Senior Information Security Engineer

Posted Yesterday
Be an Early Applicant
Hunt Valley, MD, USA
Hybrid
93K-124K Annually
Senior level
News + Entertainment
The Role
Supports an enterprise information security program through third-party and vendor risk assessments, policy governance, vulnerability remediation, security awareness and phishing campaigns, disaster recovery assessments, litigation holds, eDiscovery, metrics, and security process automation. The role evaluates architectures, manages policy exceptions, collaborates with Legal, Privacy, IT, and external partners, and presents security risks and recommendations to diverse stakeholders.
Summary Generated by Built In

The Senior Information Security Engineer will support an enterprise security program including conducting deep-dive Third-Party Risk Management (TPRM) assessments, developing and delivering security awareness training campaigns, identifying, tracking, and coordinating vulnerability remediations based on threat intelligence feeds, performing litigation support and investigations, establishing policy enforcement processes, and engineering automations to improve time to deliver using Artificial Intelligence (AI) or automation platforms.

The applicant must have prior experience engineering security solutions with successful deployments in complex commercial enterprise environments. The candidate should have prior experience in a security operations or engineering role, with expertise conducting third-party, software, and vendor risk assessments. Additional required skills are, developing and enhancing security policies and standards, and hands-on knowledge of cloud (SaaS) and hybrid network infrastructure environments, establishing automations to improve accuracy and speed of outcomes, and performing disaster recovery (DR) /Continuity of Operations (COOP) assessments. The candidate will possess strong and polished communication skills, willingness and ability to present security topics to internal and external customers and thrive in a highly visible and fast-paced role. 

Responsibilities:

Process & Execution

  • Conduct high-quality and timely third-party/vendor/service provider/software risk assessments, with the ability to meet SLAs and communicate effectively with all stakeholders.
  • Contributes to the creation and maturation of information security policies and processes. 
  • Identifies opportunities to automate manual processes and successfully engineers and delivers on process improvements according to assigned timelines.
  • Develops and delivers Disaster Recovery and Continuity of Operations risk assessments to business units successfully establishing resiliency plans for the company. 
  • Assist with the governance of the enterprise Policy Exception process including stakeholder engagement, driving completion with internal teams, and providing balanced reports that will be visible to senior leaders.
  • Create, adapt, and enhance weekly metrics to measure program effectiveness.
  • Evaluate security architectures including the ability to identify risks, compensating controls, and mitigation plans.
  • Develop custom security awareness and phishing campaigns to elevate employee knowledge of current trends and threats to Sinclair.
  • Perform, and maintain litigation and data retention holds using eDiscovery and other actions to support Sinclair Legal requests.
  • Ability to multitask, prioritize, and remain organized with simultaneous assignments while remaining flexible and resilient. 
  • Maintain a high level of professionalism and integrity with the ability to effectively communicate with internal and external stakeholders. 
  • Ability to think strategically, plan methodically, and execute tactically.
  • Take ownership of personal and professional development needed to excel in the role.

Collaboration & Partnerships

  • Apply excellent communication skills to efficiently collaborate with company stakeholders and business partners.
  • Ability and prior experience delivering live training sessions to diverse audiences.
  • Evaluate and recommend new products, maintain knowledge of emerging technologies, and maximize value from existing tool sets to ensure return on investment. 
  • Demonstrate strong problem-solving skills by identifying gaps or issues and clearly formulating solutions.
  • Ensure compliance with Sinclair policies and standards by communicating requirements to internal stakeholders.
  • Proactively respond to information security tickets and requests according to team SLA.
  • Collaborate with third parties to remediate risks to effectively minimize attack surface.
  • Operating with a strong sense of teamwork and personal accountability.

Performance Improvement

  • Identify areas of improvement within the security team to maintain a level of excellence.
  • Design, document, and implement procedures for analyzing and evaluating risk. 
  • Proactively and effectively look for ways to improve and optimize processes and techniques. 
  • Research emerging technologies and provide options to leadership for problem solving. 
  • Champion collaboration amongst teams, quality execution on assignments, and take personal accountability for deliverables.
  • Thrive within fast-paced operational environment requiring priority adjustments, multi-tasking, and a high-level of communication skills.
  • Ability to self-motivate and go the extra mile to ensure team success. 
  • Maintain a positive and customer-oriented approach to daily operations.         
  • Comfortable working directly with other teams such as Legal, Privacy, and IT.

 

Qualifications:

  • Bachelor’s degree in Information Security, Information Technology, or related discipline. 
  • 7 years of relevant work experience or a combined background in the following areas: third-party risk management, security operations, security engineering, risk management, vulnerability management.
  • Experience with enterprise threat intelligence and third-party risk management platforms.
  • Demonstrated experience leveraging artificial intelligence (AI) and automation tools to streamline workflows, improve operational efficiency, and enhance decision-making.
  • Understanding of SOC-2, ISO-27001, and NIST SP 800 “series” frameworks with the ability to identify and mitigate control gaps.
  • Exceptional verbal and written communication skills with an ability to present complex information to audiences of varying subject knowledge. 
  • Solid technical background with the ability to understand network and systems architectures. 
  • Prior experience working in commercial multi-cloud provider environments.
  • Industry certification required in one of the following areas: (e.g., CISSP, CISM, CRISC, Security+, CISA, or equivalent).
  • Basic knowledge of current data privacy laws (CCPA/CPRA, GDPR).
  • Prior experience in the broadcast/media entertainment industries preferred.
  • Experience conducting litigation holds, retention requests, and eDiscovery is a big plus.
  • Commercial enterprise experience is required. 

