Cloud Security Engineer
Security Engineer Job In Bloomfield, CT
W2 only!
Duration: 6 mo++
Our client is seeking several Cloud Security Engineers for their growing team. This role will play an integral role in helping to protect company data in the Cloud from any security threats or attacks through the development of advanced security capabilities. As a cloud security engineer you will provide hands-on technical engineering to implement security automation, event based detection and preventative capabilities, apply machine learning models to detect security anomalies, as well as threat intrusion and detection capabilities. The cloud security engineer also provides security recommendations to application teams across a diverse set of cloud platforms and technologies including containers (EKS and AKS), secure coding practices, API security and the development of secure patterns for serverless and cloud-native computing. The individual will be part of a highly motivated team that is focused on a growing multi-year cloud security program. This individual ultimately would help strengthen the overall security posture of the organization for the long haul.
Major Duties and Responsibilities:
• Proven ability to manage protection of the network within the cloud, through services like security groups, network ACL's, and AWS Network Firewall.
• Proven ability to automate security component and policy changes.
• Proven ability to quickly learn and experiment with new security related cloud technologies and tools.
• Proven ability to design end-to-end security patterns and solutions that may include on-premise and cloud resources that meet enterprise security policies and best practices.
• The individual should have a passion for new emerging technology in the cloud security space
• Solid understanding of services and capabilities delivered by mainstream cloud service providers
• Ability to influence technical discussions and decisions
• Ability to perform security research and document and communicate the findings of their research
Qualifications
• 3+ years of progressive hands-on technical experience in cybersecurity and cloud security
• AWS Certified Security - Specialty or Azure AZ-500 Azure Security Engineer Associate certification required
• Proficiency in Python, Terraform, ARM templates and CloudFormation
• BA/BS degree in MIS/Computer Science or related degree required
• Has a strong capability to work with and partner with delivery teams and stakeholders
AI Developer and Security Analyst
Security Engineer Job In New Haven, CT
We are seeking a forward-thinking AI Innovation Analyst to join our team and drive transformative technology initiatives within our firm. This role is instrumental in evaluating, implementing, and optimizing innovative technology solutions, with a strong emphasis on legal-specific generative AI applications. The ideal candidate will combine legal technology expertise, analytical skills, and a passion for enhancing practice efficiency through modern tools and strategies.
Key Responsibilities:
Collaborate with attorneys, practice groups, clients, and cross-functional teams to identify and implement innovative technology solutions, including legal-specific generative AI applications.
Develop and lead group and individual training sessions on legal technologies and AI solutions. Create engaging training materials and maintain a repository of resources.
Manage materials, resources, and best practices to support the effective use of approved technologies.
Stay ahead of emerging legal AI technologies and service models, recommending new or improved solutions to enhance practice efficiency.
Provide support for various projects, adapting to changing needs to help achieve the firm's innovation objectives.
Conduct in-depth research and analysis of emerging trends and technologies, with a focus on AI.
Collaborate with cross-functional teams to define AI project use cases, requirements, and objectives, ensuring alignment with overall business goals.
Evaluate current and new technologies to identify effectiveness and security gaps.
Stay up to date with industry developments and regulatory changes affecting technology and AI.
Contribute to parts of security questionnaires to ensure compliance with security standards and regulations.
Collaborate with the Director of Privacy and Data Security on creating AI policies.
Qualifications:
Proven experience in technology analyst or similar role.
Strong understanding of technology principles, practices, and emerging trends.
Knowledge of AI technologies and their applications in a law firm environment.
Excellent analytical and problem-solving skills
Ability to think creatively and propose innovative solutions.
Experience in a Legal environment.
Experience with AI frameworks and tools.
Strong communication and collaboration skills.
Preferred Qualifications:
Degree in Technology, Computer Science, or related field.
Ability to work independently and as part of a team in a fast-paced environment.
Experience with cyber security technologies and review of AI security standards.
Essential Physical/Mental Demands
Ability to sit extended periods of time and operate standard office equipment including computers/keyboards.
Principal Security Engineer
Security Engineer Job In Hartford, CT
The Oracle Cloud Infrastructure (OCI) team can provide you the opportunity to build and operate a suite of massive scale, integrated cloud services in a broadly distributed, multi-tenant cloud environment. OCI is committed to providing the best in cloud products that meet the needs of our customers who are tackling some of the world's biggest challenges.
We offer unique opportunities for smart, hands-on security engineers with the expertise and passion to solve difficult problems in distributed highly available services and virtual infrastructure. At every level, our engineers have a significant technical and business impact designing and building innovative new systems to power our customer's business critical applications. Our customers run their businesses on our cloud, and our mission is to provide them with the most secure cloud services.
We're looking for hands-on security engineers with expertise and passion in solving difficult security problems in distributed systems, multi-tenant services and large-scale infrastructures. If this is you, at Oracle Cloud you can help design and build innovative new systems from the ground up. These are exciting times in our space - we are growing fast, and working on ambitious new initiatives.
Things you'll do:
+ Prototype, design, and implement security solutions for new and challenging problems
+ Drive and champion security tool development (e.g. scanning tools)
+ Champion and consult on secure development lifecycle practices
+ Design and build verification mechanisms
+ Define security configuration and implementation best practices
+ Conduct hardware security reviews
Must have Qualifications:
+ Bachelor's or Master's degree in Computer Science or related field
+ 6+ years of experience in security engineering or related field or equivalent experience
+ Experience building automated security solutions
+ Strong security experience, particularly with focus in one of the following areas:
+ Defensive Security
+ Offensive Security
+ Service architecture and Design Patterns
+ Strong collaboration and communication skills
Preferred Qualifications
+ Experience working in a large cloud or Internet software company
+ Expertise in bridging security engineering requirements into software developers life cycle.
+ Experience scaling operational activities via Python, Bash, and other tools
+ Expertise in designing databases schemas in (NoSQL / SQL).
+ Experience with statistical/mathematical predictive modeling
+ Experience with machine learning / artificial intelligence
+ Experience collaborating with software development teams, data scientists, business and other technical roles
+ Experience with Python, R, or Java development
Career Level - IC4
**Responsibilities**
+ Responsible for advanced planning, design and build of security systems, applications, environments and architectures; oversees the implementation of security systems, applications, environments and architectures and ensures compliance with information security standards and corporate security policies and procedures.
+ Provides technical advice and direction to support the design and development of secure architectures.
+ May participate in an incident management team, bringing advanced-level skills to respond to security events in line with Oracle incident response playbooks.
+ Evaluates existing and proposed technical architectures for security risk, provides technical advice to support the design and development of secure architectures and recommends security controls to mitigate those risks. Evaluations of internal security architecture may include design assessment, risk assessment, and threat modeling.
+ Brings advanced-level skills to research, evaluate, track, and manage information security threats and vulnerabilities in situations where in-depth analysis of ambiguous information is required, and where computer programming/scripting knowledge is required.
+ Work with Senior management to develop and implement a multi-year security roadmap
+ Focus on operational and strategic level tasks, and provide counsel and guidance to the junior level security operations engineers in the department.
Disclaimer:
**Certain US customer or client-facing roles may be required to comply with applicable requirements, such as immunization and occupational health mandates.**
**Range and benefit information provided in this posting are specific to the stated locations only**
US: Hiring Range in USD from: $109,200 to $223,400 per annum. May be eligible for bonus and equity.
Oracle maintains broad salary ranges for its roles in order to account for variations in knowledge, skills, experience, market conditions and locations, as well as reflect Oracle's differing products, industries and lines of business.
Candidates are typically placed into the range based on the preceding factors as well as internal peer equity.
Oracle US offers a comprehensive benefits package which includes the following:
1. Medical, dental, and vision insurance, including expert medical opinion
2. Short term disability and long term disability
3. Life insurance and AD&D
4. Supplemental life insurance (Employee/Spouse/Child)
5. Health care and dependent care Flexible Spending Accounts
6. Pre-tax commuter and parking benefits
7. 401(k) Savings and Investment Plan with company match
8. Paid time off: Flexible Vacation is provided to all eligible employees assigned to a salaried (non-overtime eligible) position. Accrued Vacation is provided to all other employees eligible for vacation benefits. For employees working at least 35 hours per week, the vacation accrual rate is 13 days annually for the first three years of employment and 18 days annually for subsequent years of employment. Vacation accrual is prorated for employees working between 20 and 34 hours per week. Employees working fewer than 20 hours per week are not eligible for vacation.
9. 11 paid holidays
10. Paid sick leave: 72 hours of paid sick leave upon date of hire. Refreshes each calendar year. Unused balance will carry over each year up to a maximum cap of 112 hours.
11. Paid parental leave
12. Adoption assistance
13. Employee Stock Purchase Plan
14. Financial planning and group legal
15. Voluntary benefits including auto, homeowner and pet insurance
The role will generally accept applications for at least three calendar days from the posting date or as long as the job remains posted.
**About Us**
As a world leader in cloud solutions, Oracle uses tomorrow's technology to tackle today's challenges. We've partnered with industry-leaders in almost every sector-and continue to thrive after 40+ years of change by operating with integrity.
We know that true innovation starts when everyone is empowered to contribute. That's why we're committed to growing an inclusive workforce that promotes opportunities for all.
Oracle careers open the door to global opportunities where work-life balance flourishes. We offer competitive benefits based on parity and consistency and support our people with flexible medical, life insurance, and retirement options. We also encourage employees to give back to their communities through our volunteer programs.
We're committed to including people with disabilities at all stages of the employment process. If you require accessibility assistance or accommodation for a disability at any point, let us know by emailing accommodation-request_************* or by calling *************** in the United States.
Oracle is an Equal Employment Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability and protected veterans' status, or any other characteristic protected by law. Oracle will consider for employment qualified applicants with arrest and conviction records pursuant to applicable law.
