At Oshkosh, we build, serve and protect people and communities around the world by designing and manufacturing some of the toughest specialty trucks and access equipment. We employ over 15,000 team members all united by a common purpose. Our engineering and product innovation help keep soldiers and firefighters safe, is critical in building and keeping communities clean and helps people do their jobs every day.
JOB SUMMARY:
Oshkosh Corporation owns significant assets in the form of information. Some of these assets lose substantial value if they are improperly disclosed, and similar disclosure of other assets could result in significant harm to the organization. This role will support the Cybersecurity mission by working with the business as a trusted advisor to reduce cybersecurity risks to acceptable levels. Specifically, by acting as the organization’s mechanism to identify, maintain, and improve cybersecurity controls by using risk-based approach and creating effective education and awareness to preserve the confidentiality, integrity, and availability of company information.
ESSENTIAL DUTIES AND RESPONSIBILITIES:
These duties are not meant to be all-inclusive and other duties may be assigned.
- Ensure the information security awareness program communicates our security policies and requirements in a manner which facilitates knowledge and understanding. Create dynamic interactive lessons designed to hold the attention of adults with various learning styles.
- Coordinate with IT and business regional leads to develop or modify awareness for different cultures, nationalities, and languages. Develop deeper training for job related security competencies in critical functions.
- Coordinate the production of training materials for targeted audiences that address various learning styles through visual, auditory, and kinesthetic methods. Prepare and deliver targeted awareness campaigns (phishing, cyber security month, personal security, etc.).
- Create phishing simulations and other security awareness trainings with internal team members for the rest of the corporation. Keep informed on the latest research, trends, developments in all areas of adult education. Incorporate best practices into the Security and Awareness (SEA) program.
- Triage alerts, collect related data from various analysis systems, review available open and closed source information on related threats and vulnerabilities, diagnose observed activity for likelihood of system infection, compromise, or unintended/high-risk exposure. Prepare reports detailing background, observables, analysis process and criteria, and conclusions from incidents, news, or other intel. Analyze network flows, system logs, and meta data for patterns/characteristics or general anomalies to trend/baseline activity and correlate for alerts, activities, and detections.
- Leverage programing/scripting skills to automate data-parsing, reporting, or any repetitive task that is in daily or common work tasks. Interpret IDS/IPS or SEIM offense signatures as part of a layered defense strategy leveraging multiple technologies throughout our environment.Work in the Security Incident Response Team to improve process, procedures, and training such as creating playbooks for investigations and response procedures, creating table tops scenarios based on different aspects of our environment, and working through investigations with other analyst to train on proper techniques for investigation.
- Be involved in threat hunts and purple team events that are put on to strengthen our knowledge of our environment. Work closely with principals, architects, and analyst to ensure adequate security solutions are in place throughout all systems to mitigate identified risks sufficiently, while meeting business objectives and regulatory requirements.
- Serve as a trusted advisor to business functional areas (e.g., Finance, HR, Engineering) and/or internal IT resources (such as infrastructure, applications, IT services).
- Ensure that business and technical requirements are aligned to policy and are implemented within regulatory and contractual compliance. Advocate for cyber risk mitigation during planning sessions and implementational of new services. Maintain expert awareness of all aspects of information security and compliance, including PCI, SOC, and HIPPA requirements for information systems and industry best practices, such as, NIST 800-53, 800-171.
- Contribute to the development and maintenance of the information security strategy. Build and update metrics for measuring performance of the Security Incident Response Team (SIRT).
MINIMUM QUALIFICATIONS:
- Bachelor’s Degree in Cybersecurity, Information Systems, Communications or equivalent.
- Five (5) or more years of Cybersecurity experience.
PREFERRED QUALIFICATIONS:
- Relevant industry recognized certifications (CISSP, CEH, GIAC, Security+, SSAP, etc.)
- Demonstrate knowledge of security controls for network, applications, and operating systems.
- Experience communicating conceptual and technical information both verbally (on phone, one-on-one, to groups) and in writing (emails, letters, reports, presentations) to various audiences (work group, team, company management, external clients).
- Excellent organizational skills and ability to communicate with internal/external entities and executives.
- Experience identifying intruder techniques (new vulnerability, attack vectors, exploits, etc.).
