Security Engineer, Business Information Risk
4 weeks ago
About this role:
Audible is seeking an experienced Security Engineer to join our Information Security team. As a Security Engineer, you will be responsible for advocating for information security throughout all our software development and business processes. You will work with other Security Engineers, Application Developers, and System Engineers to protect our customers and Audible's business.
About the team:
Audible's Information Security team is a world-class team that is obsessed with protecting customer trust. We are a hands-on team working to protect our computer networks, servers, applications, and data assets. This role will be focused on managing risk across our business functions.
Responsibilities:
- Perform third-party security risk assessment and due diligence, including managing questionnaire response, evidence verification, and report preparation.
- Assess and secure third-party integrations, services, solutions, and partnerships, ensuring controls are implemented to the highest security standards.
- Assess, identify, and develop recommendations regarding data protection, insider threat, data sharing, identity, and access management.
- Execute internal security and confidential information usage security assessments, audits, and investigations.
- Assess and prioritize security assessment findings and recommend appropriate mitigations.
- Respond to security violations, vulnerabilities, and incident detections.
- Provide guidance on risk, compliance, and policy to technical and non-technical internal customers, including security training and outreach to internal teams and external supply chain partners.
- Apply your security and business knowledge to drive secure and pragmatic improvements to Audible people, process, and assets, while guiding technical trade-offs between short versus long-term security and business goals.
- Contribute to and provide feedback on the development of security standards and control requirements.
About Audible:
Audible is the leading producer and provider of audio storytelling. We spark listeners' imaginations, offering immersive, cinematic experiences full of inspiration and insight to enrich our customers' daily lives. We are a global company with an entrepreneurial spirit. We are dreamers and inventors who are passionate about the positive impact Audible can make for our customers and our neighbors. This spirit courses throughout Audible, supporting a culture of creativity and inclusion built on our People Principles and our mission to build more equitable communities in the cities we call home.
Basic Qualifications:
- Bachelor's degree in computer science or equivalent.
- Experience with AWS products and services.
- Experience applying threat modeling or other risk identification techniques or equivalent.
- 5+ years of any combination of the following: threat modeling experience, secure coding, identity management and authentication, software development, cryptography, system administration, and network security experience.
- Experience with the information security principles and the Common Body of Knowledge (CBK) domains and core technologies (CIA, encryption, identity, authN/authZ, SSO, web protocols, and privacy).
- Experience in advocating security best practices for third-party integrations (e.g., with SAAS solutions, third-party libraries, etc.).
Preferred Qualifications:
- Ability to communicate effectively with both technical and non-technical stakeholders across multiple business units.
- MS in Cybersecurity, Computer Science, or other relevant degree.
- Current knowledge around web and mobile application vulnerabilities, attacks, and mitigation methods.
- Experience with developing and maintaining relevant security assessment risk metrics.
- Experience using GRC tools and technologies.
- Proficient in at least one programming language – Java preferred.
- AWS certifications such as AWS Certified Security – Specialty, AWS Certified Cloud Practitioner, or other security-related certifications (e.g., CISSP, SANS/GIAC or GSEC, CISA, OSCP/OSWA/OSWE).
-
Senior Software Engineer
4 weeks ago
Newark, Delaware, United States Moody's Full timeAbout the RoleMoodys is a global integrated risk assessment firm that empowers organizations to make better decisions. We are seeking a Senior Software Engineer to join our team to create state-of-the-art commercial and consumer application solutions to understand and manage risks, from earthquakes, hurricanes, and floods to terrorism and infectious...
-
Cyber Security Analyst CyberArk
1 month ago
Newark, Delaware, United States PSEG Full timeJob SummaryThis position is an experienced, senior-level, hands-on technical lead, performing privileged access management (PAM) security functions and PAM maintaining systems, while providing technical guidance to the team. Manages PAM technologies, as well as PAM security policies and procedures, and incident response as needed. Provides technical...
-
Business Risk and Control Manager
4 weeks ago
Newark, Delaware, United States Citigroup Inc Full timeJob SummaryThe Business Loans Risk and Control Senior Manager is a strategic professional who stays abreast of developments within own field and contributes to directional strategy by considering their application in own job and the business.Key ResponsibilitiesEstablishes and oversees the application of operational risk policies, technology and tools, and...
-
Application Security Specialist
4 weeks ago
Newark, Delaware, United States Prudential Ins Co of America Full timeJob Title: Application Security SpecialistAt Prudential Ins Co of America, we're seeking a highly skilled Application Security Specialist to join our team. As a key member of our Global Technology team, you will play a critical role in advancing our application security program.Key Responsibilities:Partner with security professionals to advance our...
-
Cyber Security Analyst CyberArk
1 month ago
Newark, Delaware, United States Public Service Enterprise Group Inc Full timeJob SummaryThis position is an experienced, senior-level, hands-on technical lead, performing privileged access management (PAM) security functions and PAM maintaining systems, while providing technical guidance to the team.Key ResponsibilitiesLeads and manages PAM technologiesProvides technical expertise in threat/risk assessments related to privileged...
-
Information Security Specialist
4 weeks ago
Newark, Delaware, United States BCforward Full timeJob Title: Information Security SpecialistJob Summary:BCforward is seeking a highly motivated Information Security Specialist for an opportunity in a Hybrid environment. As an Information Security Specialist, you will be responsible for preparing Information Security Policies and Standards for annual review or when there are changes required. You will also...