Application Security Engineer
Security Engineer Job In Stamford, CT
**Our Mission** As the world's number 1 job site*, our mission is to help people get jobs. We strive to cultivate an inclusive and accessible workplace where all people feel comfortable being themselves. We're looking to grow our teams with more people who share our enthusiasm for innovation and creating the best experience for job seekers.
**Day to Day**
As an Application Security Engineer, your role involves close collaboration with software development teams to ensure the safety of our customers during the development of innovative services. On any given day, your tasks may include code inspections to identify security issues, the development of new frameworks to enhance the speed and security of software development, and fine-tuning service designs in collaboration with software developers. As an Application Security Engineer, you'll apply your skills towards our mission of helping people find jobs and secure our global cloud-native environment which serves 200M unique visitors per month.
**Responsibilities**
+ Creating, updating, and maintaining threat models for a wide variety of software projects
+ Executing Manual and Automated Secure Coding Reviews, primarily in Java, Python and Javascript
+ Assist in development of security processes and automated tooling that prevent classes of security issues.
+ Developing security training and guidance for internal development teams
+ Work closely with software developers to advise on secure coding practices and to establish a proactive security posture.
+ Partnering with engineering teams to incrementally improve their security processes, priorities, and choices on a continual basis
+ Support and consult with product and development teams in the area of application security, including threat modeling and AppSec reviews
+ Assist teams in reproducing, triaging, and addressing application security vulnerabilities.
**Skills/Competencies**
+ Bachelor's Degree in Computer Science, Engineering, Computer Security, Information Systems, or related field
+ You demonstrate excellent judgment in assessing and prioritizing technical risk
+ You have knowledge of security best practices and standards such as OWASP Top 10 and SANS Top 25 with a focus on scalable solutions
+ You have excellent communication skills with the ability to articulate complex security issues to technical and non-technical collaborators, with an inclusive mindset
+ You work to identify and remove bottlenecks for your teammates, both in process and technology
+ You have familiarity with a wide variety of security tools, technologies, and methodologies.
+ You have some level of scripting/development experience (e.g. Python, Java, Ruby, etc.)
**Education Requirement** : Bachelor's Degree in Computer Science, Engineering, Computer Security, Information Systems, or related field
**Salary Range Transparency**
Austin, Metro Area 110,000- 154,000 USD per year
New York City, Metro Area 118,000 - 172,000 USD per year
Seattle, Metro Area 134,000 - 188,000 USD per year
San Francisco, Bay Area 143,000 - 200,000 USD per year
Remote, US 110,000- 154,000 USD per year
**Salary Range Disclaimer**
The base salary range represents the low and high end of the Indeed salary range for this position in the given work location. Actual salaries will vary depending on factors including but not limited to location, experience, and performance. The range(s) listed is just one component of Indeed's total compensation package for employees. Other rewards may include quarterly bonuses, Restricted Stock Units (RSUs), a Paid Time Off policy, and many region-specific benefits.
**Benefits - Health, Work/Life Harmony, & Wellbeing**
We care about what you care about. We have a multitude of benefits to support Indeedians, as well as their pets, kids, and partners including medical, dental, vision, disability and life insurance. Indeedians are able to enroll in our company's 401k plan, as well as an equity-based incentive program. Indeedians will also receive open paid time off, 12 paid holidays a year and up to 26 weeks of paid parental leave. For more information, select your country and learn more about our employee benefits, program, & perks at **************************** !
**Equal Opportunities and Accommodations Statement**
Indeed is deeply committed to building a workplace and global community where inclusion is not only valued, but prioritized. We're proud to be an Equal Employment and Affirmative Action employer seeking to create a welcoming and diverse environment. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity or expression, family status, marital status, sexual orientation, religious creed, national origin, genetics, neuro-diversity, disability, age, status as a protected veteran, or any other non-merit based or legally protected grounds.
Indeed is dedicated to providing reasonable accommodations to qualified individuals with known disabilities to participate in the employment application process. To request an accommodation, an applicant should contact Talent Attraction Accommodations at **************, or by email at accommodations@indeed.com. In the request for an accommodation, please inform us of the nature of your request and your contact information. If you are requesting accommodation for an interview, please reach out at least one week in advance of your interview.
For more information about our commitment to Equal Employment Opportunity and Affirmative Action, please review our Equal Employment Opportunity and Affirmative Action Statement of Policy (************************************************************************
**Inclusion & Belonging**
Inclusion and belonging are fundamental to our hiring practices and company culture, forming an integral part of our vision for a better world of work. At Indeed, we're committed to the wellbeing of our employees and on a mission to make this the best place to work and thrive. We believe that fostering a diverse and inclusive environment where every employee feels respected and accepted benefits everyone, fueling innovation and creativity.
We value diverse experiences, including those who have had prior contact with the criminal legal system. We are committed to providing individuals with criminal records, including formerly incarcerated individuals, a fair chance at employment.
Those with military experience are encouraged to apply. Equivalent expertise demonstrated through a combination of work experience, training, military experience, or education is welcome.
**Indeed's Employee Recruiting Privacy Policy**
**Fair Chance Hiring**
We value diverse experiences, including those who have had prior contact with the criminal legal system. We are committed to providing individuals with criminal records, including formerly incarcerated individuals, a fair chance at employment.
**Indeed's Employee Recruiting Privacy Policy**
Like other employers Indeed uses our own technologies to help us find and attract top talent from around the world. In addition to our site's user and privacy policy found at ***************************** we also want to make you aware of our recruitment specific privacy policy found at *****************************************
**Req ID:** **45401**
**This position accepts applications on an ongoing basis, and there is no deadline to apply.**
Reference ID: 45401
Identity and Access Management (IAM) - Staff Security Engineer
Security Engineer Job In Connecticut
Bring your heart to CVS Health. Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand - with heart at its center - our purpose sends a personal message that how we deliver our services is just as important as what we deliver.
Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable.
Position Summary
The Staff Security Engineer of IAM will be a product owner and lead engineer within Identity Access Management (IAM) space for CVS Health. This position will include leading multiple projects simultaneously and hands-on engineering of IAM solutions. Operating within DevOps and Agile frameworks as part of our Product Management Model, an ideal candidate will have strong soft skills and engineering skills. Team Player mentality is a must. This position will require strong Program/Product Management skills and is expected to lead team-members in assignment of and completion of tasks, with an ability to keep projects on schedule as well as assist with strategic IAM direction of the CVS Health workforce.
Daily Responsibilities:
Lead team-members through the engineering of IAM solutions
Lead or coordinate the IAM team's work and keep projects on schedule
Influence and align key stakeholders
Manage implementations and releases via CI/CD strategies
Implementation of IAM technologies such as LDAP, Neo4J, Java/.NET Development, MySQL, SAML, OpenID Connect, and REST/SCIM APIs.
Address issues and break down problems to be solved.
Required Qualifications
7+ years of direct experience within Identity Access Management (IAM)
5+ years of hands-on technical IAM engineering experience
3+ years of leading resources
2+ years of experience with one or more of the following: JAVA, .NET, LDAP queries, Neo4J, automated provisioning/deprovisioning, and MySQL
Preferred Qualifications
3+ years of access management experience with SSO and/or MFA
General understanding of DevOps Methodology
Working knowledge one or more of the following: OpenID Connect, SAML, JAVA, .NET, LDAP queries, Neo4J, Ping Directory, Radiant Logic, automated provisioning/deprovisioning, and MySQL
Experience with REST API integration
Experience writing Linux shell scripts
Strong team player that works well horizontally and vertically with others of varying skill levels and experience
Ability to clearly define and present solution development ideas in a team environment
Product/Program management leadership
CISSP preferred
Education
Bachelor degree from accredited university or equivalent work experience(HS diploma + 4 years relevant experience)
Business Overview
Bring your heart to CVS Health Every one of us at CVS Health shares a single, clear purpose: Bringing our heart to every moment of your health. This purpose guides our commitment to deliver enhanced human-centric health care for a rapidly changing world. Anchored in our brand - with heart at its center - our purpose sends a personal message that how we deliver our services is just as important as what we deliver. Our Heart At Work Behaviors™ support this purpose. We want everyone who works at CVS Health to feel empowered by the role they play in transforming our culture and accelerating our ability to innovate and deliver solutions to make health care more personal, convenient and affordable. We strive to promote and sustain a culture of diversity, inclusion and belonging every day. CVS Health is an affirmative action employer, and is an equal opportunity employer, as are the physician-owned businesses for which CVS Health provides management services. We do not discriminate in recruiting, hiring, promotion, or any other personnel action based on race, ethnicity, color, national origin, sex/gender, sexual orientation, gender identity or expression, religion, age, disability, protected veteran status, or any other characteristic protected by applicable federal, state, or local law. We proudly support and encourage people with military experience (active, veterans, reservists and National Guard) as well as military spouses to apply for CVS Health job opportunities.
Pay Range
The typical pay range for this role is:
$124,372.50 - $247,200.00
This pay range represents the base hourly rate or base annual full-time salary for all positions in the job grade within which this position falls. The actual base salary offer will depend on a variety of factors including experience, education, geography and other relevant factors. This position is eligible for a CVS Health bonus, commission or short-term incentive program in addition to the base pay range listed above. This position also includes an award target in the company's equity award program.
In addition to your compensation, enjoy the rewards of an organization that puts our heart into caring for our colleagues and our communities. The Company offers a full range of medical, dental, and vision benefits. Eligible employees may enroll in the Company's 401(k) retirement savings plan, and an Employee Stock Purchase Plan is also available for eligible employees. The Company provides a fully-paid term life insurance plan to eligible employees, and short-term and long term disability benefits. CVS Health also offers numerous well-being programs, education assistance, free development courses, a CVS store discount, and discount programs with participating partners. As for time off, Company employees enjoy Paid Time Off (“PTO”) or vacation pay, as well as paid holidays throughout the calendar year. Number of paid holidays, sick time and other time off are provided consistent with relevant state law and Company policies.
