Senior Cybersecurity Engineer
TKO Group Holdings, Inc. (NYSE: TKO) is a premium sports and entertainment company that owns iconic properties including UFC, WWE, and PBR, reaching 1 billion households across 210 countries and territories.
About the role
Supports the maturing of the organization’s cybersecurity posture by further establishing and delivering on key strategic initiatives. Recommends, configures, enhances, and maintains relevant security systems and tools based on areas of responsibilities and current threat landscape. Works with cross-functional teams to drive broad-reaching technology initiatives related to cybersecurity.
Manages and contains information cybersecurity incidents and events to protect critical assets, intellectual property, related data, and the company’s reputation. Maintains cybersecurity-focused programs to ensure the organization is prepared to protect, detect, respond, and recover from a cyber-attack. Promotes best practices, implements, and maintains critical cybersecurity controls, supporting processes and procedures.
Aligns closely with the Cybersecurity Architect and Security Operations functions (internal and/or outsourced). Liaises with other technical and business teams regarding secure architecture, management, and monitoring events to ensure threat indicators are rated by severity and responded to in a manner consistent with the threat.
Works in partnership with the technology departments and provides support for infrastructure/networking, cloud and platform, enterprise applications, web development, content engineering, and data technology divisions as it relates to security best practices. Collaborates with the data privacy and compliance team to prioritize risk remediation efforts.
Participates in on-call after-hours support rotation to ensure that critical performance issues are resolved, and security events and incidents are addressed in a timely manner, in accordance with internal SLAs. Supports management of managed security services provider (MSSP) and threat intelligence vendors.
Responsibilities
- Recommend, configure, enhance, and maintain security systems and tools based on the current threat landscape.
- Work with cross-functional teams to drive cybersecurity initiatives.
- Manage and contain cybersecurity incidents to protect critical assets and data.
- Maintain cybersecurity programs for protection, detection, response, and recovery.
- Promote and implement best practices and critical cybersecurity controls.
- Align with Cybersecurity Architect and Security Operations functions.
- Liaise with technical and business teams on secure architecture and threat monitoring.
- Support infrastructure, cloud, applications, and data technology divisions on security best practices.
- Collaborate with data privacy and compliance teams to prioritize risk remediation.
- Participate in on-call after-hours support for critical issues and incidents.
- Support management of MSSP and threat intelligence vendors.
Requirements
- 4-year degree in computer science or related combined work/education experience.
- Minimum 5 years of relevant work experience in cybersecurity.
- Certified Information Systems Security Professional (CISSP) is a plus.
Skills
- Hands-on experience with cybersecurity technologies and tools, including Next Generation Firewalls (NGFW), Web Application Firewalls (WAF), Unified Threat Management (UTM), Security Information and Event Management (SIEM), Network Access Control (NAC), Endpoint Detection and Response (EDR), and related security appliances.
- Experience in security programs such as vulnerability and patch management, application security, IoT security, and mobile security.
- Experience supporting Microsoft EntraID (Azure AD), Microsoft Active Directory (AD), Windows Server, and Linux Server platforms.
- Experience in Identity Access Management (IAM).
- Experience with Multi-Factor Authentication (MFA), Single Sign-On (SSO), or other authentication methods.
- Experience with secure configuration management and system hardening.
- Cloud security experience (AWS, Google, or Azure) is a plus.
- Experience in computer forensics and cyber incident investigations is a plus.
- Strong knowledge of TCP/IP, DNS, NAT, and the OSI Model.
- Knowledge of NIST Controls, NIST Cyber Security Framework (CSF), and ISO/IEC 27000 series frameworks.
- Knowledge of or experience deploying the Center for Internet Security (CIS) Critical Security Controls.
- Ability to analyze complex information and communicate key points effectively.
- Strong operational and process background.
- Excellent verbal and written communication skills.
- Strong attention to detail, organization, and time management.
- Team player with the ability to collaborate at all levels.
- Ability to maintain composure in stressful situations, including incident response.
- Ability to make timely critical decisions with limited or ambiguous information.
Pay
Hiring rate range: $142,500 – $190,000 annually (minimum will not fall below applicable state/local minimum salary thresholds).