Swoon · 15 hours ago
Cyber Security Engineer
Swoon is seeking a Senior Cybersecurity Engineer to support Cat Technology in the Autonomy & Automation Business Unit. The role involves providing thought leadership in embedding cybersecurity into products, solutions, and services while collaborating with various business teams to execute strategic cybersecurity initiatives.
ConsultingHuman ResourcesInformation TechnologyLegalStaffing Agency
Responsibilities
Integrate and collaborate with DT&D business partners to ensure understanding of key business strategies and challenges
Provide cybersecurity expertise and leadership in defining, prioritizing, and executing key initiatives that deliver cyber safe solutions and enable business strategy
Evaluate solutions and identify technical and process improvements that deliver alignment with secure SDLC & DevSecOps best practices and Caterpillar Information Security Directives
Assist in solution architecture development/documentation and perform architecture security reviews
Provide technical and process expertise associated with cyber governance, risk, and compliance activities
Drive the remediation of known vulnerabilities while developing and executing strategies that deliver operationally sustainable vulnerability management
Identify, track, and report key cyber metrics to business unit stakeholders
Develop/own documented strategies to address key cyber risk areas
Maintain current knowledge on existing security procedures, directives and technology controls including secure application architecture, threat modeling, attack and penetration testing, data classification and data handling
Participate in working groups and provide insights into solution development teams on leading architecture, design, and security practices
Qualification
Required
Bachelor's degree with 10+ years experience in this capacity OR Master's degree with 8+ years experience in this capacity
8-10+ years in information security or solution development/engineering
Experience with relevant industry standards, such as: EU-CRA, ISO 27001, NIST CSF, NIST 800-82, ISA 62443, OWASP
Experience with a wide variety of information security processes and principles, such as: Power BI, Application architecture and DevOps tooling, Connected Asset Security, Developing and deploying services within cloud platforms, Integration and automation of security into SDLC and CI/CD development processes, Threat modeling & Risk analysis, Vulnerability assessment and remediation, Identity and Access Management standards and best practices, Defense in depth, Embedded systems security, Networking concepts on-prem and cloud, API & Web services security
Professional information security certification (CISSP, CCSP, CSSLP, GISCP, GPEN, GWEB, etc.)
Excellent written and verbal communications skills; demonstrated ability to communicate highly technical security concepts to non-security audiences
Ability to adjust to multiple demands, changing priorities, ambiguity, and rapid change, while multitasking effectively
Ability to coordinate multiple teams in accomplishing process review and improvement
Demonstrated ability in project management and change management
Demonstrated ability to develop metrics, perform critical analysis and develop executive decision support content
Effectiveness Measurement: Knowledge of effective measurement techniques and ability to measure the quality and quantity of work effort for the purpose of improvement
Planning: Tactical, Strategic: Knowledge of effective planning techniques and ability to contribute to operational (short term), tactical (1-2 years) and strategic (3-5 years) planning in support of the overall business plan
Analytical Thinking: Knowledge of techniques and tools that promote effective analysis; ability to determine the root cause of organizational problems and create alternative solutions that resolve these problems
Consulting: Knowledge of techniques, roles, and responsibilities in providing technical or business guidance to clients, both internal and external; ability to apply consulting knowledge appropriately
Decision Making and Critical Thinking: Knowledge of the decision-making process and associated tools and techniques; ability to accurately analyze situations and reach productive decisions based on informed judgment
Technical Excellence: Knowledge of a given technology and various application methods; ability to develop and provide solutions to significant technical challenges
Information Security Administration: Knowledge of information security administration; ability to develop and apply an organization's information security policies, standards and procedures ensuring the integrity and safety of information
Benefits
Optional benefits
401K
Company
Swoon
In 2010, Swoon launched an agile, client-focused team that is not only savvy in our core industries but elbow-deep, every day, getting to know the strongest talent in the technology and professional fields.
H1B Sponsorship
Swoon has a track record of offering H1B sponsorships. Please note that this does not
guarantee sponsorship for this specific role. Below presents additional info for your
reference. (Data Powered by US Department of Labor)
Distribution of Different Job Fields Receiving Sponsorship
Represents job field similar to this job
Trends of Total Sponsorships
2023 (2)
2022 (1)
2021 (1)
2020 (1)
Funding
Current Stage
Late StageCompany data provided by crunchbase