Information Security Engineer, FedRAMP (ThousandEyes)
Location:
Area of Interest: Security
Compensation Range: 157400 USD – 222200 USD
Job Type: Professional
Job Id:
Who We Are
The name ThousandEyes was born from two big ideas: the power to see things not ordinarily possible and the ability to collect insights from a multitude of vantage points. As organizations rely more on cloud services and the Internet, the network has become a black box they can't understand. Our Internet and cloud intelligence platform delivers the only collectively powered view of the Internet, cloud and SaaS platforms, helping enterprises and service providers work together to identify problems before it impacts revenue, damages brand reputation, or halts employee productivity.
In August 2020, Cisco Systems completed the acquisition of ThousandEyes, which now forms the ThousandEyes Business Unit within Cisco's Network Services Business Group and is a foundational component of Cisco's growing Observability business.
About The Role
ThousandEyes is seeking an exceptional information security engineer with strong project management skills to support our Information Security and Privacy Risk Management function. This is a combination of project/program management and risk analysis: a hands–on role that requires experience and expertise managing projects and processes related to security of networks, systems and applications. The Information Security Risk Management team is responsible for managing and mitigating risks faced by ThousandEyes to protect its systems, services and data. Our scope includes everything from customer applications to enterprise services that support our business operations. We work cross–functionally with internal teams providing security consulting services while driving new program initiatives. You should be strongly driven and excited about learning new processes. You will be collaborating with ThousandEyes' project teams to ensure the success of the information security risk management program. We are looking for an information security engineer/project manager that will be aggressive in following up on tasks, achieving deadlines, and holding resource owners accountable to risk remediation plans. The security engineer role will be highly engaged with all aspects of the risk assessment process. A successful candidate will need strong project management fundamentals and excellent communication skills.
What You'll Do
- Analyze vulnerabilities to determine risk, and remediation and/or mitigation steps.
- Track remediation tasks, engage with systems/services owners and stakeholders to ensure vulnerability management compliance.
- Investigate and report threats or software issues, recommend and drive remediation.
- Assist with enterprise–wide risk assessment processes and specifically with application security assessments.
- Coordinate cross–functional team meetings to remediate previously identified security risks and close out pending action plans.
- Proactively assess potential areas of risk and opportunities of vulnerability in the network.
- Interact with internal and external customers on security–related projects and operational tasks.
- The individual must have a strong background in Python, shell scripting, and database knowledge. He/she/they must possess strong organizational skills, be action–oriented, results–driven, and work with minimal direction.
Qualifications
- 5 to 7 years of experience in the Information Security or related domains.
- BS or MS degree in Computer Science (or equivalent).
- Practical use and implementation of information security principles and practices; Understanding of IT methodologies, such as the software development lifecycle, secure infrastructure as code and related operations.
- Familiar with vulnerability management tools.
- Understanding of cloud computing services.
- Strong scripting skills, automation and containerization.
Preferred Qualifications
Technology and compliance knowledge of the following:
- Python, Bash, Qualys, Rapid7, Nessus, SIEMs, Docker, Linux, Amazon Web Services, LAN and WAN, VMWare/Virtualization, Firewalls, Access Controls, Authentication/Authorization, Encryption, FIPS 140–2 / FIPS 140–3, IPS, SSL, VPN, IPSec, TCP/IP, DNS, OWASP, CDN, & Proxy Services.
Cisco values the perspectives and skills that emerge from employees with diverse backgrounds. That's why Cisco is expanding the boundaries of discovering top talent by not only focusing on candidates with educational degrees and experience but also placing more emphasis on unlocking potential. We believe that everyone has something to offer and that diverse teams are better equipped to solve problems, innovate, and create a positive impact. We encourage you to apply even if you do not believe you meet every single qualification.
#J-18808-Ljbffr