About this opportunity
Quest Diagnostics lists this Principal Engineer, IT Security opportunity in secaucus, New Jersey. Review the employer’s description below for duties, qualifications and application requirements.
Job description
Job Description
We are seeking a Senior Security Engineer to champion the security, integrity, and compliance of our global infrastructure. In this high-visibility role, you will act as a strategic bridge between deep technical execution and executive-level governance, routinely interfacing with Senior Leadership and the CIO to present risk postures, security metrics, and SLA compliance. Balancing multi-disciplinary expertise across host and network security, with a sharp specialization in vulnerability management, you will drive critical initiatives to help drive a more robust asset management framework and lifecycle refresh programs (maintaining N/N-1 standards), and accelerate system decommissions to minimize our attack surface. You will also sit on our Security Review Board to assist with security architecture reviews for IT initiatives throughout the company. On the operational front, you will provide direct assistance in maintaining an uncompromising, pristine security posture in both appearance and reality. This includes incorporating the outputs of various tools in our cloud and datacenter environments, establishing direct, collaborative relationships with Firewall and Infrastructure Operations teams, and prioritizing the remediation of confirmed vulnerabilities over potential ones to systematically reduce true risk. As a core representative on the Vulnerability Council, and Security Review Board (SRB), you will drive the security messaging, synthesizing SRB findings, vulnerability reporting and exception data into a unified, accurate narrative. The Principle IT Security Engineer also must support the continual improvement of our IT security infrastructure. The person in this position will be a thought leader in the IT organization and considered a subject matter expert in multiple security-related areas as well as in the field of IT Security and or risk overall. This position requires advanced security expertise. Additionally, strong written and oral communication skills are important for this role. To maintain our security posture, this position may occasionally collaborate on after-hours or weekend response for high-priority security events.
Please note this is a hybrid opportunity (3 days in office & 2 days WFH). This position can be based in Secaucus, NJ or Schaumburg IL.
Pay Range: $160,000 - $170,000 / year
Benefits Information
Day 1 Medical, supplemental health, dental & vision for FT employees who work 30+ hours
Best-in-class well-being programs
Annual, no-cost health assessment program Blueprint for Wellness®
healthyMINDS mental health program
Vacation and Health/Flex Time
6 Holidays plus 1 "MyDay" off
FinFit financial coaching and services
401(k) pre-tax and/or Roth IRA with company match up to 5% after 12 months of service
Employee stock purchase plan
Life and disability insurance, plus buy-up option
Flexible Spending Accounts
Annual incentive plans
Matching gifts program
Education assistance through MyQuest for Education
Career advancement opportunities
and so much more!
Responsibilities
Develops security and or risk strategies and solutions to improve, augment and enhance the posture of IT Security at Quest Diagnostics.
Advise on and/or support a variety of security tools. These may include products and tools in various areas including: network vulnerability scanning, application vulnerability scanning; network and application access controls; intrusion detection systems; data loss prevention, security incident and event management (SIEM), etc.
Assists in the review and alignment of applicable IT security SOP’s.
Periodically reviews and updates corporate IT Security standards and procedures as required by such changes in technologies, business activities, corporate policies and/or regulations.
Work with IT leadership and the business to develop strategies and plans to enforce security requirements and address identified risks.
Is a subject matter expert in multiple areas of IT Security including the field of IT Security and or risk overall, and provides technical guidance on any IT projects.
Develops and maintains detailed knowledge of security products, tools, regulations, best practices, and trends.
Reports to IT management concerning risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
Plays a consultative role in security aspects of application development and lead security role in acquisition/merger projects to assess security requirements and controls and to ensure that security controls are implemented as planned.
Collaborates on critical IT projects to ensure that IT security issues are addressed throughout the project life cycle.
Fully understand security policies, standards, processes and procedures, and supports service-level agreements (SLAs) to ensure that security controls are managed and maintained.
Researches, evaluates and recommends IT and information-security-related hardware and software, including developing business cases for security investments.
Assumes highly visible technical project management role.
Manages relationships with key IT Security product and service vendors.
Provide oversight and expertise to assist in deployment, configuration, and maintenance of our suite of security tools.
Works closely with Enterprise Architecture in the overall design and implementation of security solutions.
When appropriate represents IT Security to Senior IT Management and customers
Qualifications
Required Work Experience:
Minimum 10 years’ experience with the implementation and support of an IT Security program including: aspects of security design and engineering; threat and vulnerability management; data protection; incident management and response; application security development, testing and assessments; and security management,
This person should be able to perform a variety of technical tasks, including, for example, the installation of security software, configuration of software, and problem determination and resolution.
Preferred Work Experience
Minimum 10 years’ experience with the implementation and support of an IT Security program including: aspects of security design and engineering; threat and vulnerability management; data protection; incident management and response; application security development, testing and assessments; and security management.
Skills
Demonstrated ability in defining and/or evaluating security requirements and relate them to appropriate security measures and controls.
Ability to interact with company personnel at all levels and across all business units and organizations, and to comprehend business imperatives.
Strong leadership abilities, with the capability to develop an IT security team and guide team members and to work with only minimal supervision.
Sound communications skills, including both oral and written, are important for the candidate to be successful in this role.
Creativity
Timely Decision Making
Peer Relationships
Problem Solving
Intellectual Horsepower
Decision Quality
Directing Others
Presentation Skills
Communication Skills
Education
Bachelor’s Degree B.A. or B.S. Degree or equivalent education and experience required (Preferred)
Master’s Degree Specialized education and/or training in information security highly desirable (Preferred)
Licenses and Certifications
Certified Information Systems Security Professional (CISSP) (Preferred)
GIAC Security Expert (GSE) (Preferred)
Systems Security Certified Practitioner (SSCP) (Preferred)
About The Team
Quest Diagnostics honors our service members and encourages veterans to apply.
While we appreciate and value our staffing partners, we do not accept unsolicited resumes from agencies. Quest will not be responsible for paying agency fees for any individual as to whom an agency has sent an unsolicited resume.
Equal Opportunity Employer: Race/Color/Sex/Sexual Orientation/Gender Identity/Religion/National Origin/Disability/Vets or any other legally protected status.
#J-18808-Ljbffr
Worksite address
secaucus, NJ, 07094, US
Who can apply
Review the original listing for work authorization, qualifications and employer requirements.