Jobs · Information Technology · California

InfoSec Senior Engineer – Security Engineering & Architecture

Bank of Hope · Los Angeles, CA · 5 days ago
Information Technology$150k–$160k/yrFull-time

About the role

The InfoSec Senior Engineer – Security Engineering & Architecture is responsible for building security solutions that protect the business, but also allow the business to execute and innovate. The Engineer works closely with many diverse and dynamic teams, including, but not limited to, Security Engineering, IT Infrastructure, Application Development, Security Operations, Security Audit and End users. This position is also responsible for building solutions to secure business-to-business initiatives, third-party relationships, outsourced solutions, and vendors.

Responsibilities

  • Builds security solutions that protect the business, but also allow the business to execute and innovate.
  • Works closely with many diverse and dynamic teams, including, but not limited to, Security Engineering, IT Infrastructure, Application Development, Security Operations, Security Audit and End users.
  • Builds solutions to secure business-to-business initiatives, third-party relationships, outsourced solutions, and vendors.
  • Provides guidance for addressing current security issues but is expected to proactively deliver optimal secure solutions.
  • Thinks like an adversary and identifies how solutions should evolve as the threat landscape changes.
  • Provides technical leadership to delivery and solution engineering team members.
  • Develops strategies and plans to achieve security requirements and address identified risks.
  • Assists in the development of security architecture and security policies, principles, and standards.
  • Gathers, analyzes, and assesses the current and future threat landscape, and assists in providing leadership with a realistic overview of risks and threats in the enterprise environment.
  • Identifies security requirements, using methods that may include risk and business impact assessments.
  • Performs security testing and vulnerability assessments to identify security strengths and weaknesses, to assess the effectiveness of existing controls, and to recommend remediation action.
  • Participates in incident management and response activities as a member of the bank’s incident management team. As required, assists in triage, response and mitigation, postmortem analysis, and forensic analysis.
  • Reviews audit trails, system logs and other monitoring data sources regularly and ensures they are in compliance with policies and audit requirements.
  • Performs duties outside of normal work hours based on business needs.

Qualifications

  • Minimum Education Level: Bachelor’s Degree in related field
  • Minimum Job Experience: 8+ years
  • Required: 8+ years of experience in technology risk management
  • In-depth knowledge of risk assessment methods and technologies
  • Proficient use of various tools and techniques, including risk, business impact, control, and vulnerability assessments, used to identify business needs and determine control requirements
  • Excellent technical knowledge of Microsoft Windows operating systems and a wide range of security technologies, such as network security appliances, identity and access management systems, anti-malware solutions, automated policy compliance, logging and filtering tools, and desktop security solutions
  • Knowledge of network infrastructure, including routers, switches, firewalls and associated network protocols and concepts
  • Experience in system and application technology security testing, including static and dynamic code review, vulnerability scanning and penetration testing
  • Experience with IDS/IPS/SIEM and related security tools and technologies
  • Familiarity with router and firewall operations and maintenance
  • Ability to interact with personal at all levels and across all business units / organizations, and to understand business imperatives
  • Strong knowledge in core internet protocols (e.g., TCP/IP, DNS, SMTP, HTTP, etc.)
  • Experience working with security tools such as SIEM, vulnerability scanning, laptop data encryption, endpoint data protection, and application pen testing

Similar jobs