Bill International Co.,Ltd. - San Jose, CA

posted 3 months ago

Full-time - Senior
Hybrid - San Jose, CA
Professional, Scientific, and Technical Services

About the position

As a Senior Staff/Staff Cloud Security Engineer at BILL, you will play a pivotal role in safeguarding the financial automation solutions we provide to small and mid-size businesses. BILL is dedicated to automating the future of finance, and as part of our Information Security department, you will be instrumental in ensuring the security of our cloud and infrastructure environments. Your expertise will help us identify, track, and mitigate security vulnerabilities, working closely with engineering and technical operations teams. You will also collaborate with the Security Operations Center and Threat Intelligence and Detection Engineering to address security-related engineering tasks. In this role, you will be expected to design, implement, and manage security solutions that align with industry standards and best practices. You will conduct security assessments, gap analyses, vulnerability assessments, and penetration testing to identify and mitigate security risks. Additionally, you will develop and maintain security policies, procedures, and guidelines for cloud and infrastructure security, ensuring that security is integrated into the development and deployment processes. Your leadership will be crucial in mentoring junior security engineers and fostering a culture of security awareness within the organization. Staying up-to-date with the latest security trends, threats, and technologies will be essential for continuously improving our security posture. You will also support the response to security incidents, providing expert analysis and recommendations for remediation. Your ability to communicate effectively with stakeholders and guide team members in line with BILL's security culture and business priorities will be key to your success in this role.

Responsibilities

  • Design, implement, and manage security solutions for cloud and infrastructure environments with industry standards and best practices.
  • Conduct security assessments, gap analysis, vulnerability assessments, and penetration testing to identify and mitigate security risks.
  • Develop and maintain security policies, procedures, and guidelines for cloud and infrastructure security.
  • Collaborate with cross-functional teams to integrate security into the development and deployment processes.
  • Support in the response to security incidents, providing expert analysis and recommendations for remediation.
  • Stay up-to-date with the latest security trends, threats, and technologies to continuously improve our security posture.
  • Provide mentorship and guidance to junior security engineers, fostering a culture of security awareness and best practices.
  • Work closely with the IT and Technical Operations teams to ensure secure configuration and management of cloud and infrastructure resources.
  • Develop and deliver security training and awareness programs for employees and stakeholders.
  • Participate in security audits and assessments, providing detailed reports and recommendations for improvement.

Requirements

  • Bachelor's degree in Computer Science, Information Security, or a related field; advanced degree preferred.
  • Minimum of 7-10 years of experience in information security, with a focus on cloud and infrastructure security.
  • Strong knowledge of cloud platforms (e.g., AWS, Azure, Google Cloud) and their security features.
  • Experience with infrastructure-as-code (IaC) tools such as Terraform, CloudFormation, or Ansible.
  • Proficiency in security assessment tools and techniques, including vulnerability scanning, penetration testing, and threat modeling.
  • In-depth understanding of network security, encryption, identity and access management (IAM), and security monitoring.
  • Relevant certifications such as CISSP, CISM, CEH, or cloud-specific certifications (e.g., AWS Certified Security Specialty) are highly desirable.
  • Excellent problem-solving skills and the ability to work under pressure in a fast-paced environment.
  • Strong communication and interpersonal skills, with the ability to effectively convey complex security concepts to technical and non-technical stakeholders.
  • Proven track record of leading security initiatives and projects to successful completion.

Nice-to-haves

  • Advanced degree in a related field.
  • Experience with additional cloud platforms beyond the primary ones mentioned.
  • Familiarity with compliance frameworks such as PCI-DSS, HIPAA, or GDPR.

Benefits

  • 100% paid employee health, dental, and vision plans (choose HMO, PPO, or HDHP)
  • HSA & FSA accounts
  • Life Insurance, Long & Short-term disability coverage
  • Employee Assistance Program (EAP)
  • 11+ Observed holidays and wellness days and flexible time off
  • Employee Stock Purchase Program with employee discounts
  • Wellness & Fitness initiatives
  • Employee recognition and referral programs
  • And much more
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service