Information Security Engineer - Findings Management Engineer

Job summary

Remote

Work model

Hybrid · 3 days home
1 month ago
Job description

Overview

Outstanding long-term contract opportunity! A well-known Financial Services Company is looking for an Information Security Engineer in Charlotte, NC (Hybrid).

Work with the brightest minds at one of the largest financial institutions in the world. This is a long-term contract opportunity that includes a competitive benefit package! Our client has been around for over 150 years and is continuously innovating in today's digital age.

  • Contract Duration: 6 Months

Required Skills & Experience

  • 5 years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of the following: work experience, training, military experience, education.
  • 2 years of experience with and strong understanding of Azure and Google public cloud - platforms, services, configurations, workloads, and hardening practices.
  • 1 year of experience with Wiz or a similar cloud security or "CNAPP" product.
  • 1 year of experience with scripting/automation languages such as Python, Bash, Terraform and/or PowerShell.
  • 1 year of experience delivering integration between cloud security tools and other enterprise tools such as Splunk Cloud and ServiceNow.
  • 1 year experience with data visualization/reporting tools such as PowerBI, Tableau or similar technologies.
  • Solid understanding of Identity & Access Management, as well as Information Protection concepts as they apply to monitoring and responding to related alerts/findings.
  • Strong verbal and written communication skills.
  • Proven ability to work independently, as well as having strong interpersonal skills to work effectively within a Team and with partners.
  • Strong analytical skills, proven critical thinking capabilities and ability to solve complex problems with minimal direct oversight.
  • Intermediate to advanced experience working with Microsoft Office products (e.g. Word, Excel, PowerPoint, Visio, Outlook, MS Teams, SharePoint).
  • Ability to handle multiple, high priority deliverables concurrently.
  • Ability to communicate confidentially, professionally, and effectively, in both written and verbal formats, with stakeholders and partners.
  • 1 year experience working on teams practicing Agile Scrum or Kanban methodologies.

Desired Skills & Experience

  • Experience supporting Cloud implementation/migrations and/or Cloud Security engineering and/or operations.
  • Experience with databases such as MongoDB or similar.
  • Experience with Microsoft Defender, Google Security Command Center, Aqua Security, Microsoft Sentinel or HashiCorp Sentinel.
  • Experience with change and incident management practices in large enterprises.
  • Understanding of information security threats, trends and industry best practices and security tools.
  • Finance sector security experience or other regulated industry (e.g., utilities, health care, government).
  • Familiarity with various cloud security and related risk frameworks (Cloud Security Alliance (CSA), CIS, NIST, etc.).
  • Security certifications such as Certified Information Systems Security Professional (CISSP), Global Information Assurance Certification (GIAC), or equivalent, CISA, CISM, CISSP, CRISC, CCSK.
  • Microsoft Azure and/or Google Cloud Certifications.
  • Kubernetes Security (CKS) certification.

What You Will Be Doing

  • Consult on complex initiatives with broad impact and large-scale planning for Information Security Engineering.
  • Review and analyze complex multi-faceted, larger scale or longer-term Information Security Engineering challenges.
  • Contribute to the resolution of complex and multi-faceted situations requiring solid understanding of the function, policies, procedures, and compliance requirements.
  • Strategically collaborate and consult with client personnel.
  • Actively support and perform "hands-on" technical and engineering work with the Wiz product, with a focus on Findings Management.
  • Define/operationalize alerts in Wiz.
  • Perform engineering related to Alerts/Findings data analysis and engineering of reporting processes and visualization dashboards (e.g. PowerBI, Tableau).
  • Design/develop automation & utility scripts to make team processes more efficient.
  • Build Python pipelines to download, merge, enrich, and analyze Wiz, cloud, and security datasets.
  • Collaborate with partners to support the remediation or "burn down" of alerts/findings in Wiz.
  • Provide professional expertise relating to Application Lifecycle Security and resolving application vulnerabilities or compliance issues detected via Wiz.
  • Be a motivated self-starter quick to adapt and stay focused on delivering results in a fast-paced environment with aggressive deadlines.
  • Share your Wiz expertise and knowledge with teammates, while completing assigned duties.