Security Engineer Lead

About:

Macy’s is proudly America’s Department Store. For more than 160 years, Macy’s has served generations at every stage of their lives. Customers come to us for fashion, value and celebration. Now is an exciting time to join Macy’s, Inc. The face of retail is changing, and change requires innovation.

Macy’s Tech provides modern tools, platforms, and services to all parts of the business. Our team supports millions of customers in connected commerce across the technology hub at Macy’s Join our team to help shape the future of e-commerce and set the pace in retail technology. Whether focused on store technology, supply chain tech, application security, merchandising systems, or the mobile app – you’ll have opportunities to grow your career while finding meaningful ways to make a difference.

Job Overview:

The Lead, Security Incident Response Engineer will monitor and investigate normal and escalated security events to determine risk and exposure and perform additional forensics investigations to understand impact and mitigation. This position will mentor other Engineers as a technical leader and work closely with them to manage & resolve multiple incidents simultaneously and prioritize based on risks. This is a position for an experienced Security Engineer that will receive minimal supervision from management and will be required to lead and make decisions on day to day activities and forensics investigations. This position will be required to have good written and oral communication skills to present the results of the technical analysis and research of each incident or investigation.

The Lead, Security Incident Response Engineer should have experience and understanding of multiple security platforms and layers including Anti-virus, Firewalls, Proxy servers, Intrusion Prevention Systems, Logging Correlation/management, Operating systems, Protocols and Incident Response. Perform other duties as assigned.

Essential Functions:

The Lead, Security Incident Response Engineer makes decisions based on security events and situations that arises and will make final recommendations to management based on actions taken, incident status and potential exposure and/or risks. The Engineer will continue to be engaged with management to provide updates and status to help clarify any decision that is needed to be made about a current security incident or risk exposure. The Lead SRE will make decisions and recommendations on implementing and improving standard operating procedures as impact to improve efficiencies. The Lead SRE will be involved with any and all proof of concept product testing to deciding how the product/tool can be integrated into daily activities, forensics investigations and how it impacts the team. The Lead SRE will make the decision for junior Engineers on whether a security event is a false positive or real security incident.

  • Responds to escalated security events or incidents and implements counter-measures to reduce and/or mitigate further exposure. The Engineer performs triage on events which are reported by various detection devices to filter out things such as false positives and known accepted activities.
  • Leads and manages security investigations from discovery to resolution and works as an incident response manager for each security incident.
  • Creates reports to display trends and overall statistics based on correlated security incidents and event data to produce monthly exception and management reports.
  • Responsible for mentoring, training and support of Level 1and 2 Engineers.
  • Creates and implements standard operating procedures and processes to help streamline investigations, daily monitoring and analysis research to ensure all analysts are effective and following the same guidelines.
  • Consistently demonstrates regular, dependable attendance and punctuality.

Qualifications and Competencies:

  • Bachelor’s Degree from a 4-year college or university
  • 5+ years direct experience
  • Experience working with Host Security Event Logs.
  • Working knowledge of Host or Network based Honeypots.
  • Have an understanding and working knowledge of regulatory and audit mandates to ensure environments meet PCI, FFIEC, SOX and corporate standards.
  • Understanding of web applications authentication, session management, requests, form submission processes.
  • Ability to identify common network and web site attacks such as SQL injection, cross site scripting, remote file inclusion and cookie manipulation.
  • Ability to decode and understand netflow and traffic flow at packet level traces (skilled with TCPDUMP, PCAPs, traffic generators, etc.).
  • Knowledge or skill to create correlation rules to detect threats.
  • Ability to understand, analyze and correlate security events and implement counter-measures to mitigate against intrusion attacks.
  • Maintaining security monitoring and reporting appliances in addition to leading and analyzing security reporting.
  • Experience or working knowledge of various networking devices and/or technologies like routers, switches and aggregators.
  • Have experience with using or managing SIEM technologies.
  • Strong knowledge of TCP/IP, HTTP, FTP, cookies, authentication, virus scanning, web servers, SSL/encryption and reporting packages.
  • An understanding of a wide array of server grade applications to include Lotus Notes, Exchange, DNS, SMTP, IIS, Apache, SharePoint, Active Directory, Identity Management, Patch Management, LDAP, SQL, and others.
  • Experience with a host based FIM (File Integrity Monitoring) solutions.
  • Experience or working knowledge of Authentication technologies like Radius or Tacacs.
  • Working knowledge of Two-Factor Authentication solutions.
  • Working knowledge of Intrusion Detection Systems/Technologies.
  • Practices open and continuous communication, values keeping others informed, effectively presenting information in a clear, concise manner.
  • Excellent leadership, facilitation, and interpersonal skills, with the ability to work across functional lines and at many levels.
  • Ability to think creatively, strategically and technically
  • Ability to work a flexible schedule based on department and Company needs.

TECH00

More Information

Apply for this job

Leave your thoughts

Share this job