For more detailed information on available benefits, please visit Benefits | CVS Health
We anticipate the application window for this opening will close on: 01/31/2025
Qualified applicants with arrest or conviction records will be considered for employment in accordance with all federal, state and local laws.
Lead Firewall & Security Engineer
Security Engineer Job In Hartford, CT
Network Firewall Engineer Recruiting for this role ends on May 31, 2025 Work you'll do Provides engineering, security compliance and administration of the firewalls. The position works closely with other Deloitte groups and vendors to provide exceptional customer support. Including the Deloitte Cyber organization for any requests about security compliance from the different agencies and to mitigate any gaps.
Creates configurations and scripts for enterprise deployment of solutions that align business and DT - US strategies.
Responsible for providing second level incident support, defining, and updating standards, ensuring compliance on all internal and external projects, enforcing consistent policies and processes.
Contributes to the transition of new technologies between Architecture and Engineering and confirms all appropriate documents and processes are developed.
Responsibilities:
* Manages the day-to-day activities of design, analysis, planning, and implementation.
* Oversees the development and evaluation of network performance criteria and measurement methods for short-team and long-term needs including capacity.
* Evaluates network architecture design, in addition to feasibility and cost studies
* Monitors performance and health, ensures capacity planning is performed, and assesses and makes recommendations for improvement.
* Provide skilled expertise for the compliance, engineering, administration and 24x7 operations of the firewalls serving the Deloitte Federal practice.
* Perform routine assessments of system hardening in accordance with DOD security technical implementation guides (STIGs).
* Ensure the maximum information assurance (IA) compliance of DODIN-N systems
* Lead service request fulfilment for firewall policy and other security extension changes (VPN, IPS, URL Filtering, Application Control, etc.).
* Provide visibility and insight to assist customers with firewall activity and usage information.
* For the Federal firewalls, first responder to monitored alerts, incidents, and issues.
* Lead the follow through with firm and vendor resources to close out availability, performance, and security incidents that involve firewalls.
* Accountable for executing tasks according to established standards, procedures, and processes. Assist to develop new standards, procedures and processes.
* Performs other job-related duties as assigned.
* Ability to manage support cases with external technology vendors.
The team
Deloitte Technology US (DT - US) helps power Deloitte's success, which serves many of the world's largest, most respected organizations. We develop and deploy cutting-edge internal and go-to-market solutions that help Deloitte operate effectively and lead in the market. Our reputation is built on a tradition of delivering with excellence.
The ~3,000 professionals in DT - US deliver services including:
* Cyber Security
* Technology Support
* Technology & Infrastructure
* Applications
* Relationship Management
* Strategy & Communications
* Project Management
* Financials
Technology & Infrastructure
The Technology and Infrastructure Organization works together to transform how DT - US deploys technologies and services to meet the dynamic needs of Deloitte professionals and help increase their productivity.
Required Qualifications:
* 8+ years in supporting infrastructure environments but not limited to security/firewall, networks, systems
* 3+ years of experience in related experience in firewall environments performing engineering (hardware and software) and operations.
* Bachelor's degree in Computer Science, Computer Engineering, Business Administration or similar and/or additional relevant professional experience.
* Ability to travel 0-10%, on average, based on the work you do and the clients and industries/sectors you serve
* Must be a US Citizen (GPS initiatives)
Preferred Qualifications:
* Expert level knowledge of Checkpoint or Palo Alto.
* Advanced level skill in firewall policy management.
* Knowledge of monitoring tools and commands to ensure quick resolution to issues.
* Hands-on experience with security policy and automation tools such as Firemon, Tufin. Algosec...
* Knowledge on Scripting language.
* Knowledge of LAN/WAN and network protocols.
* Experience in security assessments and audits, ensuring compliance with industry standards and best practices, and addressing vulnerabilities proactively.
* Knowledge of applying DoD STIGs to network equipment
* Knowledge of information assurance (IA) compliance of DODIN-N systems
Information for applicants with a need for accommodation: ************************************************************************************************************
The wage range for this role takes into account the wide range of factors that are considered in making compensation decisions including but not limited to skill sets; experience and training; licensure and certifications; and other business and organizational needs. The disclosed range estimate has not been adjusted for the applicable geographic differential associated with the location at which the position may be filled. At Deloitte, it is not typical for an individual to be hired at or near the top of the range for their role and compensation decisions are dependent on the facts and circumstances of each case. A reasonable estimate of the current range is $88,600 to $181,900.
You may also be eligible to participate in a discretionary annual incentive program, subject to the rules governing the program, whereby an award, if any, depends on various factors, including, without limitation, individual and organizational performance.
EA_ExpHire
#LH-1
Recruiting tips
From developing a stand out resume to putting your best foot forward in the interview, we want you to feel prepared and confident as you explore opportunities at Deloitte. Check out recruiting tips from Deloitte recruiters.
Benefits
At Deloitte, we know that great people make a great organization. We value our people and offer employees a broad range of benefits. Learn more about what working at Deloitte can mean for you.
Our people and culture
Our inclusive culture empowers our people to be who they are, contribute their unique perspectives, and make a difference individually and collectively. It enables us to leverage different ideas and perspectives, and bring more creativity and innovation to help solve our client most complex challenges. This makes Deloitte one of the most rewarding places to work.
Our purpose
Deloitte's purpose is to make an impact that matters for our clients, our people, and in our communities. We are creating trust and confidence in a more equitable society. At Deloitte, purpose is synonymous with how we work every day. It defines who we are. We are focusing our collective efforts to advance sustainability, equity, and trust that come to life through our core commitments. Learn more about Deloitte's purpose, commitments, and impact.
Professional development
From entry-level employees to senior leaders, we believe there's always room to learn. We offer opportunities to build new skills, take on leadership opportunities and connect and grow through mentorship. From on-the-job learning experiences to formal development programs, our professionals have a variety of opportunities to continue to grow throughout their career.
As used in this posting, "Deloitte" means Deloitte Services LP, a subsidiary of Deloitte LLP. Please see ************************* for a detailed description of the legal structure of Deloitte LLP and its subsidiaries.
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability or protected veteran status, or any other legally protected basis, in accordance with applicable law.
Requisition code: 210088
Security Engineer
Security Engineer Job In Middlebury, CT
L3 Resource with good experience in handling end to end infrastructure security operations which includes o Perimeter security (Checkpoint & CISCO ASA Firewalls etc.) o Endpoint security (Sophos , Symantec etc.) o Web Gateways ( Sophos, Blucote) o Email Gateways ( Sophos, Symantec etc.)
o Vulnerability Management (Qualys, DDI etc.)
o Information security & Compliance ( IS Auditing, Policies & Procedure reviews)
o Global Access Management
o SIME (ArcSight etc.)
· Should have hands on experience in troubleshooting issues
· Should have good experience in ITIL Processes(Change management, Problem management, Incident Management etc. )
· Technically sound on the above listed technologies / tools
· Good experience in performing Security incident analysis
· Preferably the candidate should have certifications like CISSP, CISA, CISM
· Should have good communication & presentation skills
Additional Information
All your information will be kept confidential according to EEO guidelines.
Application Security Engineer II - Container Security
Security Engineer Job In Hartford, CT
Who Are We?
Taking care of our customers, our communities and each other. That's the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 160 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.
Job CategoryTechnologyCompensation Overview
The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.
Salary Range$111,600.00 - $184,200.00Target Openings1What Is the Opportunity?Travelers is seeking an Application Security Engineer II to join our organization as we grow and transform our Technology landscape. This engineer will focus on supporting and driving security initiatives related to containerized development. Additionally, the individual will complete advanced end to end security engineering tasks for specific system including security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews, and will provide defensive coding techniques consulting. Works with circle leads in a Value Stream on security and performs Application Security testing for Value Stream. Provides guidance on testing to Application Security Engineer I. Performs application architecture security reviews. Partners with Cybersecurity and Enterprise Security Engineering on testing and remediation of vulnerabilities and implementation of Cybersecurity patterns.What Will You Do?
Support the development of a container image security strategy to include supply chain risk initiatives.
Support the container image security strategy implementation and integration with DevOps pipelines.
Promote a culture around secure container development.
Perform security research, application security testing, interpretation of vulnerability scan results, threat modeling code reviews and advise on defensive coding techniques with a high degree of accuracy and speed, operating as an individual contributor to team goals.
Work independently to tackle well-scoped and loosely scoped problems.
Seek opportunities to expand technical knowledge and capabilities.
Provide technical guidance and mentorship to less experienced employees.
Perform other duties as assigned.
What Will Our Ideal Candidate Have?
Bachelor's degree plus four years of modern application development or application security experience.
Moderate experience in Container Security working with technologies like Kubernetes and container technologies such as Docker or OpenShift
Moderate experience with development in AWS
Moderate knowledge and understanding of container security and related risks.
Moderate knowledge and experience with build (CI/CD) pipeline technologies such as GitHub Actions, Jenkins, and/or GitLab CI/CD.
Experience with container image hardening and base image management.
Experience with integrating and managing tools involving SAST, SCA, and Secrets scanning capabilities.
Familiarity of microservices architecture and design patterns.
Delivery - Intermediate delivery skills including the ability to estimate accurate timelines for tasks and deliver work at a steady, predictable pace to achieve commitments, contribute to the software design strategy and methodologies used to best meet the system requirements, consider and build for many different use cases, avoid over engineering, and ensure automation, deliver complete solutions but release them in small batches, and identify important tradeoffs and negotiate them.
Domain Expertise - Demonstrated track record of domain expertise including understanding technical concepts necessary to do the job effectively and aware of industry trends, demonstrate willingness, cooperation, and concern for business issues and priorities, and possess in depth knowledge of immediate systems worked on and some knowledge of adjacent systems.
Problem Solving - Strong problem solver who ensures solutions are built for the long term, is able to resolve new issues, recognizes mistakes using them as learning and teaching opportunities and consistently breaks down large problems into smaller, more manageable ones.
