Job Description
RESPONSIBILITIES
Develop and mature an internal security hardening and baselines program. This effort develops standards and process to ensure attack surface risk is reduced and configuration baseline is met both according to CIS Controls and cyber threats actively targeting the firm.
Perform assessments and communicate to stakeholders on the likelihood of exploitation and potential impact of vulnerabilities, misconfiguration findings, and other potential vectors to determine the appropriate course of action to mitigate potential risk.
Leverage Cloud Native Application Protection Platform (CNAPP) technology to assess findings and contribute guidance and expertise to application custodians on fixing issues.
Act as a security liaison between Information Security and the Development staff to bring a security mindset to the software development lifecycle. Assess and understand the Wellington CI/CD pipeline to be able to provide recommendations to developers for securing their code.
Stay up to date with current and relevant cyber security threats as well as any associated countermeasures. Participate in internal meetings to map industry cyber threats to our current attack surface.
Review of both internal and open-source threat intelligence sources for recently disclosed vulnerabilities at risk of introduction into the Wellington environment.
Work with our Third-Party Risk team to engage third parties in Wellington’s vendor ecosystem to understand when third and fourth parties may be exposed to critical vulnerabilities.
Contribute to team documentation for updates to existing processes, new processes, assessment tool infrastructure details and workflows.
Contribute to firmwide documentation by being an SME contributor to policies and standards.
NON-TECHNICAL QUALIFICATIONS
A Passion for cyber-security is a must.
Ability to self-motivate, with an eagerness to dig into potential risks. Ask questions, be curious, dig deeper.
BS degree in Information Systems/related discipline or equivalent IT work experience
Experience in developing new processes and procedures that match evolving attack surfaces.
Excellent oral and written communication skills with a proven ability to effectively interact with teams representing a wide variety of technical disciplines.
Ability to work with global teams effectively.
Ability to mentor junior team members and share discoveries about your work.
TECHNICAL QUALIFICATIONS
Experience working with best practices frameworks such as CIS Critical Security Controls to drive an internal discovery and risk assessment program for a system baselines / hardening program.
Knowledge of common cyber-attack types such as DDoS, SQLi, XSS, and others. This experience relied upon to make rational decisions in our baselines program.
Hands-on experience with vulnerability assessment software and prioritizing results using a combination of various frameworks tied to internal objects (CVE, CVSS, EPSS, etc.).
Previous experience assessing, documenting, and communicating information security risk, particularly related to cyber vulnerabilities is preferred.
Experience in the use of common scripting languages such as python to automate job functions.
Working knowledge of IaC (Infrastructure as Code) concepts, especially with AWS.
Knowledge in the areas of network architecture and engineering and software application development
Working knowledge of the use of threat intelligence feeds and resources
💡 Quick Summary
Seeking a career-building opportunity? The Senior Systems Engineer position is now open for candidates interested in the IT Engineer & Developer Jobs sector. This role in London offers a professional environment and growth potential.
Requirement Snapshot: Candidates should possess basic communication skills, a proactive attitude, and the ability to work in a team. Experience in IT Engineer & Developer Jobs is a plus.
