Job Description:
The Senior Cybersecurity Specialist will be a member of a team that focuses on systemic remediation programs such as Application, Infrastructure and Vendor security as well as efforts focused on supporting other cyber policy and operational programs. The goal is to ensure that Enterprise Cybersecurity (ECS) has effective operational, monitoring and oversight processes in place to minimize cyber risk and ensure that gaps are identified and remediated.
- Collaborate within a team of cybersecurity professionals that can assess and assist in remediation efforts while holding accountable owners responsible for addressing gaps
- Work with the ECS Penetration Test and Red Teams (referred to subsequently as AppSec findings) to understand and triage security vulnerabilities (findings) identified during a Penetration Test or Red Team campaign
- Identify AppSec finding owner(s), work with Business Unit (BU) and application development teams to remediate or reduce the risk of those vulnerabilities and provide guidance and support to finding owners throughout the remediation process
- Ensure solutions and remediation timeframes balance risk, cost, and capacity
- Ensure monitoring processes are working effectively; strive for continuous improvement
- Partner with the ISO Team to ensure proper escalation and remediation occurs according to policy and commitments
Want more jobs like this?
Get jobs delivered to your inbox every week.
The Expertise You Have and The Skills You Bring
- Understanding of Cloud and SaaS security concepts, configurations, and operations.
- Exposure to Security Posture Management on SaaS/Cloud/Data/Applications is highly desired.
- Bachelor's degree in a technology discipline (Cybersecurity/Computer Science/IT).
- Proven knowledge of cybersecurity concepts, security controls, policy, risk management, and common application security vulnerabilities
- Understanding of Vulnerability Remediation
- Working knowledge of on-prem and cloud (AWS and/or Azure) environments and their key components
- Understanding of Compensating Controls and when to apply them
- Balance and drive multiple responsibilities and bodies of work across multiple teams
- Familiarity and/or practical experience with API security concepts
- Secure Application Development and Architecture
- Security testing tools and frameworks
Preferred Skills
- Cybersecurity certifications: CISSP, CISM, Security + and similar credentials
- Security centered knowledge of at least one leading SaaS Platforms (e.g. M365/Salesforce/Service Now/Snowflake).
- Programming knowledge in Python or equivalent
- Experience with DevOps
- Knowledge of third-party governance, risk & compliance tools, processes and systems
- Web application development experience
- Understanding security tools and reference guides (Burp Suite, Zap, OWASP Top 10)
- Security operations experience
- Enterprise-centric project management experience; PMI or Agile certification
- Familiarity/experience with developing Business Intelligence for Security data
The Team
The Cyber Remediation team oversees the remediation of foundational or systemic cybersecurity policy, program, or risk standards and monitor for drift over time. We are part of the Cyber Operations & Analytics unit within Enterprise Cybersecurity and partner with each area to ensure an improved risk posture across the cyber environment to reduce the security risk to Fidelity Investments and ensure our customers can depend on us to lead the industry in securing their valuable information and financial assets they trust us to protect. Together, we can and do make a difference.
Certifications:
Company Overview
Fidelity Investments is a privately held company with a mission to strengthen the financial well-being of our clients. We help people invest and plan for their future. We assist companies and non-profit organizations in delivering benefits to their employees. And we provide institutions and independent advisors with investment and technology solutions to help invest their own clients' money.
Join Us
At Fidelity, you'll find endless opportunities to build a meaningful career that positively impacts peoples' lives, including yours. You can take advantage of flexible benefits that support you through every stage of your career, empowering you to thrive at work and at home. Honored with a Glassdoor Employees' Choice Award, we have been recognized by our employees as a top 10 Best Place to Work in 2024. And you don't need a finance background to succeed at Fidelity-we offer a range of opportunities for learning so you can build the career you've always imagined.
Fidelity's hybrid working model blends the best of both onsite and offsite work experiences. Having the majority of our associates work onsite is important for our business strategy and our culture. We also value the benefits that working offsite offers associates. Most roles listed as Hybrid will require associates to work onsite all business days of every other week in a Fidelity office. This does not apply to roles listed as Remote or Onsite.
At Fidelity, we value honesty, integrity, and the safety of our associates and customers within a heavily regulated industry. Certain roles may require candidates to go through a preliminary credit check during the screening process. Candidates who are presented with a Fidelity offer will need to go through a background investigation, detailed in this document, and may be asked to provide additional documentation as requested. This investigation includes but is not limited to a criminal, civil litigations and regulatory review, employment, education, and credit review (role dependent). These investigations will account for 7 years or more of history, depending on the role. Where permitted by federal or state law, Fidelity will also conduct a pre-employment drug screen, which will review for the following substances: Amphetamines, THC (marijuana), cocaine, opiates, phencyclidine.
We invite you to Find Your Fidelity at fidelitycareers.com.
Fidelity Investments is an equal opportunity employer. We believe that the most effective way to attract, develop and retain a diverse workforce is to build an enduring culture of inclusion and belonging.
Fidelity will reasonably accommodate applicants with disabilities who need adjustments to participate in the application or interview process. To initiate a request for an accommodation, contact the HR Accommodation Team by sending an email to accommodations@fmr.com.