Communication - Strong communicator who possesses the ability to articulate information clearly and concisely with the business, document work in a clear, easy to follow manner, collaborate well with team members as both a mentor and mentee, take in vague requirements and ask the right questions to ensure clarification, offer feedback appropriately and effectively, seek out and receives constructive criticism well, listen when others are speaking and make space for colleagues to share their thoughts.
Leadership - Intermediate leadership skills with the ability to help create a safe environment for others to learn and grow as engineers and a proven track record of self-motivation in identifying opportunities and tracking team efforts.
What is a Must Have?
Three years of system security experience.
What Is in It for You?
Health Insurance: Employees and their eligible family members - including spouses, domestic partners, and children - are eligible for coverage from the first day of employment.
Retirement: Travelers matches your 401(k) contributions dollar-for-dollar up to your first 5% of eligible pay, subject to an annual maximum. If you have student loan debt, you can enroll in the Paying it Forward Savings Program. When you make a payment toward your student loan, Travelers will make an annual contribution into your 401(k) account. You are also eligible for a Pension Plan that is 100% funded by Travelers.
Paid Time Off: Start your career at Travelers with a minimum of 20 days Paid Time Off annually, plus nine paid company Holidays.
Wellness Program: The Travelers wellness program is comprised of tools, discounts and resources that empower you to achieve your wellness goals and caregiving needs. In addition, our mental health program provides access to free professional counseling services, health coaching and other resources to support your daily life needs.
Volunteer Encouragement: We have a deep commitment to the communities we serve and encourage our employees to get involved. Travelers has a Matching Gift and Volunteer Rewards program that enables you to give back to the charity of your choice.
Employment Practices
Travelers is an equal opportunity employer. We value the unique abilities and talents each individual brings to our organization and recognize that we benefit in numerous ways from our differences.
In accordance with local law, candidates seeking employment in Colorado are not required to disclose dates of attendance at or graduation from educational institutions.
If you are a candidate and have specific questions regarding the physical requirements of this role, please send us an email so we may assist you.
Travelers reserves the right to fill this position at a level above or below the level included in this posting.
To learn more about our comprehensive benefit programs please visit *********************************************************
Senior Cloud Security Engineer
Security Engineer Job In Greenwich, CT
Interactive Brokers Group, Inc. (Nasdaq: IBKR) is a global financial services company headquartered in Greenwich, CT, USA, with offices in over 15 countries. We have been at the forefront of financial innovation for over four decades, known for our cutting-edge technology and client commitment.
IBKR affiliates provide global electronic brokerage services around the clock on stocks, options, futures, currencies, bonds, and funds to clients in over 200 countries and territories. We serve individual investors and institutions, including financial advisors, hedge funds and introducing brokers. Our advanced technology, competitive pricing, and global market help our clients to make the most of their investments.
Barron's has recognized Interactive Brokers as the #1 online broker for six consecutive years. Join our dynamic, multi-national team and be a part of a company that simplifies and enhances financial opportunities using state-of-the-art technology.
About INTERACTIVE BROKERS!
This is a hybrid role (three days in the office/two days remote).
Interactive Brokers Group has been consistently at the forefront of trading innovation, starting with the invention of the first floor-based handheld computer in 1983. We pride ourselves on being primarily a technology company and challenging the status quo. We push boundaries to offer our clients the best trading platform with the most sophisticated features at the lowest cost. Software development is the lifeblood of our firm, and it shows in our stellar brokerage platform. Interactive Brokers is regularly recognized as a leader in the financial services industry.
About your Team:
As IBKR Cloud Security Engineer, you will be responsible for designing, deploying, and operating a secure cloud infrastructure while supporting operational innovation, workflow automation, and elevation of IBKR's security posture within a cloud computing infrastructure. You will possess advanced troubleshooting skills and be knowledgeable about architecture, engineering, and design principles. They will consistently assess the threat landscape and adapt quickly to protect the business from identified threats. You will work closely with cloud infrastructure and application development teams to review their outputs for security risks and provide guidance on appropriate security practices.
What will be your responsibilities within IBKR:
* Develop and maintain secure, resilient enterprise-grade cloud security infrastructure and processes in collaboration with system architects, infrastructure engineers, and application developers.
* Conduct rigorous oversight of security systems and security configuration administration to reduce risk to enterprise systems and accounts.
* Develop and deploy strong identity and access management (IAM) controls across applications and computing environments.
* Advise on developing and utilizing scripts (e.g., Python, Ruby, Perl, etc.) to support custom Extract, Transform and Load (ETL) tools with a security focus on data flow.
* Actively monitor, assess and recommend tactical and strategic initiatives based on new and emerging threats to cloud computing environments.
* Manage and track remediation efforts triggered by security assessments related to cloud computing environments.
* Formulate, document, and implement security improvements that balance risks with business operations efficiency and the need for innovation.
Which skills are required:
* Must have five years of experience in cybersecurity with at least two years of exposure to cloud-based technologies and operations, preferably Amazon Web Services (AWS) or Microsoft Azure.
* Detailed technical understanding of how cloud environments operate "under the hood" (in addition to familiarity with best practices related to how cloud services should be utilized)
* Good understanding of security concepts and technologies
* Experience with network and host-based monitoring, logging, alerting, and response frameworks.
* Experience in scripting languages like Python, PowerShell, Javascript, Ruby, Perl, Unix Shell (bash/ksh), etc.
* Experience with Continuous Integration & Continuous Deployment (CI/CD) technologies, such as Jenkins, CodeBuild, Puppet, etc.
What would be nice to have:
* Experience creating and deploying Indications of Compromise (IoC), gathering system metrics, and responding to triggered alerts.
* Operational experience in maintaining and administrating the security posture of large-scale deployments
* Familiarity with common security frameworks and standards, such as NIST CSF, ISO/IEC 27001:27013, CIS CSC, PCI DSS, etc.
To be successful in this position, you will have the following:
* Self-motivated and able to handle tasks with minimal supervision.
* Superb analytical and problem-solving skills.
* Excellent collaboration and communication (Verbal and written) skills
* Outstanding organizational and time management skills
Company Benefits & Perks
* Competitive salary, annual performance-based bonus and stock grant
* Retirement plan 401(k) with a competitive company match
* Excellent health and wellness benefits, including medical, dental, and vision benefits and a company-paid medical healthcare premium
* Wellness screenings and assessments, health coaches and counseling services through an Employee Assistance Program (EAP)
* Paid time off and a generous parental leave policy
* Daily company lunch allowance provided, and a fully stocked kitchen with healthy options for breakfast and snack
* Corporate events, including team outings, dinners, volunteer activities and company sports teams
* Education reimbursement and learning opportunities
* Modern offices with multi-monitor setups
IDC Security Analyst
Security Engineer Job In Hartford, CT
Meta is seeking a highly skilled Security Engineer to join our Infrastructure Data Center (IDC) team as an individual contributor (IC). As a key member of our team, you will play a critical role in managing security risk to our global and rapidly scaling Data Center infrastructure footprint and innovative operational processes and services. This role will specifically focus on defining, operationalizing, and maturing a clear mid-to-long term security strategy for IDC's subsea infrastructure and operations.
**Required Skills:**
IDC Security Analyst Responsibilities:
1. Establish and mature a risk-informed baseline strategies and programs to secure a diverse global portfolio of mission-critical infrastructure and operations.
2. Serve as a comprehensive security expert accountable for security risk management across multiple logical and physical security domains (e.g., Data Security, Physical Security, Security Systems Architecture and Design, Governance Risk and Compliance, Incident Response, Threat Modeling, and/or Security Risk Management).
3. Assess security risk and communicate information about security threats and vulnerabilities to inform business decisions and drive strategy.
4. Assess and report on effectiveness of security controls to inform security strategy, manage security risk, and enable business operations.
5. Develop technical security guidance (e.g., standards, guidelines, playbooks) that aligns corporate policy, industry best practices, and regulatory requirements for securing IDC infrastructure.
6. Collaborate with network, software, and production engineering teams to develop security solutions that address physical and cyber/logical threats at scale.
7. Influence and align work to the overarching team and organizational vision and strategy.
8. Coach, mentor, support and care for the team to enable long-term career development, happiness, and success at scale.
**Minimum Qualifications:**
Minimum Qualifications:
9. Bachelors degree in Cyber Security or Computer Science or related technical field or equivalent relevant experience in information security.
10. 10+ years combined experience in physical security, logical/cyber security, risk management, compliance, and/or mission-critical infrastructure design, construction and operations
11. Technical experience across multiple security disciplines
12. Experience establishing, scaling, and maturing security services and programs
13. Experience managing, executing, and successfully delivering multiple complex projects and programs simultaneously
14. Experience identifying and communicating security roadmaps, risks, and requirements to inform leadership and drive execution-focused partners
15. Basic understanding and awareness of prevailing industry standards and guidelines
**Preferred Qualifications:**
Preferred Qualifications:
16. Master's degree in a related field
17. Experience securing large scale and globally dispersed mission-critical infrastructure (e.g., hyperscaler data centers, subsea and terrestrial cable, nuclear, major utilities, etc.)
18. Experience working on or managing projects that have enterprise-wide impact and/or multi-organization cross functional stakeholders
19. Experience in data analysis, visualization, and automation to streamline processes and measure security efficiency and effectiveness.
20. Experience securing physical and logical network infrastructure and operations
**Public Compensation:**
$167,000/year to $233,000/year + bonus + equity + benefits
**Industry:** Internet
**Equal Opportunity:**
Meta is proud to be an Equal Employment Opportunity and Affirmative Action employer. We do not discriminate based upon race, religion, color, national origin, sex (including pregnancy, childbirth, or related medical conditions), sexual orientation, gender, gender identity, gender expression, transgender status, sexual stereotypes, age, status as a protected veteran, status as an individual with a disability, or other applicable legally protected characteristics. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law. Meta participates in the E-Verify program in certain locations, as required by law. Please note that Meta may leverage artificial intelligence and machine learning technologies in connection with applications for employment.
