Talent.com
IT Security Engineer

IT Security Engineer

Kia AmericaIrvine, CA, United States
3 days ago
Job type
  • Full-time
Job description

At Kia, we're creating award-winning products and redefining what value means in the automotive industry. It takes a special group of individuals to do what we do, and we do it together. Our culture is fast-paced, collaborative, and innovative. Our people thrive on thinking differently and challenging the status quo. We are creating something special here, a culture of learning and opportunity, where you can help Kia achieve big things and most importantly, feel passionate and connected to your work every day.

Kia provides team members with competitive benefits including premium paid medical, dental and vision coverage for you and your dependents, 401(k) plan matching of 100% up to 6% of the salary deferral, and paid time off. Kia also offers company lease and purchase programs, company-wide holiday shutdown, paid volunteer hours, and premium lifestyle amenities at our corporate campus in Irvine, California.

Status

Exempt

General Summary

Under the direction of Information Security management, the Penetration Test Engineer is responsible for protecting Kia America (KUS) including subsidiaries from cyberattacks which can result in loss of sensitive data, harm to the company brand or disruption to business operations. This position will report to the Manager, Information Security and be a key member of the Information Security team.

This critical role will coordinate the information security reviews of company IT initiatives either directly or through IT service providers. This includes conducting security risk assessments, performing penetration tests, identifying threats and vulnerabilities, and presenting recommendations to address them.

The Penetration Test Engineer will take necessary actions and preventive measures, such as analyzing security system logs, to protect company information systems, including employee, dealer and consumer facing systems, from being compromised. This role will investigate the security vulnerabilities of company information systems and provide solutions and methods to remediate them. This role is also responsible for creating, updating, and testing the company's incident response procedures for handling security events. This includes conducting regular table-top exercises to continuously improve the effectiveness of these procedures and minimize the recovery time and business impact of an actual security event. This role will work with internal and external parties to conduct forensic analysis to determine root causes and implement corrective and preventive plans.

The Penetration Test Engineer works closely with KUS business units and security service providers to develop optimal solutions for short-term and long-term enhancements of KUS's security maturity.

Essential Duties and Responsibilities

1st Priority - 70%

  • Conduct penetration tests against Kia America's corporate web / business applications, servers, APIs, mobile apps, networks, cloud environments and connected cars.
  • Create detailed technical reports describing discovered vulnerabilities, approach taken to identify them, method to duplicate findings, vulnerability risk level and recommendations to mitigate the risks.
  • Oversee, or perform, all penetration test phases (Reconnaissance, Scanning, Vulnerability Assessment, Exploitation, Remediation and Reporting)
  • Stay current on new and emerging security threats and the security tools and methods necessary to mitigate them.

2nd Priority - 30%

  • Establish security incident response policies and procedures and conduct regular training.
  • Conduct table-top exercises to verify incident response procedures and documentation are effective.
  • In the event of a security event, lead the efforts to analyze logs and investigate details of the event to take appropriate actions
  • Qualifications / Education

  • Bachelor's degree or comparative experience with emphasis on information security
  • Advanced degree and / or certification(s) in cyber security a plus
  • Job Requirement

    Overall Experience :

  • 8+ years of experience in an organization with mature security practices
  • 3+ years of experience in conducting hands-on security penetration tests and vulnerability management. Experience working on Red Teams to identify vulnerabilities with Internet facing business systems is preferred.
  • 3+ years of experience within information security incident response, cybersecurity, and / or IT risk management
  • Experience with conducting penetration testing on vehicles a plus
  • Substantial experience, and successes, in CTF competitions and / or bug bounty programs.
  • Familiar with security related regulations and compliance requirements
  • Familiar with the information security auditing process and evidence collection
  • Other Requirements :

  • Must be proactive, self-motivated, and lead team to multiple concurrent solutions.
  • Specialized Skills and Knowledge Required

