Talent.com
Senior IT Security Engineer
Senior IT Security EngineerLos Angeles Times • El Segundo, CA, United States
Senior IT Security Engineer

Senior IT Security Engineer

Los Angeles Times • El Segundo, CA, United States
3 days ago
Job type
  • Full-time
Job description

The Senior IT Security Engineer will assess, recommend, and maintain a robust information security infrastructure and ensure the company's adherence to policy compliance, such as Payment Card Industry Data Security Standards (PCI DSS). This position involves conducting thorough and independent assessments of the management, operational, and technical security protocols across the company's cloud and on-premise Information Technology (IT) infrastructure. This position oversees project management for security initiatives, manages relationships with managed information security providers, and ensures the effectiveness of current cybersecurity measures. This role will oversee risk management, ensure vulnerability compliance and reporting, handle internal controls, and contribute to IT optimization efforts.

Responsibilities :

  • Oversee the Managed Security Services Provider (MSSP), ensuring their services and performance delivery are consistent with our published SLAs.
  • Conduct internal assessments and audits to ensure compliance with the most recent PCI DSS and other relevant security standards.
  • Collaborate with various departments to identify, evaluate, and mitigate vulnerabilities and risks in payment card processing environments.
  • Develop, maintain, and update a comprehensive PCI compliance program, including policies, procedures, and documentation.
  • Oversee the management of security infrastructure and ensure its robustness against potential threats
  • Provide guidance and support to business units and IT teams on implementing secure payment card processing practices.
  • Liaise with external Qualified Security Assessors (QSAs) during annual PCI DSS assessments and facilitate the remediation of any identified gaps.
  • Train and educate staff on PCI DSS requirements and best practices for protecting cardholder data.
  • Track updates to PCI DSS standards and ensure timely implementation of required updates and changes within the organization.
  • Prepare Reports on Compliance (ROCs) and Self-Assessment Questionnaires (SAQs) for annual reporting on the Company's status to the Payment Card Industry Data Security Standard (PCI-DSS).
  • Present and obtain Senior IT Management approval of process improvements and implement process modifications successfully.
  • Determines whether company information systems comply with existing policies, standards, architectures, procedures, laws, regulations, and other requirements.
  • Generate and audit monthly vulnerability reports, quarterly network scans, and bi-annual penetration tests to ensure compliance and remediation tasks and activities are completed within SLA periods.
  • Work collaboratively with Application Support, Network Infrastructure, Enterprise Architecture & DevOps, Product & Program Management, Data Science, Digital Engineering, and IT Operations teams.
  • Work with the legal department to develop and maintain IT Security Compliance and Governance contract provisions for external service providers and vendors.
  • Perform quarterly follow-up activities to report on status and / or mitigation completion.
  • Assist in the development and maintenance of a robust incident response plan for security breaches and incidents involving cardholder data.
  • Generate regular reports on compliance status, security assessments, and remediation efforts for senior executive management and relevant stakeholders.
  • Participate in security and compliance projects as required.
  • Perform other tasks as assigned

Requirements :

  • Bachelor's degree in Information Technology, Information Security, Computer Science (or a related field), and 8+ years of experience in information security, with specific experience in PCI DSS compliance OR 10+ years of experience in information security, with specific experience in PCI DSS compliance.
  • 6+ years of experience with security tools and technologies used for information security and compliance monitoring.
  • Expert knowledge of information security principles, vulnerability scanning, remediation, reporting, data protection laws, and payment industry standards.
  • Excellent analytical, problem-solving, and decision-making skills.
  • Adaptable communicator tailoring messages for diverse audiences.
  • Detail-oriented with the ability to manage multiple tasks and projects simultaneously.
  • In-depth understanding and experience in IT governance, risk management, and compliance software tools.
  • Advanced knowledge of IT security principles, including those that apply to cloud infrastructure (Azure, AWS, Google Cloud), network, database, application security, firewalls, multi-factor authentication mechanisms, and identity and access management.
  • Adept at the application of technical understanding of the following areas : Access and Authentication, Data Security, Secure Software Development, Infrastructure and IT Operations, Boundary Protection, Vulnerability Management, Business Continuity, and Disaster Recovery.
  • Ability to work independently and within a team to accomplish assigned tasks timely and accurately.
  • Demonstrated work ethic and professionalism.
  • Preferred Qualifications :

