Job Details

ID #21756980
State Pennsylvania
City Philadelphia
Job type Permanent
Salary USD TBD TBD
Source ConsultNet, LLC
Showed 2021-10-27
Date 2021-10-26
Deadline 2021-12-24
Category Security
Create resume

IoT Security Engineer

Pennsylvania, Philadelphia, 19019 Philadelphia USA

Vacancy expired!

Job Description

Job Title: Principal IoT Security Engineer Location: Philadelphia, PA, Houston, TX or fully remote in USA Status: Full-time job Our client, a global leader in SaaS and Data Analytics supporting the property management industry, is looking for a IoT Security Engineer. While you will be able to work from home during the peaks of the pandemic, the team is going into the office during better times. So candidates who reside in Philadelphia or Houston are preferred. As the Internet of Things (IoT) Security Engineer for a start-up business unit inside a 30 year old company, you will partner with the Chief Information Security Officer (CISO) and the IoT device business unit to plan, organize and conduct security assessments and risk mitigation plans for our use of IoT technologies. Your focus will be tailored to broad risk assessment for deployed IoT technologies in operational environments to ensure secure use by a broad set of clients and customers (think apartment renters and property management companies).As you lead these capabilities, you will also articulate a shared vision of best in class IoT security and compliance programs to best leverage technology, people and processes to protect the corporation from threats that may attempt to harm their IoT based businesses. In this role, you will do the following:
  • Report to the CISO and directly support the business unit leading IoT efforts to ensure secure operational deployments of IoT capabilities.
  • Partner with leadership to govern IoT cybersecurity and risk posture of the IoT business unit.
  • Provide leadership with risk managed remediation plans to address identified risk in IoT capabilities.
  • Partner with existing business unit team to support application security capabilities to include static and dynamic testing. Ensure effective reporting and risk managed remediation actions occur.
  • Assess/manage third party/supply chain risk that may impact secure deployment of IoT capabilities.
  • Build and maintain effective relationship with not only technical teams but business units as well.
  • Deliver targeted security and risk communications (verbal and written)to business leadership
  • Contributeto the development and implementation of IoT security architecture, and the design of Information Security service and processes supporting the IoT business unit.
  • Advise stakeholders on how to achieve the relevant controls and assist with solutions to support them.
  • Ensure that processes are documented and communicated in language that is relevant and understandable to non-technical audiences as well as to be implementable by technical teams.
  • Any other duties relating to the remit of a role of this standing as required by the needs of the business.
REQUIRED KNOWLEDGE/SKILLS/ABILITIES
  • Bachelor's degree and minimum 5 years of experience in Information Security, Information Assurance and/or Cyber Security space.Relevant experience and professional certifications may be considered in lieu of a degree.
  • Experience in embedded/IoT device security or web services security specifically, with experience of performing threat modeling,software security audits,risk management,vulnerability discovery and analysis.
  • Experience with Linux, Cloud platforms (AWS, Azure, or GCP), Kubernetes, Docker, or other container platforms
  • Experience in the information security field designing and implementing enterprise security solutions.
  • Experience with common software and system security vulnerabilities and methods of exploitation to include memory corruption, privilege escalation, web application exploitation, file format vulnerabilities, protocol-based weaknesses,access control weaknesses.
  • Excellent verbal and written communication skills with a wide range of audiences including technologists, executives, business stakeholders and IT team members.
  • Must be a critical thinker with strong problem-solving skills.
  • High level of personal integrity, and the ability to professionally handle confidential matters and show an appropriate level of judgment and maturity.
  • High degree of initiative, dependability and ability to work with little supervision.
  • Ability to think at systems / architecture level I.e. How do all the parts of the solution fit together not just design at element level.
  • Interest and predisposition to learn new systems and technologies.
  • Knowledge of common wireless connectivity protocols with focus on protocol and implementation security vulnerabilities (e.g.Bluetooth,WiFi, 802.15.4,ZWave, ZigBee, LoRA)
PREFERRED KNOWLEDGE/SKILLS/ABILITIES
  • Advanced degree in applicable field
  • Knowledge of hardware security mechanisms, including secure boot, trusted execution environments
  • Experience with static and dynamic tools for vulnerability detection and exploit mitigation techniques,
  • Interest in industry conferences or meet-ups such as Defcon, B-sides, etc.
  • Cyber security risk management experience,e.g.conducting assessments, identifying risks, and recommending solutions.
  • Professional information security certification, such as a CISSP, CRISC, CISA, etc.
  • Expertise with NIST and ISO 27000 series, particularly NIST SP 800-53, NIST SP 800-171, ISO 27001/2.
Be a part of the ConsultNet difference. As a leading national provider of IT staffing and solutions, ConsultNet delivers exceptional services to startup, midmarket and Fortune 1000 companies across North America. Since 1996, we've partnered with clients to create rewarding opportunities for our consultants, successfully building teams that have surefire results. In the past two years alone, we have placed more than 1,500 consultants in contract, contract-to-hire, or direct placement opportunities. We understand communication is key to finding the right job that matches your skills and career goals. For us, it's not just the work that we do; it's how we do the work. Our breadth of offerings extends to multiple IT positions in major markets throughout the country, see more at - www.consultnet.com

Vacancy expired!

Subscribe Report job