Meta is committed to providing reasonable accommodations for candidates with disabilities in our recruiting process. If you need any assistance or accommodations due to a disability, please let us know at accommodations-ext@fb.com.
Cyber Security Operations Center (SOC) Analyst
Security Engineer Job In Hartford, CT
**Who Are We?** Taking care of our customers, our communities and each other. That's the Travelers Promise. By honoring this commitment, we have maintained our reputation as one of the best property casualty insurers in the industry for over 160 years. Join us to discover a culture that is rooted in innovation and thrives on collaboration. Imagine loving what you do and where you do it.
**Job Category**
Technology
**Compensation Overview**
The annual base salary range provided for this position is a nationwide market range and represents a broad range of salaries for this role across the country. The actual salary for this position will be determined by a number of factors, including the scope, complexity and location of the role; the skills, education, training, credentials and experience of the candidate; and other conditions of employment. As part of our comprehensive compensation and benefits program, employees are also eligible for performance-based cash incentive awards.
**Salary Range**
$75,500.00 - $124,700.00
**Target Openings**
1
**What Is the Opportunity?**
The Cybersecurity Operations Center Analyst is responsible for monitoring enterprise systems and performing incident responder in our 24x7x365 Security Operations Center (SOC). This is a shift-based, on-call position that works with a skilled cybersecurity team to help protect enterprise resources. Responsibilities will include, but not be limited to, performing cybersecurity analysis, monitoring, and incident response.
The ideal candidate will bring a background/experience in a hands-on Cybersecurity role, be a good communicator, have an aptitude for learning, finding a root cause, and can critically think through problems. Self-motivation and a desire to learn are key characteristics that will lead to success in this role.
This role works with experienced cybersecurity leads and uses modern technology to detect, analyze, and respond to alerts and cybersecurity events. You must be willing to work in a 24x7x365 team environment and be on-call during certain times, meaning you will be prepared to work evening and late-night schedules as required to perform incident response actions. Functionally, this means monitoring, researching, classifying, and analyzing security events that occur on across the cloud and on-premises environment. You will assess security events and follow procedures for overseeing these events, ranging from initial triage, investigation, and if needed, response. You will also periodically participate in broader projects, including investigations, automation development, data analysis, and process improvement.
**What Will You Do?**
+ Work in a 24x7x365 environment, have a team-centric focus, and be prepared to work evening, weekend, and holiday schedules (as required) for incident response readiness.
+ Able and willing to work off-hours for incident triage and response, on a rotational schedule.
+ Monitor environment and perform incident response via SIEM and SOAR platforms.
+ Critically think through alerts, triage through various enterprise log systems, and executive defensive technical actions in response to those alerts.
+ Maintains records of security monitoring and incident response activities, utilizing case management and ticketing technologies.
+ Evaluates and deconstructs phishing pages and malware (e.g., obfuscated code) through open-source and vendor provided tools.
+ Provide operational support, troubleshooting and maintenance of cybersecurity related processes, controls, or products.
+ Support reviewing or identifying security events and escalating to management.
+ Prepares briefings and simple reports of analysis methodology and results.
+ Creates and maintains standard operating procedures (SOPs) and other documentation including operating instructions and knowledge transfer articles.
+ Creates, debugs, modifies, and updates Security Information Event Management (SIEM) rules and SOAR automation playbooks.
+ Consolidates and performs comprehensive analysis of threat data obtained from external, proprietary, and open-source resources to provide indication and warnings of potential threats or threat vectors.
+ Generates end-of-shift reports for documentation and knowledge transfer to subsequent analysts on duty.
+ Function as a security representative at design and technology design and configuration meetings.
+ May provide guidance to more junior employees.
+ Perform other duties as assigned.
**What Will Our Ideal Candidate Have?**
+ Bachelor's Degree in a STEM (Science, Technology, Engineering, Math) discipline preferred.
+ Three years of relevant experience with Cybersecurity practices, processes, and Cybersecurity event investigation/resolution preferred.
+ Experience working in, or usable knowledge of, operations-focus team responsible for maintaining 24x7x365 availability.
+ Knowledge of cybersecurity methodologies, processes, and a conceptual understanding of other cybersecurity procedures and policies is required.
+ Working knowledge of Python.
+ Experience with GitHub.
+ Experience in some discipline of data analysis and root cause analysis.
+ Knowledge and experience in networking.
+ Knowledge and experience of breach and attack simulation (BAS) tools preferred.
+ Knowledge and experience in penetration testing preferred.
+ Ability to recognize and analyze problems of average complexity and independently consider a variety of alternatives to arrive at a timely, practical, and effective solution.
+ Ability to critically think through problems, and independently determine severity and sensitivity of various cybersecurity events.
+ An active participant in team standups, knowledge shares, and other sessions.
+ Proactively communicates status and anticipated problems.
+ Keeps team aware of status while monitoring (in relation to incident response activities).
+ Comfortable reaching out to coworkers and/or leads when progress is blocked.
+ Holds self and others accountable.
+ Flexible when selecting on-call rotations.
+ Builds relationships with teammates.
+ Works to build relationships with other departments and stakeholders.
+ Balances team and individual responsibilities.
+ Exhibits objectivity and openness to others' views.
+ Gives and welcomes feedback with both teammates and management.
+ Demonstrates the willingness to live out the values out service before self, integrity first, excellence in all we do.
+ Accountable for all tasks delegated by the supervisor.
+ Aptitude for managing own workload.
+ Seeks opportunity to lead, even as an individual contributor.
+ Able to sets appropriate goals and priorities and modify those based on team needs.
+ Ability to balance multiple tasks of competing priority on-time and with reasonable quality.
+ Provides management with accurate and timely status information.
**What is a Must Have?**
+ High school diploma or equivalent required.
+ One year of work experience within Computer Science or a related field required.
**What Is in It for You?**
+ **Health Insurance** : Employees and their eligible family members - including spouses, domestic partners, and children - are eligible for coverage from the first day of employment.
+ **Retirement:** Travelers matches your 401(k) contributions dollar-for-dollar up to your first 5% of eligible pay, subject to an annual maximum. If you have student loan debt, you can enroll in the Paying it Forward Savings Program. When you make a payment toward your student loan, Travelers will make an annual contribution into your 401(k) account. You are also eligible for a Pension Plan that is 100% funded by Travelers.
+ **Paid Time Off:** Start your career at Travelers with a minimum of 20 days Paid Time Off annually, plus nine paid company Holidays.
+ **Wellness Program:** The Travelers wellness program is comprised of tools, discounts and resources that empower you to achieve your wellness goals and caregiving needs. In addition, our mental health program provides access to free professional counseling services, health coaching and other resources to support your daily life needs.
+ **Volunteer Encouragement:** We have a deep commitment to the communities we serve and encourage our employees to get involved. Travelers has a Matching Gift and Volunteer Rewards program that enables you to give back to the charity of your choice.
**Employment Practices**
Travelers is an equal opportunity employer. We value the unique abilities and talents each individual brings to our organization and recognize that we benefit in numerous ways from our differences.
In accordance with local law, candidates seeking employment in Colorado are not required to disclose dates of attendance at or graduation from educational institutions.
If you are a candidate and have specific questions regarding the physical requirements of this role, please send us an email (*******************) so we may assist you.
Travelers reserves the right to fill this position at a level above or below the level included in this posting.
To learn more about our comprehensive benefit programs please visit ******************************************************** .
Mobile Security Engineer - Req# 1077
Security Engineer Job In Connecticut
Who we are... COCC delivers complete enterprise processing solutions to financial institutions throughout the northeastern United States. Listed among American Banker's FinTech 100 and the Inc. 5,000 fastest growing companies in the nation, COCC inspires the industry with innovation and top quality support. Designated as a Top Workplace in Connecticut, COCC recognizes employees as the core of our success! COCC offers a progressive training program to support employees in personal and professional development.
What we need
A Mobile Security Engineer to focus on identifying vulnerabilities, coding security enhancements, and educating the team on secure coding practices within our software development division. In this role, you will work collaboratively across teams to conduct regular security audits, author security policies and procedures, and better integrate security into our software development lifecycle. This role will combine experience in full-stack development and security engineering to enhance our mobile banking product.
What s in it for you
COCC offers a unique and collaborative experience as you grow your career with us and all of the benefits you d expect from an award-winning employer plus:
Hybrid schedules and ample paid time off allowing you work/life balance and flexibility
Customized training and onboarding to support you in your first year at COCC
Robust employee development programs aligned with career pathing objectives
Cutting-edge training and educational resources from vendors like SANS, PluralSight and CBTNuggets
Generous PTO offerings, benefits and competitive compensation
On-site fitness centers, wellness incentives, and lifestyle spending accounts
Tuition Reimbursement
One-on-one career coaching
DEIB initiatives championing inclusion and encouraging you to bring your whole self to work
Financial planning assistance with certified professionals
Peer recognition programs
What you ll do
Identify vulnerabilities in our applications, creating security policies and procedures, and educating teams on secure coding practices
Work with the relevant teams to assess and integrate network security tools into our software development lifecycle (SDLC) processes
Conduct regular security audits and assessments of production environments/mobile applications.
Support security teams in monitoring and analyzing production data and help respond to security threats.
Develop and maintain security monitoring tools and scripts.
