Information Security Engineer - PKI

Ameriprise Financial Services, Inc.
Minneapolis, MN, United States
2 months ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
3 years minimum
Compensation
$120,000.0 - $147,000.0
Working hours
Regular working hours
Job source

Tech stack

Cyber Security Information Systems Databases Database Design Disaster Recovery Network Architecture Network Planning and Design Public Key Infrastructure Remote Access Technology Service Pack Security Information and Event Management Software Engineering
+4 more
Software Vulnerability Management Software Security Firewalls (Computer Science) Information Technology

Job description

We have an exciting opportunity as an Info Security Engineer at Ameriprise! Responsible for effectively planning, crafting, implementing and monitoring security technologies and projects that support the firms’ underlying security policies and procedures. Design, document and implement appropriate policies and standards that protect the firms’ information assets. Use highly technical and physical forensics to ensure that security policies, standards and best practices are followed throughout the technology organization-including where vendors are utilized to provide services. Come apply today!, * Design, coordinate and/or perform comprehensive risk/vulnerability systems assessments to identify vulnerabilities, including providing reporting on assessment results as well as risk mitigation and remediation recommendations and plans. Keep current with emerging security trends, issues and alerts. Communicate known security risks and solutions to mitigate risks to business and technology partners as needed. Manage audits of vendor security processes, procedures and compliance controls.

  • Serve as a security expert on application development, database design, network and/or platform (operating system) projects, helping project teams align with enterprise and Technology security policies, industry regulations and best practices. Through a deep understanding of the business requirements, identify the appropriate security requirements for each project. Design, develop and lead the testing approach and execution plan to ensure that new and existing solutions meet security requirements.
  • Analyze application security needs based on the sensitivity or proprietary nature of the data and work with the appropriate teams to develop and implement new or existing security technologies or processes to support the business strategy. Participate in network architecture reviews and develop detailed security engineering design and deployment plans. Design, test, implement, maintain and support current and future information security technologies, processes and procedures.
  • Responsible for the configuration of security controls to ensure the safety of information systems assets and to protect from unauthorized access or intentional destruction. Develop, implement, maintain and coordinate the enforcement of all technology information security policies, procedures and associated plans based on industry standards, best practices and legal compliance requirements. Implement changes to existing security policies and control standards to know the latest with the threat landscape.
  • Assist and/or lead projects related to information security regulatory compliance and the implementation and maintenance of all information security programs, processes and technologies. Assess and document the need for all security configurations or re-configurations and work with appropriate teams to complete them as required. Research, design and advocate new security technologies, architectures and security products that will support the security requirements of the firm.
  • Assume the subject matter expert (SME) role in the management, investigation and response to suspected and actual information security breaches or system failures. Using data collected from a variety of tools, provide forensic analysis of security events. Analyze security incidents to determine root cause and identify process or system changes to prevent reoccurrence. Recommend and schedule fixes, security patches, disaster recovery procedures and other required measures in the event of a security breach.

Requirements

  • Bachelor’s degree in Computer Science, MIS, Technology Forensics, or related technical field; or equivalent work experience.
  • 5-7 years of relevant experience required. Certifications required: CISSP, CISA, CISM, CRISC, or equivalent security certification.
  • 5+ years’ experience installing, monitoring and maintaining information security solutions - including policy design and implementation.
  • 3+ years’ experience evaluating and crafting security solutions for technology projects.
  • Demonstrated understanding of security related technologies and practices, including authentication and authorization systems, endpoint protection, encryption, segmentation strategies, vulnerability management, secure remote access, and fire walls. Strong/diverse technical background in enterprise networking, firewall, storage options, server infrastructure, operating systems, database technologies, and desktop operating systems and security., * Advanced knowledge and experience designing, implementing, and supporting Zscaler technologies.
  • Advanced network design knowledge with substantial experience troubleshooting and resolving network performance issues.
  • Advanced knowledge and experience solving application connectivity and performance issues.
  • Demonstrated experience contributing and collaborating effectively as an informal leader in a high-functioning team.
  • Effective organizational, analytical and independent problem-solving skills. Successful experience coordinating and completing multiple tasks within established and changing deadlines.
  • Strong presentation skills with experience addressing and working with executives and technical staff.
  • Experience working in the financial services industry or other highly regulated/compliance-oriented environments. Experience with regulatory compliance issues such as: FFIEC, OFCC, SEC and Federal Reserve plus: SOX, GLBA and PCI.

Benefits & conditions

3.73.7 out of 5 stars Minneapolis, MN Hybrid work $120,000 - $147,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Dental insurance
  • Life insurance, The estimated base salary for this role is $120,000 - $147,000 / year. We have a pay-for-performance compensation philosophy. Your initial total compensation may vary based on job-related knowledge, skills, experience, and geographical work location. In addition, most of our roles are eligible for variable pay in the form of bonus, commissions, and/or long-term incentives depending on the role. We also have a competitive and comprehensive benefits program that supports all aspects of your health and well-being, including but not limited to vacation time, sick time, 401(k), and health, dental and life insurance.

About the company

We’re a diversified financial services leader with more than $1.5 trillion in assets under management, administration and advisement as of year-end 2024. Our team of 22,000 people across 19 countries, serves more than 3.5 million individual, small business and institutional clients. We are a longstanding leader in financial planning and advice, a global asset manager and an insurer. Our unwavering focus on our clients and strong financial foundation connects each of our unique businesses - Ameriprise Financial, Columbia Threadneedle Investments and RiverSource Insurance and Annuities. Here, we foster meaningful careers, invest in the future, and make a difference for clients, institutions and communities around the world.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · WWC 2022

2:39 min

Navigating strict environments for enterprise banking

Lea Fragner · LIVE

Videos

See all

Related articles

See all