholders.
- Developsand enforces protocols to contain and mitigate security events, coordinatingcross-functional response efforts.
- Leadspost-event review meetings to identify improvement areas, ensuring feedback isincorporated into ongoing security processes.
- Providesguidance to stakeholders who come to the security team with security events orconcerns.
Compliance:
- Conductscompliance assessments and coaches employees providing compliance assessments.
- Ensuresteam's security compliance deliverables adhere to internal and externalobligations.
- Overseesinventory, operability, and accountability of company assets, implementingrobust tracking systems.
BusinessContinuity Support:
- Guidesthe development of business continuity and disaster recovery plans, processes,and procedures.
- Ensuresthe availability and resilience of critical systems and data, overseeingefforts to withstand disruptions.
- Directsreadiness assessments for certifications and audits, implementing improvementsto meet evolving standards.
DataSecurity and Privacy:
- Guidesemployees on using advanced tools and techniques for data security such asencryption, hashing, masking, and access management to ensure theconfidentiality and integrity of sensitive information.
- Overseesthe review of documentation and procedures, identifying and implementingimprovements in data security practices.
Researchand Innovation:
- Drivesindustry security knowledge advancement, fostering research and innovationefforts.
- Alignsthe team on emerging trends, ensuring shared knowledge of evolving threats andvulnerabilities.
- Promotesnovel techniques to solve unique security problems, encouraging creative andeffective solutions.
CoreResponsibilities
Planning& Execution:
- Managesmultiple medium- to large-scale projects or initiatives across teams, ensuringtimelines, deliverables, and budgets when applicable are monitored and met.
- Providesdirection to teams on project work, setting priorities, and aligning withbusiness needs.
- Guidesteams on adjusting plans to accommodate resource or timeline changes.
Collaboration& Partnership:
- Drivescross-functional partnerships to align expectations and shared objectivesacross multiple teams.
- Coachesteam members to develop strategic relationships with business leaders,stakeholders, and external partners to foster collaboration and long-termsuccess.
- Promotesinclusivity by actively seeking and listening to diverse perspectives, ensuringothers feel heard and respected.
ProblemSolving:
- Providesdirection to multiple teams on addressing complex operational and/or technicalissues as well as providing guidance on analyzing complex data and/orinformation to identify solutions.
- Reviewsand provides insights into unresolved or critical issues, helping the team toidentify potential solutions.
ContinuousLearning:
- Modelsengaging in continuous learning to deepen expertise and stay ahead of industrytrends, integrating best practices into strategic planning.
- Leveragesfeedback to drive personal and team skill improvements.
- Identifiesskill gaps across teams, and empowers team members to pursue learning andknowledge sharing opportunities that build their expertise in new areas andcoaches them to apply learnings to advance the organization.
ContinuousImprovement:
- Drivesteam to collaborate on, develop, and implement ideas to increase the efficiencyand effectiveness of processes, protocols, and workflows within and acrossteams, providing oversight.
- Guidesteam to adopt new ideas for alternative approaches and methods and encouragesfeedback for continued improvement.
Performanceand Development:
- Drivesperformance across teams by providing feedback and coaching in alignment withperformance management processes, guidelines, and expectations.
- Discussesdevelopment goals with team members, shares opportunities to facilitate careerdevelopment, and ensures individual goals are aligned with broaderorganizational goals.
- Developsand manages talent acquisition pipeline by leading candidate interviews, monitoringpromotion eligibility, and/or orchestrating talent resources.
Qualifications
Minimum Job Qualifications
Education and/or Experience:
9 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 5 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 3 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.
Job Skills:
Same skills as prior level plus;
Incident Management and Response Demonstrated ability in or knowledge of incident management and response, including timely handling and escalation of incidents to minimize business impact.
Threat Modeling Demonstrated ability in or knowledge of threat modeling, including applying techniques to identify and mitigate security risks and vulnerabilities.
Cloud Security Demonstrated ability in or knowledge of cloud security, including protecting cloud infrastructure and data using risk management frameworks.
Preferred Job Qualifications
Education and/or Experience:
11 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Bachelor's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 7 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field
OR
Master's Degree in Computer Science, Information Technology, Computer Security, Engineering, or related field AND 5 years of experience in IT security (e.g., cloud, endpoint, logging), vulnerability and risk assessment, identity and access management, compliance, or related field.
Job Skills:
Same skills as prior level.
People Leadership / Management Experience:
3 years of experience in a leadership role with direct reports.
Budget Experience:
2 years of experience working with operating budgets and/or project financials.
Cloud or Internet Software Security Experience:
3 years of experience working on high-impact projects related to cloud or internet software security.
Programming/Scripting Experience:
3 years of experience working with one or more of the following programming or scripting languages (e.g., Go, Java, Python, or C/C++).
Cloud Experience:
6 months of experience with AWS Solution, Azure 900 Fundamentals, OCI Fundamentals, or equivalent cloud experience.
Information Security Certifications:
Information security or equivalent certifications (e.g., Certified Oracle Cloud Infrastructure Security Professional, Certificate of Cloud Security Knowledge [CCSK], Certified Information Security Manager [CISM], Certified Information Systems Security Professional [CISSP], Certified Ethical Hacker [CEH], Certified Cloud Security Professional [CCSP], Offensive Security Certified Professional [OSCP], Cisco Certified Network Associate [CCNA], Certified Information Systems Auditor [CISA], CompTIA Security+).