STS Security Engineer ComplianceLocation: Remote
Posted On: 07/21/2023
Requirement Code: 64621
Today's world is fueled by vast amounts of information, which means that data is even more valuable than ever before. Protecting data and information systems is central to doing business, and therefore everyone in EY Information Security has an important role to play. Join a global team of almost 950 people who collaborate to support the business of EY by protecting EY and client information assets! Information Security professionals enable EY to work securely and deliver secure products and services, as well as detect and quickly respond when things go wrong. Together, the efforts of our dedicated team help protect the EY brand and build client trust.
Within Information Security we blend risk strategy, digital identity, cyber defense, application security and technology service solutions as we consider the entire security lifecycle. You will join a team of hardworking, security-focused individuals dedicated to supporting, protecting, and enabling the business through secure solutions and information systems.
As a Security Engineer for SIEM technologies within the Security Technology Services (STS) group, you will become part of a global team responsible for the complete life cycle of our solutions and services; design, engineering, implementation, and early life cycle support within our EY multi-cloud and on-premises environments. This role will work closely with Security Architects, Security Service Delivery, Security Operations, and Information Security teams for enablement of security solutions and services across various Security Domains, as well as, across various Global EY Teams and Technologies. You will also provide consulting services to other teams, as well as a level four contact for operational issues.
Your key Responsibilities
Articulate technology issues/concerns that may emerge at any level of the technical stack, and from any component across the ecosystem, to technology leaders.
Engineer security solutions and services following all relevant EY standards and practices for On-Premise, Hybrid and Cloud-Based environments.
Provide detailed input into the design and leads the implementation and testing of security solutions and services for large, complex projects from initial design to completion which includes production support and documentation.
Take accountability for the design, delivery and maintenance of new and existing security solutions or services, driving compliance with and contributing to the development of relevant standards.
Apply modern standards/principles, global product-specific guidelines, security standards, design standards, to security solutions and services as appropriate.
Collaborate with Security Architecture, Service Owners, and Security Operations teams to promote automation and innovation throughout the security solutions that are being maintained, thereby enhancing the security posture of these solutions.
Represent the team in specific Project activities, including participating in projects and driving your deliverables towards successful completion.
Work in a diverse global environment and build strong relationships across all levels of a matrixed, geographically and culturally dispersed organization.
No direct supervisory responsibilities, however, Technical Leadership will be required within assigned services and solutions.
Skills and Attributes for Success
We are seeking individuals with practical experience in functional and/or technical security engineering within a large enterprise setting, specifically in the implementation and maintenance of Compliance, Vulnerability and Response security solutions.
The successful candidate will have:
Advanced technical proficiency in designing and implementing security compliance and risk solutions within a very large enterprise:
o Experience with Archer applications, solutions, and components.
o Windows Server Support.
o Knowledge of IIS configuration.
o Knowledge of languages such as Python and or PowerShell a plus.
o Several years' experience working in a large global virtual environment.
Communicate fluently in English, both written and verbal, and able to communicate technical concepts effectively.
Excellent interpersonal communication and organizational skills and the ability to work within tight timeframes.
Rapidly learn new and emerging technologies with the ability to define engineering standards quickly and efficiently.
To qualify for the role, you must have
Detailed knowledge of several of the following: EDR, AV/AM, Vulnerability Scanning, Cloud Operations, IPS/IDS, O365 Tenants, networking concepts & mechanisms, scripting in Python or another language, and other relevant technologies.
At least 5 years of experience in Security, including demonstratable knowledge of Compliance and Vulnerability technologies.
3~~@~~ years demonstrated ability in an engineering function.
Several years' experience working in a large global virtual environment and enterprise environments at scale.
A strong understanding of other technologies required to run a secure, enterprise level infrastructure that adhere to security best practices.
Excellent time management, organizational, and decision-making skills.
The ability to design and document processes, procedures, and security designs clearly and accurately for distribution to internal teams and customers.
Demonstrated experience in dealing with external vendors and suppliers in the security industry.
Technical proficiency with interacting with APIs and scripting tools (Python, Ansible, PowerShell, etc.), is a plus.
Ideally, you'll also have
A bachelor's degree in Computer Science, Engineering, IT, Mathematics or a related field, or equivalent work experience.
GSEC/CISSP or other security related generalist certification from ISC2 or GIAC.
Experience in project management, service introduction, and service readiness.
What we look for
This role is perfect for you, if you have excellent problem solving, decision making, and communication skills.
We are looking for people who are comfortable working with culturally diverse on/offshore team members, able to react appropriately during stressful and ambiguous situations.
Independent thinkers with team driven values.
Compensation: 90-100 Hourly W2