Demo

Security and Privacy Professional

DevSelect
Seattle, WA Full Time
POSTED ON 2/4/2025
AVAILABLE BEFORE 3/3/2025

Title: Security and Privacy Professional
Reports to: CIO
Salary: DoE

POSITION SUMMARY

This position resides within the  Digital Services  group of  CLIENT. The  Security  and Privacy  Professional,  in close partnership with the CIO and CISO, oversees  and coordinates day-to-day  activity  related to information security  and privacy   oriented initiatives,  policies, standards  and procedures   throughout  the organization.  The Security  and  Privacy Professional  is responsible  for  planning,  influencing,  and coordinating the company's information security  policies, setting procedures and guidelines  to ensure that all information systems  are functional,  secure  and safeguarded throughout  the  company  and are  in compliance  with privacy  and information security  laws and regulations  applicable to retail institutions.  Additionally,  the Security  and Privacy  Professional  is responsible for providing leadership during security  events,  as well  as ensuring the technical  and administrative  support for  the development  of  Disaster  Recovery  and  Business Continuity programs for the company. The incumbent  interfaces with theInformation and Digital
Services  Core IT Operations  team on matters of security  and privacy  operational  controls. In addition, the  incumbent  acts as an internal consultant and to the organization  on issues involving security  and privacy.
 
 

RESPONSIBILITIES

  • Work to determine acceptable risk levels for the enterprise and ensure that the IT environments are adequately protected from potential risks and threats
Participate in development and implementation of the appropriate and effective controls to mitigate identified threats and  risks
Assist in tactical follow-up on detected security issues and drive the design and implementation of solutions to reduce security risks
Drive the  research, development,  and communication  around  Security  and Privacy matters,  by maintaining and working  with the  operational  units on the enforcement ofIT security  architecture,  policies,  procedures, solutions  and standards
Participate in and provide specific IT security oriented leadership during incident response planning as well as the investigation of security breaches, and assist with disciplinary and legal matters associated with such breaches as necessary
Keep abreast and advise the company with regard to the latest industry security and privacy   best-practices  and technologies
Coordinate with Business Owners to analyze, document and define requirements associated with new development or maintenance and enhancements to existing security  roles  and permissions.
Deliver services that meet regulatory specifications. Work with internal and external auditors to document and confirm that all security administrative duties are properly performed as well as demonstrate overall compliance .
 
 

Qualifications

A minimum of 5 years operational and strategic experience in IT controls and information security, IT compliance, networking security or IT audit is required.
Artifact management experience including the development and maintenance of Policies, Standards, and other supporting documentation. Ability to document and maintain the details of IT remediation projects, committee meetings, and the findings  of security testing and assessment   projects.
Operational experience with IT compliance requirements and processes, especially PCI DSS and adjacent PCI industry controls, mitigations, and incident   responses.
Operational experience in the inventory and classification of IT assets, and the update and maintenance thereof
Access control and identity management experience, including the principles and management of access to network infrastructure, server platforms, Active Directory domains, and databases. Ability to provide subject matter expertise in the areas of configuration management and maintenance of access control and assessment of access for these systems. Knowledge of RADIUS, LDAP, and Cloud SSO solutions  is a plus
Skilled in the principles and management of key management and encryption systems, for information in transit and at rest. Extensive knowledge of both symmetric  and  asymmetric  cryptographic systems
Demonstrate  extensive  experience  with  vulnerability management
 
 

Education

4-year  college  degree or demonstrated  equivalent  experience  with appropriate time-in-role,  with subject matter majors  in Computer  Science, Information Management, Information Security  or equivalent  disciplines
A SANS, CISSP or other equivalent industry-recognized Security certification is required.
Additional certifications in IT audit or IT controls design and management are preferred
CObIT and/orITIL certifications, education, or equivalent experience  with control  and operational  frameworks  a strong  plus
 
 

Technical Skills

Information security  assessment  and auditing  procedures, from  both technical  and business perspectives,  and the  use of formal  methodologies  such as  NSAIAM
  • Vulnerability sanning and auditing tools
Enterprise-scale  network and host-basedIDS architectures Enterprise-scale firewall  architectures
E-commerce  application security

Computer investigation and forensics methods and technologies Secure messaging architectures
Strong Knowledge of regulatory bodies, and the regulations and guidance issued by these bodies
Strong knowledge of control and privacy laws and standards, such as GLBA, 581386, SOX and PCI
Must possess strong project management and leadership aptitude; demonstrated professionalism  in managing  multiple  projects  and  resources effectively.
 
 

General Knowledge and  Abilities

Experience with PKI certificate management and root certificate repositories Working  experience  with  penetration testing
  • Experience working in a SaaS oriented Cloudenvironment Project Management experience
Strong  communication  and  facilitation skills
 
 

Physical  Requirements

Office based professional,  no physical  requirements

If your compensation planning software is too rigid to deploy winning incentive strategies, it’s time to find an adaptable solution. Compensation Planning
Enhance your organization's compensation strategy with salary data sets that HR and team managers can use to pay your staff right. Surveys & Data Sets

What is the career path for a Security and Privacy Professional?

Sign up to receive alerts about other jobs on the Security and Privacy Professional career path by checking the boxes next to the positions that interest you.
Income Estimation: 
$74,406 - $101,969
Income Estimation: 
$124,273 - $166,183
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$194,072 - $240,547
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$77,991 - $108,747
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$112,673 - $137,290
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$123,246 - $161,441
Income Estimation: 
$152,549 - $188,894
Income Estimation: 
$135,994 - $168,063
Income Estimation: 
$161,209 - $233,553
Income Estimation: 
$111,725 - $147,313
Income Estimation: 
$139,945 - $168,577
Income Estimation: 
$140,233 - $181,029
Income Estimation: 
$161,209 - $233,553

Sign up to receive alerts about other jobs with skills like those required for the Security and Privacy Professional.

Click the checkbox next to the jobs that you are interested in.

  • Cybersecurity Skill

    • Income Estimation: $87,466 - $114,731
    • Income Estimation: $92,662 - $117,866
  • Data Security Skill

    • Income Estimation: $81,253 - $112,554
    • Income Estimation: $93,919 - $117,786
View Core, Job Family, and Industry Job Skills and Competency Data for more than 15,000 Job Titles Skills Library

Job openings at DevSelect

DevSelect
Hired Organization Address Remote, MD Full Time
Title: AWS Architect Location: Remote (USA) Openings: 1 Type: Permanent Hire CLIENT’s engineering team is comprised of l...
DevSelect
Hired Organization Address Seattle, WA Full Time
Title: Senior Release/DevOps Engineer Location: Seattle, WA Openings: 1 Type: Full Time Hire Job Description The CLIENT ...
DevSelect
Hired Organization Address Redmond, WA Full Time
Solutions Architect Category: Systems Engineering Type: Employee W-2 Description: Exciting opportunity for a Solutions A...
DevSelect
Hired Organization Address Redmond, WA Full Time
Sr. Network Engineer Category: Information Technology Type: Employee W-2 Description: We are looking for network enginee...

Not the job you're looking for? Here are some other Security and Privacy Professional jobs in the Seattle, WA area that may be a better fit.

Security Professional (SE1014)

PalAmerican Security, Mountlake Terrace, WA

Unarmed security professional

PalAmerican Security, SeaTac, WA

AI Assistant is available now!

Feel free to start your new journey!