Tech Stack
ITSMJ2EELinuxPerlPythonRubyServiceNowSplunkUnix
About the role
- 100% customer-facing role to manage technical security controls, vulnerabilities, exploits, and incidents for customers
- Day-to-day management of client's security infrastructure and monitoring/response to security events
- Perform security assessments, gap analysis, and document findings with recommendations for technical and non-technical audiences
- Conduct vulnerability scans and penetration tests across multiple assessment types (social engineering, wireless, mobile, physical, web apps)
- Assist customer staff with security architecture recommendations, writing policies/procedures, security research, and product/tool evaluation
- Act as technical SME for security operations, handling escalations, outages, and incident handling across teams
- Lead planning, documentation, process development, and technical procedures for global security operations
- Lead technical project efforts and participate in expansion of new opportunities with existing customers
- Configure, manage, and operate Akamai solutions (Account Protector, Kona Site Defender, WAF, Bot Manager, CDN, SSL/TLS)
- Implement and optimize Akamai Account Protector for ATO and fraud prevention, integrate into login flows, and tune policies for emerging threats
- Ensure high availability, performance tuning, capacity planning, monitoring, troubleshooting, and incident resolution for Akamai services
- Conduct regular risk assessments, compliance checks, and assist with PCI DSS audits, reporting, and documentation
- Develop automation scripts (Python, Shell) to streamline Akamai operational tasks and configuration updates
- Maintain comprehensive documentation, operational procedures, and provide expertise during internal/external PCI DSS audits
Requirements
- 6 to 7 years of experience in Senior level roles as IT Security Architect, IT Security Engineer, IT Security Auditor, Cyber-Security Analyst or Cyber-Intelligence Analyst
- Four years of College resulting in a Bachelor's Degree or equivalent
- One or more certifications (role-dependent): GIAC/SANS (GCIH, GCIA, GCFE, GCFA, GREM, GSEC), ISC2 (CC, SSCP, CCSP, CISSP), CompTIA Security+, Akamai Security, Microsoft, Linux technical certifications
- Experience with Akamai Account Protector and Akamai security solutions (Kona Site Defender, WAF, Bot Manager, Client-Side Script Protector, Account Protector)
- Strong understanding of PCI DSS requirements and experience implementing/maintaining compliance in large-scale web environments
- Experience performing vulnerability scans and penetration tests (including social engineering/phishing, wireless, mobile, physical, web apps)
- Enterprise security architecture, auditing, and risk assessment experience
- Experience with host protection systems, enterprise vulnerability management, IPS/IDS, and APT/Cyber Crime attack TTPs
- Incident response, intrusion analysis, network and host forensics experience
- Experience with Splunk or similar log analysis tools and reviewing security events
- Scripting experience a plus (Python, Perl, Ruby, Shell)
- Experience with public speaking, technical training, and presentation
- Strong knowledge of Microsoft Windows, Linux, Unix environments and securing distributed/J2EE applications and web servers
- Knowledge of encryption technologies and secure network configurations
- Experience with Crowdstrike, Proofpoint, or DTEX a plus
- ITSM experience (Incident/Problem/Change/Request Management), ServiceNow preferred
- Excellent verbal and written communication, problem-solving, organizational skills
- May be subject to extensive U.S. government background check for non-US citizens (disclosure of PII)