
Senior Security Manager (Security Engineering & Tooling)
- Bethesda, MD
- Permanent
- Full-time
- 1. Build a high performing team by hiring and nurturing security talent.
- a. Security Tool Management: Should have overseen the evaluation, deployment, and maintenance of security tools, including but not limited to SIEM, IDS/IPS, DLP, vulnerability management tools, endpoint protection, and threat intelligence platforms.
- b. Technical Expertise: Hands-on experience with a wide range of security tools such as SIEM, EDR, vulnerability management platforms, firewalls, intrusion detection systems, and automation platforms (SOAR).
- c. Cloud Security Tooling: Familiarity with cloud-native security tools (e.g., AWS Security Hub, Azure Sentinel) and securing cloud environments.
- d. Automation and Optimization: Should have identified opportunities to automate security processes and improve operational efficiency through better use of security tooling. Proficiency with automation tools and scripting languages (e.g., Python, PowerShell) to automate security processes.
- a. Leadership: Proven ability to lead and mentor a technical security team and manage complex projects involving security tool deployment and management.
- b. Problem Solving: Strong analytical and troubleshooting skills, particularly related to the performance and configuration of security tools.
- a. Tool Integration: Should be able to work with IT, cloud, and engineering teams to integrate security tools into the organization's infrastructure, ensuring seamless interoperability between different systems and platforms.
- b. Vulnerability Management: Implemented and managed tools for continuous vulnerability scanning and patch management, ensuring vulnerabilities are identified, reported, and remediated in a timely manner.
- a. Collaboration: Collaborated with other security functions such as GRC (Governance, Risk, and Compliance), security operations, and application security to ensure tooling supports broader security objectives.
- b. Communication: Excellent verbal and written communication skills, with the ability to explain technical concepts to non-technical stakeholders.
- BS (or higher) in Computer Science, Cybersecurity, Engineering, or equivalent experience
- 10+ years of experience in designing, building, or operating data protection services
- 5+ years of building and leading highly complex, technical security teams
- Vendor Management: Experience working with and managing relationships with security vendors, including negotiation of contracts, ensuring SLA compliance, and keeping tools updated with the latest features and patches.
- Monitoring and Reporting: Led the design and development of security dashboards, ensuring real-time visibility into the organization's security posture. Implement alerting and reporting mechanisms to provide actionable insights to stakeholders.
- Incident Detection and Response: Ensured security tooling is effectively configured to detect and respond to security incidents. Continuously improve detection capabilities and reduce false positives.
- Tooling Lifecycle Management: Maintained an inventory of security tools and managed their lifecycle, including regular evaluations to ensure they remain effective and up-to-date.
- Research and Development: Stay abreast of the latest trends and advancements in security tooling, and recommend new tools or technologies that could enhance the organization's security posture.
- Sitting for prolonged periods of time. Extensive use of computers and keyboard. Occasional walking andlifting may be required.