What are the responsibilities and job description for the Principal Cybersecurity Engineer position at Infyshine, Inc?
Company Description
Infyshine Technologies is a Staffing, IT Services, and Product Development Company that provides innovative solutions to give businesses a competitive advantage. With a team of experts, we offer consulting services like Staffing and Hiring Solutions, Program Management, and Technology Training Solutions. Our focus is on providing ERP solutions, especially in Web and Mobile Applications, using proprietary frameworks designed for cost-effective solutions.
Role Description
This is a contract Principal Cybersecurity Engineer role based in Grand Rapids, MI with hybrid work options. The Principal Cybersecurity Engineer will be responsible for developing and implementing cybersecurity strategies, conducting risk assessments, designing security controls, and monitoring security protocols. They will also lead cybersecurity incident response and provide ongoing support for security initiatives.
Qualifications
• Leads information security review of new technologies, designs, and remediation planning efforts.
• Collaborates with Engineering & Operations Teams to address security vulnerabilities found via PSIRTs, scans or breaches
• Investigates and/or leads identifying security needs & recommends plans/resolutions. Implements, tests & monitors info security improvements.
• Significant experience with the analysis of underlying technologies that form the solution necessary for the application of threat identification, analysis, and thread model design. The threat model depicts trust boundary, threat agent(s), threat vector(s), and safeguard(s) necessary to protect person, asset, data, and brand.
• Significant experience with implementation of various threat modeling approaches pertaining to one or more of the following STRIDE, PASTA, TRIKE, ATTACK TREE, DREAD, KILL CHAIN, CAPEC
• Deep application security knowledge: Focus on expertise in secure coding practices, vulnerability management (SAST/DAST/IAST), and application security testing (OWASP Top 10 )methodologies.
• Mobile Application threat model, Cyber Threat Tree, and data flow diagram
• Subject matter expert in multiple facets of network & information security, including Firewall policy design, SSL Certificate management,
• vulnerability analysis & mitigation, and other topics as assigned.
• Advanced understanding of IP/Security solutions & technologies applicable to the Wireless Network Architecture.
• Subject matter expert in all facets of network & information security, including Firewall policy design, SSL Certificate management, vulnerability analysis & mitigation, and other topics as assigned.
• Ability to create technical specification and requirements and work independently and with no direction/supervision. Able to quickly adapt to new or evolving technologies related to new product & services requiring validation or research.
• Strong verbal and communication skills with diverse cross functional groups. Ability to present advanced concepts to leadership, peers, and others in subordinate roles.
• Understanding load balancers (ex - A10, F5), firewalls (ex - CheckPoint), Venafi, MDM (ex - Mobile Iron), Cloud (ex - AWS, Azure), Malware Protection (ex -FireEye), Advanced Persistent Threats (ex - Damballa), Privileged Accounts (ex - CyberArk), SIEM (ex - ArcSight), Log & Event (ex - Splunk), Intrusion IDS/IPS (ex - Symantec),
• Cloud Platform (ex - PCF, Docker), Scanning (ex - Qualys), AppSec (ex - Veracode)
• Advance knowledge of Scripting tools (Python/Perl/Shell/HTML/PHP)
• Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI
• Working knowledge of web application development, RESTful APIs, and skills in Java, frameworks, python, Nodejs.
• Experience with mobile applications, and handset security.