
IT Security Engineer
- Irvine, CA
- $125,000-150,000 per year
- Permanent
- Full-time
- Conduct penetration tests against Kia America's corporate web/business applications, servers, APIs, mobile apps, networks, cloud environments and connected cars.
- Create detailed technical reports describing discovered vulnerabilities, approach taken to identify them, method to duplicate findings, vulnerability risk level and recommendations to mitigate the risks.
- Oversee, or perform, all penetration test phases (Reconnaissance, Scanning, Vulnerability Assessment, Exploitation, Remediation and Reporting)
- Stay current on new and emerging security threats and the security tools and methods necessary to mitigate them.
- Establish security incident response policies and procedures and conduct regular training.
- Conduct table-top exercises to verify incident response procedures and documentation are effective.
- In the event of a security event, lead the efforts to analyze logs and investigate details of the event to take appropriate actions
- Bachelor's degree or comparative experience with emphasis on information security
- Advanced degree and/or certification(s) in cyber security a plus
- 8+ years of experience in an organization with mature security practices
- 3+ years of experience in conducting hands-on security penetration tests and vulnerability management. Experience working on Red Teams to identify vulnerabilities with Internet facing business systems is preferred.
- 3+ years of experience within information security incident response, cybersecurity, and/or IT risk management
- Experience with conducting penetration testing on vehicles a plus
- Substantial experience, and successes, in CTF competitions and/or bug bounty programs.
- Familiar with security related regulations and compliance requirements
- Familiar with the information security auditing process and evidence collection
- Must be proactive, self-motivated, and lead team to multiple concurrent solutions.
- Skilled in leading cross-functional teams in responding to security events
- Deep knowledge of IT and security infrastructure (Networks, Server HW & SW, Security Components (FW, IPS, IDS, EDS, etc.)
- Skilled with automation and scripting (Python)
- Advanced level of expertise with penetration testing tools (Burp Suite, Kali Linux, Metasploit, John the Ripper, Nmap, Wireshark, OWASP ZAP, Aircrack-ng, Tenable Nessus, and others)
- Skilled in identifying application vulnerabilities (OWASP) and advising application teams on how to remediate them
- Ability to manage external vendors in the development and delivery of related products, programs, and services.
- Excellent customer service ability and strong verbal and written communication skills
- Expert level knowledge and understanding of the attack chain, adversary tactics, techniques, and procedures, emerging threats and vulnerabilities.
- Expert level knowledge of SIEM's, how they work, how their value can be maximized and leveraged to mature monitoring and detection processes.
- Requires high-level organizational, planning, analytical, and technical skills.
- Care for People
- Chase Excellence Every Day
- Dare to Push Boundaries
- Empower People to Act
- Move Further Together