- Location
- Oklahoma AF Corporate Home Office, United States of America
- Workplace
- Hybrid
- Type
- Full-time
- Department
- Engineering
- Source
- Workday
Description
The Security Operations Engineer is responsible for the development, design, and implementation of secure solutions and processes for the corporation and sub-entities. They identify, implement, support and maintain tool-driven and highly automated solutions to deliver key security management processes using existing tool sets and/or identify new tools as innovations in security are realized. They develop corporate governance in support of MAR, FINRA and other compliance/governance policies/procedures following NIST/Hi-Trust best practices. They are responsible for ensuring that the software development lifecycle (SDLC) follows security best practices and adhering to secure coding principles by facilitating the scanning and testing of software applications against security risks/vulnerabilities before release.
- The Security Operations Engineer leads Security Operation integrations between various security technologies and business software within existing infrastructure platforms (e.g. on premises, cloud, and hybrid). Work closely with various technology, project, and business teams to engineer and implement security controls with a focus on Security Operations. Provide mentoring for other project teams or individual team members regarding security concepts. Enable the business to achieve goals in a secure manner. Respond to, resolve, and escalate security incidents to all appropriate parties. Report unresolved security exposures, misuse of resources, and noncompliance situations using defined escalation processes.
- The Security Operations Engineer builds security utilities and tools for internal use that enables high speed and wide scale security and identity solutions, monitoring and coverage. Evaluate and recommend use of machine learning, artificial intelligence, and data analytic services to enable action based decisions. With an emphasis on securing systems, applications, third-party connections, identities, service providers and ancillary systems, the security engineer is responsible for securing business-to-business initiatives, third-party relationships, outsourced solutions and vendors. Considered a highly knowledgeable individual, the security engineer is expected to implement, monitor and manage secure solutions that address modern day issues.
Skillsets:
1. Identify, architect, implement, support and maintain tool-driven and highly automated solutions to deliver key security management processes for identity management, vulnerability management, application security, incident response, technology governance, and threat intelligence using existing tool sets and/or identify new tools as innovations in security are realized.
40%
2. Lead Security Operations integrations between various security technologies and business software within existing infrastructure platforms (e.g. on premises, cloud, and hybrid). Work closely with various technology and project teams to engineer and implement security controls with a focus on Security Operations.
20%
3. Builds and Reviews security utilities, playbooks and tools for internal use that enables high speed and wide scale security monitoring and coverage over our enterprise data and intellectual property. Evaluate and recommend use of machine learning, artificial intelligence, and data analytic services to enable security-related action based events and triggers.
20%
4. Respond to, resolve, and escalate security incidents to all appropriate parties. Report unresolved security exposures, misuse of resources, and noncompliance situations using defined escalation processes. Actively engage in threat hunting using manual and automated tools.
10%
5. Provide mentoring for other team members and other IT and business colleagues in order to improve overall security understanding and awareness within the organization.
10%
Additional Workday Skillset:
Workday Responsibilities - Designs, implements, and maintains Workday security architecture, including security groups, domain security policies, business process security configuration, and advanced access control models. Engineers automated identity governance and lifecycle integrations between Workday and enterprise IAM platforms, enabling secure provisioning, deprovisioning, SSO, compliance reporting, access certification, segregation of duties enforcement, and audit readiness.
• Expert experience with Workday Security administration and architecture, including security groups, domain security policies, business process security, role-based access controls, and segregation of duties controls.
• Experience designing and supporting Workday integrations with IAM, IGA, PAM, SSO, and provisioning platforms.
• Experience implementing SAML, OAuth, and related authentication and authorization technologies within Workday environments.
•Experience supporting Workday security audit, compliance, governance, and identity lifecycle management requirements.
#AFC