Lead Engineer, Information Security
Innovate in Charlotte and help shape the future of information security at Lowe’s.
About the role
The primary purpose of this role is to provide consultation and technical direction to engineers focused on supporting the design, implementation, and ongoing operation of information security tools and services. This includes providing expert direction for effectively translating business requirements and functional specifications into robust enterprise security software solutions that ensure information assets are adequately protected with acceptable levels of control. You will facilitate successful monitoring, testing, and evaluation of security assessments of systems and lead the design and implementation of remediation solutions.
Responsibilities
- Drive the strategic design, development, and optimization of advanced cybersecurity platforms, harnessing expert-level scripting methodologies and custom code development to uphold the highest standards of security infrastructure and resilience.
- Serve as a technical expert for project teams throughout the implementation and maintenance of assigned information security solutions; define and oversee the documentation of detailed standards (e.g., guidelines, processes, procedures).
- Educate others on current architectural standards and guidelines to drive efficiency in the design and implementation of information security solutions.
- Resolve complex problems spanning multiple applications to drive overall improvements in security across systems and applications.
- Identify, report, and lead technical support activities during information security incidents as part of an Incident Response Team; review and respond to security alerts to investigate malicious activity.
- Lead the technical evaluation of new security technologies that address both current and future needs based on emerging threats and industry trends.
- Keep up to date with exploits relevant to the retail sales environment; research possible preventative measures.
- Solve complex cross-functional architecture/design and business problems; solutions are extensible; work to simplify, optimize, and remove bottlenecks.
- Mentor and advise others, sharing an in-depth understanding of company and industry methodologies, policies, standards, and controls.
- Make recommendations to Business and Technology leadership to ensure alignment of infrastructure applications and data with current and future security standards.
- Respond to escalated security issues for enterprise systems; facilitate advanced diagnosis and troubleshooting when necessary.
- Provide input into security breach response procedures; lead security breach response activities.
- Lead break/fix activities, escalating problems to senior management and/or vendors as appropriate.
- Analyze the output of industry-standard cybersecurity tools and identify remediations to reduce risk and exposure of applications.
- Complete custom enhancements of applications using secure coding techniques to reduce the threat of remote or local vulnerabilities.
- Evaluate entire applications (Container, Infrastructure, host platform) to identify potential threats and vulnerabilities.
- Evaluate complex application and hosting environments to identify potential weaknesses and provide remediation plans to reduce risk.
- Design application pipelines with secure configuration parameters to remove or reduce known threat vectors.
Requirements
- Bachelor’s degree in Computer Science, CIS, Engineering, Cybersecurity, or related field or equivalent years of experience in lieu of education requirement, if applicable.
- 7 years of experience in technology system support, software development, or a related field.
- 5 years of experience with information security applications and systems.
- 4 years of experience evaluating complex application and hosting environments to identify potential weaknesses and provide remediation plans to reduce risk.
- 5 years of experience designing complex application and infrastructure systems.
Preferred Qualifications
- Master’s degree in Computer Science, CIS, Business Administration, or related field.
- 6 years of experience working on project(s) involving the implementation of solutions applying development life cycles (SDLC).
- 3 years of DevOps experience.
- 1 year of experience with Cloud technologies.
- 4 years of experience designing application pipelines with secure configuration parameters to remove or reduce known threat vectors.
- 5 years of experience working with diverse application and infrastructure environments to identify and provide technical guidance on threat reduction at both the application and supporting infrastructure layer.
- 6 years of IT experience developing and implementing business systems within an organization.
- 6 years of experience working with defect or incident tracking software.
- 6 years of experience writing technical documentation in a software development environment.
- 4 years of experience working with an IT Infrastructure Library (ITIL) framework.
- 4 years of experience leading teams, with or without direct reports.
- 6 years of experience working with source code control systems.
- Experience working with Continuous Integration/Continuous Deployment tools.
- PCI ISA, CRISC, OSCP, or GPen certifications.
Pay
Pay Range: $111,600.00 - $212,000.00 annually. Starting rate of pay may vary based on factors including, but not limited to, position offered, location, education, training, and/or experience.
Benefits
For information regarding our benefit programs and eligibility, please visit Lowe’s Benefits.