Security Lead ( Threat Modeling )
Position Overview
At PNC, our people are our greatest differentiator and competitive advantage in the markets we serve. We are all united in delivering the best experience for our customers. We work together each day to foster an inclusive workplace culture where all of our employees feel respected, valued and have an opportunity to contribute to the company's success.
As a Security Lead within PNC's Enterprise Technology & Security organization, you will be based in Pittsburgh, PA. Remote work will be considered for a well-qualified candidate.
The Security Lead is a subject matter expert in threat modeling who is responsible for ensuring that PNC application developers have the necessary training, knowledge, requirements, tools, and assistance as they deliver quality application code, free of security risks.
Responsibilities within this position will include: • Deep level knowledge of application security vulnerabilities and ability to explain and provide solutions at both an architectural and development level to build a defense in depth security controls across enterprise.• Participate in threat modeling with the explicit purpose of influencing design decisions to address the most likely threats to an application's security and resiliency. • Validate that applications have met documented security standards at each stage of development through deep knowledge and understanding on OWASP top 10 as well as application security vulnerabilities and ability to explain and provide solutions at both an architecture and development level• Provide expert assistance to developers as they work to implement security standards or to remediate discovered deficiencies • Strong knowledge of API Security, crypto primitives, authentication protocols, and authorization standards (SSL/TLS, SAML, OAuth, JWT). Experience with cloud security, microservices and container security.• Work with project teams to prioritize security milestones. Ensure that project managers give security requirements the same attention that functional requirements generally receive during the development process. • Enforce security training and professional development and serve as a repository of security expertise for teams and enterprise.• Certifications such as CISSP, CSSLP, GWAPT, GWEB and others are nice to have.
As an integral part of this dynamic and progressive team, you will assist in the enforcement of corporate-wide information security policies, guidelines and best practices. You will also provide technical advice to support internal Cyber Security teams on a wide variety of information security issues, concerns, and problems
Job Description
- Provides technical evaluation and analysis. Supports activities, process, and tools needed to improve overall security posture of the organization.
- Applies security concepts, reviews information, executes defined tasks, analyzes requirements, reviews logs, and creates documentation. Performs investigation and data loss prevention, data manipulation, and coordination of activities. Performs actions to address or mitigate risks and vulnerabilities. Reviews and defines controls.
- Advises on more complex security procedures and products for clients, security administrators and network operations. Participates in enforcement of control security risks and threats; potential of one more controls subject to manager discretion. Shares knowledge with staff.
- Conducts security assessments and other information security routines consistently. Investigates and recommends corrective actions for data security related to established guidelines.
- Provides training and development to other team members; coordinates staff contributions to effectively meet business needs.
PNC Employees take pride in our reputation and to continue building upon that we expect our employees to be:
- Customer Focused - Knowledgeable of the values and practices that align customer needs and satisfaction as primary considerations in all business decisions and able to leverage that information in creating customized customer solutions.
- Managing Risk - Assessing and effectively managing all of the risks associated with their business objectives and activities to ensure they adhere to and support PNC's Enterprise Risk Management Framework.
Competencies
Analytical Thinking - Knowledge of techniques and tools that promote effective analysis and the ability to determine the root cause of organizational problems and create alternative solutions that resolve the problems in the best interest of the business.
Effective Communications - Understanding of effective communication concepts, tools and techniques; ability to effectively transmit, receive, and accurately interpret ideas, information, and needs through the application of appropriate communication behaviors.
Information Assurance - Knowledge of and the ability to protect information and information systems while ensuring their confidentiality, integrity and availability.
Information Security Management - Knowledge of and the ability to manage the processes, tools, techniques and practices for assuring adherence to standards associated with accessing, altering and protecting organizational data.
Information Security Technologies - Knowledge of technologies and technology-based solutions dealing with information security issues.
IT Environment - Knowledge of an organization's IT purposes, activities and standards; ability to create an effective IT environment for business operations.
IT Standards, Procedures & Policies - Knowledge of and the ability to utilize a variety of administrative skill sets and technical knowledge to manage organizational IT policies, standards, and procedures.
IT Systems Management - Knowledge of and ability to utilize a variety of technical tools and techniques to guarantee service availability and ensure IT system performance.
Problem Solving - Knowledge of approaches, tools, techniques for recognizing, anticipating, and resolving organizational, operational or process problems; ability to apply this knowledge appropriately to diverse situations.
Software Security Assurance - Knowledge of and the ability to detect and prevent data security vulnerabilities of coding throughout the software development life cycle within software development organizations.
Work Experience
Roles at this level typically require a university / college degree, with 3+ years of relevant / direct industry experience. Certifications are often desired. In lieu of a degree, a comparable combination of education and experience (including military service) may be considered.
Education
Bachelors
Additional Job Description
Base Salary: $55,000 - $142,600
Where a person is paid in the compensation range is aligned to their experience and skills. Placement within the compensation range is based on the specific role and the following factors:
- Lower in range - Building skills and experience in the job
- Within the range - Experience and skills align with proficiency in the role
- Higher in range - Experience and skills add value above typical requirements of the role
Compensation Range may vary based on Geographic Location
INCENTIVE
Role is incentive eligible with the payment based upon company, business and individual performance.
Benefits
PNC offers employees a comprehensive range of benefits to help meet your needs now and in the future. Depending on your eligibility, options for full-time employees include medical/prescription drug coverage (with a Health Savings Account feature); dental and vision options; employee and spouse/child life insurance; short- and long-term disability protection; maternity and parental leave; paid holidays, vacation days and occasional absence time; 401(k), pension and stock purchase plans; dependent care reimbursement account; back-up child/elder care; adoption assistance; educational assistance and a robust wellness program with financial incentives. To learn more about these and other programs, including benefits for part-time employees, visit pncbenefits.com > New to PNC.
Disability Accommodations Statement:
The PNC workplace is inclusive and supportive of individual needs. If you have a physical or other impairment that might require an accommodation, including technical assistance with the PNC Careers website or submission process, please call 877-968-7762 and select Option 4: Recruiting or contact us via email at [email protected].
The Human Resources Service Center hours of operation are Monday - Friday 9:00 AM to 5:00 PM ET.
Equal Employment Opportunity (EEO):
PNC provides equal employment opportunity to qualified persons regardless of race, color, sex, religion, national origin, age, sexual orientation, gender identity, disability, veteran status, or other categories protected by law.
California Residents
Refer to the California Consumer Privacy Act Privacy Notice to gain understanding of how PNC may use or disclose your personal information in our hiring practices.