Summary
Join NBCUniversal's Security Engineering team as a Cyber Security Engineer, partnering with Global Streaming Technology and Cyber Security organizations. Conduct end-to-end security and threat analysis of enterprise initiatives, ensuring Information Security best practices are integrated into system designs. Serve as a technical and engineering subject matter expert across various Cyber Security technology areas. Collaborate across the Cyber organization and with business stakeholders to provide security guidance and mitigation requirements. Effectively communicate the importance of key Cyber initiatives to gain business support and buy-in. This is a fully remote position offering competitive benefits.
Requirements
- 2+ years of experience partnering with business and technical teams to architect and deliver Cyber solutions
- 2+ years of experience consulting with business teams regarding threat mitigation best practices in one or more technical areas (Perimeter Security, Application Security, Core Systems, EDR, Cloud etcβ¦)
- Explain common threats to components including Network, Cloud, Web and Application environments
- Collaborate with other staff to ensure Cyber requirements are understood and clear during all phases of a project
- Awareness of best practices in the Cyber Security industry, including remediations for OWASP Top 10, CWE/SANS Top 25, CIS controls, and NIST guidelines
- Technical knowledge in at least one of the above listed Cyber security areas, highlighting your ability to navigate complex challenges
- Give and receive constructive feedback in a team environment, fostering a culture of continual improvement and excellence
- Willingness to provide mentorship to all members of the team
- Written/verbal communication and presentation skills with the ability to tailor to both technical, and non-technical audiences
- Experience using diagramming tools to communicate secure designs and controls
- Time management skills to appropriately prioritize multiple concurrent projects
Responsibilities
- Partner with business and technical teams to architect and deliver Cyber solutions
- Consult with business teams regarding threat mitigation best practices in one or more technical areas (Perimeter Security, Application Security, Core Systems, EDR, Cloud etcβ¦)
- Explain common threats to components including Network, Cloud, Web and Application environments
- Collaborate with other staff to ensure Cyber requirements are understood and clear during all phases of a project
- Conduct end to end security and threat analysis of enterprise initiatives involving new or modified technology deployments; ensuring that they incorporate Information Security best practices and guidelines into system designs
- Function as a technical and engineering subject matter expert across various Cyber Security technology areas with a focus on network, application, cloud, and enterprise security controls
- Effectively communicate the importance of key Cyber initiatives and services to obtain support, trust and buy-in from the business
Preferred Qualifications
- Formal Degree is not required, relevant experience in the above mentioned areas prioritized
- Experience performing Threat Analysis and modeling leveraging best in industry frameworks such as MITRE ATT&CK, indicating your proficiency in implementing robust security measures
- Detailed knowledge of common Cloud Services offered (IaaS, PaaS, SaaS) and the different potential risks posed by each
- Familiarity with security controls such as Cloud Security Matrix, NIST CSF, CIS Critical Security Controls
- Understanding of various data and privacy regulations, including PCI DSS, SOX, HIPAA, GDPR, CCPA
- Experience developing and documenting security guidelines or security best practices
- Empathy for engineering teams with the ability to balance security guidelines and policies with operational needs to maintain desired end-state corporate security posture
Benefits
- Medical, dental and vision insurance
- 401(k)
- Paid leave
- Tuition reimbursement
- A variety of other discounts and perks