What you ll bring
Bachelors in Computer Science, IT or related field is preferred for this role but will consider appropriate work experience and/or relevant certifications
4-6 years full stack software development experience with a focus on security engineering
Familiarity with Android and iOs specific security practices, binary protection and application integrity checks
Knowledge of security monitoring tools and techniques
Knowledge of of industry-standard encryption algorithms (e.g., AES, RSA) to secure data both in transit (via SSL/TLS) and at rest
Hands on experience securing API calls and utilization of best practices in securing API interactions
Experience with WAF, digesting WAF logs, SAST, DAST and SCA tools
Experience conducting or supporting penetration tests, including web application and API penetration testing
Ability to effectively communicate and collaborate across varying teams and departments
Desire to continue learning and developing skills in the latest security and software development practices
GMOB certification required; GSEC and OSCP certifications a plus
Available to work in the Southington, CT office on a hybrid schedule
The salary range for this position is $110000 - 155000 annually
Applicants for employment in the US must have work authorization that does not currently or in the future require sponsorship of a visa for employment authorization in the United States.
COCC is committed to maintaining a drug-free workplace. All applicants are required to pass a credit, background, and substance test prior to employment. COCC procures background and consumer reports in compliance with all Federal and State regulations, including The Fair Credit Reporting Act and CT Department of Labor laws regarding pre-employment screens. COCC is an equal opportunity employer committed to a community of inclusion, and an environment free from discrimination, harassment, and retaliation.
Accessibility - If you re a job seeker with a disability and require accessibility assistance or an accommodation to apply for one of our jobs, please let us know by calling ************ or emailing *************************. Please specify the help you need and we ll be happy to get back to you!
Microsoft Security Engineer - Information Protection
Security Engineer Job In Hartford, CT
Who You'll Work With As a modern technology company, our Slalom Technologists are disrupting the market and bringing to life the art of the possible for our clients. We have passion for building strategies, solutions, and creative products to help our clients solve their most complex and interesting business problems. We surround our technologists with interesting challenges, innovative minds, and emerging technologies.
The Global Technology Microsoft Center of Excellent (MCoE) drives strategic direction and enablement. We accelerate innovation and learning, advance sales and delivery excellence by amplifying Slalom's proven local model with high-caliber Microsoft technology expertise. Our focus is Microsoft's six go-to-market solution areas: Modern Work, Security, Azure Infrastructure, Digital & Application Innovation, Data & AI, and Business Applications.
Slalom is targeting Sr. Consultant or Consultant hires for this role.
What You'll Do
* Implement and manage security solutions for Microsoft environments.
* Focus on enhancing the end user experience across secure solution architectures.
* Deploy tailored M365 Compliance configurations with Purview Information Protection, Data Loss Prevention (DLP), data lifecycle management, and records management.
* Implement and manage Azure data governance solutions.
* Collaborate with IT and security teams to ensure compliance with security policies.
* Conduct security audits and assessments.
* Provide technical support and guidance on security matters.
* Develop and maintain security policies, standards, and guidelines.
* Stay current with emerging security threats and technologies.
Who You Are
* Experience as a Microsoft Security Engineer or similar role.
* Proficiency in Microsoft security technologies and tools, including Purview Information Protection, DLP, data lifecycle management, records management, and Azure data governance.
* Strong troubleshooting and problem-solving skills.
* Excellent communication and teamwork skills.
* Ability to work independently and as part of a team.
* Strong understanding of security best practices and regulatory requirements.
* Experience with security frameworks such as NIST, ISO 27001, and CIS Controls.
About Us
Slalom is a purpose-led, global business and technology consulting company. From strategy to implementation, our approach is fiercely human. In six countries and 43 markets, we deeply understand our customers-and their customers-to deliver practical, end-to-end solutions that drive meaningful impact. Backed by close partnerships with over 400 leading technology providers, our 13,000+ strong team helps people and organizations dream bigger, move faster, and build better tomorrows for all. We're honored to be consistently recognized as a great place to work, including being one of Fortune's 100 Best Companies to Work For seven years running. Learn more at slalom.com.
Compensation and Benefits
Slalom prides itself on helping team members thrive in their work and life. As a result, Slalom is proud to invest in benefits that include meaningful time off and paid holidays, parental leave, 401(k) with a match, a range of choices for highly subsidized health, dental, & vision coverage, adoption and fertility assistance, and short/long-term disability. We also offer yearly $350 reimbursement account for any well-being-related expenses, as well as discounted home, auto, and pet insurance.
Slalom is committed to fair and equitable compensation practices. For this position at the Consultant level the base salary pay range is $96,000 to $177,000. For this position at the Senior Consultant level the base salary pay range is $110,000 to $203,000. In addition, individuals may be eligible for an annual discretionary bonus. Actual compensation will depend upon an individual's skills, experience, qualifications, location, and other relevant factors. The salary pay range is subject to change and may be modified at any time.
EEO and Accommodations
Slalom is an equal opportunity employer and is committed to inclusion, diversity, and equity in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veterans' status, or any other characteristic protected by federal, state, or local laws. Slalom will also consider qualified applications with criminal histories, consistent with legal requirements. Slalom welcomes and encourages applications from individuals with disabilities. Reasonable accommodations are available for candidates during all aspects of the selection process. Please advise the talent acquisition team if you require accommodations during the interview process.
We are accepting applicants until 4/4/2025..
In-Vehicle Cyber Security Engineer
Security Engineer Job In Hartford, CT
We are the movers of the world and the makers of the future. We get up every day, roll up our sleeves and build a better world -- together. At Ford, we're all a part of something bigger than ourselves. Are you ready to change the way the world moves?
The In-Vehicle Cybersecurity Engineer will act as a technical lead designing security into our vehicles. Engineers will evaluate, critique, and drive secure designs from concept to implementation. In-Vehicle Cybersecurity Engineers identify new methods of securing our technologies from drafting specifications to executing testing.
Engineers need to be able to understand and evaluate risk for in-vehicle systems. Recognizing and accommodating the limitations of embedded in-vehicle systems is essential. Engineers are expected to take ownership of assignments including developing in-depth understanding of the technologies under review, working to close security gaps and mitigate identified vulnerabilities, and report out to security management. Over time, Engineers will grow to become subject matter experts acting to develop and mature security controls and features in the vehicle.
**What you'll do...**
+ Own ECU and Vehicle level cyber security design and process integration
+ Interface with cross-functional teams on technical issues related to cyber security
+ Perform risk analysis (i.e. TARA) so that appropriate countermeasures can be developed
+ Develop and maintain security requirements and design validation methodologies (DVM)
+ Develop and maintain technical documentation as required
+ Provide training and consulting to internal Ford function teams
+ Support major product programs/new features with security needs
+ Collaborate on Advanced Engineering projects with internal and external partners
+ Research technologies and security benchmarking data gathering
+ Some traveling may be required (conferences, regional team meetings, government/academia visits, etc.)
**You'll have...**
+ Bachelor's Degree in Electrical Engineering, Computer Engineering, Software Engineering or Computer Science OR a combination of education and experience
+ 5+ years of experience with embedded, IoT and/or automotive systems cyber security
+ Experience with security system engineering, development, and testing
+ Experience with networking and communication protocols (e.g. firewall config, TLS, MACsec, etc.)
+ Experience designing cyber security controls such as secure communication/networking, secure gateway, IDS, IPS, secure boot, etc.
+ Experience developing and maintaining engineering documentation including requirements, specifications, test plans, etc.
+ Self-starter with ability to work independently and collaboratively
+ Strong communication and analytical skills
**Even better, you may have...**
+ Master's Degree in Cyber Security, Electrical Engineering, Computer Engineering, Software Engineering or Computer Science is a plus
+ 7+ years of experience with embedded, IoT and/or automotive systems cyber security
+ Experience with in-vehicle network architecture, modules, and protocols (Automotive Ethernet, CAN/CAN-FD, J1939, USB, SPI, UART, JTAG, etc.)
+ Experience with symmetric and asymmetric cryptography, digital signature, hash, message authentication, encryption, key exchange
+ Experience with HSM, SHE, TEE, SELinux, hypervisor, etc.
+ Experience with SecOC, AUTOSAR
+ Understanding of embedded RTOS and Linux based operating systems
+ Understanding of system level architecture, development, design principals
+ Experience with at least one modern software programming language (C, C++, C#, Python, Java, etc.)
+ CISSP, GSEC, etc. are a plus
This description outlines the general nature and scope of work typically performed in this job. It is not intended to be an exhaustive list of all duties, responsibilities, knowledge, skills, work requirements, etc. It may vary slightly based on business or geographic needs and is subject to being reviewed and updated periodically.
You may not check every box, or your experience may look a little different from what we've outlined, but if you think you can bring value to Ford Motor Company, we encourage you to apply!
As an established global company, we offer the benefit of choice. You can choose what your Ford future will look like: will your story span the globe, or keep you close to home? Will your career be a deep dive into what you love, or a series of new teams and new skills? Will you be a leader, a changemaker, a technical expert, a culture builder...or all of the above? No matter what you choose, we offer a work life that works for you, including:
- Immediate medical, dental, vision and prescription drug coverage
- Flexible family care days, paid parental leave, new parent ramp-up programs, subsidized back-up child care and more
- Family building benefits including adoption and surrogacy expense reimbursement, fertility treatments, and more
- Vehicle discount program for employees and family members and management leases
- Tuition assistance
- Established and active employee resource groups
- Paid time off for individual and team community service
- A generous schedule of paid holidays, including the week between Christmas and New Year's Day
- Paid time off and the option to purchase additional vacation time.
For a detailed look at our benefits, click here:
******************************* (****************************************************************************************************************************************************************************
This position is a range of salary grades **7-8.**
Visa sponsorship is not available for this position.
SOUTHEAST MI RESIDENTS: Please note, this job is posted as remote unless the selected candidate lives within 50 miles of Dearborn, MI. In this case we request the candidate to be on-site 1-2 days a week.
Candidates for positions with Ford Motor Company must be legally authorized to work in the United States. Verification of employment eligibility will be required at the time of hire.
We are an Equal Opportunity Employer committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race, religion, color, age, sex, national origin, sexual orientation, gender identity, disability status or protected veteran status. In the United States, if you need a reasonable accommodation for the online application process due to a disability, please call **************.
