Job Description
Job Description
The Security Design and Controls Team (SecDesign) team is part of the Cyber Data Risk & Resilience (CDRR) organization. The mission of the SecDesign team is to provide security architecture assessments of technology systems and processes to identify business risks and recommend remedial action based on established security standards or security best practices. The SecDesign Generalist is an internal consultant that is working on multiple security architecture and design assessments spanning multiple classes of technologies. It is an opportunity to get involved in multiple business units and technologies inherent to the mission of SecDesign. The Integrator works with team members (Technology, Business, Suppliers, Stakeholders and Partners) globally to perform SecDesign assessments. To be successful as an Integrator the candidate must have broad technology experience coupled with risk management, communication, and time management skills. The candidate will also be working with a global team of experts on modernizing the Firm’s SDLC platform to enable deployment automation to private and public cloud endpoints and SaaS-based tooling. This role affords the opportunity to get in on the ground floor to help build the next generation of development and deployment tooling across a diverse set of tech stacks for the next decade.
A SecDesign Generalist has the following responsibilities:Security Architecture Skills:
1. Required: In depth knowledge of application, network, and platform security vulnerabilities. Ability to explain these vulnerabilities to developers.
2. Required: Experience in conducting Information Security, IT Security, Audit assessments. Presenting the outcomes of the assessment and obtaining buy in.
3. Required: Strong focus on reviewing technical designs and functional requirements to identify areas of Security weakness.
4. Required: Knowledge of Cloud Service Providers (AWS/Google/Azure) cloud, DevOps and CI/CD
5. Required: The candidate must have working experience in at least three of the following application/network security domains:
a. Authentication: SAML, SiteMinder, Kerberos, OpenId
b. Entitlements and identity management
c. Data protection, data leakage prevention and secure data transfer and storage
d. App Security – validation checking, software attack methodologies.
e. Cryptography: encryption and hashing
6. Desired – Prior experience administering systems for version control (Bitbucket, Github), issue tracking
SecDesign Generalist • Montreal Quebec, Canada