Staff Security Engineer - Vulnerability Management
Johns Creek, GA, United States
Be part of an amazing story
Macy’s is more than just a store. We’re a story. One that’s captured the hearts and minds of America for more than 160 years. A story about innovations and traditions…about inspiring stores and irresistible products…about the excitement of the Macy’s 4th of July Fireworks, and the wonder of the Thanksgiving Day Parade. We’ve been part of memorable moments and milestones for countless customers and colleagues. Those stories are part of what makes this such a special place to work.
Job Overview
The Staff, Vulnerability Engineer specializes in penetration testing and information security vulnerability management. This hands-on role conducts penetration tests and vulnerability assessments on complex applications, operating systems, and wired and wireless networks. In response to an ever-changing threat landscape, this role establishes a proactive program to assess Macy’s resilience against real-world tactics, techniques, and procedures (TTPs).
What You Will Do
- Establish a risk-based approach to evaluate and prioritize new and emerging threats.
- Stay informed on emerging technology trends and the evolving threat landscape, providing subject matter expertise on adversarial threats and risks to support mitigation strategies.
- Design, coordinate, and lead simulations based on defined organizational threat scenarios.
- Review and develop security strategies, best practices, policies, and procedures.
- Provide leadership, share knowledge, and mentor team members.
- Build strong working relationships with Macy’s TMRC, leadership, and third parties to identify and address top threats.
- Develop standardized Rules of Engagement for real-time testing.
- Document detailed findings, analysis, and recommendations.
- Foster an environment of acceptance and respect that strengthens relationships, and ensures authentic connections with colleagues, customers, and communities
- In addition to the essential duties mentioned above, other duties may be assigned.
Skills You Will Need
Regulatory Compliance: Strong knowledge of regulatory compliance requirements, including PCI-DSS, SOX, and GLBA.
Security Infrastructure: Advanced knowledge in security infrastructure design and architecture for both new implementations and existing infrastructure.
Enterprise Security: Experience in designing and implementing enterprise-wide security strategies, policies, and standards.
Threat Protection: Experience protecting large enterprise environments from internal and external attacks.
Vulnerability Management: Strong understanding of network, physical, application, and web security as it relates to vulnerability management. Advanced knowledge of common vulnerabilities, testing approaches, and remediation strategies.
Security Technologies: Expert understanding of current and emerging security technologies, defense strategies, and industry standards. Ability to determine and recommend security-related products and activities, influencing decision-making processes.
Interpersonal Skills: Advanced leadership, facilitation, and interpersonal skills to work across functional lines and at various levels.
Communication: Excellent written and verbal communication skills, with the ability to read, write, and interpret instructional documents.
Certifications: One or more certifications such as CISSP, OSCP, OSCE, OSWE, etc.
Who You Are
- Candidates with a bachelor’s degree or equivalent work experience in a related field are encouraged to apply.
- Regularly required to sit, talk, hear; use hands/fingers to touch, handle, and feel.
- Occasionally required to move about the workplace and reach with hands and arms
- Requires close vision
- Able to work a flexible schedule based on department and company needs
What We Can Offer You
Join a team where work is as rewarding as it is fun! We offer a dynamic, inclusive environment with competitive pay and benefits. Enjoy comprehensive health and wellness coverage and a 401(k) match to invest in your future. Prioritize your well-being with paid time off and eight paid holidays. Grow your career with continuous learning and leadership development. Plus, build community by joining one of our Colleague Resource Groups and make a difference through our volunteer opportunities.
Some additional benefits we offer include:
- Merchandise discounts
- Performance-based incentives
- Annual merit review
- Employee Assistance Program with mental health counseling and legal/financial advice
- Tuition reimbursement
Access the full menu of benefits offerings here.
About Us
This is a great time to join Macy’s! Whether you’re helping a customer find the perfect gift, streamlining operations in one of our distribution centers, enhancing our online shopping experience, buying in-style and on-trend merchandise to outfit our customers, or designing a balloon for the Thanksgiving Day Parade, we offer unique opportunities to be part of some of the most memorable moments in people’s lives.
Join us and help write the next chapter in our story - Apply Today!
This job description is not all-inclusive. Macy's, Inc. reserves the right to amend this job description at any time. Macy's, Inc. is an Equal Opportunity Employer, committed to a diverse and inclusive work environment.
LEGALRE00
TECH00
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: CISSP Compliance GLBA OSCE OSCP OSWE Pentesting SOX TTPs Vulnerabilities Vulnerability management
Perks/benefits: 401(k) matching Career development Competitive pay Flex hours Flex vacation Health care Wellness
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.