\#LI-Remote
**Requisition ID** : 41638
Manager, Application Security Engineer
Security Engineer Job In Stamford, CT
Known for being a great place to work and build a career, KPMG provides audit, tax and advisory services for organizations in today's most important industries. Our growth is driven by delivering real results for our clients. It's also enabled by our culture, which encourages individual development, embraces an inclusive environment, rewards innovative excellence and supports our communities. With qualities like those, it's no wonder we're consistently ranked among the best companies to work for by Fortune Magazine, Consulting Magazine, Seramount, Fair360 and others. If you're as passionate about your future as we are, join our team.
KPMG is currently seeking a Manager, Application security Engineer to join our Global Technology & Knowledge group which is part of the KPMG International organization.
Responsibilities:
* Collaborate with development teams to incorporate security best practices and principles into application design and development
* Conduct manual and automated source code reviews to identify security vulnerabilities in software applications
* Perform application threat modeling to identify potential security weaknesses and risks in software architecture
* Identify, track and remediate vulnerabilities in applications and related infrastructure using security testing tools
* Work closely with Development, DevOps, and Infrastructure teams to automate security checks and ensure secure coding practices are followed
* Support security architects to generate and maintain regular reports on security posture of applications and infrastructure, including metrics, KPIs, vulnerabilities status, and more
Qualifications:
* Minimum four years of recent experience with relevant application development and information technology (IT) security experience
* Bachelor's degree from an accredited college or university in computer science, information technology or engineering or relevant work experience; professional certifications in information technology security
* Minimum four years of recent work experience writing production-level code in any programming language and/or developer frameworks, such as C#, ASP.NET, MVC, Python, Ruby, Go, and more; minimum four years of recent work experience identifying and mitigating security issues in software and knowledge of best practice secure code development
* Experience or knowledge of security tools such as GitHub Advanced Security, Fortify, Fortify On-Demand, Mend, Qualys, Visual Studio Team Suite, Microsoft Defender for Cloud, and more
* Proven communication skills and high attention to detail; experience in designing, analyzing and conducting threat model assessments of enterprise software and services; experience in penetration testing or red team operations preferred
* Must be authorized to work in the U.S. without the need for employment-based visa sponsorship now or in the future. KPMG LLP will not sponsor applicants for U.S. work visa status for this opportunity (no sponsorship is available for H-1B, L-1, TN, O-1, E-3, H-1B1, F-1, J-1, OPT, CPT or any other employment-based visa)
KPMG complies with all local/state regulations regarding displaying salary ranges. If required, the ranges displayed below or via the URL below are specifically for those potential hires who will work in the location(s) listed. Any offered salary is determined based on relevant factors such as applicant's skills, job responsibilities, prior relevant experience, certain degrees and certifications and market considerations. In addition, the firm is proud to offer a comprehensive, competitive benefits package, with options designed to help you make the best decisions for yourself, your family, and your lifestyle. Available benefits are based on eligibility. Our Total Rewards package includes a variety of medical and dental plans, vision coverage, disability and life insurance, 401(k) plans, and a robust suite of personal well-being benefits to support your mental health. Depending on job classification, standard work hours, and years of service, KPMG provides Personal Time Off per fiscal year. Additionally, each year the firm publishes a calendar of holidays to be observed during the year and provides two firmwide breaks each year where employees will not be required to use Personal Time Off; one is at year end and the other is around the July 4th holiday. Additional details about our benefits can be found towards the bottom of our KPMG US Careers site at "Benefits & How We Work".
Follow this link to obtain salary ranges by city outside of CA:
**********************************************************************
California Salary Range: $101200 - $215100
KPMG LLP (the U.S. member firm of KPMG International) offers a comprehensive compensation and benefits package. KPMG is an equal opportunity employer. KPMG complies with all applicable federal, state and local laws regarding recruitment and hiring. All qualified applicants are considered for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, citizenship status, disability, protected veteran status, or any other category protected by applicable federal, state or local laws. The attached link contains further information regarding the firm's compliance with federal, state and local recruitment and hiring laws. No phone calls or agencies please.
KPMG does not currently require partners or employees to be fully vaccinated or test negative for COVID-19 in order to go to KPMG offices, client sites or KPMG events, except when mandated by federal, state or local law. In some circumstances, clients also may require proof of vaccination or testing (e.g., to go to the client site).
KPMG recruits on a rolling basis. Candidates are considered as they apply, until the opportunity is filled. Candidates are encouraged to apply expeditiously to any role(s) for which they are qualified that is also of interest to them.
Los Angeles County applicants: Material job duties for this position are listed above. Criminal history may have a direct, adverse, and negative relationship with some of the material job duties of this position. These include the duties and responsibilities listed above, as well as the abilities to adhere to company policies, exercise sound judgment, effectively manage stress and work safely and respectfully with others, exhibit trustworthiness, and safeguard business operations and company reputation. Pursuant to the California Fair Chance Act, Los Angeles County Fair Chance Ordinance for Employers, Fair Chance Initiative for Hiring Ordinance, and San Francisco Fair Chance Ordinance, we will consider for employment qualified applicants with arrest and conviction records.
Senior Security Sales Engineer - Commercial Northeast
Security Engineer Job In Hartford, CT
As a Senior Sales Engineer at Rapid7, you will partner closely with our Sales team as the technical point of contact to new and existing customers across all of Rapid7's award winning solutions.
If you are comfortable going toe-to-toe in a technical discussion with engineers before shifting gears and having a business value conversation with a CIO, this may be the opportunity for you!
Data Security Engineer
Security Engineer Job In Stamford, CT
div itemprop="description"section class="job-section" id="st-"divp class="googlejobs-paragraph--empty"/ph2 class="title"Job Description/h2/divdiv class="wysiwyg" itemprop="responsibilities"pstrong What you'll do/strong/pp• Design and implement comprehensive data security architectures, with particular focus on database platforms (primarily SQL Server)br/
• Develop and maintain enterprise-wide encryption strategies for securing structured and unstructured data both in transit and at rest, both and both on-premise and in the cloudbr/
• Enhance logging, monitoring and SecOps capabilities of enterprise databases and other data storesbr/
• Configure and optimize Identity and Access Management (IAM) solutions across data platforms and repositories to align to least privilege principlesbr/
• Implement Data Loss Prevention (DLP) strategies and controlsbr/
• Implement and maintain Information Rights Management (IRM) and Digital Rights Management (DRM) solutionsbr/
• Design and implement data tokenization strategies where appropriatebr/
• Secure data processing pipelines and ensure appropriate controls for data workflowsbr/
• Create and maintain data security documentation, including policies, procedures, and standardsbr/
• Collaborate with development teams to ensure security best practices in data handlingbr/
• Conduct vulnerability assessments of the firm's database architecture and associated data storage and processing systemsbr/
• Assist in monitoring and managing security patching and upgrade processes for database platformsbr/
br/
strong What's required/strongbr/
• Bachelor's degree in computer science, cybersecurity, or related technical fieldbr/
• 6+ years of experience in data/database security engineering and governancebr/
• Deep expertise in database security, particularly SQL Serverbr/
• Comprehensive understanding of data warehouse/data lake architectures and tools, particularly Databricks (required)br/
• Subject matter expertise in Object Storage (eg: S3, Azure Blob, etc) and related securitybr/
• Understanding of Active Directory Delegation (constrained vs. unconstrained) and associated best practicesbr/
• Experience with 3rd-party SQL Server security governance and monitoring products (eg: Idera, Solarwinds)br/
• Extensive knowledge of encryption technologies for both structured and unstructured databr/
• Broad knowledge of secure data/file sharing solutions and ETL workflowsbr/
• Experience designing and implementing data tokenization solutionsbr/
• Experience with data classification and DLP technologiesbr/
• Scripting/automation capabilities (eg: SQL, PowerShell, Python)br/
• Commitment to the highest ethical standards/p/div/sectionsection class="job-section" id="st-qualifications"divp class="googlejobs-paragraph--empty"/ph2 class="title"Qualifications/h2/divdiv class="wysiwyg" itemprop="qualifications"pstrong Ivy league/strong colleges education preferred or huge plus./pp /p/div/sectionsection class="job-section" id="st-additional Information"divp class="googlejobs-paragraph--empty"/ph2 class="title"Additional Information/h2/divdiv class="wysiwyg" itemprop="incentives"pAll your information will be kept confidential according to EEO guidelines./p/div/section/div
Firewall Security Engineer
Security Engineer Job In Stamford, CT
Duration: 6+ Months Experienced Firewall administrator for operational implementation, maintenance and configuration of firewalls. Key Responsibilities: Performs maintenance and changes in firewalls as required. Implementation of new firewalls as required
Assists with troubleshooting network connectivity as it relates to firewalls
Utilizes change management, request, and ticketing systems, documents status updates and problem resolutions
Complete All assignments in a timely manner with an acceptable level of quality
Maintains documentation related to work area
Completes network change requests
Follows documented processes, procedures and policies
Performs customer service duties and responds to customer and project requests as defined by management
Other related duties assigned as needed.
Qualifications/Requirements:
Bachelor's degree and with 3 to 4 years of operational experience administering Firewalls
4 or more years networking/firewall background
Must have networking TCP/IP routing protocol experience
Desired Characteristics:
In-depth experience in security aspects of multiple platforms, operating systems, software, communications and network protocols is desired
Competency in verbal, written, and presentation communications and interpersonal understanding
Ability to understand customer's business needs.
Leadership of work teams/groups
Ability to work with all levels of employees
Highly motivated and able to work effectively under minimal supervision in a fast-paced environment
Team-oriented, placing priority on quality and the successful completion of team goals
Organization and planning skills that include: time management, project coordination and management, and the ability to handle multiple deadlines and associated pressures.
