At T-Mobile, we invest in YOU! Our Total Rewards Package ensures that employees get the same big love we give our customers. All team members receive a competitive base salary and compensation package - this is Total Rewards. Employees enjoy multiple wealth-building opportunities through our annual stock grant, employee stock purchase plan, 401(k), and access to free, year-round money coaches. That's how we're UNSTOPPABLE for our employees!
Job Overview
The Insider Threat Senior Engineer will help ensure that our software, systems, and infrastructure are monitored and managed to the highest security standards. Performs reviews and user analysis to protect data within the environment to improve overall security. Works closely with other T-Mobile Engineers to design and build proactive methods to enhance our security posture.
Job Responsibilities
1. Lead investigations of complex and high-risk insider threat cases.
2. Improve process efficiency by creating and implementing creative and sustainable changes to existing investigative methodologies.
3. Recommend strategies to prevent potential insider threat behavior or incidents.
4. Conduct analytical and critical thinking; understand problem set, review facts, make accurate observations and judgments, and provide recommendations and reporting.
5. Respond to and analyze insider threat alerts using specialized monitoring tools.
6. Work with groups such as application support, engineering ops, finance, privacy, risk management, etc.
7. Collaborate with partner teams to enhance the Insider Threat Program behavioral models and detection techniques.
8. Build and implement processes and technologies to detect high-risk insider activities that are accidental or malicious in nature.
9. Mentor peers and junior team members in security technologies, enterprise solution design and facilitation and effective interactions.
10. Validate network alerts by coordinating with enterprise-wide cyber defense staff.
11. Analyze security incidents for trends and patterns to identify gaps and propose risk mitigation solutions.
The threat model depicts trust boundary, threat agent(s), threat vector(s), and safeguard(s) necessary to protect person, asset, data, and T-Mobile brand. Also responsible for other duties/projects as assigned by business management as needed.
Education
Bachelor's Degree in Computer Science or Information Technology or equivalent work experience.
Work Experience
4-7 years of experience in info security technology or related field. Experience with incident handling for security breaches. Expert in security subject areas. 2-4 years of technical project management experience. Experience with high-level design architecture, security technologies, networking, web services, and SOA. Understanding of encryption, obfuscation, and tokenization technologies.
Knowledge, Skills and Abilities
1. Medium to advanced knowledge of scripting tools (Python/Perl/Shell/HTML/PHP).
2. Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI.
3. Familiarity with load balancers (e.g., A10, F5), firewalls (e.g., CheckPoint), Venafi, MDM (e.g., Mobile Iron), Cloud (e.g., AWS, Azure), Malware Protection (e.g., FireEye), Advanced Persistent Threats (e.g., Damballa), Privileged Accounts (e.g., CyberArk), SIEM (e.g., ArcSight), Log & Event (e.g., Splunk), Intrusion IDS/IPS (e.g., Symantec), Cloud Platform (e.g., PCF, Docker), Scanning (e.g., Qualys), AppSec (e.g., Veracode).
4. Solid understanding of T-Mobile's network elements and how they work together (EIT, Engineering & 3rd Party).
5. Strong presentation skills to large and small audiences.
6. In-depth knowledge of security standard processes in large-scale environments.
7. Strong problem-solving/troubleshooting skills.
8. Dedicated and able to work under timelines.
9. Always act with tact and integrity, and collaborate with a variety of individuals in a positive and productive manner.
10. Strong verbal and communication skills with diverse multi-functional groups & the ability to communicate effectively to small & large groups.
11. Knowledge of information security policies and regulatory controls (per team function).
12. Demonstrable knowledge of current technological trends and developments in the area of info security.
13. Ability to plan, organize and prioritize tasks to complete independently; Ability to work under pressure and meet timelines.
14. Authority in many facets of network & information security, including Firewall policy design, SSL Certificate management, vulnerability analysis & mitigation, and other topics as assigned.
Licenses and Certifications
Certified Information Systems Security Professional (CISSP), CISSP and/or CCSK and/or CCSP and/or CISA/CISM certification a plus (Preferred). Certified Information Security Manager (CISM) (Preferred). Certified Information Systems Auditor (CISA) (Preferred).
Minimum Requirements
* At least 18 years of age
* Legally authorized to work in the United States
Travel
Travel Required: Yes
DOT Regulated Position: No
Safety Sensitive Position: No
Base Pay Range
$103,400 - $186,400
Corporate Bonus Target
15%
Company Details
Company: T-Mobile USA, Inc.
Industry: Wireless Telecommunications Carriers (except Satellite)
Job Information
Location: Bellevue, WA
Website: t-mobile.com
#J-18808-Ljbffr