Public Cloud Compliance Security Engineer - Sr Level (REMOTE Option)
Company: USAA
Location: Saint Petersburg
Posted on: May 11, 2022
Job Description:
Purpose of JobThe CTOC is USAA's equivalent to a Security
Operations Center (SOC). The CTOC exists to detect, analyze, and
respond to cyber security events. The CTOC is comprised of several
teams, all reporting to the AVP of IS Engineering & Cybersecurity.
These teams are individual units that partner as needed to provide
centralized and coordinated response activities. We are seeking a
versatile Public Cloud Compliance Security Engineer - Sr Level to
join our Public Cloud Security team.USAA values a culture that is
highly collaborative, and we have found that a hybrid work type
helps employees gain the best of both worlds - collaborating
in-person in the office and working from home when needed to
achieve focused results. The actual days' onsite are resolved
between each employee and the employee's manager. This position may
also have the option of working 100% remotely in the U.S.This job
profile is designated as a Sensitive Position. Sensitive Positions
are those positions in which individuals have the authority and
ability to conduct in-scope activities (movement of USAA or Member
funds) as defined within the Enterprise Sensitive Positions
Mandatory Time-Away Compliance Policy. Employees in Sensitive
Positions are required to fulfill a Mandatory Time-Away (MTA)
requirement of 10 consecutive business days each calendar year.Job
RequirementsAbout USAAUSAA knows what it means to serve. We
facilitate the financial security of millions of U.S. military
members and their families. This singular mission requires a
dedication to innovative thinking at every level.About USAA ITOur
most meaningful qualification isn't technical, it's human. Here, we
don't just sit in front of a screen. We stand behind our 13 million
members who rely on us every day.We're proud of USAA's strong
history -- and we're even more passionate about our future. That's
why we have a team of supportive and collaborative hardworking
technology professionals focused on doing more for our members. And
why we're continuing to add innovative problem solvers to our team.
With us, you'll find exciting challenges that inspire you to
continue learning and growing.Job Responsibilities:
- Identifies and handles existing and emerging risks that stem
from business activities and the job role.
- Ensures risks associated with business activities are optimally
identified, measured, monitored, and controlled.
- Follows written risk and compliance policies, standards, and
procedures for business activities.
- Leads peers and junior team members in the execution of
Information Security domain activities while anticipating efforts
that will affect their team.
- Researches and analyzes the latest capabilities of specific
Information Security (e.g. Cloud services, encryption, PKI etc.)
and IT technologies (e.g. operating systems, networks, storage,
virtualization etc.).
- Develops and maintains expertise in the USAA implementations of
these technologies.
- Creates, publishes, maintains, and interprets Information
Security baselines for specific technologies (e.g. operating
systems, databases). Socializes Security baselines with
stakeholders.
- Operates and maintains hardware and software of Information
Security solutions and technologies (e.g. firewalls, intrusion
prevention (IPS), web application firewalls (WAF), web
proxies).
- Participates in vendor roadmap discussions and feature
requests.
- Monitors and fixes sophisticated systems, tools and/or
networking solutions.
- Performs investigative research, analysis and troubleshooting
to identify, resolve, and report complex security issues.
- Collaborates with Security Analysts to tune and improve
Information Security solutions and technologies to keep up with the
latest threats.
- Writes code/scripts/automation to detect or prevent new threats
that do not have commercial solutions available yet or to automate
Information Security processes to increase efficiencies.
- Designs and develops new tools/technologies as related to
Information Security.
- Provides insight on issues and serves as a mentor to peers and
team members for assigned area of responsibility.Minimum
requirements:
- Bachelor's degree; OR 4 years of related experience (in
addition to the minimum years of experience required) may be
substituted in lieu of degree.
- 6 years of related experience in Information Security,
Cybersecurity, Identity and Access Management (IAM) and/or
Information Technology with a security focus to include
accountability for complex tasks and/or projects.
- 4 years of related experience in AppSec, Cloud, Firewall, Web
Proxies, Web Application Firewall, Intrusion Prevention Systems
(IPS/IDS), Mainframe, Windows, Linux, Apple, Security Information
and Event Management (SIEM), Identity and Access Management
engineering and /or Security Orchestration, Automation, and
Response (SOAR) solutions.
- Sophisticated level of discernment in the areas of business
operations, risk management, industry practices and emerging
trends.
- Advanced troubleshooting skills. (Packet analyzer a plus)
- Programming or scripting experience. (Python or PowerShell
preferred)When you apply for this position, you will be required to
answer some initial questions. This will take approximately 5
minutes. Once you begin the questions you will not be able to
finish them at a later time and you will not be able to change your
responses.Preferred experience:
- Experience with multi-cloud native technologies (AWS, Azure,
and GCP) and adoption/migration patterns
- Experience with cloud security models and DevOps practices
- Prior success creating and leading a comprehensive security
compliance strategy/program
- Experience with compliance frameworks and industry standards
such as NIST 800-53, CSA CCM, FFIEC, CRI or other comparable
frameworks and standards
- Experience with advising on security architecture, methods, and
controls required to meet security, compliance, and audit
requirements
- Experience developing and maintaining documentation for cloud
security systems, procedures, baselines, and best practices for
security assurance functions and audit readiness
- Experience and technical knowledge in multiple areas of:
security engineering, system and network security, authentication
and security protocols, cryptography, and application securityThe
above description reflects the details considered necessary to
describe the principal functions of the job and should not be
construed as a detailed description of all the work requirements
that may be performed in the job.Compensation:USAA has an effective
method for assessing market data and establishing ranges to ensure
we remain competitive. You are paid within the salary range based
on your experience and market position. The salary range for this
skill is: $106,800 - $192,300Employees may be eligible for pay
incentives based on overall corporate and individual performance or
at the discretion of the USAA Board of Directors. Geographical
Differential: Geographic pay differential is additional pay
provided to eligible employees working in locations where market
pay levels are above the national average.Shift premium: will be
addressed on an individual-basis for applicable roles that are
consistently scheduled for non-core hours. Benefits:At USAA our
employees enjoy best-in-class benefits to support their physical,
financial, and emotional wellness. These benefits include
comprehensive medical, dental and vision plans, 401(k), pension,
life insurance, parental benefits, adoption assistance, paid time
off program with paid holidays plus 16 paid volunteer hours, and
various wellness programs. Additionally, our career path planning
and continuing education assists employees with their professional
goals. Please click on the link below for more details.USAA Total
RewardsRelocation assistance is Not Available for this
position.
Keywords: USAA, St. Petersburg , Public Cloud Compliance Security Engineer - Sr Level (REMOTE Option), Engineering , Saint Petersburg, Florida
Didn't find what you're looking for? Search again!
Loading more jobs...