Principal Systems Engineer - Durham, United States - Fidelity Investments

    Fidelity Investments background
    Description

    Job Description: Principal Perimeter Security Engineer

    The job involves performing functions related to Network and Perimeter specialized Security Engineers, including Web Application Firewall, Network and cloud security. Looking for an energetic, hard charging individual able to keep up in an exciting and fast-moving security operations team that is engaged in several high-profile security projects to enhance Fidelity's security posture. The candidate will be immersed in a quick changing environment in a very rapid changing threat landscape, working with numerous security professionals. The qualified candidate must be adaptable and able to work in a fast-paced environment where learning new skills and understanding new system architectures quickly is a key to success.

    The Team

    The Principal Security Engineer will be working on external defense team to ensure indications of compromise are promptly identified and stakeholders are informed with actionable and complete information. This role will assist and coordinate with incident response staff, threat intelligence, vulnerability management, and perimeter security teams during response activities and cyber investigations. This position works closely with our Perimeter operations to ensure proper rule coverage is in place on the WAF's.

    The Expertise You Have

    Technical:

    • Strong knowledge of Akamai and AWS WAF for creating and implementing rules.
    • Experience and working knowledge of AWS Cloudfront and WAF
    • Strong experience in Web application firewall with understanding of API Security. Good exposure to how to proactively combat OWASP top 10, Account take over , API and other bot external attacks .
    • Evaluate, deploying and managing Akamai / AWS / Azure Web Application Firewall security configuration.
    • Analyzing web traffic patterns to improve protections.
    • Reviewing policy enforcement change requests; interviewing submitters who have requested security configuration changes and require additional requirements gathering.
    • Perimeter and cloud security Expert with an outstanding understanding of the latest practices and trends in edge security.
    • Advance experience on Splunk or other SIEM (Security information and event management) Monitoring. Log Analysis Expertise- Web logs, NetFlow and Packet Analysis

    Behavioral

    • Positive personality and can-do attitude; you also have good communication skills with an excellent command of the English language.
    • Open-minded, empathic and a team-mate with a partnering approach and an enthusiastic and motivated personality, with demonstrated experience in solving complex challenges
    • Intellectually curious and therefore remain abreast of new technologies and developments relating to technical products that might be used enterprise wide and software delivery methodologies
    • Proficient in balancing business partner views and interests
    • Team player with excellent interpersonal & communication skills (written and verbal)
    • Senior technical and non-technical Stake holder management skills

    The Skills You Bring

    • Security experience with any WAF provider, API definitions, custom rules, writing bot management rules and analyzing traffic logs.
    • Proven experience troubleshooting and simulating HTTP client requests (e.g., curl, postman, HAR file analysis).
    • Strong understanding of core networking concepts (e.g. - TCP/IP, DNS, HTTP, proxy, load-balancing, etc.).
    • Functional experience with Splunk, SIEM, or other log aggregation & analysis technologies.
    • Experience with cloud solutions such as AWS or other IaaS/PaaS/SaaS environments.
    • Ability to interact with both technical and non-technical staff, including management and executives, with experience articulating technical material in business terms.
    • Functional understanding of network controls and policies to stop cyber threats.
    • Familiarity with external facing security controls that can stop external attacks that may occur: such as WAF tuning, Bot management, API protection, network policy governance, troubleshooting.
    • Familiarity with criminal activities and the attacks that may occur in each layer of the OSI model.
    • Ability to make information security risk determinations based on intelligence analysis.
    • Understanding cyber threats, malicious cyber threat actor motivations, and capabilities relevant to regions of interest.

    Education and Certification

    • Bachelor's degree in computer science or in lieu of:
    • Industry certifications in cyber security incident management, such as, Certified Information Systems Security Professional (CISSP), GIAC and other related credentials.
    • AWS

    Certifications:

    Company Overview

    Fidelity Investments is a privately held company with a mission to strengthen the financial well-being of our clients. We help people invest and plan for their future. We assist companies and non-profit organizations in delivering benefits to their employees. And we provide institutions and independent advisors with investment and technology solutions to help invest their own clients' money.

    Join Us

    At Fidelity, you'll find endless opportunities to build a meaningful career that positively impacts peoples' lives, including yours. You can take advantage of flexible benefits that support you through every stage of your career, empowering you to thrive at work and at home. Honored with a Glassdoor Employees' Choice Award, we have been recognized by our employees as a top 10 Best Place to Work in 2024. And you don't need a finance background to succeed at Fidelity-we offer a range of opportunities for learning so you can build the career you've always imagined.

    Fidelity's working model blends the best of working offsite with maximizing time together in person to meet associate and business needs. Currently, most hybrid roles require associates to work onsite all business days of one assigned week per four-week period (beginning in September 2024, the requirement will be two full assigned weeks).

    At Fidelity, we value honesty, integrity, and the safety of our associates and customers within a heavily regulated industry. Certain roles may require candidates to go through a preliminary credit check during the screening process. Candidates who are presented with a Fidelity offer will need to go through a background investigation, detailed in this document, and may be asked to provide additional documentation as requested. This investigation includes but is not limited to a criminal, civil litigations and regulatory review, employment, education, and credit review (role dependent). These investigations will account for 7 years or more of history, depending on the role. Where permitted by federal or state law, Fidelity will also conduct a pre-employment drug screen, which will review for the following substances: Amphetamines, THC (marijuana), cocaine, opiates, phencyclidine.

    We invite you to Find Your Fidelity at

    Fidelity Investments is an equal opportunity employer. We believe that the most effective way to attract, develop and retain a diverse workforce is to build an enduring culture of inclusion and belonging.

    Fidelity will reasonably accommodate applicants with disabilities who need adjustments to participate in the application or interview process. To initiate a request for an accommodation, contact the HR Accommodation Team by sending an email to , or by calling , prompt 2, option 3.

    PDN-9b4cb59c-e45d-4895-b5db-635c00a1448f