CyberSecurity Engineer III- US
United States - Remote•United StatesNorth America•April 27, 2024
Job Summary: In this role, you will be a part of an Elastic Engineering for Security team prioritizing vulnerability management, incident response reporting, compliance advisement, developing and coordinating strategic projects and initiatives, including capabilities such as static and dynamic security testing, and supporting and establishing the reporting, processes, and automation to make remediation of any findings above successful. If you like a challenge, you’ll love it here, because we’re solving complex business problems every day, building and promoting great technology solutions that impact our customers’ success. The best part is, we’re committed to you and your growth, both professionally and personally. Work Location: Remote
Key Responsibilities:
- Be a technical leader for security, developing a strategy to improve the security posture and overall program, including capabilities, processes, metrics, user experience, partnerships, and overall maturity.
- Select, build, improve, integrate, and/or manage tools to perform automated and manual application security testing of web applications, APIs, containers, and other software components
- Interpret, prioritize, and summarize findings into clear remediation actions, and create a vulnerability reporting process to ensure successful follow through
- Respond to external vulnerability disclosure, or bug bounty, reports
- Prioritize projects and vulnerability findings based on expected value and impact to the organization
- Identify, track, and report KPIs for the health of the application security program
- Create and improve security processes through automation, integration, and documentation
- Build up security brand and team by regularly sharing skills, knowledge, and advice
- Be called on as a subject matter expert for challenging and sometimes time sensitive security events
- Work independently with general guidance on new assignments
Qualifications:
- 5+ years in the information security field
- Experience being a member of, or leading, security and or SOC team
- Strong understanding of the SDLC, security concepts and strategy, and vulnerability assessments
- Experience with or strong understanding of programming and scripting languages including one or more of the following: Python, C, Java, Node.js, Go, Ruby, Groovy, PHP, and Scala; databases such as SQL; and other related tools such as Github, Gitlab, Jenkins, and CircleCI
- Deep understanding of vulnerabilities, remediation, and industry-standard classification and prioritization schemes (CVE, CWE, CVSS, OWASP Top 10) and how to prioritize and communicate vulnerabilities to stakeholders
- A general understanding of relevant compliance regulations, such as PCI, SOX, HIPAA, HITRUST, or FedRAMP
- Passion for security, staying up to date on new technologies and security vulnerabilities
- Desire to be a team player that help train and build team members up, and partner closely with key contacts external to the team and company to solve complex problems
- At least two advanced security certifications, or equivalent work experience. For example, GIAC certification (GCIH, GWAPT, or GPEN), or (ISC)2 certification (CISSP, SSCP, CCSP), and/or Security certifications such as CompTIA Security+, A+, Network+ .
- Prefer Bachelor’s Degree within an Information Technology field of study; HS diploma is required Discover your inner Racker: Racker Life