Security Engineer
Novawatch · Scottsdale, AZ · Yesterday
Information TechnologyFull-time
Responsibilities
- Design and build security tools and processes for integration and deployment to systems across the enterprise
- Develop and support integration and automation within security, monitoring, reporting, and ticketing platforms
- Design, implement, and support cloud-based systems security solutions for both public and private cloud infrastructures
- Research and develop modern/next-gen systems security toolsets to augment existing controls
- Design and build hardened configuration requirements for Linux and work with multiple teams to help implement suggested solutions
- Review and analyze existing processes and suggest improvements for increased security, including operationalization of process and standard improvements
- Conduct security research to keep abreast of the latest security issues and help communicate and respond internally to mitigate any identified vulnerabilities
Requirements
- Experience in deploying and maintaining security controls within various public cloud environments (AWS, Azure, Google)
- Experience in deploying and maintaining security controls within on-premises data centers and physical server infrastructures
- Experience developing automation solutions in scripting/programming languages such as Perl and Unix shell such as Bash (Python a plus)
- Experience with Splunk, RASP technologies, Endpoint security software, and other advanced security and system security tools
- Familiarity with different styles of source control, automation technologies (such as Puppet, Ansible, Terraform and CloudFormation) and CI/CD pipelines
- Experience deploying security agent software for Linux systems and other enterprise technologies
- Proficient in documenting and building detailed systems security diagrams and related documentation
- Understanding of various architectural frameworks and controls
- Understanding of information security concepts, protocols, “industry best practices”
- Able to translate infrastructure technologies such as network, database, server issues into risks for threat assessments and monitoring
- Experience performing systems security analysis, baselining, hardening, and automation across a large diverse set of systems
- 2– 5 years of secure system design responsibility including practical experience with system security compliance requirements (PCI, SOX, HIPAA, etc.) in a high-volume e-commerce or enterprise environment
- GCUX, CISSP, GSEC, or similar security / Unix professional certification