Skip to main contentA logo with &quat;the muse&quat; in dark blue text.
Fidelity Investments

Senior Manager, Cybersecurity

Westlake, TX

Job Description:

Position Description:

Identifies and remediates vulnerabilities in software applications and infrastructure. Develops, documents, and operationalizes technical procedures necessary to respond to externally-sourced security reports. Targets known application and network security vulnerabilities using methods - vulnerability assessments, penetration testing, red teaming, incident response, and security engineering. Researches and reproduces security vulnerabilities reported. Develops timely remediation plans to security threats in collaboration with technical leadership across the business.

Primary Responsibilities:

  • Collaborates with security researchers and application teams to ensure validation, prioritization, and remediation of vulnerabilities.
  • Researches and reproduces security vulnerabilities, proposes risk mitigation strategies, and ensures appropriate security controls to safeguard digital files and electronic infrastructure.
  • Supports proactive technical assessments and applications.
  • Provides assistance and support to developers for remediating and re-validating vulnerabilities until closure.
  • Conducts targeted vulnerability training sessions for team members to enhance knowledge and understanding of specific vulnerabilities.
  • Communicates cybersecurity program results and trend analyses to stakeholders on a regular cadence.
  • Ensures continuous improvement of overall enterprise cybersecurity.
  • Plans, implements, upgrades, or monitors security measures for the protection of computer networks and information.

Want more jobs like this?

Get Software Engineering jobs in Westlake, TX delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.

Education and Experience:

Bachelor's degree (or foreign education equivalent) in Applied Computer Science, Computer Science, Engineering, Information Technology, Information Systems, Mathematics, Physics, or a closely related field and five (5) years of experience as a Senior Manager, Cybersecurity (or closely related occupation) developing, documenting, and operationalizing technical procedures to respond to externally-sourced security reports.

Or, alternatively, Master's degree (or foreign education equivalent) in Applied Computer Science, Computer Science, Engineering, Information Technology, Information Systems, Mathematics, Physics, or a closely related field and three (3) years of experience as a Senior Manager, Cybersecurity (or closely related occupation) developing, documenting, and operationalizing technical procedures to respond to externally-sourced security reports.

Skills and Knowledge:

Candidate must also possess:

  • Demonstrated Expertise ("DE") estimating risks on security flaws that are uncovered during static or dynamic analysis using NIST framework; conducting pen-testing on applications to uncover security exploits - XSS, XSRF, SQL, CSV Injection, XXE Processing, HTTP Request Smuggling, Broken Access Control, and Privilege escalation - using BurpSuite Enetrprise Edition, Fiddler, Kali Linux, and SQLMap; and conducting retests to determine mitigation measures implemented by the development teams, using retesting tools specific to the environment and application being tested.
  • DE designing and implementing processes for receiving, assessing, and responding to externally-sourced security reports, using issue tracking system (JIRA), email communication, and vulnerability management platforms (HackerOne and Bugcrowd); conducting thorough assessments of reported vulnerabilities, determining their severity, and potential impact on the security posture, using security testing tools (BurpSuite, Qualys, and Kali Linux), CVSS calculator, and NIST framework; and coordinating and triaging reported vulnerabilities, working closely with technical teams to ensure timely remediation within SLA requirements.
  • DE improving security assessment processes by performing root cause analysis on issues encountered and facilitating risk analysis - determining severity score for vulnerabilities - using CVSS score; analyzing Common Vulnerability Exposure (CVE) on third party libraries, using Veracode SCA, MEND, SourceClear, and NVD databases; performing application log file analysis to determine information disclosure; and coordinating vulnerability fixes with stakeholders using collaboration and communication tools (Microsoft Teams) and project management platforms (JIRA).
  • DE performing in-depth analysis of internal environments, system, applications, and network infrastructure to identify similar vulnerabilities and potential areas of improvement, using application security testing tools (Burp Suite), vulnerability scanner (Qualys), and network scanning tools (Nmap); and conducting comprehensive false negative analysis to identify gaps and threats, using code review tools (Veracode SCA), penetration testing tools, and log analysis tools (Splunk).

