Live opening · Posted 11 days ago
At a glance
The key details from the original listing.
Your early-applicant advantage
Live timing from JobBeeper.
About the role
Description supplied by the original job listing.
The ideal candidate is a self-starter, problem-solver, and successful in combining technology and data into best-in-class outcomes. The candidate is energized by solving complex business problems and consistently effective in making high-judgment decisions at a rapid pace amidst the frequent ambiguity that comes with charting a course of action with no precedent. Moreover, the ideal candidate is energized by an environment where strategy, innovation, and decision-making are intentionally distributed; where candor, speed, and data are highly valued; and where colleagues at all levels hold each other to unusually high standards on behalf of our customers.
Responsibilities:
Develops and manages Quince's overall approach to data security and information protection.
Align standards, frameworks, and security with the overall business and technology strategy.
Design security architecture elements to mitigate threats as they emerge.
Audits the collection, use, and retention of all personal data within Quince.
Ensures all Quince policies around data protection and information security are up to date and fit for purpose.
Defines, implements, and maintains corporate security policies.
Leads on the identification of data security and information protection risks across the organization and works with stakeholders to develop and implement mitigation plans, escalating issues as appropriate.
Acts as a subject matter expert on data security for projects looking to implement new tools, products, or processes.
Supports the Global IT Operations Manager to achieve the highest standards of information security across Quince's network.
Oversees maintenance of systems to protect data from unauthorized users.
Develops and maintains process maps, which show how data flows through the organization.
Leads and facilitates organizational training and communications around data security and information protection issues.
Oversee incident response planning as well as the investigation of security breaches and assist with disciplinary and legal matters associated with such breaches as necessary.
Implements measures to protect digital files and information systems against unauthorized access, modification, or destruction.
Requirements:
Experience in building cloud security infrastructure on AWS, GCP, or other public clouds.
Experience with Conducting Web/API and Infrastructure Security Assessments.
Know about conducting a security architecture review and threat modeling.
Familiar with the integration of scanning tool automation into the CI pipeline.
Strong knowledge of securing code review and developer security education.
Knowledge of Securing Federated Architectures, SAML2.0 Remediation of OWASP Top 10 classes, CWE-25 XSS, XSRF, Command Injection, etc.
Experience conducting penetration testing.
Know about Jenkins Pipeline Automation.
Good experience with any scripting language; Python preferred.
Sensitive Data Review: Securing data at rest and in transit.
Familiar with security incident response and management and customer engagement.
Experience building Key Management Infrastructure.
Experience with Linux OS hardening, OSCAP tools, and Red Hat STIG/DISA STIG.
Degree in Information Technology, Computer Science, Software Engineering, or a related field.
Knowledge of information technology security issues and approaches to managing them.
Information technology security.
Knowledge of data protection operations and legislation (GDPR), CCPA.
At least one recognized security certification:
Certified Ethical Hacker (CEH).
CompTIA Security+.
Certified Information System Security Professional (CISSP).
Certified Information Security Manager (CISM).
Certified Information Systems Auditor (CISA).
Experience
2-6 yrs
More openings worth a look
Recently tracked roles with full details and direct application links.