IT Security Principal Engineer -NATIONWIDE_

Posted Yesterday
Be an Early Applicant
Raleigh, NC, USA
In-Office
Expert/Leader
Information Technology
The Role
Lead security consulting across IT and applications: drive Secure Development Lifecycle, run source-code analysis (Fortify), perform network and WLAN security assessments, penetration/red-team engagements, firewall policy design, ensure PCI/HIPAA/SOX compliance, and provide security training and threat modeling.
Summary Generated by Built In
Company Description

GlobalXperts is a leading IT Solution Provider whose business focus is to provide Day 2 remote monitoring & co-managed support and professional services for advanced Cisco, Microsoft and Data Center solutions. Our Level 1 through Level 3 networking experts (CCNA through CCIE) are available around-the-clock and have a deep understanding of internetworking technologies (Collaboration, Data Center, Borderless networking, Security) and products from leading equipment manufacturers giving you access to multi-technology support from a single source. Our professional services approach track with Cisco's PPDIOO model which is to prepare, plan, design, implement, operate, and optimize. And, while each phase of the service delivery model is strategically designed to build upon the previous phase, GlobalXperts technical staff has been successfully utilized by our customers for any or all phases. 

Job Description

The IT Security Principal Engineer will deliver security technical consulting to internal organizations and Information Technology Services (ITS). The IT Security Principal Engineer will evaluate needs of key stakeholders to find solutions to challenging situations. Primary areas of expertise are IT infrastructure and information security compliance (HIPAA, SOX, PCI, Penetration Testing, etc.).

Responsibilities:
• Drive SDL across ITS and business segments, for internal and externally facing applications, including Ecommerce sites, Mobility (Android, Apple IOS), and legacy applications;
• Source code analysis and remediation using Fortify; Network security assessments and analysis for corporate and non-corporate network environments;
• Firewall policy evaluation, review, and design;
• Ensure compliance across applications and networks for PCI, HIPAA, and SOX;
• Provide training and guidance for security including Threat Modeling, Penetration Testing, SDL, and Code Security Reviews.

Qualifications

• Bachelor's degree required, preferably in computer science or information systems

• 5+ years of experience leading penetration testing, application testing, and red team engagements
• 10+ years of Information Technology, with a background in Security and Compliance experience

Additional Requirements:

• Experience with security tools such as – Nmap, Metasploit, Kali Linux, Burp Suite Pro, etc., as well as other various commercial and self-developed testing tools
• Experience with scripting languages such as python, ruby, POSIX shell, as well as familiarity with programming languages such as: C/C++/ObjC/C#, Java, PHP, or .NET
• Understanding of:
- Web protocols (e.g., HTTP, HTTPS, and SOAP)
- Web technologies (e.g., HTML, JavaScript, XML, AJAX, JSON, and REST)
• Experience with WLAN security concepts and testing
• Strong technical communication skills, both written and verbal; ability to explain technical security concepts to executive stakeholders in business language
• While experience in a number of IT disciplines may provide a solid framework for this position, hands-on results from performing IT risk assessments, information security consulting or IT audits are most beneficial.
• Experience in the following regulations and Frameworks: PCI, ISO 27001/2, HIPAA, GLBA, NIST

Additional Information

All your information will be kept confidential according to EEO guidelines.

Skills Required

  • Bachelor's degree (preferably Computer Science or Information Systems)
  • 10+ years Information Technology experience with Security and Compliance
  • 5+ years leading penetration testing, application testing, and red team engagements
  • Experience with security tools (Nmap, Metasploit, Kali Linux, Burp Suite Pro, etc.)
  • Experience with source code analysis and remediation (Fortify)
  • Experience with scripting languages (Python, Ruby, POSIX shell)
  • Familiarity with programming languages (C, C++, Objective-C, C#, Java, PHP, .NET)
  • Understanding of web protocols (HTTP, HTTPS, SOAP)
  • Understanding of web technologies (HTML, JavaScript, XML, AJAX, JSON, REST)
  • Experience with WLAN security concepts and testing
  • Hands-on IT risk assessments, information security consulting, or IT audits
  • Experience with regulations and frameworks (PCI, ISO 27001/2, HIPAA, GLBA, NIST)
  • Strong written and verbal technical communication skills
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Raleigh, NC
62 Employees
Year Founded: 2005

What We Do

Business has gone global… and so have we! By providing support services based on industry best practices, GlobalXperts has broken barriers on communications and unleashed a global movement of innovation and success. About GlobalXperts: GlobalXperts is an IT solutions provider whose business focus is professional and managed services for advanced IT infra-structure solutions. Our technical resources range from “Smart Hands” to SMEs (Subject Matter Experts) and are available around-the-clock Globally. Our professional services include full life cycle support and services (plan, architect, design, implementation, migrations, automation, orchestration and operations). They have a deep understanding of Data Center (SDN, SDWAN), Cloud (AWS, Azure, GCP), Security, Collaboration, Contact Center and Enterprise networking technologies that incorporates products from leading equipment manufacturers such as AWS, Azure, Google, Open Stack, Cisco, Microsoft, Arista, Palo Alto, F5, etc. Our customers are companies ranging from small to enterprise level infrastructures and other solutions providers and integrators that deploy internetworking solutions to their SMB and Fortune-500 customers. We offer a full range of managed services to keep your IT solutions performing properly and ensuring that access is maintained to widely dispersed work forces where BYOD is the norm. GlobalXperts' 24X7 NOC staff utilizes several leading network tools such as Service Now, Prognosis, SolarWinds, N-Able, Kaseya, Advent Net and CA Service Desk.

Similar Jobs

Applied Systems Logo Applied Systems

Director, Product Marketing - Carrier

Cloud • Insurance • Payments • Software • Business Intelligence • App development • Big Data Analytics
Remote or Hybrid
United States
3079 Employees
150K-180K Annually
Hybrid
3 Locations
1100 Employees
203K-323K Annually

Identity Digital Logo Identity Digital

Staff Devops Engineer

Consumer Web • eCommerce • Internet of Things
Remote or Hybrid
United States
240 Employees
175K-220K Annually

MetLife Logo MetLife

Customer Care Advocate Disability Intake - Cary, NC 9.14.26 - 18272

Fintech • Information Technology • Insurance • Financial Services • Big Data Analytics
Hybrid
Cary, NC, USA
43000 Employees
42K-42K Annually

Similar Companies Hiring

Standard Template Labs Thumbnail
Artificial Intelligence • Information Technology • Software
New York, NY
25 Employees
NODA AI Thumbnail
Artificial Intelligence • Information Technology • Software • Cybersecurity
Sydney, AU
54 Employees
Golden Pet Brands Thumbnail
Digital Media • eCommerce • Information Technology • Marketing Tech • Pet • Retail • Social Media
El Segundo, California
178 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account