Cyber SDC- Secure Design Pattern Analyst - Staff 2 - Consulting - Location OPEN
Dallas, TX, US, 75219
EY
Mit unseren vier integrierten Geschäftsbereichen — Wirtschaftsprüfung und prüfungsnahe Dienstleistungen, Steuerberatung, Unternehmensberatung und Strategy and Transactions — sowie unserem Branchenwissen unterstützen wir unsere Mandanten dabei,...In an ever-evolving IT landscape, EY stands as a beacon of trust for clients across diverse industries seeking reliable solutions to address their intricate risks and vulnerabilities. As a vital member of our Secure Design Pattern team, you will play a vital role in achieving this objective by empowering clients to comprehend, navigate, and secure all applicable layers of business applications. This is an opportunity to leverage both your technical prowess and business acumen to drive our mission and make a significant impact on global cybersecurity.
The opportunity
We currently offer an exciting career opportunity for a Secure Design Pattern Analyst responsible for establishing blueprints to standardize implementation of security controls across layers of business applications and architectures.
At our core, our Secure Design Pattern services play a pivotal role in assisting our clients to implement business applications securely and in line with industry best practices and client policies and standards. The ideal candidate will be responsible for documenting secure design patterns, interfacing with application owners, architects, and subject matter resources, as well as discuss and apply secure patterns, guidelines, and principles.
Your Key Responsibilities
- Create and maintain design patterns documentation and playbooks
- Coordinate and streamline the processes to create, update, manage, and control design patterns. at clients.
- Engage with security architects, product owners, engineers, and subject matter resources to support new design patterns and updates to design patterns.
- Promote security best practices within discussions.
- Review and process design pattern service requests, ensuring timely resolution.
- Track and report the status of secure design pattern requests, provide regular updates on progress and outcomes.
Skills and Attributes for Success
- Proven experience writing technical documentation, standard operating procedures, policies, standards supporting the implementation of security controls and architecture patterns.
- Understanding and apply secure design concepts.
- Strong communication skills, with the ability to convey technical information in discussions and documentation.
- Knowledge of industry security frameworks and compliance standards and regulations (e.g., CMMC, NIST, ISO 27001, CIS, OWASP, TOGAF, SABSA, etc.)
- Familiarity with cloud security platforms (e.g., AWS, Azure) and cloud-native security controls.
- Basic understanding of authentication (OAuth, SAML, OpenID), authorization (RBAC, ABAC), and Zero Trust
- Understanding of encryption algorithms, key management, digital signatures, and PKI.
- Familiarity with SIEM, SOAR, XDR, log management, and anomaly detection.
- Familiarity with secure coding practices, DevSecOps, SAST/DAST tools, and software security design.
- Familiarity with firewalls, VPNs, TLS, micro-segmentation, and intrusion detection.
- Excellent problem-solving skills and the ability to manage multiple tasks effectively.
- Strong communication skills to collaborate with team members and stakeholders (e.g., business, information technology, product owners, cybersecurity.
- A track record of delivering high-quality client services and work products within expected timeframes.
- Ability to managing and maintain inventories of documentation
To qualify for the role you must have
- Understanding of security principles
- Bachelor’s degree in computer science, information technology, cybersecurity, technical writing, or a related field
- Proven experience in technical writing
- Hands on experience managing or working on a security architecture and/or GRC team
- Basic knowledge of cloud platforms (AWS, Azure) and their security features
- Knowledge of common industry security frameworks and regulations (e.g., CMMC, NIST, ISO 27001, CIS, OWASP, etc.)
- Knowledge of general security concepts and methods, such as security policy creation, enterprise security strategies, architectures, governance, vulnerability assessments, privacy assessments, intrusion detection, and incident response
- Experience in leading process definition, workflow design, and process mapping
- Experience in ServiceNow managing tickets and generating basic reports.
Ideally, you’d also have
- Professional certifications in cybersecurity, such as CISSP, CISM, or specific vendor certifications like from AWS, Azure, and Google Cloud.
- Hands on experience in cloud-based security solutions
- Prior experience as a security architect
- Experience in assessing compliance to regulations and standards
- Strong interpersonal and communication skills, with the ability to collaborate effectively with clients and cross-functional teams to present solution designs, options, and innovations.
What we look for
We are interested in intellectually curious people with a genuine passion for cybersecurity. With your broad exposure across security architecture and enterprise applications, we will turn to you to speak up with innovative new ideas that could make a lasting difference not only to us – but also to the industry at large. If you have the confidence in both your writing, presentation, and technical abilities to grow into a leading expert here, this is the role for you.
What we offer We offer a comprehensive compensation and benefits package where you’ll be rewarded based on your performance and recognized for the value you bring to the business. The base salary range for this job in all geographic locations in the US is $57,700 to $94,800. The salary range for New York City Metro Area, Washington State and California (excluding Sacramento) is $69,000 to $107,100. Individual salaries within those ranges are determined through a wide variety of factors including but not limited to education, experience, knowledge, skills and geography. In addition, our Total Rewards package includes medical and dental coverage, pension and 401(k) plans, and a wide range of paid time off options. Join us in our team-led and leader-enabled hybrid model. Our expectation is for most people in external, client serving roles to work together in person 40-60% of the time over the course of an engagement, project or year. Under our flexible vacation policy, you’ll decide how much vacation time you need based on your own personal circumstances. You’ll also be granted time off for designated EY Paid Holidays, Winter/Summer breaks, Personal/Family Care, and other leaves of absence when needed to support your physical, financial, and emotional well-being.- Continuous learning: You’ll develop the mindset and skills to navigate whatever comes next.
- Success as defined by you: We’ll provide the tools and flexibility, so you can make a meaningful impact, your way.
- Transformative leadership: We’ll give you the insights, coaching and confidence to be the leader the world needs.
- Diverse and inclusive culture: You’ll be embraced for who you are and empowered to use your voice to help others find theirs.
Tags: AWS Azure CISM CISSP Cloud CMMC Compliance Computer Science DAST DevSecOps Encryption Firewalls GCP Governance Incident response Intrusion detection ISO 27001 NIST OpenID OWASP PKI Privacy SAML SAST SIEM SOAR Strategy TLS TOGAF VPN Vulnerabilities XDR Zero Trust
Perks/benefits: Career development Flex hours Flex vacation Health care
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.