资深信息安全工程师
Principal Information Security Engineer
让第五三银行更出色®
我们为优秀的人才提供卓越的机会。你准备好迈出下一步了吗?在第五三银行开启你的银行业职业生涯。
这是信息安全部门数据安全部的一个高级工程师职位。理想的候选人应具备数据安全领域的实际经验,熟悉加密、令牌化、证书管理、AWS/云等技术,并能在交付成果的同时指导和培养初级团队成员。
一般职责:
信息安全工程师(ISE)将负责定义、实施并支持与IT工程团队合作开发的企业安全工具和架构。ISE还将参与各种信息安全项目,并支持信息安全部门的日常运营。
通过公开交流想法和意见、提升关注的问题,并亲自遵循已定义的政策和程序来对风险负责。对为客户和同事做正确的事负责,并确保行为和行动推动积极的客户体验。在银行的风险偏好范围内,通过持续识别、评估、管理、监控和报告各类风险来实现成果。
核心职责与任务:
- 指导团队中更初级的成员。
- 负责Venafi/Cyberark(信任保护平台)及其与其他工具和平台的关联组件。
- 为新应用程序和项目的实施定义安全需求。
- 作为加密管理计划的团队成员。
- 为加密管理计划提供专家指导。
- 在项目中担任数据安全工程师/顾问。
- 参与开展针对威胁和修复技术/产品的安全研究,向IS/IT团队提出建议并监督其实施。
- 支持银行的操作信息安全职责,包括制定和维护标准、流程和指南,以满足信息安全部门的运营需求。
- 协助进行风险评估,以评估现有控制措施的有效性,并确定对业务流程、应用程序和系统的拟议变更的影响。
- 为监管机构、外部审计师和内部审计师提供技术支持
查看英文原文
Make banking a Fifth Third better®
We connect great people to great opportunities. Are you ready to take the next step? Discover a career in banking at Fifth Third Bank.
This is a Principal Engineer role on the Data Security team in the Information Security organization. Ideal candidate will have hands on experience in the data security space with technologies like encryption, tokenization, certificate management, AWS/cloud and will have ability to coach, mentor junior team members while delivering results.
GENERAL FUNCTION:
The Information Security Engineer (ISE) will be responsible for defining, delivering and supporting the enterprise security tools and architecture developed in collaboration with the IT Engineering team. The ISE will also participate in a diverse variety of IS projects and support the ongoing operations of the Information Security department.
Responsible and accountable for risk by openly exchanging ideas and opinions, elevating concerns, and personally following policies and procedures as defined. Accountable for always doing the right thing for customers and colleagues, and ensures that actions and behaviors drive a positive customer experience. While operating within the Bank's risk appetite, achieves results by consistently identifying, assessing, managing, monitoring, and reporting risks of all types.
ESSENTIAL DUTIES & RESPONSIBILITIES:
- Mentor more junior members of the team.
- Responsibility for the Venafi/Cyberark (Trust Protection Platform) and it's associated connectors to other tools and platforms.
- Define security requirements for the implementation of new applications and projects.
- Team member on the Encryption Management Program.
- Provide SME guidance on the Encryption Management Program.
- Serve as a data security engineer/consultant on projects.
- Participate in conducting security research on threats and remediation techniques/ technology, make recommendations to the IS/IT teams and oversee their implementation.
- Support the Bank's operational information security responsibilities, including the development maintenance of standards, procedures, and guidelines necessary to satisfy the Information Security department's operations.
- Assist in conducting risk assessments to evaluate the effectiveness of existing controls and determine the impact of proposed changes to business processes, applications and systems.
- Provide technical support to regulatory agencies, external auditors, and internal auditors, as required, to respond to audits and examinations of the Bank's control environment.
- Seeking and maintaining knowledge (cross/up skill) of current and upcoming IT security technologies.
- Awareness of latest and common security threats.
- Knowledge of virtualization technologies.
SUPERVISORY RESPONSIBILITIES: None.
MINIMUM KNOWLEDGE, SKILLS & ABILITIES REQUIRED:
- Expertise in encryption, cryptography, and certificate management
- Hands on experience with Venafi/Cyberark
- Working knowledge of AWS and cloud security
- Familiarity with Digicert, Sectigo, and various certificate types
- Ability to coach/mentor junior team members
- Ability to communicate well with peers/leaders/junior members/cross functional teams.
- IT Security experience required.
- Bachelor's degree in Computer Science/Information Systems or equivalent combination of education and experience. Master's degree a plus.
- Industry Standard Certifications such as, but not limited to: CompTIA A+, CompTIA Network +, CompTIA Security +, ISC2 CISSP, and EWS are preferred.
- Must be able to communicate ideas both verbally and in writing to management, business and IT sponsors, and technical resources in language that is appropriate for each group.
- Eight+ years of IT work experience relevant to the position.
- Experience working with and supporting Unix/Linux and Windows systems.
- Solid conceptual understanding of distributed computing principles.
- Working knowledge of application and data security concepts, best practices, and common vulnerabilities.
- Financial industry experience is a plus.
- Excellent ability to diagnose and troubleshoot accessibility issues.
Principal Information Security Engineer (Remote)Total Base Pay Range 96,500.00 - 207,500.00 USD AnnualAt Fifth Third, we understand the importance of recognizing our employees for the role they play in improving the lives of our customers, communities and each other. Our Total Rewards include comprehensive benefits and differentiated compensation offerings to give each employee the opportunity to be their best every day.
The base salary for this position is reflective of the range of salary levels for all roles within this pay grade across the U.S. Individual salaries within this range will vary based on factors such as role, relevant skillset, relevant experience, education and geographic location. In addition to the base salary, this role is eligible to participate in an incentive compensation plan, with any such payment based upon company, line of business and/or individual performance.
Our extensive benefits programs are designed to support the individual needs of our employees and their families, encompassing physical, financial, emotional and social well-being. You can learn more about those programs on our 53.com Careers page at: or by consulting with your talent acquisition partner.
LOCATION -- Virtual, Ohio 00000Attention search firms and staffing agencies: do not submit unsolicited resumes for this posting. Fifth Third does not accept resumes from any agency that does not have an active agreement with Fifth Third. Any unsolicited resumes – no matter how they are submitted – will be considered the property of Fifth Third and Fifth Third will not be responsible for any associated fee.
Fifth Third Bank, National Association is proud to have an engaged and inclusive culture and to promote and ensure equal employment opportunity in all employment decisions regardless of race, color, gender, national origin, religion, age, disability, sexual orientation, gender identity, military status, veteran status or any other legally protected status.
Originally posted on Himalayas