  • Skilled in leading cross-functional teams in responding to security events
  • Deep knowledge of IT and security infrastructure (Networks, Server HW & SW, Security Components (FW, IPS, IDS, EDS, etc.)
  • Skilled with automation and scripting (Python)
  • Advanced level of expertise with penetration testing tools (Burp Suite, Kali Linux, Metasploit, John the Ripper, Nmap, Wireshark, OWASP ZAP, Aircrack-ng, Tenable Nessus, and others)
  • Skilled in identifying application vulnerabilities (OWASP) and advising application teams on how to remediate them
  • Ability to manage external vendors in the development and delivery of related products, programs, and services.
  • Excellent customer service ability and strong verbal and written communication skills
  • Expert level knowledge and understanding of the attack chain, adversary tactics, techniques, and procedures, emerging threats and vulnerabilities.
  • Expert level knowledge of SIEM's, how they work, how their value can be maximized and leveraged to mature monitoring and detection processes.
  • Requires high-level organizational, planning, analytical, and technical skills.
  • Competencies

  • Care for People
  • Chase Excellence Every Day
  • Dare to Push Boundaries
  • Empower People to Act
  • Move Further Together
  • Pay Range

    $125,000 - $150,000

    Pay will be based on several variables that are unique to each candidate, including but not limited to, job-related skills, experience, relevant education or training, etc.

    Equal Employment Opportunities

    KUS provides equal employment opportunities (EEO) to all employees and applicants for employment without regard to race, color, religion, ancestry, national origin, sex, including pregnancy and childbirth and related medical conditions, gender, gender identity, gender expression, age, legally protected physical disability or mental disability, legally protected medical condition, marital status, sexual orientation, family care or medical leave status, protected veteran or military status, genetic information or any other characteristic protected by applicable law. KUS complies with applicable law governing non-discrimination in employment in every location in which KUS has offices. The KUS EEO policy applies to all areas of employment, including recruitment, hiring, training, promotion, compensation, benefits, discipline, termination and all other privileges, terms and conditions of employment.

    Disclaimer : The above information on this job description has been designed to indicate the general nature and level of work performed by employees within this classification and for this position. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job.

    Create a job alert for this search

    It Security Engineer • Irvine, CA, United States

    Related jobs
    • Promoted
    Security Engineer

    Security Engineer

    ExperisIrvine, CA, United States
    Full-time
    The Security Engineer is a hands-on technical expert responsible for implementing, maintaining, and optimizing MNAO's security tooling. This role works closely with platform and infrastructure teams...Show moreLast updated: 3 days ago
    • Promoted
    Network Engineer

    Network Engineer

    ATI Restoration, LLCAnaheim, CA, United States
    Full-time
    THIS IS NOT A REMOTE POSITION!.ATI Restoration is seeking an experienced and security-focused.Ideal candidates will also possess knowledge in. Architect, deploy, and maintain enterprise network infr...Show moreLast updated: 2 days ago
    • Promoted
    Senior Security Engineer, Network

    Senior Security Engineer, Network

    Anduril IndustriesCosta Mesa, CA, United States
    Full-time
    Anduril Industries is a defense technology company with a mission to transform U.By bringing the expertise, technology, and business model of the 21st century's most innovative companies to the def...Show moreLast updated: 1 day ago
    • Promoted
    Manager of IT Cyber Security

    Manager of IT Cyber Security

    Eleven RecruitingPasadena, CA, United States
    Full-time
    We are a specialized technology staffing agency supporting professional and financial services companies.Why do we stand out in technology staffing? We listen and act as advisors for our candidates...Show moreLast updated: 3 days ago
    • Promoted
    IT Security Engineer

    IT Security Engineer

    Hyundai GlovisIrvine, CA, United States
    Full-time
    About Hyundai GLOVIS America Inc.Since our inception in 2002, we are committed to delivering our customers' products via truck, rail, or ocean vessel throughout the U. Glovis America makes every eff...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    AmpcusTustin, CA, United States
    Full-time
    Technology and Business consulting services.We are in search of a highly motivated candidate to join our talented Team.As a SIEM Engineer for Cortex XSIAM, you will be responsible for assisting wit...Show moreLast updated: 3 days ago
    • Promoted
    IT Security Analyst

