Sr. Infosec Engineer
De Leon Consulting Group · Flower Mound, Texas, United States · Today
EngineeringFull-time
About the role
As a Senior Information Security Engineer, you will work closely with the Manager of the Governance, Risk and Compliance Program. The role will coordinate the DLC program in alignment with established security policies, standards, methodologies, and processes. You will lead and drive assessments to ensure compliance with internal and external requirements, identifying risks, and communicating the posture to the leadership team. You will also act as the domain specialist for Security Governance, Risk, and Compliance.
Responsibilities
- Assist and influence management in the development, evolution, and execution of security risk strategies.
- Take the lead in the creation effort of the Information Security Risk Program by crafting a Security Risk Assessment methodology, policy, strategy, and process.
- Proactively work with local and remote Security teams and business owners to define the risk roadmap and program direction. Communicate and advocate for security enhancements and continuous improvements.
- Lead gap and risk assessments to identify and document significant information security risks associated with all aspects of our systems, data, and infrastructure.
- Partner with Engineering leadership on the development and review of IT initiatives and Security controls to identify operational efficiency.
- Lead remediation efforts and document completion status of deficiencies.
- Advance GRC and other Security tools to collect, maintain and share security risk information with senior leadership.
- Serve as a project lead by providing professional and expert-level security consulting services to business owners and partners.
- Maintain broad knowledge of standard methodologies and trends in the field of Information Security and other technologies relevant to systems operated by the Operations teams.
- Find opportunities for collaboration, inclusion, and alignment across the security program.
- Act as a mentor and train other security analysts.
Requirements
- Extensive experience implementing and assessing security in a cloud-hosted environment.
- High-level of knowledge of security technologies, information systems, and risk assessment methodologies.
- Desire to learn new and evolving technologies in a fast-paced environment.
- At least 8+ years of working within the technical arena with 5+ years of information security work experience.
- Technical background in IT systems and networking in Cloud environments.
- Experience analyzing vulnerability assessment reports and data and writing risk mitigation plans according to the assessment.
- Ability to lead and collaborate with technical and non-technical teams to further the goals and mission of the Security Risk and Compliance team.
- Excellent written and oral communication skills, as well as interpersonal skills including the ability to articulate to both technical and non-technical audiences.
- Experience in security standards such as ISO 27001, 27002, 27005; NIST, COBIT, ITIL, PCI.