PRIMARY FUNCTION: The Enterprise Security Engineering Manager (ESEM) is responsible for protecting TJU against a variety of threats to systems, infrastructure, and applications. The ESEM will manage the Offensive Security and Cyber Threat Intelligence functions to improve the organization’s overall security posture. This role will be responsible for leading the organization’s threat intelligence and threat hunting, adversarial simulation, security control validation, penetration testing/read team operations, application security, and attack surface monitoring functions. The ESEM's will act as an interface between strategic and process-based activities and the work of the key technology-focused analysts, engineers, architects and administrators in the IT organization. ESSENTIAL FUNCTIONS: Develop, maintain and continually evolve the Offensive Security Operations and Cyber Threat Intelligence function using internal and vendor resources/services to protect, defend and react to cyber threats faced by the enterprise Manage a staff of information security professionals, hire and train new staff, conduct performance reviews, and provide leadership and coaching, including technical and personal development programs for team members. Improve and execute the Offensive Security and Cyber Threat Intelligence strategy, plan, and roadmap based on sound enterprise security practices Oversee the daily operations of the Offensive Security and Cyber Threat Intelligence programs. Lead all Offensive Security initiatives including internal and external penetration tests, adversarial simulations, and other related Red Team Operations. Assist and provide leadership as a member within the organization’s Cybersecurity Incident Response team Tracks developments and changes in the digital business and threat environments to ensure that they're adequately addressed in security strategy plans and architecture artifacts Interacts with co-workers, visitors, and other staff consistent with the iSCORE values of Jefferson. Researches, evaluates, designs, tests, recommends or plans the implementation of new or updated information security hardware or software, and analyze its impact on the existing environment; provide technical and managerial expertise for the administration of security tools. OTHER FUNCTIONS AND COMPETENCIES: Stays current with all relevant IT security and compliance issues, technologies, and requirements. Provides professional and technical training and direction for internal team members as well as external staff. Oversee the efficient collection, analysis, and dissemination of information on emerging cybersecurity threats Identify relevant cyber threats and provide information that enables cybersecurity teams to make informed and relevant decisions that strengthen the organization’s defensive posture A strong understanding and knowledge of adversarial tactics, techniques, and procedures, communication methods, and motivations. A strong understanding and knowledge of offensive security tactics, techniques, and procedures. Offensive Security experience in an complex enterprise environment. In-depth understanding of social, political, and criminal movements worldwide, their impact on cyber related threats Knowledge of common cyber threat groups, including criminal organizations & nation state actors, and operational tactics used by different threat actors Performs other duties as assigned. Implement application security/automated testing tools and integrate offensive security testing into DevSecOps pipelines.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
501-1,000 employees