Senior Engineer Vulnerability Management, ITC

Nike, Inc. · Other US Location

Company

Nike, Inc.

Location

Other US Location

Type

Full Time

Job Description

WHO ARE WE LOOKING FOR

We’re looking for a Senior Engineer Vulnerability Management to be focused on the automation and integration of various security vulnerability assessment tools to drive accountability & visibility of Nike's high-risk findings. This role will work with multiple data sources, including all vulnerability data and other enterprise data, for contextual enrichment to drive actional output and automated vulnerability management lifecycle. In addition, this individual will work with technical and business teams to understand customer use cases for remediation of the vulnerabilities and provide solutions to create self-service visibility into security findings for mitigation and automated reporting. You will also improve Nike's security posture by advocating for security best practices and implementation. Ours is a fast-paced, forward-thinking team constantly innovating and passionate about data and risk reduction.Β 

WHAT WILL YOU WORK ON

  • Developing automation & complex orchestration to scale out the vulnerability tools, output of vulnerability data and correlated (enrichment) data across the organization

  • Assist with maintaining pipeline integration of security tools into various development SDLCs

  • Educate Engineers, developers, and product teams on the importance of vulnerability management, effectively utilize the tools and remediate findings identified in an automated fashion

  • Continually evaluate the current state of the program; work with the team constantly find ways to automate and develop future roadmap

  • Communicate complex technical issues simply to different audiences

  • Ability to quickly learn new Information Security concepts and adapt to a fast-paced, ever-changing organization

WHO WILL YOU WORK WITH

This role is part of the Attack Surface Management team within Corporate Information Security (CIS) and reports to the local Director for Cyber Defense. You will work with teams within CIS, including the Nike Cyber Defense Center & Incident Response (NCDC/IR) and CIS Cyber Defense Management team.

WHAT YOU BRING

  • BS or MS degree preferred in computer science, information assurance

  • Expertise in interpreted languages (Python is a must) and high-level languages (Java script, .Net, PowerShell) with full-stack development experience

  • Hands on experience with ETL tools (i.e. Apache Nifi, MS-SSIS, jasper) and concepts

  • Software development background and strong knowledge of software development lifecycles

  • Previous experience deploying and maintaining configuration as code systems, services, containers and applications in AWS, Azure and/or GCP

  • Hands on experience with Vulnerability management tools such as Tenable, Rapid7, or Qualys, Twistlock

  • Ability to develop and communicate recommendations to management

  • Ability to translate technical security vulnerabilities into business risk

  • Strong problem-solving and conceptual thinking abilities

  • Strong ability to reverse engineer tools, exploits and open-source applications and ability to develop them

  • Experience looking for application security vulnerabilities such as Cross Site Scripting, SQL Injection, Cookie Manipulation, Buffer Overflows, etc.

  • In-depth familiarity with Windows and Unix Operating Systems

Apply Now

Date Posted

09/23/2024

Views

0

Back to Job Listings Add To Job List Company Profile View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Senior Software Engineer (Scala/Java) - HERE Technologies

Views in the last 30 days - 0

HERE Technologies is seeking an experienced backend engineer with strong Java or Scala skills to join the Map Processing Pipelines team The role invol...

View Details

Software Architecture Engineering and Cloud Computing Engineer - The Aerospace Corporation

Views in the last 30 days - 0

The Aerospace Corporation is seeking a Senior Project Engineer with expertise in software architecture engineering and cloud computing The role involv...

View Details

Senior Finance Business Partner (d/f/m) - Personio

Views in the last 30 days - 0

Personio an intelligent HR platform is seeking a Senior Manager for FPA to lead financial planning and analysis for key departments The ideal candidat...

View Details

Senior Lead, Talent Acquisition - Sales (Relocation to Munich) (d/f/m) - Personio

Views in the last 30 days - 0

Personio a leading HR platform is seeking a Senior Lead Talent Acquisition professional to drive growth in the Revenue and Success functions across Eu...

View Details

Senior Pricing Analyst - Cencora

Views in the last 30 days - 0

Cencora formerly known as AmerisourceBergen is a leading global pharmaceutical solutions organization They are currently experiencing rapid growth in ...

View Details

Senior Product Analyst - FinCrime Platform - WISE

Views in the last 30 days - 0

Wise is seeking a Senior Product Analyst for its FinCrime Platform The role involves driving analytics efforts in the Financial Crime Platform product...

View Details