#PE1M2

Certifications:

Company Overview

Fidelity Investments is a privately held company with a mission to strengthen the financial well-being of our clients. We help people invest and plan for their future. We assist companies and non-profit organizations in delivering benefits to their employees. And we provide institutions and independent advisors with investment and technology solutions to help invest their own clients' money.

Join Us

At Fidelity, you'll find endless opportunities to build a meaningful career that positively impacts peoples' lives, including yours. You can take advantage of flexible benefits that support you through every stage of your career, empowering you to thrive at work and at home. Honored with a Glassdoor Employees' Choice Award, we have been recognized by our employees as a top 10 Best Place to Work in 2024. And you don't need a finance background to succeed at Fidelity-we offer a range of opportunities for learning so you can build the career you've always imagined.

Fidelity's working model blends the best of working offsite with maximizing time together in person to meet associate and business needs. Currently, most hybrid roles require associates to work onsite all business days of one assigned week per four-week period (beginning in September 2024, the requirement will be two full assigned weeks).

At Fidelity, we value honesty, integrity, and the safety of our associates and customers within a heavily regulated industry. Certain roles may require candidates to go through a preliminary credit check during the screening process. Candidates who are presented with a Fidelity offer will need to go through a background investigation, detailed in this document, and may be asked to provide additional documentation as requested. This investigation includes but is not limited to a criminal, civil litigations and regulatory review, employment, education, and credit review (role dependent). These investigations will account for 7 years or more of history, depending on the role. Where permitted by federal or state law, Fidelity will also conduct a pre-employment drug screen, which will review for the following substances: Amphetamines, THC (marijuana), cocaine, opiates, phencyclidine.

We invite you to Find Your Fidelity at fidelitycareers.com.

Fidelity Investments is an equal opportunity employer. We believe that the most effective way to attract, develop and retain a diverse workforce is to build an enduring culture of inclusion and belonging.

Fidelity will reasonably accommodate applicants with disabilities who need adjustments to participate in the application or interview process. To initiate a request for an accommodation, contact the HR Accommodation Team by sending an email to accommodations@fmr.com.

Client-provided location(s): Westlake, TX, USA
Job ID: Fidelity-2096239
Employment Type: Other

Perks and Benefits

  • Health and Wellness

    • Health Insurance
    • Dental Insurance
    • Vision Insurance
    • Life Insurance
    • Short-Term Disability
    • Long-Term Disability
    • FSA
    • HSA
    • HSA With Employer Contribution
    • Fitness Subsidies
    • On-Site Gym
    • Pet Insurance
    • Mental Health Benefits
    • Virtual Fitness Classes
  • Parental Benefits

    • Birth Parent or Maternity Leave
    • Non-Birth Parent or Paternity Leave
    • Fertility Benefits
    • Adoption Assistance Program
    • Family Support Resources
    • Adoption Leave
  • Work Flexibility

    • Flexible Work Hours
    • Remote Work Opportunities
    • Hybrid Work Opportunities
  • Office Life and Perks

    • Commuter Benefits Program
    • Casual Dress
    • Snacks
    • Company Outings
    • On-Site Cafeteria
    • Holiday Events
  • Vacation and Time Off

    • Paid Vacation
    • Paid Holidays
    • Personal/Sick Days
    • Leave of Absence
  • Financial and Retirement

    • 401(K)
    • 401(K) With Company Matching
    • Company Equity
    • Performance Bonus
    • Relocation Assistance
    • Financial Counseling
    • Profit Sharing
  • Professional Development

    • Tuition Reimbursement
    • Promote From Within
    • Mentor Program
    • Shadowing Opportunities
    • Access to Online Courses
    • Lunch and Learns
    • Internship Program
    • Work Visa Sponsorship
    • Leadership Training Program
    • Associate or Rotational Training Program

Company Videos

Hear directly from employees about what it is like to work at Fidelity Investments.