  • Professional certifications such as PCI ISA (Internal Security Assessor), PCIP (PCI Professional), CISSP (Certified Information Systems Security Professional), CISM, CISA (Certified Information Systems Auditor), CIS, NIST, HIPAA are highly desirable
  • The L.A. Times is an equal opportunity employer and welcomes all qualified applicants regardless of race, ethnicity, religion, gender, gender identity, sexual orientation, disability status, protected veteran status, or any other characteristic protected by law. We actively work to create an inclusive environment where all of our employees can thrive. This Privacy Notice for Los Angeles Times sets forth how we will use the information we obtain when you apply for a position with us . E xplore our company history, achievement, values, mission and more on our career site .

    The pay scale the Company reasonably expects to pay for this position at the time of the posting is $145,000 to $160,000 and takes into account a wide range of factors including but not limited to skill set, experience, training, licenses, certifications, and other business or organizational needs. Compensation will be determined based on the above factors along with the requirements of the position. At the L.A. Times, it is not typical for an individual to be hired at or near the top of the range for the role. Please visit our career site to view the benefits available to our employees. We recommend adding our applicant tracking system domain (@dayforce.com) as a safe sender or contact, sometimes these emails get filtered to candidates' spam folders.

    Create a job alert for this search

    It Security Engineer • El Segundo, CA, United States

    Related jobs
    Compliance and Security Engineer

    Compliance and Security Engineer

    VirtualVocations • Long Beach, California, United States
    Full-time
    A company is looking for a Compliance and Security Engineer.Key Responsibilities Conduct vulnerability scans and analyze results to drive remediation planning Operate enterprise SIEM solutions a...Show more
    Last updated: 2 days ago • Promoted
    Senior Authentication Engineer

    Senior Authentication Engineer

    VirtualVocations • Fullerton, California, United States
    Full-time
    Key Responsibilities Design, implement, and optimize secure authentication workflows and manage identity federation and SSO integrations Support multi-factor and passwordless authentication solu...Show more
    Last updated: 2 days ago • Promoted
    Cyber Security Engineer

    Cyber Security Engineer

    VirtualVocations • Fullerton, California, United States
    Full-time
    A company is looking for a Cyber Security Engineer.Key Responsibilities : Support the implementation and integration of the new ADR solution to meet security requirements Collaborate with teams t...Show more
    Last updated: 30+ days ago • Promoted
    Staff Security Engineer

    Staff Security Engineer

    VirtualVocations • Pasadena, California, United States
    Full-time
    A company is looking for a Staff Security Engineer - Privileged Access Management.Key Responsibilities : Lead global PAM security engineering projects and mentor other engineers Design and implem...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cloud Security Engineer

    Senior Cloud Security Engineer

    VirtualVocations • Van Nuys, California, United States
    Full-time
    A company is looking for a Senior Cloud Security Engineer to join their fully remote team.Key Responsibilities Drive effective security detection and response across the production platform Desi...Show more
    Last updated: 30+ days ago • Promoted
    Application Security Engineer

    Application Security Engineer

    VirtualVocations • Long Beach, California, United States
    Full-time
    A company is looking for an Application Security Engineer to enhance the security of their platform.Key Responsibilities Design and deploy scalable, integrated security solutions that fit seamles...Show more
    Last updated: 30+ days ago • Promoted
    Advanced Security Engineer - Cyber Security

