Cyber Security Engineer

3 weeks ago


New York, United States Saxon Global Full time

FULL TIME POSITION:

Title-Cyber Security Engineer/NIST Title Client - Peoples Bank - Location-Hybrid/Midtown, New York City - salary$ 145K Salary Target -Visa:USC,GC,GC-EAD

**We need a senior (7+ Years) Cyber Security Engineer with great experience working with Cyber Security and Information Risk management with Strong understanding and hands on implementation experience with SANS/CIS Top 20, FFIEC, NIST CSF, 800-53, ISO27001 controls. Candidates must have certifications and the more the better( - CISSP, CISM, CCSP, OSCP, GIAC GCIH, GCTIA, GDSA or equivalent, or relevant AWS or Azure certification). Candidates should have great experience working with Strong understanding and hand-on experience of cloud concepts and components as they relate to O365/Azure, DevOps, Candidates must me local to the New York or New Jersey area and commute into the city two times a week in Midtown, NYC. NO RELOCATION CONSIDERED

Candidates Must Have:

1. Cyber Security/ Information Risk management

2. Strong understanding and hands on implementation experience with SANS/CIS Top 20, FFIEC, NIST CSF, 800-53, ISO27001 controls.

3. Azure/DevOps/O365

4. Certifications

Job Description:

  • The Cyber Security & Information Risk Engineer will be responsible for ensuring that Information Security systems and cloud services are configured, deployed, and maintained in accordance with SMBC's polices and standards. This position requires participation in technical research and development to enable continuing innovation for Cyber Security and Information Risk management. Strong understanding and hands on implementation experience with SANS/CIS Top 20, FFIEC, NIST CSF, 800-53, ISO27001 controls.
  • Focuses on hands on engineering and architecting cybersecurity solutions using industry's best practices to protect the firm from various threat actors.
  • Performs as the Subject Matter expert focused in multiple technologies within the Security arena (IAM, Cloud Security, Data Security, Network Security, Encryption, Privileged Access Management, Federation etc.).
  • Works with cloud technologies including Amazon Web Services and Azure, including the deployment of security groups, VPC networks, Certificate Management Systems and Key Management Systems.
  • Works with DevOps practices and use of Terraform or CloudFormation to deploy services and infrastructure, including Docker and Kubernetes.
  • Provides technical guidance and security reviews / assessments on architecture for new applications in AWS and Azure.
  • Develops cloud security policies, standards and procedures.
  • Coordinates and performs security audits and vulnerability assessments to assess internal security procedures and compliance requirements related to cloud environments.
  • Work with relevant internal IT Application, Infrastructure, Network and Support teams to ensure that security controls are implemented at all significant layers, test those controls and perform gap analysis to find areas of improvement.
  • Strong understanding and hands on implementation experience with SANS/CIS Top 20, FFIEC, NIST CSF, 800-53, ISO27001 controls.
  • Strong Incident Response skillset using MITRE ATT&CK and Cyber Kill Chain frameworks. Being able to conduct threat modeling in order to determine major threats facing the firm.
  • Good understanding of Zero Trust principles.
  • Supporting offensive architecture analysis and design of defense-in-depth solutions
Participate in the development of the security roadmap and communicate the Technology Security vision to senior management and technical departments.
  • 5+ Years of hands-on architecting, implementation and design experience required, designing globally scalable security solutions using latest cloud technologies and platforms.
  • Strong understanding and hand-on experience of cloud concepts and components as they relate to O365/Azure, AWS, and/or GCP.
  • 3+ years of hands-on experience with IAM permissions, SSO, Managed AD including permissions access to S3 buckets, IAM roles, executing Lambda functions, AWS Config, Cloudtrail, KMS, Cert Manager etc.
  • Experience with Microsoft Defender for Cloud, Azure Kye Vault, Azure Monitor, Sentinel, RBAC, Azure AD, Azure MFA, conditional access, Federation is highly desired.
  • Cloud formation and/or terraform experience required
  • Good understanding of DevSecOps concepts and associated implementations
  • Good understanding of CI/CD pipeline concepts as it relates to security
  • Working knowledge of common and industry standard cloud-native/cloud-friendly authentication mechanisms (SAML, OAuth, OpenID).
  • 2+ years of experience in container solution (Kubernetes and Docker).
  • Experience with API Security highly desired.
  • Deep understanding of Unix, Linux, Windows Security principles and Microsoft Active Directory
  • Python, Bash or PowerShell scripting experience required.
  • Strong knowledge of enterprise Information Security pillars (Perimeter security, Identity Management and Governance, Privileged Account Management, Compliance, Penetration testing, Encryption, Cloud Security, Incident Response, Vulnerability Management)
  • Deep packet analysis experience required using wireshark/tcpdump.
  • Incident Response experience highly desired as it relates to Cloud environments.
  • Advanced experience in process documentation, flow charting and re-engineering.
  • Understanding of OWASP Top 10 highly desired.
  • Good understanding of Zero Trust principles highly desired.
  • Performing gap analysis within different environments coupled with an in depth understanding of regulatory guidelines as well as standards and best practices related to CIS Top 20, ISO 27001, FFIEC CAT and NIST CSF frameworks.
  • Bachelor's degree in Information Security, Computer Science or related field required
  • Good influencing, relationship and stakeholder management skills
  • One of the following certifications is required - CISSP, CISM, CCSP, OSCP, GIAC GCIH, GCTIA, GDSA or equivalent, or relevant AWS or Azure certification(s).
  • Weekend and night work may be needed at times based on project, support, and business needs.


