Posted in

Sr Staff Security Operations Engineer

Sr Staff Security Operations Engineer

CompanyGeico
LocationBethesda, MD, USA
Salary$130000 – $260000
TypeFull-Time
Degrees
Experience LevelSenior, Expert or higher

Requirements

  • Demonstrated understanding of application security tooling and testing including, SAST, DAST, SCA, etc. as well as cross-functional awareness of security operations including SOC, Incident Response, Privacy, Legal, Vulnerability Management, and Data Protection.
  • Familiar with OWASP projects and implementation within the product security organization such as, Web Top Ten, API Top Ten, Mobile Top Ten and ASVS.
  • Knowledge of data access languages such as SQL and GraphQL and the ability to construct queries against data sources.
  • Extensive experience in engineering and solution delivery in a dynamic service provider environment.
  • Strong knowledge of project management methodologies and best practices.
  • Proven track record of successfully managing large/complex projects across cross-functional teams, building processes and coordinating delivery.
  • Working knowledge of security services and their impact on production systems including runtime protection services, detective and protective agents and/or daemon sets, vulnerability and application scanning, etc..
  • Experience in a multi-cloud environment including AWS, Azure, and/or Google Cloud.
  • Experience communicating and presenting to senior and junior staff with the ability to influence development partners and stakeholders.
  • Detail and deadline oriented with effective organizational and analytic skills
  • Strong critical thinking, problem solving, decision making, and analytical skills
  • Outstanding time management skills and attention to detail
  • Excellent verbal/written communication skills, including the ability to clearly document findings, proposals, issues, and status
  • Experience with continuous delivery
  • Self-motivated and able to work independently while coordinating activities with cross-divisional teams
  • Effective leadership qualities, ability to influence without direct management authority
  • Ability to excel in a fast-paced, startup-like environment.
  • Knowledge of industry-standard security control frameworks including NIST, PCI, SOX, NYDFS.

Responsibilities

  • Monitor and track signals of security gaps, initiative delays, compliance risks due to system issues, and drive resolution.
  • Create visuals on current performance and risk indicators related to product security initiatives and operations.
  • Help to develop standards on reporting product security tool effectiveness, maturity, resilience and other factors in determining risks as they come up.
  • Help drive automation of routine tasks to drive growth in security protection and detection technologies.
  • Provide expert guidance, demonstrations and lead discussions on security best practices to stakeholders and leadership.
  • Works in lockstep with our CSIRT, GRC, Platform Security, Development/Product organizations and Technology partner teams to ensure protection coverages, proper detection event notifications, documentation and standards we can all use.
  • Organize, store and manage operational best practices documentation for security solutions to protect our business products including applications, services, code and associated repositories, infrastructure as code (IaC), and code related to deployment pipelines.
  • Partner with the project sponsors, delivery teams, and stakeholders to deliver quality solutions on time and within budget by coordinating project activities across multiple systems, departments, and teams.
  • Create, maintain, and actively manage a detailed project schedule, change control process, and documentation.
  • Identify and raise appropriate security risks, in addition to presenting detailed and implementable solutions or alternatives, and drive those campaigns to resolution.

Preferred Qualifications

  • Knowledge in a hybrid cloud environment such including Containerization, VMs, CI/CD pipeline, IaC
  • Experience defining KPI’s/SLA’s used to drive multi-million-dollar businesses and reporting to senior leadership.