Senior Security Engineer - Information (REMOTE)
Job Description
Job Summary:Ā
The Senior InfoSec Engineer is responsible for implementation and administration of information security policies, practices, procedures, and technologies to ensure securely architected systems, applications, databases, cloud services, networks, and data in a hybrid cloud ecommerce environment.
The Senior InfoSec Engineer designs, implements, and oversees activities related to deploying, monitoring, improving, and managing iHerbās security stack and security strategy across the enterprise.Ā With regular reporting and feedback from management, manages and leads the implementation of information security processes, tools, and services.
This position is an advanced hands-on practitioner and representative of the cybersecurity defense team. The role is technical, and candidates must possess a solid understanding of multiple information security domains.Ā The candidate must understand applications, operating systems, networking, cloud infrastructure, attacker tactics, techniques, and procedures (TTPs).Ā The candidate is expected to maintain a high level of rigor to stay up to date with advancements in technology, while also retaining knowledge of older systems and applications in use.
This role will be responsible for overseeing, monitoring, analyzing, improving, and troubleshooting security systems, Red/Purple Team (offensive security) and Blue Team (defensive security) exercises, evaluation of security controls/services/solutions, as well as provide recommendations for enhancement and improvement.
We seek out Information Security Engineers with a broad range of skills who can pivot to other technologies, and who can passionately learn other skills and technologies.Ā At iHerb, you will have the ability to āchoose your own adventureā a percentage of the time in other areas of Cyber Security, including and not limited to:Ā Incident Response, Incident Handling, SOC and Intrusion Analysis, Automation, Cyber Threat Intelligence, Cyber Defense, Offensive Security, etc.
Job Expectations:Ā
Knowledge, Skills and Abilities:
Strong knowledge of multiple security tools for both Cloud and On-Prem scenarios.
Good knowledge of AWS (Amazon Web Services), GCP (Google Cloud Platform), Azure, or other cloud platforms and related technologies is strongly desired.Ā
Strong knowledge of SIEM, such as Splunk, and related tooling and automation.
Experience with Content Delivery Networks (CDN), Web Application Firewall (WAF), Bot Management and Distributed Denial of Service (DDOS) tooling strongly desired.
Provide support for strategic business process/reengineering consulting as appropriate and work on multiple technically complex high-profile projects.Ā
Demonstrate an understanding of key IT operational policies, processes and methodologies applicable to governance, risk management and compliance.Ā
Demonstrable experience with integration in Splunk or other SIEMs for various security tools.Ā
General understanding of security fundamentals (cryptography, least privilege, segregation of duties, ā¦) and general security technologies, including operating systems, network security (firewalls, VPNs, EDR, Web Content Filtering, etc.), security incident and event management, business continuity, physical security, identity management, directory services, etc.Ā
Knowledge of Active Directory, DDNS, Group Policy (GPO), Microsoft Windows Server and Desktop operating systems, Linux, MacOS.
Maintain knowledge of new and emerging tools, tactics and techniques that may post threats and risks to the organization. Advise and implement threat mitigations.
Research, recommend, and implement changes to enhance systems security and develop appropriate security controls to address vulnerabilities found during assessments.
Strong work ethic, including consistent documentation and tracking of activities.
Possess an understanding of PCI Compliance and EU GDPR Requirements. Participate in audit response management and provide ongoing guidance on solutions to achieve and maintain security compliance.
Ability to work in fast paced, rapidly changing environment and a strong desire to learn.
You are a self-starter and require only minimal guidance to produce results.
This position may require on-call activities at off-hours.
High degree of accuracy and attention to detail.
Excellent organization skills and ability to multi-task.
Equipment Knowledge:Ā
Experience with cloud, systems, email, and network security.
Experience with containers (Docker, Kubernetes, ā¦) strongly desired.
Experience with various tooling in the Information Security space.
Experience working with and setting up alerts and queries in Splunk or other SIEM tools.
Experience with OpenText Encase Forensics, or similar forensics tooling.
Knowledge of IT/Information Security Audit and assessment.Ā
Knowledge of PCI DSS and EU GDPR.
Knowledge researching, analyzing, and recommending information security solutions.
A working knowledge of information security practices and concepts including intrusion detection/ prevention, EDR, NetFlow analysis, access controls, risk analysis, vulnerability scanning, application whitelisting and data encryption.
Experience with Microsoft Office Suite (e.g., Word, Excel, PowerPoint, etc.).
Experience with Google Business Suite (e.g., Gmail, Drive, Docs, Sheets, Forms. etc.) preferred.
