Information Security Architect

Stelle nicht auf LinkedIn

🕒 vor 26 Tagen

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

🔴 Experte

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

Jetzt Bewerben
Ähnliche Remote-Jobs finden

📊 Überprüfen Sie Ihre Lebenslauf-Bewertung für diese Stelle

Verbessern Sie Ihre Chancen auf ein Vorstellungsgespräch, indem Sie Ihre Lebenslauf-Bewertung vor der Bewerbung überprüfen.

Logo of U.S. Department of Labor

U.S. Department of Labor

10.000+ Mitarbeiter

Gegründet 1913

🏛️ Regierung

📋 Compliance

Government • Compliance • Human Resources

Das U. S. Arbeitsministerium ist eine Bundesbehörde, die für die Förderung und Sicherstellung des Wohlergehens von Arbeitssuchenden, Lohnempfängern und Rentnern verantwortlich ist. Sie überwacht verschiedene Aspekte der Arbeitsgesetze und -vorschriften in den Vereinigten Staaten, einschließlich Arbeitssicherheit, Arbeitslosenversicherung, Lohn- und Arbeitszeitgesetze sowie Sozialleistungen für Arbeitnehmer. Die Behörde spielt eine entscheidende Rolle bei der Festlegung von Standards und der Bereitstellung von Richtlinien für sowohl Arbeitgeber als auch Arbeitnehmer, um faire Arbeitspraktiken zu gewährleisten und die Gesundheit und Sicherheit der Arbeitskräfte zu verbessern.

Beschreibung

• Evaluate the financial costs of recommended technologies quantifying purchasing and licensing options, estimating labor costs for a given service or technology, and estimating the total cost of operation (TCO), the ROI, or the payback period for services or technologies replacing existing capabilities. • Develops and maintains a security architecture process that enables the enterprise to develop and implement security solutions and capabilities that are clearly aligned with business, technology, and threat drivers • Develops security strategy plans and roadmaps based on sound enterprise architecture practices • Develops and maintains security architecture artifacts (e.g., models, templates, standards, and procedures) that can be used to leverage security capabilities in projects and operations • Determines baseline security configuration standards for operating systems (e.g., OS hardening), network segmentation and identity and access management (IAM) • Develops standards and practices for data encryption and tokenization in the organization, based on the organization's data classification criteria • Drafts security procedures and standards to be reviewed and approved by executive management and/or formally authorized by the chief information security officer (CISO) • Establishes a taxonomy of indicators of compromise (IOCs) and share this detail with other security colleagues, including the security operations center (SOC), information security managers and analysts, as well as counterparts within the network operations center (NOC) • Tracks developments and changes in the digital business and threat environments to ensure that they're adequately addressed in security strategy plans and architecture artifacts • Validates IT infrastructure and other reference architectures for security best practices and recommend changes to enhance security and reduce risks, where applicable • Validates security configurations and access to security infrastructure tools, including firewalls, IPSs, WAFs and anti-malware/endpoint protection systems • Conducts or facilitate threat modeling of services and applications that tie to the risk and data associated with the service or application • Ensures a complete, accurate and valid inventory of all systems, infrastructure and applications that should be logged by the security information and event management (SIEM) or log management tool • Coordinates with DevOps teams to advocate secure coding practices, and to escalate concerns related to poor coding practices to the CISO • Coordinates with the privacy officer or office to document data flows of sensitive information in the organization (e.g., PII or ePHI) and recommend controls to ensure that this data is adequately secured (e.g., encryption and tokenization) • Reviews network segmentation to ensure least privilege for network access • Supports the testing and validation of internal security controls, as directed by the CISO or the internal audit team • Reviews security technologies, tools, and services, and makes recommendations to the broader security team for their use, based on security, financial and operational metrics • Evaluates the statements of work (SOWs) for these providers to ensure that adequate security protections are in place. Assesses the providers' SSAE 16 SOC 1 and SOC 2 audit reports (or alternative sources) for security-related deficiencies and required "user controls" and report any findings to the CISO and vendor management teams • Coordinates with operational and facility management teams to assess the security of operational technology (OT) and Internet of Things (IoT) systems • Participates in application and infrastructure projects to provide security-planning advice • Liaises with important security and risk management constituencies and works collaboratively with both individuals and leaders across the organization. Translates complex security-related matters into business terms that are readily understood by colleagues. • Presents analyses in person and in written formats to all personnel levels within the organization. • Draft project plans for security service and technology deployments and coordinate with stakeholders across the organization. • Respond to changing circumstances altering standard procedures, when necessary. • Develop approaches and solutions that are clearly linked to the organizational strategies and goals for optimal performance. • Synthesize facts, theories, trends, inferences, and key issues and/or themes in complex and variable situations.

