Security Engineer - SaaS Cybersecurity

Overview

On Site
USD 135,000.00 - 145,000.00 per year
Full Time

Skills

Data Security
SCS
IT Management
Collaboration
Relationship Building
IT Risk
IT Risk Management
Auditing
Writing
Documentation
Cyber Security
Payment Card Industry
ISO/IEC 27001:2005
Regulatory Compliance
COBIT
Thought Leadership
RESTful
Git
Continuous Delivery
Web Services
Evaluation
Mentorship
System Administration
Communication
Windows PowerShell
Python
Bash
SQL
DLP
Scripting
Reporting
Motivation
Continuous Improvement
Computer Networking
Firewall
Proxies
Virtual Private Network
Dragon NaturallySpeaking
DNS
HTTP
TCP/IP
SIEM
Apache Kafka
Version Control
Unit Testing
Agile
SANS
FOCUS
Science
IT Security
Computer Science
SaaS
Cloud Security
Management
Palo Alto
Cloud Computing
Amazon Web Services
Google Cloud
Google Cloud Platform
Continuous Integration
Continuous Integration and Development
Orchestration
JIRA
Confluence
BMC Remedy
GitHub
Microsoft Azure
DevOps
Bitbucket
Bamboo
Terraform
Ansible

Job Details

Your Opportunity

Schwab's Cloud & Data Security Engineering (CDSE) group designs and develops next-generation cloud (XasS) security solutions for the Schwab Cybersecurity Services (SCS) organization, providing high security assurance and the safeguarding of Firm data. The Senior Cloud Security Engineer will join an elite team of cloud security engineers and analysts whose mission is to protect Schwab's most valuable assets: our client information and their trust.

As a Cloud Security Engineer, you will contribute directly to the protection and the adoption of SaaS applications within the enterprise. With you, we will build on and around core SaaS security technologies including Security Posture Management (SSPM) and Cloud Access Security Broker (CASB) platforms. In collaboration with technical leadership, you will be responsible for designing and developing major areas of the platforms that implement preventative and detective capabilities to support Schwab's growing SaaS portfolio, improving upon overall SaaS security posture and use.

What you're good at

  • Collaboration and relationship building with multiple cross-functional areas of the enterprise (consumer, business, technology, risk, audit)
  • Identifying and communicating complex business and technical problems related to information risk
  • Ability to swiftly identify bottlenecks or problems while not being constrained by in-the-box thinking or legacy process
  • Writing professional level documentation covering topics related to Cybersecurity or SaaS application technologies. These include design and implementation documents, process documents, SLAs, diagrams, etc..
  • Working with industry standards like; NIST, CIS, CSA, and PCI, and ISO 27001 as it relates to cloud platforms and services.
  • Monitoring, detecting, and responding to potential threats, drift, or anomalies of SaaS usage and posture.
  • Ensuring compliance and meeting the stipulations of regulatory bodies and acts (NIST, COBIT, etc.)
  • Proven thought leadership with development pipelines and RESTful methodologies, Git, and Continuous Integration/Deployment (CI/CD) tooling & automation
  • Working with and consuming web service APIs
  • Translating business & technology security requirements into functional controls and policy
  • Evaluation and prioritization of workstreams for efficient delivery via an Agile methodology
  • Coach, mentor, and develop less experienced colleagues

What you have

  • 5+ years' large enterprise technical experience in IT (systems administration preferred)
  • 5+ years' cloud experience working with as-a-service platforms and technology
  • 3+ years' operational experience with security technologies and teams
  • Demonstrable experience in the deployment, configuration, and management of cloud security platforms and tools (CASB, SSPM, SSE, CSPM)
  • Deep understanding of today's SaaS threat landscape, mitigations, and remedies
  • Flawless communication skills (both written and verbal)
  • Solid functional familiarity with one or more of the following programing/scripting languages; Go, PowerShell, Python, Bash, SQL, BASIC
  • Experience implementing & utilizing technology lifecycles and best practices
  • An understanding of regulatory requirements and industry standards related to cloud security
  • Significant understanding of functionality and capabilities related to CASB, SSPM, and DLP platforms and associated networking technologies within large, distributed environments
  • Knowledge and understanding across multiple security domains, concepts, and how they are interconnected
  • Development and scripting experience in cloud service providers (CSP) environments, SaaS, and their associated APIs
  • A track record of prioritizing and analyzing large amounts of data, creating metrics, and reporting
  • High motivation as a self-starter and standout colleague in a team environment
  • A passion for technology and committed to continual improvement of yourself, your team, and your technology
  • Good understanding of networking technologies and protocols within large enterprise environments, such as firewalls, traffic management, proxies, VPN, DNS, HTTP, TCP/IP
  • Hand-on experience with monitoring and logging concepts, content solutions, and tools; SIEM, SOAR, Kafka, pub-sub, syslog, etc.
  • Expertise in source control, unit testing, and agile methodologies
  • Security certifications from ISC2, CSA or SANS (cloud focus preferred)
  • Bachelor of Science in Information Technology, Security Assurance, Computer Science or related field (preferred)

Platforms

  • Cloud Access Security Broker (CASB) - Zscaler/Netskope
  • SaaS Security Posture Management (SSPM) - Adaptive Shield/AppOmni/Obsidian
  • Cloud Security Posture Management (CSPM) - Palo Alto Prisma
  • Cloud Service Provider(s): AWS, Azure, Google Cloud Platform

Continuous Integration/Continuous Deployment & Orchestration

  • Plan, Track & Support: JIRA, Confluence, Remedy
  • Code, Build & Ship: GitHub, Azure DevOps, BitBucket, Bamboo
  • Infrastructure as Code: Terraform, SaltStack, Ansible, CloudFormation
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.