Search jobs > Jersey City, NJ > Principal security engineer

Principal IaC Security Engineer

LPL Financial
Jersey City NJ
$143.1K-$238.5K a year
Full-time

Job Overview :

As a member of the Information Security team, the Principal Cloud Code Security Engineer will be responsible for developing, maturing, and sustaining the Cloud Security program with an emphasis on Infrastructure as Code security.

This position will partner with the Application Security, Cloud Engineering / Operations, and Security Engineering teams to ensure that company private cloud resources are securely deployed through established automated pipelines.

Responsibilities :

Implement and maintain appropriate controls within the CI / CD pipelines used to deploy cloud resources to ensure that resources are securely designed and deployed

Review Infrastructure as Code scripts and code repositories using Terraform to identify potential security issues or noncompliance with coding best practices

Implement and maintain tools to perform automated security scanning / analysis of Infrastructure as Code, containers, and serverless functions

Review security scan results and work with Application Development and Cloud Engineering teams to prioritize remediation efforts, review potential false positives and evaluate potential mitigating factors

Produce and track routine reports / metrics on security vulnerabilities, coding deficiencies, and exposures

Mentor and educate other teams within the organization on secure development and cloud security best practices

Monitor and review CVEs, and industry developments, and provide inputs for continuous improvement

Work with Internal Audit, IT Governance, IT Compliance and other key stakeholder groups on specific projects to ensure compliance with applicable regulatory requirements

Act as an SME in the area of Cloud and Code Security

What are we looking for?

We want strong collaborators who can deliver a world-class client experience . We are looking for people who thrive in a fast-paced environment, are client-focused, team oriented , and are able to execute in a way that encourages creativity and continuous improvement .

Requirements :

8+ years of Cloud experience specifically working with AWS and Azure environments

6+ years of experience specifically working with Infrastructure as Code (Terraform) and helping to secure automated Cloud deployment pipelines

5+ years of experience using Cloud Security and IAC scanning tools including Prisma Code Security or similar tools

5+ years of experience with reviewing and analyzing vulnerabilities, including cloud-related issues, and tracking closure of vulnerabilities

Preferences :

Bachelor’s Degree or equivalent in Information Security, Engineering, or Computer Science.

Experience developing Infrastructure as Code using tooling such as Terraform, Cloud Formation, or HashiCorp

Expert-level knowledge in securing Infrastructure as Code scripts and Cloud resource deployments

Expert-level knowledge of the major Cloud platforms and their associated resources, common cloud misconfigurations / vulnerabilities and how to securely deploy each resource type

Experience working with Cloud Security Posture Management (CSPM) technologies such as Wiz, Prisma, Laceworks, Orca and Compute Security tools such as Twistlock and Aquasec

LI-Hybrid

Pay Range :

$143,100.00 - $238,500.00Actual base salary varies based on factors, including but not limited to, relevant skill, prior experience, education, base salary of internal peers, demonstrated performance, and geographic location.

Additionally, LPL Total Rewards package is highly competitive, designed to support your success at work, at home, and at play such as 401K matching, health benefits, employee stock options, paid time off, volunteer time off, and more.

Your recruiter will be happy to discuss all that LPL has to offer!

20 days ago
Related jobs
LPL Financial
Jersey City, New Jersey

As a member of the Information Security team, the Principal Cloud Code Security Engineer will be responsible for developing, maturing, and sustaining the Cloud Security program with an emphasis on Infrastructure as Code security. This position will partner with the Application Security, Cloud Engine...

WELLS FARGO BANK
Woodbridge Township, New Jersey

The Principal Engineer will lead engineering on Continuous Integration/Continuous Delivery (CI/CD) security tooling optimization (Static Application Security Testing - SAST, Software Composition Analysis - SCA, Dynamic Application Security Testing - DAST, Interactive Application Security Testing - I...

BAE Systems
Totowa, New Jersey

Our Need: Creative and innovative engineers with prior systems, hardware, or software engineering experience with the potential to outthink world class reverse engineers. Our engineers design solutions that achieve the optimum balance between product capability and defense-in-depth security. They ap...

EA Team Inc.
Secaucus, New Jersey

JOB SUMMARY: The IT Security Principal Engineer position is working within an IT security team to review, evaluate, design, engineer, implement, and or maintain advanced security products, processes, and associated policies for the Corporation. The intended engineered solutions can represent IT secu...

Promoted
JPMorganChase
Jersey City, New Jersey

As a Principal Software Engineer at JPMorgan Chase within the Consumer & Community Banking Technology team, you, you provide expertise and engineering excellence as an integral part of an agile team to enhance, build, and deliver trusted market-leading technology products in a secure, stable, an...

Promoted
Cisco Systems, Inc.
Woodbridge Township, New Jersey

CSSs bring strategic vision, the latest technology from Cisco Engineering, and tactical expertise to ensure successful customer engagements. Provide feedback to Engineering and Product Management Teams for product improvements, promote the CX offer strategy, and highlight feature opportunities. BS i...

Promoted
SPHERE Technology Solutions
Newark, New Jersey

SPHERE is seeking a self-starting and experienced security professional to join our team.Your passion for finding creative approaches to solve security problems will shine as you troubleshoot existing and create new security capabilities that close information gaps, strengthen our defenses, and defe...

Promoted
TestingXperts Inc. DBA Damcosoft
Clifton, New Jersey

Juniper Network Security Engineer with Juniper and Firewall (Clifton, NJ). Experience with leading team of engineers in maintaining network infrastructure,. Oversee and maintain the daily operation of network systems, including routers, switches, and firewalls, primarily focusing on Juniper hardware...

Promoted
Capital One
Belleville, New Jersey

We are seeking Data Engineers who are passionate about marrying data with emerging technologies. Center 2 (19050), United States of America, McLean, VirginiaSenior Data EngineerDo you love building and pioneering in the technology space? Do you enjoy solving complex business problems in a fast-paced...

Promoted
Iceberg Cyber Security
NJ, United States

I’m currently representing a financial institution who are looking to bridge the gap between cybersecurity and data to fight financial crime and fraud. There are looking for data engineers with strong experience in engineering and integration databases and generating insights to fight financial crim...