Competency in developing effective solutions to business problems
Ability to analyze problems and to make decisions
REQUIRED SKILLS
YEARS OF EXPERIENCE
WHEN THE SKILL WAS LAST USED
Expert knowledge of Cisco Security products, ASA and Firepower
Expert knowledge of NSX
Expert knowledge of Palo Alto systems
Security Certifications a Plus
Must have networking TCP/IP routing protocol experience
Networking/firewall background
Operational experience administering Firewalls
Additional Information
All your information will be kept confidential according to EEO guidelines.
Infrastructure Security Engineer - FedRAMP (US Citizen)
Security Engineer Job In Hartford, CT
**Title:** Infrastructure Security Engineer (US citizen) **Salary:** $120K/annually **About PSI** We are PSI Services. We power world leading tests. Delivered with trusted science and the very best test taker experience. PSI supports test-takers on their journey to pursuing dreams and gaining certifications that are important to them. They believe that their dreams are worth working for; that their dreams are worth the effort. And we believe that too. This is our core purpose, to empower people to achieve their dreams. We do this by being the best provider of workforce solutions, which foster both technology and science to deliver the best solutions for our test takers.
We are searching for top talent to join our PSI team and help grow our products and services. We have a creative, supportive and inclusive culture where we empower people in their careers to be their authentic self and make the most of their great talent.
At PSI, we are committed to helping people meet their potential and we believe that promoting diversity, equity and inclusion is critical to our success. That's why you'll find these ideals are intrinsic to our company culture and applied throughout the employee lifecycle.
Learn more about what we do at: *************************
**About the Role**
The Infrastructure Security Engineer (ISE) is responsible for ensuring that PSI systems are secure, well maintained, and appropriately monitored. They work with senior management across all business units to design security solutions and ensure that PSI environments are designed and maintained in accordance with industry standards.
Infrastructure Security Engineers ensure adherence to ISO27001, SOC2, CIS, NIST and other standards. They possess a broad understanding of log aggregation solutions, server hardware, Linux and Windows operating systems, storage, networking, and load balancing. The Infrastructure Security Engineer leads projects and organizes teams to achieve technical and security objectives.
Infrastructure Security Engineers work as part of a global team to design, implement, and monitor security across the organization. They engage with vendors, business and technology partners to lead projects and constantly improve security posture.
**Role Responsibilities**
+ Lead projects to evaluate, select, and implement security technologies
+ Design, configure, implement, and maintain all security platforms and their associated software: firewalls, intrusion detection/intrusion prevention, antivirus/EDR, URL Filtering, email security gateway, SIEM, vulnerability assessment solutions, DLP
+ Respond to security events and incidents performing containment, root cause analysis, and remediation.
+ Maintain enterprise vulnerability scanning infrastructure, ensuring daily operation of scans and reporting are occurring as required
+ Coordinate and sequence external scans and penetration testing
+ Monitor application and system activity logs for potential threats
+ Keep up to date with evolving trends and changes in security models and methodologies
+ Threat model common attacker methods to develop appropriate mitigation techniques
+ Define and develop technical security standards and guidelines with business stakeholders
+ Participate in product security architecture planning for both on-premises and cloud-based solutions
+ Ensure server infrastructure is secure, patched and updated
+ Take proactive steps to resolve issues before they impact the business
+ Maintain accurate and up to date security documentation
+ Serve as team lead and subject matter expert for security
**Knowledge, Skills and Experience Requirements**
+ Bachelor's degree in computer science or equivalent training/certification.
+ 10+ years of working experience as a Security Engineer or Systems Engineer
+ 5+ years of working experience with email security tools such as Proofpoint
+ 5+ years of working experience with CrowdStrike EDR and SIEM solutions
+ Ability to achieve federal security clearance, must be a US Citizen
+ Experience with FedRamp security controls,
+ In-depth knowledge and understanding of the integration of AWS with fundamental Information Security methodologies for both architectural review and implementation
+ Strong knowledge of Windows and Linux environments
+ Experience drafting and promoting security policy with all levels of business stakeholders
+ Experience and detailed technical knowledge of security engineering, system and network security, authentication and security protocols, cryptography, and application security
+ Detailed knowledge of core server technologies and domain configuration and management, including DNS, DHCP, AD and group policy
+ Experience in Domain Trusts, Active Directory Federation, and Entra ID
+ Experience managing remote infrastructure across multiple time zones
+ Detailed understanding of Azure, AWS, Hyper-V, VMWare and SAN technologies
+ Understanding of network topologies such as VLANs, IPs, subnets, and routing
+ Understanding of PowerShell / VB Scripting
+ Good written and verbal communication skills with the ability to follow a project from beginning to end while providing updates along the way, while prioritizing time and dealing with multiple projects
+ Experience with CIS Hardening Standards and/or DISA STIGs
+ Experience with load balancers (F5, Barracuda, Azure)
**Benefits & Culture**
At PSI, our culture is to be transparent and fair. That's why all of our roles have been benchmarked at a competitive rate against the local market they are based in. To be transparent all of our adverts now include the salary so you can see if we align with your expectations when looking for your next role.
In addition to a competitive salary, we offer a comprehensive benefits package and supportive culture when you join us. This includes:
+ 401k/Pension/Retirement Plan - with country specific employer %
+ Enhanced PTO/Annual Leave
+ Medical insurance - country specific
+ Dental, Vision, Life and Short-Term Disability for US
+ Flexible Spending Accounts - for the US
+ Medical Cashback plan covering vision, dental and income protection for UK
+ Employee Assistance Programme
+ Commitment and understanding of work/life balance
+ Dedicated DE&I group that drive core people initiatives
+ A culture of embracing wellness, including regular global initiatives
+ Access to supportive and professional mechanisms to help you plan for your future
+ Volunteer Day and a culture of giving back to our community and industry through volunteering opportunities
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
The contractor will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with the contractor's legal duty to furnish information. 41 CFR 60-1.35(c)
Security Engineer
Security Engineer Job In Shelton, CT
We are Subway Headquarters! A dedicated team of professionals supporting thousands of franchisees around the globe.
Region: Shelton, CT
Ready for a fresh, new career? Look no further because one of the world's most iconic brands can help you get there.
Why Join Us?
At Subway, “better” is baked into our DNA. We are a brand that believes in continued improvement … in our lives, our businesses, and our planet. From the handshake that started our very first sandwich shop to earning our position as one of the world's leading restaurant brands, we've always embraced change and the path ahead. And today, we're making better living way easier.
Our purpose is about more than the food we serve in our restaurants. It's centered on fueling healthy businesses and healthier lives. It is one of the most exciting times to join the Subway team and contribute to our transformational journey.
About the Role:
We have an exciting opportunity to support our Information Security team as a Security Engineer based in Shelton, CT. We are seeking an experienced, highly skilled Information Security Engineer to serve a foundational role in building, implementing, and managing our threat detection capabilities or opportunities. An ideal candidate for this role is curious, accountable, motivated, and proficient in their craft. Applicants are adept with event data management and telemetry controls for networks, operating systems, software, data systems, CI/CD and VCS, SaaS and various Enterprise technologies. An ability to skillfully apply analytical logic and engineering techniques for the purpose of detecting threats throughout the entire Cyber Kill-Chain is desired.
This role necessitates a challenge-seeking mindset, with an intuitive sense of urgency and an ability to adapt quickly to threats while operating well-organized, mature engineering practices. Collaborating both laterally and vertically in the department is a crucial aspect of this role.
The Security Operations and Information Security department consists of high-performance, adaptive, and creative team members. As a member of the team, a desire for seeking opportunities of contribution and knowledge building is an important purpose of your role.
If you feel that this is the role for you, and you are successful with your application, be ready to be Bold, Empowered, Accountable, and ready to have Fun in a fast paced and agile working environment.
Responsibilities include but are not limited to:
Subject matter expert in interpreting SIEM, EDR and other telemetry tooling events, facts or observations.
Analyze patterns and behaviors in a variety of data flows and events from networks comprised of NGFW, cloud service provider resources, and edge network infrastructure.
Perform reverse engineering of complex behaviors and scenarios within Windows operating systems of a global Enterprise environment.
Manage threats using industry best practices and platform controls such as Microsoft 365 workforce software, messaging, email, endpoints, data protection and access controls.
Perform analysis and examine timeline observations to confirm any threats from weakness or attack within cloud service provider systems such as Azure and AWS.
Provide Incident Response support and serve as an escalation point for SOC Analyst triage workflows and threat validation.
Design, build and manage new detection capabilities in cybersecurity toolkits.
Routinely apply feedback and results from threat detection to improve accuracy.
Measure the progress and efficacy of our threat detection capabilities to meet objectives.
Research and test methods to proactively reduce threats through innovative techniques and automation opportunities.
Qualifications:
Bachelor's degree in a related field required.
Ability to assess exposure to threats in practical terms for impact and prioritization of detection engineering.
Expertise in Enterprise systems operation (such as Microsoft 365, Azure DevOps, GitHub, Amazon Web Services, and Okta IDaaS) and an ability to discover their potential threats to develop new capabilities for detection.
Expertise in networking topics such as the OSI stack, TCP/UDP protocols, OSPF/BGP, access controls, and NGFW (Palo Alto) threat management.
Expertise in endpoint threat detection and response (such as Carbon Black, CrowdStrike and Microsoft Defender).
Expertise in cloud threat detection and response (such as Microsoft Defender for Cloud, AWS GuardDuty, Dynatrace and Wiz).
Expertise in software release management and CI/CD processes (such as ServiceNow ITSM, Azure DevOps and GitHub).
Utilizing threat intelligence signals for improving detection capabilities.
Keen sense of urgency and ability to thrive in high-energy and rapid response situations.
Strong knowledge of sensitive data types and terminology in Data Management and Data Governance.
Strong knowledge of offensive and defensive cybersecurity practices and routines.
What do we Offer?
Insurance Plans (Medical/Life)
401K
Competitive Bonus