M+E Technology Job Board

Information Security Engineer

Salesforce

Job Details

Salesforce’s Threat and Vulnerability Management Team is looking for an Information Security Engineer to help ensure that our systems and software are deployed and implemented to the highest security standards and drive remediation of vulnerabilities across the enterprise.

Technical Competencies:

Strong understanding of Information Security principles and technologies.

Experience conducting vulnerability scanning and security assessments

Accurate perspective on severity of vulnerabilities detected by vulnerability scanners

Familiar with industry blogs, key publications if the field of security and awareness of any recent significant security events.

Work experience managing Linux and Windows Servers/Desktops, Mac OS X

Experience with Cloud Security, networks, firewalls, Endpoint Protection, Vulnerability Management (preferably Nessus), Log Management (preferably Splunk), Patch Management, and Active Directory

Verbal and Communication Skills.

Ability to self motivate when given strategic goals

Type of work/Responsibilities:

Monitor and analyze technical vulnerability data from security tools, determine risk-level, create and route work tickets for resolution

Use vulnerability scanners to scan devices for vulnerabilities

Provide analytical support and consultation for vulnerabilities with internal teams

Prepare and present reports that document vulnerability trends within our environments as well as key areas for improvement

Understand company security policies/standards and government regulations.

Work with internal teams to maintain compliance with these policies and regulations

Recommend new security tools and methodology to improve security posture

Execute analysis/review of vulnerability scans at least weekly

Provide support and evidence collection for Plan of Action and Milestone (POA&M)

Determine deltas and report metrics on existing and new vuls

Advocate security and secure practices throughout Salesforce.

Work to drive remediation of vulnerability across teams

Ticket Tracking and review

Provide support or present on the vulnerability data during Monthly ConMon meeting with Sponsoring Agency