Senior Principal Engineer leading information security initiatives for Cencora, safeguarding infrastructure and intellectual property. Advise leadership on risk management and compliance, driving security policies and standards.
Responsibilities
Analyze trends, news, and changes in the threat and compliance landscape; advise leadership and execute plans for risk mitigation and compliance.
Lead and coordinate responses to information system security incidents, including investigation, countermeasures, and recovery; engage with third-party responders.
Recommend and oversee implementation of security controls throughout the acquisition, development, and change management lifecycle of information systems.
Provide technical leadership on large-scale, complex, and highly analytical security projects.
Plan and lead upgrades to security tools and measures to protect information systems and networks.
Develop methodologies for monitoring and responding to security events; lead remediation efforts for cybersecurity incidents.
Guide network and system administrators in maintaining infrastructure security, improving performance, and automating administration from a security perspective.
Mentor and coach ISO Engineers, providing technical guidance and oversight.
Ensure service-level agreements (SLAs) are maintained to uphold security controls.
Lead the implementation of enterprise-wide security policies, procedures, and standards across diverse platforms and applications.
Interface with business and IT leaders to communicate security issues and respond to requests for information and support.
Refine and enforce security policies and standards to meet internal and external compliance requirements.
Collaborate with senior technical executives and IT teams to design and implement security systems that protect both physical and intangible assets.
Review technical and functional design documents; build, maintain, and implement cybersecurity, data security, and cloud security solutions.
Advise business and technical teams on the potential impacts of changes to the security environment.
Deliver security briefings to inform leadership of critical issues affecting the enterprise.
Analyze and generate insights from security metrics and KPIs for executive-level reporting.
Responds to security alerts and escalates critical incidents to correct support teams and participates in incident response exercises.
Serves as a subject matter expert (SME) for product research and development teams, working closely with software engineers, product management and development, and divisional and corporate information systems.
Requirements
Bachelor’s Degree in Computer Science, Information Technology or any other related discipline or equivalent related experience.
Eight (8) or more years of directly-related or relevant experience, preferably in information security.
Azure Security Engineer Certification
Certified Cloud Security Professional (CCSP)
Certification in Information Security Strategy Management (CISM)
Certified Information Systems Security Professional (CISSP)
CompTIA Security + Certification
Systems Security Certified Practitioner (SSCP)
Knowledge of Microsoft Office Suite
Programming and Development Languages - JavaScript, HTML/CSS, Python, SQL
Senior Cloud Security Engineer securing public cloud platforms and services in the financial industry. Collaborating with teams to enhance security posture and ensure compliance in cloud environments.
Cybersecurity Metrics and Reporting Lead overseeing development of security metrics and dashboards. Collaborating with teams to improve cybersecurity program effectiveness and compliance tracking.
Senior Developer in Defensive Security for Clio, a leader in legal AI technology. Join a team to proactively tackle application security vulnerabilities and enhance security practices.
Intern role in emerging network systems at KBR Mission Technical Solutions. Focused on network interconnection problems and quality of service metrics in a collaborative environment.
Director of Product Security leading cybersecurity initiatives for medical devices at LivaNova. Ensuring patient safety and compliance with regulatory demands across product lifecycle.
Security Engineer driving modernization and improvements in KPMG's cybersecurity services. Engaging in technology evaluation, process innovation, and stakeholder communication.
Identity and Access Security Analyst at HII’s Newport News Shipbuilding focusing on SAP Security skills. Designing secure operating systems and conducting security assessments.
Senior Security Specialist ensuring compliance and security measures at Disney. Supporting audit processes and collaborating on risk assessments to enhance cybersecurity.
Risk Analyst supporting Keyloop’s Security Governance by managing information security risks. Identifying and monitoring risks while ensuring compliance with regulatory standards.
Cloud Security Engineer responsible for designing and implementing security controls for cloud environments at Keyloop. Ensuring secure adoption and compliance while working with platform and engineering teams.