Senior Engineer Cybersecurity is responsible for supporting and providing direction to the Information security and compliance programs as well as internal controls related to information security and associated regulatory requirements. As an information security and related security controls subject matter expert, this role works closely with Information Security leadership, IT leadership peers, and business partners to help ensure information security goals are met and security controls are operating as intended. This role helps to ensure continuous compliance with enterprise information security policies, standards, and procedures as well as protect the confidentiality, integrity, and availability of information assets. Essential Functions and Key Responsibilities: Security Engineering & Operations Lead the implementation and administration of information security tools and services, including SIEM, EDR, firewalls, vulnerability scanners, and IAM systems Design, configure, and manage secure infrastructure and applications across on-prem and cloud environments (preferably Azure/M365 and OCI) Lead vulnerability management efforts and remediation follow-up across systems and applications Investigate and develop technical solutions and automation to improve security operations and reduce manual effort Monitor, triage, and respond to security alerts and incidents; lead incident response efforts and maintain documentation Support the goals of the information security program and help carry out information security strategy Governance, Risk & Compliance (GRC) Lead or support security-related audits, assessments, and evidence collection for internal and external stakeholders Develop and report on meaningful and actionable information security metrics that support strategy Manage vendors and third party risk management by coordinating and overseeing work performed by vendors including all contracted professional services Support the organization's compliance with internal policies and external requirements (e.g., GDPR, PCI, ISO 27001). Write comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement In collaboration with the Information Security team, maintain and improve the information security policy framework, standard operating procedures, and internal controls Conduct or support third-party security reviews and vendor risk assessments as needed Security Awareness & Collaboration Develop and deliver security awareness training and communications for employees Act as information security subject matter expert including mentoring and cross-functional advising Collaborate with cross-functional teams on secure architecture, project reviews, and IT initiatives
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
1,001-5,000 employees