Jobs · Engineering

Intermediate Cyber Security Engineer

Aegon · United States · 1 mo ago
RemoteRemoteEngineering$70k–$84k/yrFull-time

Job Description Summary

The Information Security Team is growing and we are looking for a multi-talented Intermediate Cyber Security Engineer. This role is part of a fast-paced, energetic team dedicated to making our enterprise more secure.

Responsibilities

  • Identify weaknesses and vulnerabilities in relation to industry best practices and provide support to the application of security frameworks and regulatory standards such as NIST CFS.
  • Gather and analyze data, draft reports, and create departmental, project, key indicator, and dashboard materials.
  • Build strong working relationships with peers and key stakeholders, including business partners, legal, internal audit, risk, and technology specialists.
  • Review security vulnerabilities across diverse technologies and rapid changing environments including on-premise and cloud infrastructure.
  • Supports the analysis, implementation, and management of administrative, technical and physical safeguards to ensure the privacy and protection of company information and supporting technology and services.
  • Supports application security activities by assisting with secure SDLC practices, static and dynamic application security testing, vulnerability validation, remediation tracking, and coordination with development and technology teams to reduce application risk.
  • Aid in the research, development, and implementation of information security initiatives, such as policy, program, process, procedural and technology improvements and solutions.
  • Enhance and automate the vulnerability management lifecycle, including intake, prioritization, remediation tracking, reporting, and continuous process improvement.
  • Serve as an application security ambassador by promoting secure coding practices, helping employees and contractors understand their role in reducing application risk, and providing practical guidance on secure SDLC requirements, vulnerability identification, testing expectations, remediation activities, and safe handling of application data.

Qualifications

  • Bachelor’s degree with emphasis in Computer Science, MIS, Auditing, Finance, or Business or equivalent education and experience required.
  • 1 to 3 years of cyber security engineering work experience required.
  • Experience with one or more application security domain areas, including secure coding, security within the SDLC, application threat modeling, static and dynamic application security testing, software composition analysis, API security, web application firewalls (WAF), container security, vulnerability validation and remediation, application data protection, and alignment with applicable security standards and control frameworks.
  • Knowledge of applicable control frameworks such as: NIST CFS.
  • Certifications desirable - OSCP, CISSP, CEH and/or CompTIA Security+/CySA/CASP+.
  • Strong foundation in core security technologies and advanced persistent threat (APT) controls, including SIEM, endpoint security platforms, firewalls, intrusion detection and prevention systems, data loss prevention, syslog servers, vulnerability scanners, web application firewalls, threat intelligence feeds, digital forensics, and application allowlisting.
  • Security in Software Development Life Cycle (SDLC)
  • 2-3 years of related work experience with application security.
  • Hands-on experience with application security, dynamic scanning, static scanning, and container security.
  • Experience with systems such as ServiceNow, JIRA or equivalent.
  • Strong background in creating and automating vulnerability reports and dashboards including trending and graphing data.

Preferred Qualifications

  • Certifications desirable - OSCP, CISSP, CEH and/or CompTIA Security+/CySA/CASP+.
  • Experience in Insurance, Financial Services or other Fin-Tech Industries.
  • Preference given to candidates with Transamerica products, systems and/or domain knowledge.

Similar jobs