Security Engineer - Cloud

$150,000 - $190,000/Yr

Costco - Chicago, IL

posted about 2 months ago

Full-time - Mid Level
Chicago, IL
10,001+ employees
General Merchandise Retailers

About the position

The Security Engineer - Cloud position at Costco involves developing, designing, implementing, and integrating security systems to protect enterprise assets from cyber threats. The role focuses on enhancing security capabilities for Costco's cloud properties, ensuring compliance with security standards, and collaborating with various teams to build secure solutions that adapt to changing business needs.

Responsibilities

  • Provide security and technical expertise to support the development of security objects to satisfy business requirements.
  • Analyze and administer security policies to control physical and virtual system access.
  • Identify and investigate security issues and develop solutions that address compliance requirements.
  • Develop and implement mechanisms to detect security incidents to enhance compliance and support security standards.
  • Assess business role requirements and support authorizations.
  • Validate system configurations to ensure the safety of information systems assets.
  • Implement best practices in information systems security standards and practices.
  • Design and coordinate activities with other departments such as loss prevention and legal.
  • Identify security gaps and develop remediation strategies.
  • Develop and execute security controls and countermeasures to prevent data infiltrations.
  • Determine strategy and protocol for network behavior and analysis techniques.
  • Identify and resolve problems proactively, developing and implementing solutions.
  • Provide subject matter expertise in systems security policies and technologies.
  • Configure, deploy, maintain, and support security tools.
  • Protect confidentiality, integrity, and availability of information.
  • Create dashboards, configure alerts, and monitor security tools/apps.
  • Identify opportunities for process improvement and increase effectiveness.
  • Document security events and incident handling procedures into Playbooks.
  • Triage, prioritize, investigate, and coordinate security events and incident handling activities.
  • Collaborate with business partners to build secure solutions that protect data.
  • Work with internal and external auditors to ensure compliance.
  • Design, configure, and maintain various degrees of security.
  • Partner with other Information Security groups to conduct security risk assessments.

Requirements

  • 2+ years' experience in Security Engineering.
  • Experience in offensive security roles, such as penetration testing or ethical hacking.
  • Experience with Security Engineering of sites hosted in Public Cloud (Google, Azure).
  • Experience working with WAFs and CDNs such as Akamai or Fastly.
  • Proficiency in scripting and programming languages (e.g. Python, JS, Java, SQL).
  • Strong understanding of operating systems, network protocols, and web application security.
  • Extensive experience with security tools and frameworks (e.g. Kasada, Microsoft DFP, Bloodhound, Cobalt Strike).
  • Vast experience in performing code review to identify vulnerabilities.
  • A passion for cybersecurity and commitment to staying current with emerging threats.
  • Recommended Bachelor's/Master's degree or equivalent experience in Computer Science, Information Security, or a related field.
  • One or more professional network and security certifications such as Security+, Network+, CCNA, GSEC, CISA or CISSP.
  • Experience performing computer forensics.
  • Familiarity with ITILv2/v3 processes.
  • Familiarity with Regulatory Compliance and industry standards, such as HIPAA, SOX, and PCI.
  • Familiarity in a DevOps or DevSecOps environment.

Nice-to-haves

  • Bachelor's or Master's degree in Computer Science, Information Security, or a related field.
  • Professional network and security certifications such as Security+, Network+, CCNA, GSEC, CISA or CISSP.

Benefits

  • 401(k)
  • AD&D insurance
  • Dental insurance
  • Dependent care reimbursement
  • Disability insurance
  • Employee stock purchase plan
  • Health insurance
  • Paid time off
  • Short-term disability and long-term disability insurance
  • Life insurance
  • Health care reimbursement account
  • Dependent care assistance plan
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service