- Knowledge and experience with InfoSec systems (SEIM, SOAR, IDS/IPS, Phishing Toolkits, Sandbox Analysis Tools, etc.).
- Hold an active or can obtain a U.S. Government Secret level or above clearance.
- Programming experience in any language.
- Demonstrate conceptual, analytical, and innovative problem-solving and evaluative skills
BASIC COMPETENCIES:
- Internal Contacts: Contact with employees or others primarily at a routine level involving basic information exchange; Contact with peers and others involving explanation of information (these contacts may be within or outside department or division), and the gathering of factual information; may include the communication of sensitive or confidential information.
- External Contacts: Frequent external contact to: gather information, answer queries, or ask assistance.
- Communication Skills: Read, write and comprehend simple instructions, short correspondence and memos; Read and interpret safety rules, operating/maintenance instructions and procedure manuals; Write routine reports, correspondence and speak effectively before both internal and external groups; Read, analyze and interpret business manuals, technical procedures and/or government regulations.
- Decision-Making: Regularly makes decisions of responsibility, involving evaluation or information. Decisions may require development or application of alternatives or precedents.
- Complexity, Judgment and Problem Solving: Typically, difficult or complex work. Generally governed by broad instructions and objectives usually involving frequently changing conditions and problems.
WORKING CONDITIONS:
- Physical Demands: Frequent Standing, Walking/Running, Sitting, Climbing, Driving, Bending/Kneeling, Hearing, Talking, Visual, Typing, Fine Dexterity, Manual Dexterity.
- Non-Physical Demands: Frequent Analysis/Reasoning, Communication/Interpretation, Math/Mental Computation, Reading, Sustained Mental Activity (i.e. auditing, problem solving, grant writing, composing reports), Writing.
- Environmental Demands: Occasionally works alone.
- Work Schedule: Routine shift hours. Infrequent overtime, weekend, or shift rotation.
- Demands/Deadlines: Occasional stress due to deadlines or workload because of intermittent or cyclical work pressures, or occasional exposure to distressed individuals within the immediate work environment.
Pay Range:
$89,500.00 - $140,500.00
The above pay range reflects the minimum and maximum target pay for the position across all U.S. locations. Within this range, individual pay is determined by various factors, including the scope and responsibilities of the role, the candidate's experience, education and skills, as well as the equity of pay among team members in similar positions. Beyond offering a competitive total rewards package, we prioritize a people-first culture and offer various opportunities to support team member growth and success.
Oshkosh is committed to working with and offering reasonable accommodation to job applicants with disabilities. If you need assistance or an accommodation due to disability for any part of the employment process, please contact us at [email protected].
Oshkosh Corporation is an Equal Opportunity and Affirmative Action Employer. This company will provide equal opportunity to all individuals without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or veteran status. Information collected regarding categories as provided by law will in no way affect the decision regarding an employment application.
Oshkosh Corporation will not discharge or in any manner discriminate against employees or applicants because they have inquired about, discussed, or disclosed their own pay or the pay of another employee or applicant. However, employees who have access to the compensation information of other employees or applicants as a part of their essential job functions cannot disclose the pay of other employees or applicants to individuals who do not otherwise have access to compensation information, unless the disclosure is (a) in response to a formal complaint or charge, (b) in furtherance of an investigation, proceeding, hearing, or action, including an investigation conducted by the employer, or (c) consistent with Oshkosh Corporation's legal duty to furnish information.
Certain positions with Oshkosh Corporation require access to controlled goods and technologies subject to the International Traffic in Arms Regulations or the Export Administration Regulations. Applicants for these positions may need to be "U.S. Persons," as defined in these regulations. Generally, a "U.S. Person" is a U.S. citizen, lawful permanent resident, or an individual who has been admitted as a refugee or granted asylum.
What We Do
Oshkosh Corporation is an industrial technology company that builds some of the industry’s toughest specialty trucks and access equipment. We serve our everyday heroes – soldiers, firefighters, people working at great height, environmental and refuse workers – through incredible technology. And with a portfolio of leading brands, we can uniquely take innovation from one brand and apply it across our portfolio.
Why Work With Us
We make equipment that moves the world forward. With ~15,000 team members united under our People First culture, a career at Oshkosh is an opportunity to do more than just impact industries -- it's an opportunity to make a difference in the world around you, protecting those who protect us.