Paul Hastings & Company Limited - Washington, DC

posted 4 months ago

Full-time - Senior
Washington, DC
Professional, Scientific, and Technical Services

About the position

Paul Hastings is a leading international law firm that provides innovative legal solutions to many of the world's top financial institutions and Fortune Global 500 companies. With a strong presence throughout Asia, Europe, Latin America, and the U.S., we have the global reach and extensive capabilities to provide personalized service wherever our clients' needs take us. As one of the world's leading law firms, we seek dynamic individuals who share our commitment to service, innovation, and professional growth. We have an opening for a Senior Security Engineer (Infrastructure/Network) in our Information Security Department. The Senior Security Engineer (Infrastructure/Network) will join the Information Security team and will be responsible for protecting system boundaries, keeping computer systems and network devices hardened against attacks, and securing highly sensitive data. Qualified candidates will have a background in cybersecurity or systems engineering. In this capacity, the Senior Security Engineer (Infrastructure/Network) will provide guidance on how servers, infrastructure, and networking technologies are managed and hardened against security threats and vulnerabilities. They will identify and implement ways to harden systems and reduce the attack surface, secure enterprise information by determining security requirements, planning, implementing, and testing security systems, and preparing security standards, policies, and procedures. The role also involves engineering, implementing, and monitoring security measures for the protection of computer systems, networks, and information. The Senior Security Engineer will integrate security tasks and activities into system development methodologies, identify and verify security requirements throughout the process, and work closely with IT and business teams to drive information security technology strategy and security architecture principles through the system development lifecycle (SDLC). They will consult on solution architecture for projects to ensure compliance with the security technical architecture, prepare and document secure system development standard operating procedures and protocols, and drive and conduct system architectural reviews, secure design reviews, risk assessments, and threat assessments. Additionally, the Senior Security Engineer will perform vendor technical solution acceptance verification and validation, develop technical solutions and new security tools to help mitigate security vulnerabilities, assess gaps in existing policy, and propose amendments to existing policy or new policy to address these gaps. They will participate in the development and implementation of enterprise-level technical standards and procedural directives, write comprehensive reports including assessment-based findings, and coordinate with system owners to resolve security issues through the system lifecycle. The role also includes providing guidance and support to self-testing, security control assessment, preparation of remediation plans, and development of continuous monitoring plans.

Responsibilities

  • Provide guidance on how servers, infrastructure, and networking technologies are managed and hardened against security threats and vulnerabilities.
  • Identify and implement ways to harden systems and reduce the attack surface.
  • Secure enterprise information by determining security requirements; planning, implementing, and testing security systems; preparing security standards, policies, and procedures.
  • Engineer, implement, and monitor security measures for the protection of computer systems, network, and information.
  • Integrate security tasks and activities into system development methodologies (e.g. planning, design, implementation, operations, maintenance, and disposal).
  • Identify and verify security requirements are met throughout the process.
  • Work closely cross functionally with IT and business teams in driving information security technology strategy and security architecture principles through the system development lifecycle (SDLC).
  • Consult on solution architecture for projects to ensure compliance with the security technical architecture.
  • Prepare and document secure system development standard operating procedures and protocols.
  • Drive and conduct system architectural reviews, secure design reviews, risk assessments and threat assessments.
  • Perform vendor technical solution acceptance verification and validation.
  • Develop technical solutions and new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
  • Assess gaps in existing policy and propose amendments to existing policy or new policy to address these gaps.
  • Participate in the development and implementation of enterprise-level technical standards and procedural directives and other guidance materials.
  • Write comprehensive reports including assessment-based findings, outcomes and propositions for further system security enhancement.
  • Participate in the development, implementation and review of security controls for the systems under their purview.
  • Coordinate with system owners to resolve security issues through system lifecycle.
  • Provide guidance and support to self-testing, security control assessment, preparation of remediation plans, and development of continuous monitoring plans.

Requirements

  • 12 years of experience in information technology or security engineering;
  • BS degree in Computer Science or related field;
  • Strong communication skills with ability to articulate and translate security and risk management terminology in business terms;
  • Familiarity with project management methodologies;
  • Hands on experience in security systems, including vulnerability management, identity and access management, security risk assessments, application testing, etc.;
  • Strong track record of implementing security architecture for complex solutions and ability to deliver results through partnering with stakeholders in IT and the business;
  • Working knowledge of IT processes (i.e., ITIL) including incident, problem, defect, change and release management;
  • Experience with secure architecture principles, secure SDLC, security system integration and configurations, and troubleshooting.

Nice-to-haves

  • Related certifications preferred;
  • Demonstrate integrity, accountability, respect and commitment to the Firm;
  • Demonstrate excellence in managing all functions of the job;
  • The knowledge and skills required to perform at the highest level;
  • Demonstrate best practices in professional relationships;
  • Focus on job execution and achieving results.

Benefits

  • Medical, Dental, Vision, Life/AD&D, Long Term Care, and Short and Long Term Disability
  • Flexible Spending Account and Health Savings Account
  • Healthcare Concierge and Advocacy
  • Voluntary 401k Plan and Profit Sharing
  • 10 Paid Holidays per year and a generous PTO program
  • Family Support including Pediatric Mental Health and Parental Support, Paid Parental Leave, Fertility Benefits, and Breast Milk Shipping
  • Back-up Child Care, Elder Care, and Tutoring
  • Wellness Programs (Employee Assistance Program, Mental Health, and Well-Being Events)
  • Retirement Plan Consulting
  • Anniversary Bonus Program
  • Professional Development Programs
  • Transportation Allowance and Commuter Benefits
  • International Travel Insurance
  • Auto/Home/Legal Insurance
  • Pet Insurance
  • Employee discounts
  • And more!
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service