    Advanced Security Engineer - Cyber Security

    Relativity • Los Angeles, CA, United States
    Full-time
    As an Advanced Cyber Security Engineer, you will ensure the security of Relativity's network and infrastructure.In this role, the main responsibilities will be to investigate and analyze emerging t...Show more
    Last updated: 30+ days ago • Promoted
    Senior IT Engineer

    Senior IT Engineer

    VirtualVocations • Signal Hill, California, United States
    Full-time
    A company is looking for a Sr IT Engineer.Key Responsibilities Coordinate and manage system and operational processes including crisis management and change management Analyze and implement admi...Show more
    Last updated: 30+ days ago • Promoted
    Information Security Engineer

    Information Security Engineer

    VirtualVocations • Whittier, California, United States
    Full-time
    A company is looking for an Information Security Engineer.Key Responsibilities Collaborate with security engineers to modernize and support email security infrastructure Act as a liaison for inf...Show more
    Last updated: 30+ days ago • Promoted
    Principal Security Engineer

    Principal Security Engineer

    VirtualVocations • Pasadena, California, United States
    Full-time
    A company is looking for a Principal Information Security Engineer.Key Responsibilities Define and execute the security strategy for infrastructure and cloud platforms Lead architecture and impl...Show more
    Last updated: 30+ days ago • Promoted
    Senior Manager, Enterprise Security

    Senior Manager, Enterprise Security

    VirtualVocations • Signal Hill, California, United States
    Full-time
    A company is looking for a Manager, Enterprise Security.Key Responsibilities : Develop and communicate a scalable enterprise security strategy for corporate infrastructure and SaaS applications L...Show more
    Last updated: 16 hours ago • Promoted • New!
    Lead IT Security Analyst

    Lead IT Security Analyst

    VirtualVocations • North Hollywood, California, United States
    Full-time
    A company is looking for a Lead IT Security Analyst to safeguard security governance, compliance, and risk management frameworks. Key Responsibilities Develop, update, and enforce comprehensive IT...Show more
    Last updated: 4 days ago • Promoted
    Senior Security Operations Engineer

    Senior Security Operations Engineer

    VirtualVocations • Pasadena, California, United States
    Full-time
    A company is looking for a Senior SecOps Engineer to enhance operational security and automate security processes.Key Responsibilities Design and maintain automation workflows to streamline SecOp...Show more
    Last updated: 30+ days ago • Promoted
    Security Operations Engineer

    Security Operations Engineer

    VirtualVocations • Norwalk, California, United States
    Full-time
    A company is looking for a SecOps Engineer.Key Responsibilities Support operational tasks including alert review, incident response, and security playbook maintenance Manage vulnerability scans ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Offensive Security Engineer

    Senior Offensive Security Engineer

    VirtualVocations • Whittier, California, United States
    Full-time
    Offensive Security Engineer to expand its red team.Key Responsibilities Conduct Red Team assessments and identify vulnerabilities in software, systems, and networks Develop reports and presentat...Show more
    Last updated: 30+ days ago • Promoted
    Senior Security Engineer

    Senior Security Engineer

    VirtualVocations • Huntington Beach, California, United States
    Full-time
    A company is looking for a Sr Security Engineer responsible for maintaining and improving the overall security posture and incident response for infrastructure and application hosting environments....Show more
    Last updated: 30+ days ago • Promoted
    Senior Information Security Engineer

    Senior Information Security Engineer

    VirtualVocations • Long Beach, California, United States
    Full-time
    A company is looking for a Senior Information Security Engineer.Key Responsibilities Modernize and govern endpoint security infrastructure and practices Act as a liaison for security design and ...Show more
    Last updated: 30+ days ago • Promoted
    Senior Cyber Security Engineer

    Senior Cyber Security Engineer

    VirtualVocations • Huntington Beach, California, United States
    Full-time
    A company is looking for a Senior Cyber Security Engineer, Security Validation (Remote).Key Responsibilities Lead Red Team engagements to emulate real-world threat actors and validate enterprise ...Show more
    Last updated: 30+ days ago • Promoted