logo

JobNob

Your Career. Our Passion.

Cyber Security Expert


Location

Bridgewater, NJ | United States


Job description

Responsibilities

In Digital Cyber Security Dept., we are looking for a Digital Cyber Security Expert into the Vulnerability Operations Center, one pilar of the Vulnerability Operations Center & Legal Ops Team.

Position is focus on Internet Risk Exposure . The activity is global, relates to different categories of assets (Web sites, APIs, Routers, IPs,…) and the team is responsible for detection, analysis and remediation to any possible cyber-threats and/or non-compliances. Digital Cyber Security Expert needs to be an expert in cyber security. He/She must have expertise in principles of ethical hacking, secure development, and system hardening (Top 10 OWASP, Top 25 CWE, Patch management, …).

Main missions: ​

Key Responsibilities:

Strategic Vision

Project management

Based on your technical experience and Cyber expertise on some key components like Web site, APIs, Infrastructure components, Database, PowerBI, build a consistent management of vulnerabilities from end-to-end, and contribute to identifying any deviation to best practices.

Leverage as much as possible existing security features already purchased and identify the best combination.

Profile:

Formal Education and Experience Required

University/Master’s Degree in Computer Science, preferably in Information Security.

Real world Vulnerability Management experience.

10 years of professional experience in IS/IT, of which 5 years is in IS/IT Security.

Security Certifications like CISSP or CEH.

Expertise and Competencies

Significant expertise in secure development of Digital components (Web site, Web services, APIs, …)

Experience feedback on Vulnerability detection scanners would be preferred

Basic understanding of network infrastructure components, WAF, proxy, and firewalls is necessary.

Experience in Vulnerability management would be preferred.

Basic skills in building SQL request and PowerBi dashboards would be preferred.

Leadership and strong communication skills.

Ability to translate complex technical stories into non-technical language is necessary.

Mastery of English is required.

Experience feedback on O365 and Zscaler cloud services would be preferred.

Basic understanding of computer networks, firewalls, intrusion prevention technologies, and Antivirus technologies is necessary.  Real world experience working with these technologies is expected.

Expertise as a red team penetration tester or a blue team system defender would be preferred.

Experience with Security Information Event Management (SIEM) systems and Event Detection and Response (EDR) technology.

Basic scripting skills in Python, Powershell and Visual Basic would be expected.  More advanced programming skills are not required but would add strongly to the profile.

Sanofi Inc. and its U.S. affiliates are Equal Opportunity and Affirmative Action employers committed to a culturally diverse workforce. All qualified applicants will receive consideration for employment without regard to race; color; creed; religion; national origin; age; ancestry; nationality; marital, domestic partnership or civil union status; sex, gender, gender identity or expression; affectional or sexual orientation; disability; veteran or military status or liability for military status; domestic violence victim status; atypical cellular or blood trait; genetic information (including the refusal to submit to genetic testing) or any other characteristic protected by law.

#GD-SA 
#LI-SA

At Sanofi diversity and inclusion is foundational to how we operate and embedded in our Core Values. We recognize to truly tap into the richness diversity brings we must lead with inclusion and have a workplace where those differences can thrive and be leveraged to empower the lives of our colleagues, patients and customers. We respect and celebrate the diversity of our people, their backgrounds and experiences and provide equal opportunity for all.

Apply for role


Job tags



Salary

All rights reserved