Senior Information Security Engineer

4 weeks ago


Seattle, Washington, United States REI Full time

Overview

REI Co-op is united around discovering, building and celebrating better ways of working in this world, all so that folks can find and pursue a love of the outdoors. When you work for the co-op, you do your best work with the support to live your best life. And you play a part in shaping the future of the outdoors, for people and our planet.

This position is responsible for maintaining the confidentiality, integrity and availability of information assets by assisting in the design, development and deployment of a broad spectrum of security services. As a senior information security engineer, you will partner with architects, business and IT teams to ensure that security is applied to the technology platforms and information within the organization in accordance with established standards and policies. Models and acts in accordance with REI's guiding values and mission.

Responsibilities and Qualifications


• Owns the development, planning and implementation of a variety of platforms including Cloud Security/CNAPP, CI/CD Security, SIEMs , IDS/IPS, firewalls, Bot Protection, WAFs, anti-malware, EDR, DDOS services, host and container configuration management, vulnerability scanning, penetration testing, , and more.


• Provides analytics and reporting from tool-based telemetry


• Builds resilient security platforms/services with strong monitoring and alerting and encouraging automation for operational processes and orchestrating workflows


• Partners with engineering, program management and operations personnel within the service delivery organization to implement changes to process and technology.


• Partners with Security Architecture to ensure platform goals and security solutions are designed to meet business strategy and needs


• Participates in the creation of roadmaps for current security capabilities


• Analyzes threats and current security controls to identify gaps in current defensive posture.


• Participates in security incident response activities.


• Ensures documentation for managed platforms/services are detailed, thorough, and kept current.


• Participates in rotating after hours on-call schedule


• Helps develop communications and actively promote related campaigns for information security awareness.


• Keeps current on organization's business practice, technology, security issues and legislation that impact the

company's security policy.


• Makes recommendations to leadership on improvements to be made to existing security controls


• Mentors junior engineers on the team.

Required Skills & Experience

  • BS or BA in Computer Science, Information Systems, Information Technology or a related field or equivalent experience

  • 3+ years' professional experience in cloud-based or online services security engineering, or service engineering.

  • Strong written and oral communication skills; can effectively communicate technical concepts

  • 1+ years' experience with at least one scripting or programming language (Python, Go, Ruby, etc.)

  • 1+ years' experience with deployment orchestration, automation, and security configuration management (Jenkins, Puppet, Chef, CloudFormation, Terraform, Ansible

  • Expert-level working knowledge and deep understanding of cyber security in at least two or more of the following disciplines: network engineering, CI/CD automation security, container security, endpoint security, penetration testing, application security, or cloud security.

  • Actively participates and collaborates with others on one's own team and across REI for the achievement of business goals.

  • Flexible in one's viewpoints and positions in order to support the direction taken by others at REI.

  • Uses business knowledge, innovative thinking, and sound judgment in the solution of problems or the pursuit of business opportunities.

  • Consolidates information from various sources including feedback from others to reach sound decisions.

  • Considers the ultimate impact of decisions and actions on internal and external customers.

  • Works smart by setting effective work goals, establishing priorities, and planning well in order to produce quality work.

  • Executes effectively by using resources efficiently, meeting deadlines, and keeping others informed of work plans and progress toward goals.

  • Clearly conveys and accurately receives information by a variety of methods and in various situations.

  • Builds rapport different people inside and outside the organization.

  • Acts upon opportunities and involves and influences others in the accomplishment of worthwhile organizational goals.

  • Challenges the status quo, champions change and influences others to change.

Preferred Qualifications

  • 1+ years' experience managing vendor relationships

  • Experience with threat modeling (ASVS 4, MITRE ATT&CK, or other)

  • Current holder of at least one recognized security-relevant certification (i.e., CISSP)

Closing

At REI, we believe the outdoors is for all. We are committed to becoming a fully inclusive, anti-racist, multicultural organization. We know that there's strength in our diversity – that each employee brings unique skills, experiences, and perspectives. Every day you are driving change, fostering a culture of respect, and knowing you're backed by benefits that support your whole life. To work towards this commitment and fulfill our brand promise of inspiring and enabling a life outside for everyone, we seek employees who demonstrate different ways of working, create a sense of belonging, and actively listen and learn.

Pay Transparency

We are committed to practices that promote pay equity and transparency. As required by applicable Pay Transparency laws, REI provides a range of compensation for roles that may be hired in locations under these requirements. Factors that may be used to determine your actual salary may include a wide array of factors, including: your specific skills and experience, geographic location or other relevant factors.

REI offers all regular employees a generous employee discount, access to health benefits, a retirement savings plan and accrued time off. Click here (https://foryourbenefit-rei.com/) for a detailed overview of benefits plans by employee profile.

Pay Range

$127,600.00 - $204,100.00 per year



  • Seattle, Washington, United States Reddit Full time

    OverviewRapidly growing Privacy and Risk Security Engineering Team seeks experienced Information Security Engineer to develop solutions to close security gaps and build robust data privacy safeguards.Key Responsibilities* Develop and implement effective technical solutions that enable privacy, compliance, and data protection by default* Translate privacy and...


  • Seattle, Washington, United States Zillow Group Full time

    About the team Join our Information Security team as we build cutting-edge solutions to protect our technology stack, products, and services Our company focuses on developing our outstanding solutions, with the team fully coordinated within the organization to prioritize application security in all our projects. We are looking for individuals who thrive at...


  • Seattle, Washington, United States Jobleads-US Full time

    Jobleads-US is at the forefront of innovation, and as an Information Security Engineer, you'll play a critical role in protecting our systems and data from potential threats. You'll work effectively with your team to identify security problems and improve the security aspects of their service(s).ResponsibilitiesDeveloping Security ControlsReviewing and...


