Full Job Description
The Senior Technology Security Engineer serves as an information security subject matter expert on highly complex enterprise projects, software, and hardware enhancements. Identifies information security risks, provides recommendations, builds, and configures solutions, and troubleshoots issues. Identifies and documents of highly complex information technology risks, assesses risk levels, recommends risk treatment, coordinates risk acceptance and remediation, and ensures appropriate remediation occurs. Serves as security subject matter expert, collaborates with stakeholders, offers guidance, and serves as main security point of contact during project planning and implementation. Collects and provides documentation for internal and external audits and assessments. Oversees assigned security tools/services and vendor life cycle management.
Essential Functions:
Security Solution Engineering
3 Serves as an information security subject matter expert on highly complex enterprise projects, software, and hardware enhancements. Identifies information security risks, provides recommendations, builds, and configures solutions, and troubleshoots issues. Collaborates with IT and security teams on project plans and meets with stakeholders to assess impacts and dependencies. Leads project activities to ensure timely deliverables and supports the establishment of a roadmap by evaluating and recommending new tools3 Leads highly complex information security projects across all security teams. Designs, builds, deploys, and maintains information security systems, including identity governance and access management solutions. Ensures the efficient operation of information security systems and resolves intricate security problems. Collaborates with other IT areas to plan for future needs3 Researches, evaluates, and proposes new information security solutions. Aligns information security systems with architectural requirements and strategies. Provides implementation and cost estimates for new solutions, including training requirements and system administration processes3 Collaborates with stakeholders to ensure the efficient operation of information security systems in alignment with architectural requirements and strategies
Risk Management
3 Identifies and documents of highly complex information technology risks, assesses risk levels, recommends risk treatment, coordinates risk acceptance and remediation, and ensures appropriate remediation occurs3 Serves as the primary contact on assigned internal and third-party IT processes, risk assessments, and audits. Provides advice to key stakeholders on the security-relevant impact of findings3 Identifies and promotes applicable information security policies, standards, and guidelines, ensuring they are followed as part of project initiatives. Evaluates and recommends appropriate controls or mitigating measures3 Leads risk assessments and coordination of internal and external audit activities by collecting and providing documentation Performs information security system control testing and reports on system functionality
Consulting and Enablement
3 Serves as security subject matter expert, collaborates with stakeholders, offers guidance, and serves as main security point of contact during project planning and implementation3 Leads troubleshooting sessions and knowledge transfers to resolve security issues including identity governance and access management3 Recommends solutions for aligning technology areas with future needs3 Offers highly technical guidance, training, and support to team members and stakeholders3 Proposes and develops automated processes to ensure consistent and appropriate event handling3 Leads the introduction of new security capabilities aligned with current standards and solutions
Documentation
3 Collects and provides documentation for internal and external audits and assessments3 Documents information security systems policies, procedures, standards, needed improvements, and guidelines3 Maintains the document life cycle, including periodic reviews, updates, and approval cycles
Support
3 Oversees assigned security tools/services and vendor life cycle management3 Schedules vendor meetings to review products, services, and vendor/tool roadmaps3 Drives renewals and new purchases through the EMC vendor management and purchase process3 Shares troubleshooting and resolution details with the team, stakeholders, and other IT teams3 Ensures purchases and renewals are processed in a timely manner, meets security budgetary goals, and avoids disruptions to security services and projects
Education & Experience:
3 Bachelors degree, preferably in information security, information technology, or a related field, or equivalent relevant experience3 Eight years of experience in information security, identity and access management, or related roles, including at least four years of experience in information security3 undefined3 Masters degree, preferably in information security, information technology, or a related field or equivalent related experience and six years of experience in information security, identity and access management, or related roles, including at least four years of experience in information security3 Information security certifications (CISSP, CCSP, CCSK, AWS, Azure, Security+, CEH, GSEC) preferred3 Prior experience in the insurance industry preferred
Knowledge, Skills & Abilities:
3 Advanced knowledge of information security and privacy standards, concepts, principles, technologies, and audit practices3 Advanced knowledge of information technology including network, servers, cloud, and PKI/cryptography and identity and access management technologies3 Excellent knowledge of identity and access management concepts, principles, technologies3 Excellent ability to assess and report on information technology risks3 Strong knowledge of Linux and Windows operating systems3 Strong knowledge of secure cloud solutions within AWS, Google, and/or Azure cloud platforms3 Strong ability to perform and create automation tasks with tools (i.e., PowerShell, Python) preferred3 Experience in designing, building, and maintaining information security systems3 Excellent analytical and problem-solving abilities3 Strong verbal and written communication skills3 Excellent ability to work effectively with others at varying levels3 Excellent documentation skills3 Ability to lead moderate to highly complex technology projects
The hiring salary range for this position will vary based on geographic location, falling within either of the following:
$103,954 - $149,372 or $114,895 - $164,309
A hiring range represents a subset of the full salary range. The actual salary will depend on several factors, including relevant education, skills, and experience of an applicant, geographic location, and business needs.
For information relating to the benefits EMC Team Members receive as part of a comprehensive rewards package, please visit www.emcins.com/careers