  • Buffalo, New York, United States Two95 International Inc. Full time

    Monitor and defend systems against unauthorized access, modification and destruction. Identify suspicious threats and activities Identify and spotlight vulnerabilities in networks, programs and applications. Correct problems and prevent security breaches. Design security elements to mitigate emerging threats Design, build, implement and...

  • Software Engineer

    5 hours ago


    New York, United States P. Chappel Associates Inc Full time

    Software application and library development in C, Cilk, Python and other languages for cyber security related unique high performance computer architecture. Position is based in New York, NY. You will be working with a team of the leading computer architects in the industry and contribute to pushing the forefront of computing. Software engineer positions...

  • Security Engineer

    3 hours ago


    New York, United States CACI International Full time

    CACI is seeking a Cyber Security Engineer to support our Makalu contract. If you are interested and passionate about working as part of a modern, fast-paced agile software development team, then this opportunity is for you! On team Makalu, cyber security engineers are an integral part of the development team. Cyber security engineers are expected to be...


  • New York, United States Saxon Global Full time

    Client: Con Edison Cyber Security Engineer Location: 4 Irving place, NY, NY (HYBRID) Duration: 12+ months Rate: $80.00/hr DOE C2C OPEN TO GC/USC (they must be local) AND H1B (Must be willing to relocate) Interview Process: Video (Teams) Interview TECHNICAL SKILLS Must Have: Experience deploying & configuring Cyberark Privledged Access Management ...


  • New York, United States Itech Edge Llc Full time

    Job DescriptionJob Description Find attached the JD for Cyber Security Architect Role. Please note that candidates must be a US Citizen Please fill out the attached Skillset matrix for the candidate you are submitting along with the resume for quicker response. Cyber Security Architect Job details Requirement Candidate must be a US Citizen Schedule 8 hour...


  • Englewood Cliffs, New Jersey, United States NBCUniversal Full time

    Job Description We are looking for a Staff Cyber Security Engineer to be part of our next generation of applications and workloads using a rapidly changing landscape of emerging technologies. The Staff Cyber Security Engineer will partner with the various NBCUniversal businesses, enterprise IT, and Cyber Security organization to ensure technology is...


  • New York, United States PamTen Full time

    Our client is seeking a Cyber Security Assessment and Migration Engineer for a one year contract. This is a remote role, but the consultant must reside within the United States and be willing to work East Coast business hours. This opportunity has the potential to be contract to hire for the right candidate. • Consolidate the ENS and Rapid7 capability...


  • New York, United States Cat America Full time

    Job DescriptionJob DescriptionTECHNICAL SKILLS Must Have:Experience deploying & configuring Cyberark Privledged Access ManagementRelevant working experience in a cybersecurity team or performing cybersecurity functionsJOB DESCRIPTIONSeeking a highly motivated candidate who demonstrates strong commitment to operational excellence, possesses technical...


