Purpose of Job
The CTOC is USAA’s equivalent to a Security Operations Center (SOC). The CTOC exists to detect, analyze, and respond to cyber security events. The CTOC is comprised of several teams, all reporting to the AVP of IS Engineering & Cybersecurity. These teams are individual units that partner as needed to provide centralized and coordinated response activities.
We are seeking a versatile AWS Cloud Security Engineer Lead to join our Public Cloud Security team.
USAA values a culture that is highly collaborative, and we have found that a hybrid work type helps employees gain the best of both worlds – collaborating in-person in the office and working from home when needed to achieve focused results. The actual days’ onsite are resolved between each employee and the employee’s manager. This position may also have the option of working remotely in the U.S. or at one of our office locations: San Antonio, Plano, Phoenix, Colorado, and Tampa.
This job profile is designated as a Sensitive Position. Sensitive Positions are those positions in which individuals have the authority and ability to conduct in-scope activities (movement of USAA or Member funds) as defined within the Enterprise Sensitive Positions Mandatory Time-Away Compliance Policy. Employees in Sensitive Positions are required to fulfill a Mandatory Time-Away (MTA) requirement of 10 consecutive business days each calendar year.
USAA knows what it means to serve. We facilitate the financial security of millions of U.S. military members and their families. This singular mission requires a dedication to innovative thinking at every level.
About USAA IT
Our most meaningful qualification isn’t technical, it’s human. Here, we don’t just sit in front of a screen. We stand behind our 13 million members who rely on us every day.
We’re proud of USAA’s strong history — and we’re even more passionate about our future. That’s why we have a team of supportive and collaborative hardworking technology professionals focused on doing more for our members. And why we’re continuing to add innovative problem solvers to our team. With us, you’ll find exciting challenges that inspire you to continue learning and growing.
- Identifies and manages existing and emerging risks that stem from business activities and the job role.
- Ensure risks associated are effectively identified, measured, monitored, and controlled.
- Follows written risk and compliance policies and procedures for business activities.
- Influences and leads team efforts across the Information Security department and enterprise as a subject matter expert in their domain.
- Researches and analyzes the latest capabilities of specific Information Security (e.g. Cloud services, encryption, PKI etc.) and IT technologies (e.g. operating systems, networks, storage, virtualization etc.).
- Considered an expert in the USAA implementations of these technologies.
- Reviews, interprets, and resolves disputes for Information Security baselines for specific technologies (e.g. operating systems, databases).
- Leads the operations and maintenance for hardware and software of Information Security solutions and technologies (e.g. firewalls, intrusion prevention (IPS), web application firewalls (WAF), web proxies).
- Initiates vendor roadmap discussions and feature requests.
- Consults with Architects to plan future technical solutions.
- Monitors and troubleshoots highly complex systems, tools and/or networking solutions.
- Performs investigative research, analysis and troubleshooting to identify, resolve, and report highly complex security issues.
- Collaborates with Security Analysts to tune and enhance Information Security solutions and technologies to keep up with the latest threats.
- Guides the development of code/scripts/automation written to detect or prevent new threats that do not have commercial solutions available yet or to automate Information Security processes to increase efficiencies.
- Designs and develops new tools/technologies as related to Information Security and shares them with the community.
- Drives and directs quality work efforts.
- Serves as the primary resource for cross-functional team members on escalated issues of a unique nature.
- Maintains expert level knowledge of USAA Information Security standards as well as industry information security best practices, frameworks, laws and regulations.
- Bachelor’s degree OR 4 additional years of related experience beyond the minimum required may be substituted in lieu of a degree.
- 8 years of related experience in Information Security, Cybersecurity, Identity and Access Management (IAM) and/or Information Technology with a security focus to include accountability for complex tasks and/or projects.
- 6 years of related experience in AppSec, Cloud, Firewall, Web Proxies, Web Application Firewall, Intrusion Prevention Systems (IPS/IDS), Mainframe, Windows, Linux, Apple, Security Information and Event Management (SIEM), Identity and Access Management engineering and/or Security Orchestration, Automation, and Response (SOAR) solutions.
- Expert level of business acumen in the areas of business operations, risk management, industry practices and emerging trends.
- Advanced troubleshooting skills. (Packet analyzer a plus)
- Programming or scripting experience (Python or PowerShell preferred).
When you apply for this position, you will be required to answer some initial questions. This will take approximately 5 minutes. Once you begin the questions you will not be able to finish them at a later time and you will not be able to change your responses.
- Experience leading the adoption/migration of AWS cloud native technologies
- Experience designing, implementing, and leading cloud security concepts and DevOps practices
- Experience with containers and container orchestration platforms like Kubernetes
- Experience working with a scripting language like Python or Golang in a large codebase
- Experience with administration of Linux operating systems
- Experience working with open source solutions like cloud native SDKs/boto3
- Experience working with platform engineers on security best practices in Infrastructure as Code, cloud design patterns, and CI/CD with built in application security controls
- Experience leading the implementation of event driven security architecture, methods, and controls
- Experience developing and maintaining documentation for cloud security systems, procedures, baselines, and best practices
The above description reflects the details considered necessary to describe the principal functions of the job and should not be construed as a detailed description of all the work requirements that may be performed in the job.
USAA has an effective method for assessing market data and establishing ranges to ensure we remain competitive. You are paid within the salary range based on your experience and market position. The salary range for this skill is: $117,600 – $211,700
Employees may be eligible for pay incentives based on overall corporate and individual performance or at the discretion of the USAA Board of Directors.
Geographical Differential: Geographic pay differential is additional pay provided to eligible employees working in locations where market pay levels are above the national average.
Shift premium: will be addressed on an individual-basis for applicable roles that are consistently scheduled for non-core hours.
At USAA our employees enjoy best-in-class benefits to support their physical, financial, and emotional wellness. These benefits include comprehensive medical, dental and vision plans, 401(k), pension, life insurance, parental benefits, adoption assistance, paid time off program with paid holidays plus 16 paid volunteer hours, and various wellness programs. Additionally, our career path planning and continuing education assists employees with their professional goals.
Please click on the link below for more details.
Relocation assistance is Not Available for this position.
- Salary Offer 117,600 - $211,700
- Address Charlotte, NC, USA
- Experience Level Senior
- Total Years Experience 10-20