  • Seattle, Washington, United States Jobleads-US Full time

    Job Summary:The Security Engineer I role is a critical part of our Prime Air Information Security team. We are looking for an experienced professional who can help us drive innovation and improvement in our security practices.In this role, you will be responsible for creating, updating, and maintaining threat models for various software projects. You will...


  • Seattle, Washington, United States Palantir Full time

    About the Job:As an Application Security Engineer at Palantir, you will have the opportunity to work on a wide range of projects and contribute to the development of our cutting-edge security technologies. Your primary responsibility will be to perform deep architecture and security reviews on complex products to identify vulnerabilities and ensure their...


  • Seattle, Washington, United States Jobleads-US Full time

    Job DescriptionAs an Information Security Engineer on our innovative Information Security team, you will play a critical role in protecting Amazon's highly sensitive data and systems from emerging threats.You will work closely with cross-functional teams to identify and mitigate potential security threats, design and implement secure architectures, and...


  • Seattle, Washington, United States McKinstry Full time

    Build the future, spark innovation and align your career with purpose. McKinstry is innovating the waste and climate harm out of the built environment and creating lasting impact. Together, we're building a thriving planet. Buildings are a leading contributor to the climate crisis, generating nearly 40% of total global energy-related carbon emissions. We're...


  • Seattle, Washington, United States Remitly, Inc. Full time

    About the RoleRemitly, Inc. is seeking an experienced Information Security Engineer Director to contribute to the establishment and development of engineering solutions that support enterprise-wide security initiatives relating to Corporate IT and Customer service systems, assets, and procedures.Key Responsibilities include:Developing and implementing...


  • Seattle, Washington, United States Axon Full time

    About the RoleWe are seeking an experienced Information Security Expert Senior to join our team. In this role, you will be responsible for evaluating and integrating new security tools and technologies into the SOC. You will also participate in an on-call rotation to investigate and remediate escalated security events, serving as a final point of escalation...


  • Seattle, Washington, United States Jobleads-US Full time

    Job DescriptionWe are seeking an experienced Principal Security Engineer to join our Information Security team at Jobleads-US. As a key member of our team, you will be responsible for leading incident response efforts, conducting in-depth technical investigations, and evaluating and integrating security tools and technologies. You will also collaborate with...


  • Seattle, Washington, United States Reddit Full time

    **Job Description:**We are looking for a skilled Information Security Engineer to develop solutions that close security gaps related to privacy, compliance, assurance, and business policy. The ideal candidate will have hands-on experience working with privacy, security, and compliance policy applications in the software development lifecycle.You will partner...


  • Seattle, Washington, United States Jobleads-US Full time

    Are you a highly skilled security professional looking for a challenging role?Why Join Our Team?We are a dynamic and innovative company that values expertise, creativity, and teamwork. As a Senior Security Engineering Manager, you will have the opportunity to lead and manage a team of talented security professionals, develop and implement effective security...


  • Seattle, Washington, United States Jobleads-US Full time

    Security Engineer I, Prime Air Information Security Amazon Prime Air is looking for a Security Engineer to focus on our applications, systems, and infrastructure security. You will work to help other teams create solutions while developing strong security culture and practices. You work with groups throughout Amazon Prime Air to help them integrate...


  • Seattle, Washington, United States Branch Metrics Full time

    At Branch, we're transforming how brands and users interact across digital platforms. Our mobile marketing and deep linking solutions are trusted to deliver seamless experiences that increase ROI, decrease wasted spend, and eliminate siloed attribution. Our Branch team consists of smart, humble, and collaborative people who value ownership over all....


  • Seattle, Washington, United States Amazon Full time

    Job ID: 2881363 | Amazon.com Services LLCJoin AWS Security as a Security Engineer and be at the forefront of safeguarding cloud computing for millions of customers worldwide In this role, you'll have the unique opportunity to work on the foundational services that form the backbone of AWS, directly influencing the security of the entire cloud infrastructure....


  • Seattle, Washington, United States Jobleads-US Full time

    About the Company:Amazon is a global company with a commitment to innovation and customer satisfaction. Our cloud security team plays a critical role in ensuring the security and availability of our cloud services. We are seeking a highly skilled Senior Cloud Security Engineer to join our team and contribute to our mission of providing a secure and reliable...


  • Seattle, Washington, United States Jobleads-US Full time

    Security Engineer I, Prime Air Information SecurityAmazon Prime Air is looking for a Security Engineer to focus on our applications, systems, and infrastructure security. If you are seeking an iterative fast-paced environment where you can drive innovation, apply state-of-the-art technologies to solve large-scale real world delivery challenges, and provide...


  • Seattle, Washington, United States Jobleads-US Full time

    Security Engineer I, Prime Air Information Security Amazon Prime Air is looking for a Security Engineer to focus on our applications, systems, and infrastructure security. If you are seeking an iterative fast-paced environment where you can drive innovation, apply state-of-the-art technologies to solve large-scale real world delivery challenges, and provide...


  • Seattle, Washington, United States Amazon Full time

    Security is paramount in today's digital landscape, and Amazon takes this responsibility seriously. As a Senior Security Engineer in AWS Managed Services, you will play a critical role in maintaining the highest level of security for our customers.We are seeking a highly motivated individual with a passion for cloud security and a proven track record in...


  • Seattle, Washington, United States Alaska Airlines Full time

    Company: Alaska Airlines The Team: Guided by our purpose, core values, and leadership principles, we are creating an airline people love. Our corporate teams set the strategies and operational plans to ensure the success of our company. Whether we use our expertise in accounting, human resources, finance, planning, legal, marketing, or any of our operational...