    IT Security Analyst

    Epson AmericaLos Alamitos, CA, United States
    Full-time
    The IT Security Analyst will be responsible to monitor and detect risks to the organization, identify sources and methods of attack, locate and preserve electronic evidence as needed.The candidate ...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    ZillowCity of Industry, CA, United States
    Permanent
    About the team Join our team as a versatile and hardworking Senior Cloud Security Engineer.This role presents an excellent opportunity to contribute to the security and reliability of our cloud inf...Show moreLast updated: 30+ days ago
    • Promoted
    Senior Security Engineer

    Senior Security Engineer

    UnavailableSan Marino, CA, United States
    Full-time
    Since 1973, East West Bank has served as a pathway to success.With over 110 locations across the U.Asia, we are the premier financial bridge between the East and West. Our teams of experienced, mult...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Software Engineer - Cloud & Infra Security

    Senior Security Software Engineer - Cloud & Infra Security

    StubHubAliso Viejo, CA, United States
    Full-time
    StubHub is on a mission to redefine the live event experience on a global scale.Whether someone is looking to attend their first event or their hundredth, we're here to delight them all the way fro...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer IS - Identity & Access Management •Virtual •

    Senior Security Engineer IS - Identity & Access Management •Virtual •

    Providence Health & ServiceIrvine, CA, United States
    Full-time
    Senior Security Engineer IS - Identity & Access Management.We are seeking a highly motivated Senior Security Engineer with a passion for Authentication and Identity technologies to join our Enterpr...Show moreLast updated: 3 days ago
    • Promoted
    Sr. Security Engineer, AWS Center for Quantum Computing

    Sr. Security Engineer, AWS Center for Quantum Computing

    AmazonPasadena, CA, United States
    Permanent
    The Amazon Web Services (AWS) Center for Quantum Computing (CQC) in Pasadena, CA, is seeking a Security Engineer who will design and oversee the security operations of a growing research and develo...Show moreLast updated: 3 days ago
    • Promoted
    Senior Security Engineer IS - Identity & Access Management •Virtual •

    Senior Security Engineer IS - Identity & Access Management •Virtual •

    Providence ServiceIrvine, CA, United States
    Full-time
    Senior Security Engineer IS – Identity & Access Management.We are seeking a highly motivated Senior Security Engineer with a passion for Authentication and Identity technologies to join our Enterpr...Show moreLast updated: 30+ days ago
    • Promoted
    Security Engineer

    Security Engineer

    Pipe RecruitOrange, CA, United States
    Full-time
    About the job Security Engineer.Orange County, CA (Local candidates preferred).Full-Time (Only USC / GC candidates).Implement and manage security controls in. SOX, PCI) and support security audits.Req...Show moreLast updated: 3 days ago
    • Promoted
    Manager, IT Cyber Security

    Manager, IT Cyber Security

    Hyundai MobisFountain Valley, CA, United States
    Full-time
    We are searching for an experienced Manager, IT Cyber Security at our Headquarters facility.We think creatively and keep challenging ourselves to help create a new future and eventually make humank...Show moreLast updated: 30+ days ago
    • Promoted
    • New!
    Senior Security Engineer

    Senior Security Engineer

    TalenerOceanside, CA, United States
    Full-time +1
    Our client is an industry leading technology firm in the financial services sector.Their state-of-the-art trading platforms are used by both brokers and dealers to facilitate the trading of securit...Show moreLast updated: 14 hours ago
    • Promoted
    IT Security Analyst

    IT Security Analyst

    Platinum Resource GroupIrvine, CA, United States
    Temporary
    Reasonable experience in IT security operations in mid-size to large multi-site organization.Not looking for a CISO, but also not a raw recruit either. Experience with Crowdstrike as an endpoint sec...Show moreLast updated: 3 days ago
    • Promoted
    Security Engineer

    Security Engineer

    Manpower Group Inc.Irvine, CA, United States
    Full-time
    The Security Engineer is a hands-on technical expert responsible for implementing, maintaining, and optimizing MNAO's security tooling. This role works closely with platform and infrastructure teams...Show moreLast updated: 3 days ago