Principal Engineer Security Services
hace 4 horas
**Principal Engineer Security Services**
The Principal Engineer Security Services will play a crucial role in ensuring the ongoing security and protection of our company's information assets. They will be responsible for designing, developing, and overseeing the implementation of cybersecurity solutions to safeguard our systems, networks, and data. The Principal Engineer Security Services manages day-to-day security operations, participates in compliance and audit activities, and will establish and maintain effective security measures. This position requires a strong technical background, exceptional problem-solving skills, and a thorough understanding of security best practices.
Responsibilities:
Cybersecurity Strategy and Architecture:
- Architect, design, recommend, implement, and maintain security controls, countermeasures, and procedures in acquisition, development, business processes, and change management lifecycle of information systems; provide oversight to ensure compliance
- Develop and document security policies and processes based on common information security management frameworks (ISO 27001, SOC2)
- Lead the development of the organization's cybersecurity strategy and provide expertise in creating a secure architecture for IT systems and networks
- Collaborate with cross-functional teams to ensure cybersecurity measures align with business goals and regulatory requirements
Security Operations and Incident Response:
- Oversee security operations, including threat monitoring, detection, and incident response
- Develop and maintain an incident response plan, including procedures for handling security incidents, communication protocols, and post-incident analysis
- Monitor information systems for security incidents and vulnerabilities
- Administer and mature Data Loss Prevention and Information Protection policies and solutions
- Oversee the response to information system security incidents, including investigation of, countermeasures to, and recovery from computer-based attacks, unauthorized access, and policy breaches
- Lead and coordinate incident response efforts to contain, investigate, and mitigate cybersecurity incidents effectively
Vulnerability Management:
- Develop and manage vulnerability assessment and penetration testing programs to identify and remediate security vulnerabilities in a timely manner
- Track and report on the status of vulnerability remediation efforts
- Consult with internal development teams to anticipate threats, advise on defensive coding strategies and remediate vulnerabilities in software
- Proactively anticipate and assess potential items of risk and opportunities of vulnerabilities in the network and systems
- Manage security information and event management (SIEM) systems, analyze logs, and detect potential security breaches
Security Compliance and Auditing:
- Mature and maintain Information Security Management System (ISMS) and further develop security policies, standards and procedures in support of ISO 27001 certification
- Participate in internal and external security audits and risk assessments/reviews, including third-party software, service providers, customers, partner, and vendor audits
- Conduct regular internal security reviews and risk assessments, identify gaps, and recommend appropriate corrective actions
Security Awareness and Training:
- Promote a culture of security awareness across the organization through the development and implementation of regular training programs, awareness campaigns, and communication initiatives
- Provide technical information to systems engineering programs, team members and managers to ensure awareness and compliance with industry standard security best practices
- Provide guidance and training to employees on security best practices, policies, and procedures
Emerging Technologies and Threat Intelligence:
- Monitor industry trends, technologies, threat intelligence, and vulnerability disclosures to stay informed about new vulnerabilities and emerging threats; educate stakeholders and provide recommendations on integration into the organization’s security strategy
Security Documentation and Reporting:
- Prepare and maintain accurate and up-to-date security documentation, including policies, procedures, standards, controls, and guidelines
- Prepare regular reports for management on the state of cybersecurity, including risk assessments and key performance indicators (KPIs)
- Develop and deliver clear, concise, and actionable vulnerability reports and recommendations to various stakeholders, including executive leadership, IT, and development teams
Requirements:
- Bachelor's degree in Computer Science, Information Security, or a related field
- 5+ years of experience in IT with a focus on IT security
- Proven experience in information security engineering/administration roles, with a focus on security operations and incident response
- Deep knowledge and experience with cloud security principles
-
-
Application Security Engineer
hace 1 semana
Heredia, Costa Rica Global Services Business A tiempo completoAn important Company in Costa Rica is looking for an Application Security Engineer **Responsibilities**: Application security reviews (SAST, DAST, Pen testing) Secure architecture design Threat modeling Security outreach to internal development teams Security guidance documentation Security metrics delivery and improvements Build deep relationships with...
-
Application Security Engineer
hace 1 semana
Heredia, Costa Rica GSB A tiempo completoAn important Company in Costa Rica is looking for an Application Security Engineer English Advanced **Responsibilities**: - Application security reviews (SAST, DAST, Pen testing) - Secure architecture design - Threat modeling - Security outreach to internal development teams - Security guidance documentation - Security metrics delivery and improvements -...
-
.NET Principal Software Engineer
hace 1 semana
Heredia, Costa Rica Prodigious A tiempo completoCompany Description Publicis Global Delivery is the talent powerhouse of Publicis Groupe, the largest global communications group. We make sure to hire, boost and develop the best people worldwide to deliver outstanding work for the most prominent clients within the Groupe. In LATAM, we are over 1,700 passionate employees that love to push boundaries and...
-
Senior Application Security Engineer
hace 3 días
Heredia, Costa Rica BMA Group A tiempo completo**Job Title**: **Senior Application Security Engineer** **Job Category**: Professional **Department/Group**: Security Engineering **Position Type**: Full time **Location**: Remote, Costa Rica **Reports to**: Engineering Manager **Senior Application Security Engineer** **What you'll be doing** **Responsibilities**: - Collaborate with software...
-
Systems Security Engineer Expert
hace 2 semanas
Heredia, Costa Rica Experian A tiempo completoCompany Description **About us, but we’ll be brief** Experian is the world’s leading global information services company, unlocking the power of data to create more opportunities for consumers, businesses and society. We are thrilled to share that FORTUNE has named Experian one of the 100 Best Companies to work for. In addition, for the last five years...
-
PAM Security Engineer Expert
hace 5 horas
Centro Corporativo el Cafetal, Heredia, Heredia, Costa Rica Experian A tiempo completoCompany Description Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and...
-
Network Security Engineer
hace 4 horas
Heredia, Costa Rica Moody's A tiempo completoThe Cybersecurity team is globally responsible for helping the organization balance risk by aligning policies and procedures with Moody’s business and regulatory requirements. The team is responsible for the development, enforcement and monitoring of security controls, policies and procedures, disaster recovery programs, GRC (Governance, Risk and...
-
Senior Pam Security Engineer
hace 1 semana
Heredia, Costa Rica Experian A tiempo completoFull-time Employee Status: Regular Role Type: Home Department: Information Technology & Systems Schedule: Full Time Shift: Day Shift **Company Description**: Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting...
-
Principal Ot Cybersecurity Engineer
hace 1 día
Heredia, Costa Rica Boston Scientific Corporation A tiempo completo**Work mode**:Hybrid**Onsite Location(s)**:Heredia, H, CR**Diversity - Innovation - Caring - Global Collaboration - Winning Spirit - High Performance** - At Boston Scientific, we recognize that nurturing a diverse and inclusive workplace helps us be more innovative and it is important in our work of advancing science for life and improving patient health....
-
Endpoint Security Techlead
hace 2 semanas
Heredia, Costa Rica Experian A tiempo completoFull-time Employee Status: Regular Role Type: Home Department: Information Technology & Systems Schedule: Full Time Shift: Day Shift **Company Description**: Experian is the world’s leading global information services company. During life’s big moments - from buying a home or a car, to sending a child to college, to growing a business by connecting...