Paul Hastings & Company Limited - Washington, DC
posted 4 months ago
Paul Hastings is a leading international law firm that provides innovative legal solutions to many of the world's top financial institutions and Fortune Global 500 companies. With a strong presence throughout Asia, Europe, Latin America, and the U.S., we have the global reach and extensive capabilities to provide personalized service wherever our clients' needs take us. As one of the world's leading law firms, we seek dynamic individuals who share our commitment to service, innovation, and professional growth. We have an opening for a Senior Security Engineer (Infrastructure/Network) in our Information Security Department. The Senior Security Engineer (Infrastructure/Network) will join the Information Security team and will be responsible for protecting system boundaries, keeping computer systems and network devices hardened against attacks, and securing highly sensitive data. Qualified candidates will have a background in cybersecurity or systems engineering. In this capacity, the Senior Security Engineer (Infrastructure/Network) will provide guidance on how servers, infrastructure, and networking technologies are managed and hardened against security threats and vulnerabilities. They will identify and implement ways to harden systems and reduce the attack surface, secure enterprise information by determining security requirements, planning, implementing, and testing security systems, and preparing security standards, policies, and procedures. The role also involves engineering, implementing, and monitoring security measures for the protection of computer systems, networks, and information. The Senior Security Engineer will integrate security tasks and activities into system development methodologies, identify and verify security requirements throughout the process, and work closely with IT and business teams to drive information security technology strategy and security architecture principles through the system development lifecycle (SDLC). They will consult on solution architecture for projects to ensure compliance with the security technical architecture, prepare and document secure system development standard operating procedures and protocols, and drive and conduct system architectural reviews, secure design reviews, risk assessments, and threat assessments. Additionally, the Senior Security Engineer will perform vendor technical solution acceptance verification and validation, develop technical solutions and new security tools to help mitigate security vulnerabilities, assess gaps in existing policy, and propose amendments to existing policy or new policy to address these gaps. They will participate in the development and implementation of enterprise-level technical standards and procedural directives, write comprehensive reports including assessment-based findings, and coordinate with system owners to resolve security issues through the system lifecycle. The role also includes providing guidance and support to self-testing, security control assessment, preparation of remediation plans, and development of continuous monitoring plans.