- Workplace
- Hybrid
- Type
- Full-time
- Department
- Finance
- Experience
- 12+ years
- Education
- Bachelor
- Closing date
- Today
- Source
- Vincere
Description
Japan Security Engineering SME (JG21)
American International Group, Inc. (AIG) is a leading global insurance organization. AIG member companies provide a wide range of property casualty insurance in approximately 70 countries and jurisdictions. These diverse offerings include products and services that help businesses and individuals protect their assets and manage risks.
We’re also committed to making a positive difference for our colleagues and in the communities where we work and live. We encourage colleagues to give back to the causes they care most about, supporting these efforts through our Volunteer Time Off and Matching Grants Programs.
Get to know the business
At AIG, technology is at the heart of everything we do, from underwriting risks to processing claims. The Information Technology team equips our colleagues with the latest tools to complete their work efficiently and with the highest standards of excellence. The team is responsible for shielding the company’s systems from security risks, while designing technology strategies that enable AIG’s businesses to achieve their goals. AIG’s Information Technology functions include enterprise architecture, software and systems engineering, cybersecurity, and technology risk and compliance.
About the role
The Japan Security Engineering SME will support security engineering efforts related to the AIG Security Stack (Crowdstrike, Tanium, Qualys, Imperva DAM/DAS, Microsoft Purview/Defender, ProofPoint, Trend Micro, Varonis, SafeBreach, Agari DMARC, Prisma, Wiz) as Subject Matter Expert. The candidate must have extensive experience securing both enterprise-level on premise and Cloud services, including Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) across multiple cloud providers, including AWS, Google Cloud Platform (GCP), Microsoft Azure (Azure). The candidate must also have subject matter expertise in on premise and Cloud Security Architectures, Vulnerability Management, and Network Security to help protect the firm’s cloud workloads and data deployed into different types of cloud and cloud/hybrid systems. The Japan Security Engineering SME will serve as a key technical expert for the Information Security Organization and other Information Security teams for all matters related to the AIG Security Stack across the Japan and APAC regions.
Responsibilities
- Key technical subject matter expert covering the deployment, management/maintenance, and ‘Follow the Sun’ support of the AIG security stack for on premise systems and cloud service offerings from AWS, Microsoft Azure, or Google Cloud Platform (GCP) to identify threats, risks, and controls to secure the services.
- Operate as a trusted advisor for on premise and cloud AIG Security Stack, mentoring junior team members and developers to understand threats and risk mitigation options for on premise and cloud services.
- Collaborate with other information security teams to help address critical security risks to the business. Ensure that cloud security risk related issues are appropriately monitored and addressed within the IT environment.
- Work with stakeholders to develop, maintain, and enforce cloud security policies and procedures.
- Collaborate with the security architecture team, cloud security engineering team, security remediation team, and application and infrastructure teams to protect on premise and cloud workloads and data deployed into different types of on premise, cloud, and cloud/hybrid systems.
- Support the development of security policies, standards, and procedures for on premise and cloud-based applications and infrastructure leveraging cloud security solutions.
Requirements
- Bachelor's degree or equivalent experience in Cybersecurity, Information Technology, or related field, such as Computer Science.
- Language proficiency in English at Fluent level.
- 12+ years of experience in on premise and cloud security or related roles, with hands-on experience in cloud platforms such as AWS, Azure, or Google Cloud
- 8+ years of direct, hands-on experience with on premise and Cloud Security Posture management solutions including compute agents, DevOps code scanning deployment, and posture management policy tuning, utilizing IaC automation for efficient and secure cloud operations.
- Deep and broad understanding of cloud/cloud hybrid platforms (IDaaS/IaaS/SaaS/PaaS) and associated security tools and processes.
- Proficiency in implementing robust security measures, including agent/agentless workload defenders, in cloud-native environments such as Kubernetes (AKS, EKS, GKS) and Azure Functions.
- Additional certifications such as, CISSP, CCSP, Security+, foundational/associate/security tracks for Azure, AWS, GCP are a plus.
- Recent and relevant experience in vulnerability analysis and exploitation techniques.
- Troubleshoot issues within the product when necessary, assisting different teams, crash dumps, performance monitor and release blockers.
- In depth knowledge of Critical Security Controls like NIST, CIS Benchmarks, DISA STIG standards etc.
- Familiarity with International Security standards and Industry framework like ISO 27001/27002, PCI DSS and SOX.
- In depth knowledge and expertise with Infrastructure hardening and Security settings for Windows and Linux.
- Intermediate to Expert level knowledge on Windows & Active Directory, Unix/Linux Operating Systems.
- Good scripting knowledge using PowerShell, Python, Linux shell is desired.
- Strong knowledge of Cloud computing, Virtualization concepts and PaaS/SaaS services.
- Strong knowledge of TCP/IP and HTTP protocols.
- Strong knowledge of Endpoint Security Concepts and Incident Response processes
- Experience with SIEM & tool integrations – CrowdStrike NextGen SIEM is preferred
- Strong Security Framework knowledge
- Be an energetic “self-starter” who is empowered to take ownership and be accountable for deliverables, both individually and as part of a growing team.
- Team player – able to lead, mentor, communicate, collaborate, and work effectively in a globally distributed team.