-
Business Risk and Control Senior Manager
4 weeks ago
Newark, Delaware, United States Hispanic Technology Executive Council Full timeJob DescriptionThe Business Loans Risk and Control Senior Manager plays a pivotal role in the organization, overseeing the management of professional teams and departments to drive results. This strategic professional stays abreast of developments within their field and contributes to directional strategy by considering their application in their job and the...
-
Newark, Delaware, United States Cognizant North America Full timeCognizant North America is a leading professional services company, transforming clients' business, operating, and technology models for the digital era.Our unique industry-based, consultative approach helps clients envision, build, and run more innovative and efficient businesses.Within Cognizant North America is Cognizant Consulting, a global consulting...
-
Business Controls Lead
4 weeks ago
Newark, Delaware, United States City National Bank Full timeJob SummaryCity National Bank is seeking a highly skilled Business Controls Lead to join our team. As a Business Controls Lead, you will be responsible for identifying, assessing, monitoring, and reporting all key risks. You will assist operations managers with monitoring of business risks and controls, and coordinate Risk Registers to support the overall...
-
High Net Worth Producer
4 weeks ago
Newark, Delaware, United States Novatae Risk Group Full timeJob DescriptionNovatae Risk Group is a national wholesale/brokerage for hard to place commercial insurance coverages. We are seeking experienced professionals to oversee the preparation of submissions, including applications and support documents, and to favorably present accounts to insurance carriers. The ideal candidate will have a strong knowledge of...
-
Identity Security Specialist
4 weeks ago
Newark, Delaware, United States SPHERE Technology Solutions Full timeJob SummaryAs an Identity Security Specialist at SPHERE Technology Solutions, you will play a critical role in ensuring the security and integrity of our clients' most critical data. You will be responsible for architecting, implementing, and maintaining Identity and Access Management (IAM) solutions to mitigate security risks and ensure compliance with...
-
Identity Security Specialist
1 month ago
Newark, Delaware, United States SPHERE Technology Solutions Full timeJob Summary:As an Identity Security Specialist at SPHERE Technology Solutions, you will play a critical role in ensuring the security and integrity of our clients' identity and access management systems. Your expertise in IAM security will help us identify and mitigate potential risks, ensuring our clients' data remains secure.Responsibilities: Actively...
-
Senior Software Engineer
4 weeks ago
Newark, Delaware, United States Moody's Full timeJob DescriptionMoody's is a global leader in integrated risk assessment, empowering organizations to make informed decisions. We're seeking a talented Senior Software Engineer to join our team and contribute to the development of state-of-the-art commercial and consumer application solutions.Key ResponsibilitiesDesign, build, and deploy scalable back-end...
-
Data Loss Prevention Specialist
4 weeks ago
Newark, Delaware, United States Prudential Full timeJob SummaryWe are seeking a highly skilled Data Loss Prevention Specialist to join our team at Prudential. As a key member of our Insider Risk Team, you will play a critical role in mitigating information security risk to the Prudential enterprise.Key ResponsibilitiesServe as a DLP subject matter expert, refining technology requirements and opportunities for...
-
Cyber Security Operations Lead
4 weeks ago
Newark, Delaware, United States Prudential Ins Co of America Full timeJob SummaryPrudential Ins Co of America is seeking a highly skilled Cyber Security Operations Lead to join our team. As a key member of our Information Security Office, you will be responsible for providing guidance and partnering with security professionals across the organization to develop integrations, correlations, processes, and SIEM content to better...
-
Senior Risk Manager
4 weeks ago
Newark, Delaware, United States Citigroup Inc Full timeThe primary focus of this role is to oversee the operational risk management of the US Cards and Lending business, ensuring effective risk identification, analysis, and mitigation.This position involves working closely with various stakeholders, including the USPB Consumer 1st Line of Defense and In-Business Operational Risk and Control organization, to...
-
Data Loss Prevention Specialist
4 weeks ago
Newark, Delaware, United States Prudential Full timeJob SummaryWe are seeking a highly skilled Data Loss Prevention Specialist to join our team at Prudential. As a critical member of the Insider Risk Team, you will serve as a subject matter expert in data loss prevention, refining technology requirements and opportunities for automation to mitigate information security risk to the Prudential enterprise.Your...
-
Head of Compliance Risk Management
4 weeks ago
Newark, Delaware, United States Sallie Mae Inc (SLM Corp) Full timeCompliance Risk Management LeadWe are seeking a highly skilled Compliance Risk Management Lead to join our team at Sallie Mae Inc (SLM Corp). As a key member of our organization, you will be responsible for managing and implementing compliance risk strategies, policies, and procedures for the Fair and Responsible Banking Program (FRB) analysis oversight and...
-
Business Development Manager
4 weeks ago
Newark, Delaware, United States Toshiba America Business Solutions Full timeJob SummaryWe are seeking a highly motivated and experienced Business Development Manager - Enterprise Thermal to join our team at Toshiba America Business Solutions, Inc. This is an excellent opportunity for a sales professional to work remotely and develop new business in the Enterprise/Thermal accounts.Key ResponsibilitiesDevelop and cultivate new...
-
Senior Identity Security Specialist
1 month ago
Newark, Delaware, United States SPHERE Technology Solutions Full timeJob OverviewAs a Senior Identity Security Specialist at SPHERE Technology Solutions, you will play a critical role in ensuring the security and compliance of our clients' identity and access management environments. This position requires a strong background in Windows and database systems, as well as experience in consultative roles and entitlement...