DevCloud Security Lead
Job Description
The US Global Technology Operations BU is seeking a Security Lead to support governance, risk, and compliance services as well as security service delivery across the US Development Platform (on-prem and public cloud).
The successful candidate will have a broad knowledge of current security practices as well as the ability to identify and apply legal, regulatory, and industry-specific security requirements. The candidates will help our clients and business partners deploy effective security solutions and strategies while addressing ever-changing regulatory and industry compliance challenges. The candidate must possess strong communication skills, be organized, detail oriented, and able to collaborate with a variety of technical and management disciplines including infrastructure and security architecture, security operations, application development, project managers, product owners, and others.
This role can be located in any CGI office in the US.
Your future duties and responsibilities:
FUTURE DUTIES AND RESPONSIBILITIES
• Act as Security Lead for the US GTO Development Cloud (on-premise and public cloud) Security Service delivery
o Work as the liaison between Corporate Security, GTO, and IP Development teams acting as the single point of contact for security services implementation and delivery
o Assess security posture of all Development environments (on-prem and public cloud)
o Work with Security Engineering (Corporate and GTO) on tools, scans, inventory, etc.
o Ensure endpoint exclusions are applied
o Work with Corporate Security, GTO, and IP Development teams on patching, vulnerability remediation, etc.
o Assist IP development teams with vulnerability reporting, assessment, tracking, and management.
o Track N-1 status for Development Cloud hosted systems and manage end of life support dates and migrations schedules in conjunction with the system owners
o Work with the App Security team to understand SAST/DAST/Pen testing, etc. for the IPs in the Development Cloud
o Assist with Security exceptions
o Respond to general security questions/issues; escalate or redirect.
o Provide security consulting / risk assessment for proposed system changes
o Create and maintain System Security Plans (SSP) for both on-prem and public cloud Development environments
Required qualifications to be successful in this role:
• Minimum Education Required: High School Diploma/GED• Five years of experience related to information security, IT infrastructure, architecture, or applications.• At least one industry recognized certification in information security (e.g., CISSP, CISA, CISM, SANS/GIAC certifications, etc.) • Five years of experience working with one or more legal, regulatory, and industry-specific security requirements, guidelines, and practices, such as:
o The NIST 800 series of Special Publications, including especially SP 800-53 and the NIST Cybersecurity Framework
o Payment Card Industry - Digital Security Standards (PCI-DSS)
o IRS Publication 1075
o Health Insurance Portability and Accountability Act (HIPAA) / Health Information Technology for Economic and Clinical Health (HITECH)
o Cloud Controls Matrix (CCM)
o Security, Trust & Assurance Registry (STAR)
o International Organization for Standardization (ISO) 2700x
o The Federal Risk and Authorization Management Program (FedRAMP)
o North American Electric Reliability Corporation (NERC)
o Critical Infrastructure Protection (CIP) Standards • Five years of experience delivering Security services including interaction with executive or senior client management • Five years of working in risk assessments, risk management, controls monitoring, and controls audits. • Five years of policy, procedures, standards, work instructions, report generation, and managing projects.
DESIRED QUALIFICATIONS/NON-ESSENTIAL SKILLS REQUIRED
• Additional industry recognized certifications in information security (e.g., CISSP, CISA, CISM, SANS/GIAC certifications, etc.) • Experience in information security testing (e.g., penetration testing, web application security assessments, vulnerability assessments and technical security assessments • Secure SDLC, Agile, or DevOps experience • Experience in virtualized security environments • Experience with security vendors providing cloud-based IAM, data protection, security monitoring, and security-related SaaS offerings • Experience with Linux and Windows operating system administration • Experience with application development • Proven ability to build, manage and foster a team-oriented environment • Proven ability to work creatively and analytically in a problem-solving environment • Desire to work in an information systems environment • Excellent communication (written and oral) and interpersonal skills • Excellent leadership and management skills
Est. Salary Range (Colorado Only): $120,000-$150,000*
*Disclaimer: In accordance with Colorado's Equal Pay for Equal Work Act, effective January 1, 2021, a good faith hourly or base salary range must be posted for all positions where the work may be performed in the state of Colorado. Therefore, this good faith salary range will only apply where this described position will be performed in the state, and should not be considered the compensation range in other locations or for other positions.