🎯 Anforderungen

• Bachelor's or master's degree in computer science, information systems, cybersecurity, or a related field or equivalent skills and experience • 12+ years’ Information Technology experience • 10+ years’ Information Security experience • 7+ years’ Cybersecurity experience • 4+ years’ Cloud experience • Can interface with, and gain the respect of, stakeholders at all levels and roles in the company • Is a confident, energetic self-starter, with strong interpersonal skills • Has good judgment, a sense of urgency and has demonstrated commitment to high standards of ethics, regulatory compliance, customer service and business integrity • Strong problem-solving and trouble-shooting skills • Experience in using architecture methodologies such as SABSA, Zachman and/or TOGAF. • Direct, hands-on experience or strong working knowledge of managing security infrastructure — e.g., firewalls, intrusion prevention systems (IPSs), web application firewalls (WAFs), endpoint protection, SIEM and log management technology. • Experience reviewing application code for security vulnerabilities. • Experience securing CI/CD pipelines. • Direct, hands-on experience or a strong working knowledge of vulnerability management tools. • Documented experience and a strong working knowledge of the methodologies to conduct threat-modeling exercises on new applications and services. • Experience designing the deployment of applications and infrastructure into public cloud services. • Full-stack knowledge of IT infrastructure: Applications, Databases, Operating systems — Windows, Unix and Linux, Hypervisors, IP networks — WAN and LAN, Storage networks — Fibre Channel, iSCSI, and NAS, Backup networks and media and Containers/Kubernetes • Direct experience designing IAM technologies and services: Active Directory, Lightweight Directory Access Protocol (LDAP), Amazon Web Service (AWS) IAM • Strong working knowledge of IT service management (e.g., ITIL-related disciplines): Change management, Configuration management, Asset management, Incident management, Problem management • Documented experience with the following regulations, standards, and frameworks: Payment Card Industry Data Security Standard (PCI-DSS), HIPAA-HITECH, Validated Systems (e.g., GAMP), Sarbanes-Oxley, General Data Protection Regulation (GDPR), Privacy Practices, ISO 27001/2, NIST Cybersecurity Framework (CSF), ITAR • The ideal candidate will maintain three or more of the following or equivalent certifications: CISSP, CISA, ISSAP, CRISC, GSTRT, GISP, GSLC, GPCS, GDSA, GCSA

🏖️ Vorteile

• Highly competitive total rewards package, including comprehensive medical, dental and vision benefits as well as a 401(k) plan that both the employee and employer contribute • Annual incentive bonus plan based on company achievement of goals • Time away from work including paid holidays, paid time off and volunteer time off • Professional development courses, mentorship opportunities, and tuition reimbursement program • Paid parental leave and adoption leave with adoption financial assistance • Employee discount program

Jetzt Bewerben

Ähnliche Jobs

🕒 vor 26 Tagen

Volkswagen Group

10.000+ Mitarbeiter

🚗 Transport

Senior Cloud Security Engineer responsible for AWS security capabilities at Volkswagen's autonomous vehicle development. Requires 7-9 years experience and expertise in cloud security.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 26 Tagen

Trulieve

5001 - 10000

👥 B2C

⚕️ Krankenversicherung

💊 Pharmazie

Information Security Engineer managing security tools and initiatives at Trulieve for patient-focused products. Transforming infrastructure security through technology and compliance best practices.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟡 Mittelstufe

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 26 Tagen

Presidio

1001 - 5000

🤝 B2B

🤖 Künstliche Intelligenz

🔒 Cybersecurity

Principal Security Governance Consultant leading client engagements to improve security posture and compliance at Presidio. Collaborating on strategic recommendations and compliance with security frameworks.

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 26 Tagen

Aledade, Inc.

501 - 1000

⚕️ Krankenversicherung

🏢 Unternehmen

Senior Network Security Engineer II at Aledade. Leading design and implementation of network security infrastructure with a focus on compliance and innovative solutions.

🇺🇸 Vereinigte Staaten – Remote

⏰ Vollzeit

🟠 Senior

👮‍♂️ IT-Sicherheitsingenieur

🗣️🇺🇸🇬🇧 Englisch erforderlich

🕒 vor 26 Tagen

Presidio

1001 - 5000

🤖 Künstliche Intelligenz

🔒 Cybersecurity

🏢 Unternehmen

Principal Security Governance Consultant managing information security risks and compliance for clients at Presidio. Leading strategic recommendations and developing tailored security policies and procedures.

🗣️🇺🇸🇬🇧 Englisch erforderlich