  • New York, United States ShiftCode Analytics Full time

    Interview : Video Visa : All apart from h1b and cpt This is onsite from day-1 Part time (15-20 hours per week) Description : VPN access and troubleshooting GRC Anti-virus Anti-malware Monitor, determine, and react to risks Update company cyber security training and policies Cyber Security certifications and/or degree required


  • New York County, New York, United States Bank of China Limited, New York Branch Full time

    Introduction: Established in 1912, Bank of China is one of the largest banks in the world, with over $3 trillion in assets and a footprint that spans more than 60 countries and regions. Our long-term outlook, institutional weight and global breadth provide our clients with a stable and reliable financial partner, whether in Corporate or Personal Banking or...


  • New London, United States Indotronix Avani Group Full time

    Job Title – Cyber Security Information Security ProfessionalJob Location – New London or Groton CTDuration: 6+ months contract to hireDescription:Required: CISSP, CISM, DOD background and knowledge with vendors, and suppliers. Interfacing with CISO and CxO levelsJob Description: Must be able to be on-site daily, at either New London and Groton CT. This...


  • New London, United States Indotronix Avani Group Full time

    Job Title – Cyber Security Information Security ProfessionalJob Location – New London or Groton CTDuration: 6+ months contract to hireDescription:Required: CISSP, CISM, DOD background and knowledge with vendors, and suppliers. Interfacing with CISO and CxO levelsJob Description: Must be able to be on-site daily, at either New London and Groton CT. This...


  • New York, United States Citi Full time

    Citi, the leading global bank, has approximately 200 million customer accounts and does business in more than 160 countries and jurisdictions. Citi provides consumers, corporations, governments, and institutions with a broad range of financial products and services, including consumer banking and credit, corporate and investment banking, securities...


  • New York, United States Aptonet Full time

    Job Title: Cyber Security Information Security Professional (W2 Only) Location: Groton, CT * Must be able to be on-site daily, at either New London and Groton CT Duration: 12 month extendable Contract Job Description Required: CISSP, CISM, DOD background and knowledge with vendors, and suppliers. Interfacing with CISO and CxO levels Key...


  • New York, United States Solarus Technologies Full time

    Are you someone who thrives on being proactive and detail-oriented with a passion for cybersecurity? If so, we’ve got an exciting opportunity for you to join us as a Level 1 Cybersecurity Analyst! Picture yourself diving into the world of monitoring, analyzing, and responding to security incidents and threats. We’re looking for someone who not only has a...


  • New Orleans, United States Fifth Circuit Court of Appeals Full time

    Main content Job Details for Cyber Security Specialist Court Name/Organization: Fifth Circuit Court of Appeals Overview of the Position: The Office of the Circuit Executive for the Fifth Circuit is accepting applications for a Cyber Security Specialist. The Fifth Circuit is composed of the federal courts and federal public defender organizations in...


  • West New York, United States UBS Full time

    Your role Do you thrive in a fast paced, dynamic environment that helps protect firm and client data? Are you someone who can make the right call in challenging situations? Are you a shrewd evaluator of the risks in cyber and data protection? Can you navigate the big picture and dive into the detail when required? We are looking for a Cyber and Information...


  • New York, United States Whiteman Osterman & Hanna LLP Full time

    Partner or Of Counsel Lateral OpportunityWhiteman Osterman & Hanna is seeking a partner-level attorney with at least 8 years of experience and established, portable business in Data Privacy and Cyber Security to lead its Privacy, Cybersecurity and Information Management practice. Experience in negotiating and drafting contracts involving privacy,...


  • New Castle, United States Delaware River and Bay Authority Full time

    **CYBER SECURITY SPECIALIST** **Location: Delaware Memorial Bridge, New Castle, DE** **$94,039 to $113,300 annualized (Grade H)** The Delaware River and Bay Authority is seeking a Cyber Security Specialist to support our administration office located in New Castle, DE. This is a unionized position that offers the opportunity to join a well-established...


  • New York, United States Claroty Full time

    Claroty empowers the world's largest enterprises to secure their cyber-physical systems across industrial (OT), healthcare (IoMT), and enterprise (IoT) environments: the Extended Internet of Things (XIoT). The Claroty Platform integrates with customers’ existing infrastructure to provide a full range of controls for visibility, risk and vulnerability...