Information Security Engineer II
Job Description
About NCR
NCR Corporation (NYSE: NCR) is a leader in transforming, connecting and running technology platforms for self-directed banking, stores and restaurants. NCR is headquartered in Atlanta, Ga., with 38,000 employees globally. NCR is a trademark of NCR Corporation in the United States and other countries.
Title: Information Security Engineer II
Location: Atlanta WHQ, US
About NCR Corporation
NCR Corporation (NYSE: NCR) is a global technology company leading how the world connects, interacts and transacts with business. NCR's assisted- and self-service solutions and comprehensive support services address the needs of retail, financial, travel, healthcare, hospitality, entertainment, gaming and public sector organizations in more than 100 countries. NCR (www.ncr.com) is headquartered in Atlanta, Georgia.
Information Security Engineer II
This role is part of NCR's Global Information Security team. This team is responsible for developing and implementing NCR's corporate information security program. The primary goal of the program is to protect the confidentiality, integrity, and availability of information resources. Key information security functions and activities include architecture and design for NCR information security controls, developing and enforcing policies and standards, security awareness training, risk management, assessment, and testing, monitoring and metrics, incident management, and threat and vulnerability management.
The Information Security Engineer II shall be responsible for the day-to-day activities required to respond for both routine and high severity incidents and vulnerabilities identified. The Information Security Engineer II shall work in a collaborative manner with incident responders, key incident management team members, management, and other stakeholders to ensure security incidents are contained, eradicated, remediated and after-action review is held according to corporate policy. The Information Security Engineer II shall work in a collaborative manner with vulnerability coordinators and remediation team to make sure the vulnerabilities are remediated with patching and compensating controls. The Information Security Engineer II is expected to contribute to weekly status calls and is On-Call which includes working off hours/weekends and respond to ad-hoc requests as part of this position. The Information Security Engineer II will work with stakeholders and team members to assist with improving incident response processes that are aligned with the mission of the office of the CISO.
Key Responsibilities
- As an active member of the team, monitor and process response for security events on a 24x7 basis.
- Coordinate Postmortem exercises post incidents with a focus to identify deficiencies requiring additional attention.
- Triage, respond to and escalate security incidents.
- Triage, respond to and escalate Zero days and high severity vulnerabilities.
- Coordinate remediation activities for Zero days/High Severity vulnerabilities.
- Leverage automation and orchestration solutions to automate repetitive tasks.
- Work alongside other security team members to hunt for and identify security issues generated from the network, including third-party relationships.
- Coordinate incident response activities across multiple independently managed environments and security teams.
- Leverage knowledge in multiple security disciplines, such as Windows, Unix, Linux, data loss prevention (DLP), endpoint controls, Public Cloud, and networking, to offer global solutions for a complex heterogeneous environment.
- Utilize multiple security/threat intelligence tools and resources to understand threats.
- Analyze and respond to minor and major incidents, reported SPAM and Phishing e-mails.
- Partner with the detection engineering team to improve tool usage and workflow, as well as with the advanced threats and assessment team to mature monitoring and response capabilities.
- Support 24/7 operations
- Perform other duties as assigned.
Skills and Qualifications
- Strong knowledge of network, backend systems, operating systems, applications, and web services in a manner that allows for the interaction of all as it relates to security and services.
- 3+ Years as a incident responder/Vulnerability management functions
- Ability to apply analytical expertise and critical thinking to security incidents and Vulnerabilities.
- Ability to assimilate, understand and utilize various security technologies.
- Ability to collaborate within a geographically distributed team of Incident Response Analysts and vulnerability remediation team.
- Current Information Security related certification preferred.
- Current Public cloud related certification preferred.
- Knowledge of relevant information security and incident response frameworks such as MITRE ATT&CK Framework and CVSS scoring systems
- Strong communication skills and ability to work in a collaborative atmosphere.
- Strong attention to detail
- Ability to deal with ambiguity and translate high level objectives into detailed tasks.
- Ability to prioritize work with multiple, simultaneous work assignments.
- Ability and willingness to learn new tools and processes.
- Experience documenting business processes or technical procedures preferred.
EEO Statement
Integrated into our shared values is NCR's commitment to diversity. NCR is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. This concept encompasses but is not limited to human differences with regard to race, ethnicity, religion, gender, culture and physical ability. Every individual at NCR has an ongoing responsibility to respect and support a globally diverse environment.
Offers of employment are conditional upon passage of screening criteria applicable to the job.
Full time employee benefits include:
- Medical Insurance
- Dental Insurance
- Life Insurance
- Vision Insurance
- Short/Long Term Disability
- Paid Vacation
- 401k
EEO Statement
Integrated into our shared values is NCR's commitment to diversity and equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. NCR is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at NCR has an ongoing responsibility to respect and support a globally diverse environment.
Statement to Third Party Agencies
To ALL recruitment agencies: NCR only accepts resumes from agencies on the NCR preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR employees, or any NCR facility. NCR is not responsible for any fees or charges associated with unsolicited resumes.
Explore More
Date Posted
06/26/2023
Views
9
Neutral
Subjectivity Score: 0.5