Please note that this position is not eligible for visa sponsorship, including employer sponsorship for an H-1B visa, OPT-STEM employment, etc.

Sinclair is proud to be an equal opportunity employer and a drug free workplace. Employment practices will not be influenced or affected by virtue of an applicant's or employee's race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, military or veteran status or any other characteristic protected by law.

About Sinclair:

Sinclair, Inc. (Nasdaq: SBGI) is a diversified media company and a leading provider of local news and sports. The Company owns, operates and/or provides services to 177 television stations in 79 markets affiliated with all major broadcast networks; owns Tennis Channel, the premium destination for tennis enthusiasts; and multicast networks CHARGE, Comet, ROAR and The Nest. Sinclair’s AMP Media produces a growing portfolio of digital content and original podcasts. Additional information about Sinclair can be found at www.sbgi.net.

 About the Team

The life-blood of our organization is our people. We have a compelling story, a goal-oriented culture, and we take really good care of people. How good? Here is a glimpse: great benefits, open-door policy, upward mobility and a strong desire to see you succeed. Ready to be part of a winning team? Let’s talk.


The base salary compensation range for this role is $93,000 to $124,000. Final compensation for this role will be determined by various factors such as a candidates’ relevant work experience, skills, certifications, and geographic location. Full time positions are eligible for benefits that include participation in a retirement plan, life and disability insurance, health, dental and vision plans, flexible spending accounts, sick leave, vacation time, personal time, parental leave and employee stock purchase plan.


Skills Required

  • Bachelor’s degree in Information Security, Information Technology, or a related discipline
  • Seven years of relevant experience, or combined experience in third-party risk management, security operations, security engineering, risk management, and vulnerability management
  • Experience with enterprise threat intelligence and third-party risk management platforms
  • Experience using artificial intelligence and automation tools to streamline workflows and improve operational efficiency
  • Understanding of SOC 2, ISO 27001, and NIST SP 800-series frameworks, including identifying and mitigating control gaps
  • Exceptional verbal and written communication skills, including presenting complex information to varied audiences
  • Solid technical understanding of network and systems architectures
  • Prior experience working in commercial multi-cloud provider environments
  • Industry certification such as CISSP, CISM, CRISC, Security+, CISA, or equivalent
  • Basic knowledge of CCPA/CPRA, GDPR, and current data privacy laws
  • Commercial enterprise experience
  • Experience in broadcast or media entertainment industries
  • Experience conducting litigation holds, retention requests, and eDiscovery
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Hunt Valley, MD
5,001 Employees
Year Founded: 1986

What We Do

Sinclair Broadcast Group, Inc. is one of the largest and most diversified television broadcasting companies in the country. Sinclair owns and operates, programs or provides sales services to more television stations than anyone and has affiliations with all the major networks. In addition, Sinclair is the leading local news provider in the country, as well as a producer of sports content. Sinclair owns a multicast network, four radio stations and a cable network. Sinclair’s broadcast content is delivered via multiple-platforms, including over-the-air, multi-channel video program distributors, and digital platforms. Sinclair, either directly or through its venture subsidiaries, makes equity investments in strategic companies. Sinclair Broadcast Group, Inc. was founded in 1986, went public in 1995 and is traded on the NASDAQ Global Select Market under the ticker symbol SBGI. Throughout our history, Sinclair Broadcast Group has been at the forefront of industry-changing events and technological advances. Our vision and first-to-market mentality drives our ‘next generation’ thinking; stimulating conversations, innovating through our expertise, and advocating for the development of technology and evolving business models. As a leading over-the-air broadcast television company, our primary business is to engage consumers on multiple platforms with relevant and compelling news, entertainment and sports content, and to provide advertisers and business efficient means and value to connect with our mass audiences. We recognize the vital role broadcast television plays in branding and local content delivery, and therefore strive to constantly be at the forefront of leading edge technology and structures to advance the industry.

Similar Jobs

Zscaler Logo Zscaler

Security Engineer

Cloud • Information Technology • Security • Software • Cybersecurity
Easy Apply
Remote or Hybrid
USA
8697 Employees
134K-168K Annually

CACI International Inc Logo CACI International Inc

Senior Systems Engineer

Information Technology • Consulting • Defense
In-Office
Fort Meade, MD, USA
17673 Employees
132K-290K Annually

The Amatriot Group Logo The Amatriot Group

Security Engineer

Information Technology • Professional Services • Cybersecurity • Defense
In-Office
Annapolis Junction, MD, USA
200 Employees
150K-210K Annually

Similar Companies Hiring

TIDAL Thumbnail
Software • News + Entertainment • Mobile • Information Technology • Music • Consumer Web
New York, NY
450 Employees
Sandbox VR Thumbnail
Events • Gaming • News + Entertainment • Retail • Virtual Reality
Tsim Sha Tsui East, Kowloon
650 Employees
Hedra Thumbnail
Software • News + Entertainment • Marketing Tech • Generative AI • Enterprise Web • Digital Media • Consumer Web
San Francisco, CA
14 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account