Spectrum - Washington, DC

posted 5 months ago

Full-time - Senior
Washington, DC
10,001+ employees
Telecommunications

About the position

The Principal Cyber Security Engineer for the Information Security Cyber Threat Intelligence team will provide strategic consultation and develop technical solutions to address complex information security challenges. This role involves profiling threats and overseeing the development, design, and management of ongoing initiatives aimed at reducing risks associated with a rapidly changing cyber landscape. The engineer will leverage a deep understanding of the cyber security threats faced by the organization and will be responsible for collaborating with both internal and external departments within Information Technology, as well as business stakeholders, to proactively identify security deficiencies and emerging threats across all IT and Information Security controls on a continual basis. In addition to providing technical guidance and solutions to meet various regulatory monitoring requirements, the Principal Cyber Security Engineer will serve as a subject matter expert for initiatives and will drive recommendations for monitoring, investigating, and mitigating risks posed by cybercriminals and advanced persistent threats. This position will also act as an escalation point in the absence of leadership for team members and inquiries from external departments. The engineer will actively support efforts to enhance the customer experience and will establish strategic consultations to automate technical solutions that continuously assess the organization's security posture. The role includes leading the design, development, and implementation of security controls to ensure adherence to IT Security standards. The engineer will present complex security requirements to executive management, IT staff, and non-technical team members to foster understanding and adoption of sound security practices. They will also develop in-depth technical processes for complex workflows to ensure continuous monitoring of all IT systems from a security perspective, and will influence and recommend technical guidance to support compliance with regulatory requirements. Furthermore, the engineer will assign work to the Cybersecurity Engineering team, provide professional development, and present root cause and trending analysis reports to senior leadership to drive awareness and continuous improvement initiatives.

Responsibilities

  • Provide strategic consultation and develop technical solutions to solve complex information security challenges.
  • Profile threats and oversee the development, design, and management of initiatives to reduce cyber risks.
  • Collaborate with internal and external departments to identify security deficiencies and emerging threats.
  • Provide technical guidance and solutions to meet regulatory monitoring requirements.
  • Serve as a subject matter expert for initiatives and drive recommendations for monitoring and investigating threats.
  • Act as an escalation point in the absence of leadership for team members and external inquiries.
  • Establish strategic consultations to automate technical solutions for assessing security posture.
  • Lead the design, development, and implementation of security controls to support IT Security adherence.
  • Present complex security requirements to executive management and non-technical audiences.
  • Develop technical processes for continuous monitoring of IT systems from a security standpoint.
  • Influence and recommend technical guidance for regulatory compliance requirements.
  • Assign work to the Cybersecurity Engineering team and provide professional development.
  • Develop and present root cause and trending analysis reports to senior leadership.
  • Liaise with business teams to align operational requirements with IT Security standards.
  • Partner with stakeholders to mitigate security risks through continuous monitoring and metrics development.
  • Organize project and communication plans and provide updates to relevant teams.
  • Interpret and maintain IT Security standards and provide recommendations for process improvement.
  • Maintain expertise in current cybersecurity threats and respond to assessments of security controls.
  • Research emerging risks and threats to present cohesive strategies to leadership.
  • Facilitate performance improvement sessions and recommend process enhancements.

Requirements

  • 8+ years of experience in IT Security and/or Corporate Risk work.
  • 4+ years of experience in Information Assurance, Risk, and Cybersecurity Program governance.
  • Bachelor's degree in Management Information Systems, Computer Science, Cybersecurity, or a related discipline, or equivalent work experience.
  • Expert knowledge of security frameworks such as PCI, SOX, HIPAA, NIST 800-53.
  • Expert knowledge of security system configuration and data visualization.
  • Expert knowledge of File Integrity Monitoring, Firewall Review, Data Loss Prevention, and Patch Management methodologies.
  • Expert knowledge of operating systems, IP networks, and database/application functionality.
  • Effective analytical and critical thinking skills to identify patterns of non-compliance.
  • Effective organization and time management skills.

Nice-to-haves

  • CISSP, CISM, or CISA certification or in the process of obtaining one.
  • Experience with Python, PowerShell, SQL, Tableau, Splunk, and various EDR/XDR solutions.
  • Experience working with Threat Intelligence vendors and platforms.
  • Experience in threat analysis and reporting.
  • Experience investigating cybercriminal organizations and in digital forensics.
  • Experience in analysis of cloud services and their attack surface.
  • Experience in written and verbal briefings to large audiences.
  • Law enforcement experience, preferably with a cyber division.

Benefits

  • Comprehensive pay and benefits package that rewards employees for their contributions.
  • Support for all aspects of employee well-being.
  • Opportunities for career growth and development.
  • Access to innovative tools and technology.
  • Supportive and inclusive workplace culture.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service