What are the responsibilities and job description for the Cyber Security Engineer position at Stefanini North America and APAC?
Job Description:
The Information Security team member will augment the Supply Chain Security team and play an integral part in the development, implementation, and compliance of technical security across the enterprise. The candidate will be key contributor to ongoing security assessments of third-party tools and products and will regularly act as a voice of Information Security to business teams and management, building cyber security confidence in support of business development and governance processes.
Responsibilities:
- Perform focused risks assessments of existing or new service providers, and technologies being introduced into the firm’s technology environment
- Provide governance and oversight over existing and new SaaS and IaaS products
- Influence the overall direction for securing infrastructure, applications and third parties service providers for the firm
- Communicate risk assessment findings to information security stakeholders or business partners and influences the risk mitigation
- Provide consultative advice to information security customers that enables them to make informed risk management decisions
- Performing assessments of new and existing Internet of Things (IoT) Deployments
- Identify appropriate controls to effectively manage information risks as needed
- Identify opportunities to improve risk posture, developing solutions for remediating or mitigating risks and assessing the residual risk
- Maintain strong working relationships with individuals and groups involved in managing information risks across the organization
- Support the documentation of Information Security Policies and Standards
- Security assessments of third-party software packages deployed on machines
- Perform vulnerability impact analysis of newly identified vulnerabilities of the firm’s critical service providers
Experience:
- Degree in Business, Computer Engineering, Computer Science, Information Security, or a related field
- Working knowledge of data analysis techniques, including Excel, Python and basic SQL skills
- Experience with agile project management
- Knowledge of Azure security, AWS security, web security, including API and token security
- 5 years Information Security experience
- 3 years with risk advisory and senior management communication, metrics, collaboration to drive risk-based results
- 3 years of experience with documenting, project management, written analysis for Information Security risk assessments
- 3 years of experience in an Enterprise Risk Management and/or assessing controls within a Technology and/or Financial Services firm
- Experience with information security management frameworks (e.g., IS027001, COBIT, NIST 800)
- Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), and/or Certified Information Systems Auditor (CISA)
- AWS, GCP, or Azure security certifications are a plus.
Salary : $70 - $80