A Place For Mom
Staff DevOps Engineer - Security
A Place For Mom, Brooklyn, New York, United States,
Job Description
We are seeking a highly skilled and experienced Staff DevOps Engineer to join our team. This role will focus on Site Reliability Engineering (SRE), enhancing our developer platform, and ensuring robust security practices. The ideal candidate will have a strong background in SRE principles, platform engineering, and security, with a proven ability to drive improvements in system reliability, performance, and security.
The Position:
Are you data-driven and have a passion for information security? Do you love data analysis and making large amounts of information understandable and actionable for others? Do you like solving new problems and building new tools and codes?
Do you like to work with others in a collaborate effort to build better more security applications?
Would you like to join a team of talented security and technology professionals who are focused on building a robust and secure infrastructure? If so, join our team to develop these skills and build your career!
A Place for Mom is updating its security monitoring and vulnerability management systems.
These systems need to provide useful information to the development teams so they can understand security concerns before they are deployed to production.
We are seeking an Information Security Engineer to work as part of a team, interpret findings, and own the issue through remediation, to help us achieve our goal of zero security incidents.
Who you are:
You are an experienced and results-oriented Information Security Engineer who can work cross-functionally to develop and implement security improvements and safeguards which will protect A Place for Mom’s assets, employees, and customers.
What you will do:
Incorporate A Place for Mom Values into each customer and co-worker interaction.
Perform configuration, network, and application technical vulnerability assessments, identify vulnerabilities, validate their relevance, and work with teams to remediate them.
Design and implement security solutions across infrastructure and applications to ensure "secure by default" principles are followed.
Monitor, analyze, and respond to alerts from automated logging and monitoring tools, including AWS Security Hub, AWS Systems Manager, Cisco Duo Security, Endpoint protect and Security Information and Event Management (SIEM) tools, like Alert Logic or Rapid7, including collaborate with DevOps teams to automate security practices, integrating security controls and checks into CI/CD pipelines
Respond to security related requests, events, and incidents; perform triaging and investigation as needed; and provide the fixes as appropriate
Analyze security threats, vulnerability assessments, and audit results to identify the root cause and recommend or implement security solutions that enable business objectives.
Lead the development and enforcement of security standards, policies, and procedures, ensuring alignment with industry best practices.
Collaborate with other teams to support response efforts to security-related findings or concerns and drive to resolution.
Analyze mean time to remediation, incident response times, and other security metrics and provide assessment reports.
Develop and maintain automated security testing and scanning tools to detect vulnerabilities during the development lifecycle.
Maintain up-to-date knowledge of the IT security industry including awareness of new or revised security solutions and improved security processes.
Evangelize a culture of security to the rest of the company through education, support, and empathy, fostering a culture of security awareness
Stay up-to-date on the latest security threats, vulnerabilities, and trends, proactively recommending improvements to security posture.
Perform additional tasks as assigned.
We are seeking a highly skilled and experienced Staff DevOps Engineer to join our team. This role will focus on Site Reliability Engineering (SRE), enhancing our developer platform, and ensuring robust security practices. The ideal candidate will have a strong background in SRE principles, platform engineering, and security, with a proven ability to drive improvements in system reliability, performance, and security.
The Position:
Are you data-driven and have a passion for information security? Do you love data analysis and making large amounts of information understandable and actionable for others? Do you like solving new problems and building new tools and codes?
Do you like to work with others in a collaborate effort to build better more security applications?
Would you like to join a team of talented security and technology professionals who are focused on building a robust and secure infrastructure? If so, join our team to develop these skills and build your career!
A Place for Mom is updating its security monitoring and vulnerability management systems.
These systems need to provide useful information to the development teams so they can understand security concerns before they are deployed to production.
We are seeking an Information Security Engineer to work as part of a team, interpret findings, and own the issue through remediation, to help us achieve our goal of zero security incidents.
Who you are:
You are an experienced and results-oriented Information Security Engineer who can work cross-functionally to develop and implement security improvements and safeguards which will protect A Place for Mom’s assets, employees, and customers.
What you will do:
Incorporate A Place for Mom Values into each customer and co-worker interaction.
Perform configuration, network, and application technical vulnerability assessments, identify vulnerabilities, validate their relevance, and work with teams to remediate them.
Design and implement security solutions across infrastructure and applications to ensure "secure by default" principles are followed.
Monitor, analyze, and respond to alerts from automated logging and monitoring tools, including AWS Security Hub, AWS Systems Manager, Cisco Duo Security, Endpoint protect and Security Information and Event Management (SIEM) tools, like Alert Logic or Rapid7, including collaborate with DevOps teams to automate security practices, integrating security controls and checks into CI/CD pipelines
Respond to security related requests, events, and incidents; perform triaging and investigation as needed; and provide the fixes as appropriate
Analyze security threats, vulnerability assessments, and audit results to identify the root cause and recommend or implement security solutions that enable business objectives.
Lead the development and enforcement of security standards, policies, and procedures, ensuring alignment with industry best practices.
Collaborate with other teams to support response efforts to security-related findings or concerns and drive to resolution.
Analyze mean time to remediation, incident response times, and other security metrics and provide assessment reports.
Develop and maintain automated security testing and scanning tools to detect vulnerabilities during the development lifecycle.
Maintain up-to-date knowledge of the IT security industry including awareness of new or revised security solutions and improved security processes.
Evangelize a culture of security to the rest of the company through education, support, and empathy, fostering a culture of security awareness
Stay up-to-date on the latest security threats, vulnerabilities, and trends, proactively recommending improvements to security posture.
Perform additional tasks as assigned.