Staff Security Engineer
It’s not just about your career or job title… It’s about who you are and the impact you will make on the world. Because whether it’s for each other or our customers, we put People First. When our people come together, we Expand the Possible and continuously look for ways to improve what we create and how we do it. If you are constantly striving to grow, you’re in good company. We are revolutionizing the way the world moves for future generations, and we want someone who is ready to move with us.   Who are we?   Wabtec Corporation is a leading global provider of equipment, systems, digital solutions, and value-added services for freight and transit rail as well as the mining, marine, and industrial markets. Drawing on nearly four centuries of collective experience across Wabtec, GE Transportation, and Faiveley Transport, the company has grown to become One Wabtec, with unmatched digital expertise, technological innovation, and world-class manufacturing and services, enabling the digital-rail-and-transit ecosystems. Wabtec is focused on performance that drives progress and unlocks our customers’ potential by delivering innovative and lasting transportation solutions that move and improve the world. We are lifelong learners obsessed with making things better to drive exceptional results. Wabtec has approximately 27K employees in facilities throughout the world. Visit our website to learn more! Who will you be working with? Join Enterprise Information Security (EIS) to help strengthen and mature Wabtec's cybersecurity risk management capabilities. Collaborate closely with infrastructure, cloud, application, operations, architecture, compliance and business teams to identify, prioritize and reduce cybersecurity risk across the enterprise. As a subject matter expert, you will work across global technology environments to ensure vulnerabilities, threats and control gaps are effectively managed and remediated. How will you make a difference? As a Staff Cybersecurity Engineer within Enterprise Information Security, you will help advance Wabtec’s vulnerability management program by leading engineering, operational execution, and governance support across on-premises, cloud, and M&A environments. You will oversee vulnerability discovery, prioritization, remediation, and reporting while partnering with technology teams to reduce risk and strengthen the company’s security posture. You will also support broader cybersecurity efforts across cloud security, security operations, and threat management to improve enterprise visibility, resilience, and operational effectiveness. What do we want to know about you? You must have: Bachelor’s degree in computer science, Information Technology, Cybersecurity or a related field, or a minimum of 5 years of full-time cybersecurity experience.  Demonstrated expertise leading enterprise vulnerability management programs across servers, endpoints, cloud platforms, applications and network infrastructure.  Extensive experience with vulnerability assessment technologies, remediation workflows, risk prioritization methodologies and security exposure management practices.  Strong understanding of vulnerability scoring frameworks, threat intelligence, exploitability analysis and risk-based remediation approaches.  Experience developing metrics, reporting and executive-level dashboards to communicate security risk and remediation progress.  Hands-on experience securing public cloud platforms such as AWS and Azure.  Experience supporting Security Operations functions including threat detection, incident response, threat hunting or security monitoring activities.  Knowledge of enterprise operating systems, networking, system administration and infrastructure technologies.  Experience partnering with technical and business stakeholders to drive remediation efforts across globally distributed environments.  Strong project execution, communication and stakeholder management skills.  Experience managing workstreams and maintaining operational transparency through IT Service Management platforms.  Must be willing to work weekends or off-shift hours, as needed during cybersecurity incidents.  We would love it if you had: Experience implementing Exposure Management or Attack Surface Management programs.  Experience integrating vulnerability management processes with Security Operations and Incident Response functions.  Knowledge of container, Kubernetes and cloud-native security technologies.  Experience automating vulnerability management workflows using scripting or API integrations.  Security certifications such as CISSP, GSEC, GCIH, Security+ or equivalent.  Proven ability to work independently with strong time management skills.  Strong communication and influencing skills.  Commitment to continuous learning and adaptation within an evolving cybersecurity landscape.  What will your typical day look like? Lead the enterprise vulnerability management program, ensuring effective identification, assessment, prioritization and remediation of vulnerabilities across global technology environments.  Manage vulnerability scanning platforms, assessment processes and reporting capabilities to maintain enterprise-wide visibility of security exposures.  Develop and continuously improve risk-based vulnerability prioritization methodologies using threat intelligence, exploitability data and business context.  Partner with infrastructure, cloud, application and business teams to drive timely remediation of identified vulnerabilities and security control weaknesses.  Monitor remediation performance, establish service-level targets and report risk reduction progress
Findigo hittar jobben och fyller i ansökan. Du klickar Skicka.
Visa jobbet och ansökUrsprunglig annons: jobs.smartrecruiters.com