Experience Requirements:
5+ years of experience in information systems as a security engineer, cloud administrator or network administrator with at least one of those with direct incident response / incident management duties.
Education Requirements:Ā
Bachelorās Degree in Information Technology, Information Security, Computer Science, or related field preferred.
Advanced industry certification is strongly desired, i.e., SANS GIAC certifications or equivalent, CompTIA, CISSP, CISM, or others.
Judgment/Reasoning Ability:Ā Able to identify, troubleshoot and resolve problems quickly using sound judgment, poise, and diplomacy.Ā Ability to use judgment and reasoning skills, and determine when to escalate issues, as required, in a timely manner.
Ā
Physical Demands: Ā The physical demands described here are representative of those that must be met by a Team Member to successfully perform the essential functions of this job. Ā While performing the duties of this job, the Team Member is regularly required to talk and hear. The Team Member is frequently required to sit, walk, climb stairs, use hands and fingers, bend, stoop and reach with hands and arms.Ā Reaching above shoulder heights, below the waist or lifting as required to file documents or store materials throughout the workday.Ā The Team Member may occasionally lift or move office products and supplies up to 25 pounds.Ā Ā Proper lifting techniques required. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
Work Environment:Ā The noise in the work environment is usually moderate.Ā Other factors are:
Ā
Hectic, fast-paced with multi-level distractions
Professional, yet casual work environment
Office / Warehouse environment
Ability to work extended hours as requiredĀ
#LI-JC1
Staffing Agency Submission Notice
iHerb does not accept unsolicited 3rd party ("Agency") candidates. If you are an Agency, please send any requests to be considered as a supplier in our Vendor Management System to [email protected]. Do not contact iHerb employees directly. If requested to work on a role, any Agency candidates would be presented through the internal recruiting organization.
About iHerb
iHerb is on a mission to make health and wellness accessible to all. We offer Earthās best-curated selection of health and wellness products, at the best possible value, delivered with the most convenient experience.
Weāre the worldās largest eCommerce platform dedicated to vitamins, minerals, and supplements, and other health and wellness products. For more than 25 years, weāve been making it simple for people all over the world to purchase the highest quality products. From supplements to skincare to grocery items, we ship over 30,000 products, from over 1,200 brands direct to our customers in 185+ countries.
Our vision is to become the #1 destination for health and wellness across the world.
With a passion for wellness and a mind for innovative solutions, iHerb team members share a vision for a healthier world that drives them each day. Our 5 Shared Values unite our global team:
Focus on the Customer Ā· Empower Our People Ā· Be Entrepreneurial & Pivot Quickly Ā·
Embrace Diversity & Inclusion Ā· Strive for Simplicity
iHerb Benefits
At iHerb, we are dedicated to offering programs designed to help our employees and their families stay healthy, live well, and plan for their financial future. Built on a strong foundation, our programs provide options and upgrades with flexibility, protection, and security in mind. For the comprehensive benefitsĀ list, visitĀ www.iHerbBenefits.com.Ā For our international team members, you may be eligible forĀ benefitsĀ depending on the country where you are employed.Ā TheĀ Talent Acquisition Partner/local HR representative will go over theĀ benefitsĀ you are eligible for.Ā
iHerb is an Equal Opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status. iHerb provides equal employment opportunities to all applicants for employment and prohibits discrimination and harassment.
Date Posted
09/29/2022
Views
6
Similar Jobs
Senior Product Designer - Org & Security - Typeform
Views in the last 30 days - 0
This job description outlines a role in developing an intelligent contact management system with AI capabilities The position involves designing user ...
View DetailsSenior Design Manager (Infrastructure) - Canonical
Views in the last 30 days - 0
Canonical a leading opensource provider seeks a Senior Design Manager to drive innovation in cloud and AI technologies The role offers remote work glo...
View DetailsSenior Business Analyst - Xpansiv
Views in the last 30 days - 0
Xpansiv promotes its role as an energy market innovator with a global platform for environmental commodities The job posting seeks a Business Analyst ...
View DetailsSenior Specialist Senior Accountant Shared Financial Services - Make-A-Wish America
Views in the last 30 days - 0
The text describes Make a Wish Foundations mission to grant childrens wishes and their community efforts It outlines job positions with remotehybrid o...
View DetailsSoftware Engineer Networking Software and Services - xAI
Views in the last 30 days - 0
The text describes xAIs mission to develop AI systems for understanding the universe and advancing human knowledge It outlines a role involving networ...
View DetailsAssociate Technical Support Engineer - Recharge
Views in the last 30 days - 0
Recharge is a subscription platform for innovative brands offering customer retention solutions They seek Technical Support roles with 247 coverage em...
View Details