At CGI we call our professionals "members" to reinforce that all who join our team are, as owners, empowered to participate in the challenges and rewards that come from building a world-class company. CGI's benefits include:• Competitive base salaries • Eligibility to participate in an attractive Share Purchase Plan (SPP) in which the company matches dollar-for-dollar contributions made by eligible employees, up to a maximum, for their job category • 401(k) Plan and Profit Participation for eligible members • Generous holidays, vacation, and sick leave plans • Comprehensive insurance plans that include, among other benefits, medical, dental, vision, life, disability, out-of-county emergency coverage in all countries of employment; • Back-up child care, Pet insurance, a Member Assistance Program, a 529 college savings program, a personal financial management tool, lifestyle management programs and more
Skills:
- Analytical Thinking
- Cloud Computing
- Compliance
- NIST
- Security Infrastructure Supprt
What you can expect from us:
Insights you can act on
While technology is at the heart of our clients' digital transformation, we understand that people are at the heart of business success.
When you join CGI, you become a trusted advisor, collaborating with colleagues and clients to bring forward actionable insights that deliver meaningful and sustainable outcomes. We call our employees "members" because they are CGI shareholders and owners and owners who enjoy working and growing together to build a company we are proud of. This has been our Dream since 1976, and it has brought us to where we are today - one of the world's largest independent providers of IT and business consulting services.
At CGI, we recognize the richness that diversity brings. We strive to create a work culture where all belong and collaborate with clients in building more inclusive communities. As an equal-opportunity employer, we want to empower all our members to succeed and grow. If you require an accommodation at any point during the recruitment process, please let us know. We will be happy to assist.
Ready to become part of our success story? Join CGI - where your ideas and actions make a difference.
Qualified applicants will receive consideration for employment without regard to their race, ethnicity, ancestry, color, sex, religion, creed, age, national origin, citizenship status, disability, pregnancy, medical condition, military and veteran status, marital status, sexual orientation or perceived sexual orientation, gender, gender identity, and gender expression, familial status, political affiliation, genetic information, or any other legally protected status or characteristics.
CGI provides reasonable accommodations to qualified individuals with disabilities. If you need an accommodation to apply for a job in the U.S., please email the CGI U.S. Employment Compliance mailbox at [email protected] . You will need to reference the requisition number of the position in which you are interested. Your message will be routed to the appropriate recruiter who will assist you. Please note, this email address is only to be used for those individuals who need an accommodation to apply for a job. Emails for any other reason or those that do not include a requisition number will not be returned.
We make it easy to translate military experience and skills! Click here to be directed to our site that is dedicated to veterans and transitioning service members.
All CGI offers of employment in the U.S. are contingent upon the ability to successfully complete a background investigation. Background investigation components can vary dependent upon specific assignment and/or level of US government security clearance held. CGI will consider for employment qualified applicants with arrests and conviction records in accordance with all local regulations and ordinances.
CGI will not discharge or in any other manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with CGI's legal duty to furnish information.
Date Posted
10/22/2022
Views
6
Similar Jobs
Lead Shipping/Receiving - Magna International
Views in the last 30 days - 0
Magna offers an engaging and dynamic environment for employees to develop industryleading automotive technologies The company invests in its employees...
View DetailsManager, IT Support - California Closets BC
Views in the last 30 days - 0
California Closets founded in 1978 is a leading custom storage solutions provider offering premium space management and exceptional service The compan...
View DetailsCommunity Manager - Sparrow Partners
Views in the last 30 days - 0
Sparrow is a company that aims to create thriving communities for active adults offering thoughtful design stateoftheart construction and engaged mana...
View DetailsClient Relations Manager - Ageless Mens Health
Views in the last 30 days - 0
Ageless Womens Health is seeking a Client Relations Manager to build and maintain patient relationships at their Scottsdale Arizona clinic The ideal c...
View DetailsBIM Coordinator - Larson Design Group
Views in the last 30 days - 0
Larson Design Group LDG is an awardwinning employeeowned Architecture Engineering and Consulting Firm They are expanding their team opening new office...
View DetailsBig Data Tester - NucleusTeq
Views in the last 30 days - 0
The job posting is for a Big Data Tester role in Phoenix AZ with a duration of 12 months The role involves building test scenarios maintaining test au...
View Details