Principal, Security Engineering
OCCAbout the role
What You'll Do:
OTSI is OCC’s technology strategy, research, and development team. The team focuses on architectural design, problem solving, and security using cutting edge technologies to deliver solutions for the organization as part of the OCC Unified Technology Strategy.
As a Principal, Security Engineer and senior member of the team, you will be responsible for collaborating with stakeholders, partner teams, and solutions architects to research and engineer available technologies as part of a comprehensive requirements-driven solution design. You will be developing technology engineering requirements and leading proof-of-concept and laboratory testing efforts using modern approaches to process and automation. With a specialty in security, you will have the opportunity to use a combination of an attacker’s mindset and a risk-based approach to integrate security into solutions.
Primary Duties and Responsibilities:
To perform this job successfully, an individual must be able to perform each primary duty satisfactorily.
Key contributor to technology platform design, testing, and implementation process to introduce new technology and improve existing technology using a zero-trust approach.
Define and implement testing and success criteria for platforms, products, and technologies to ensure alignment with business, security, and architecture objectives.
Lead and participate in exploratory proof-of-concept engagements and technology stress testing to determine solution feasibility and stability, while also identifying potential security risks.
Collaborate with various partner teams across technology, security, and business to provide technical security consultation as part of projects and daily business activities.
Create technical security knowledge and guideline documentation for new and existing technologies to assist partner teams with self-service security integration.
Design and contribute to infrastructure-as-code initiatives.
Build and maintain test and evaluation environments in the public cloud and OCC data centers.
Supervisory Responsibilities:
No direct supervision, is expected to provide mentorship to members of the team.
Qualifications:
The requirements listed are representative of the knowledge, skill, and/or ability required. Reasonable accommodations may be made to enable individuals with disabilities to perform the primary functions.
Excellent oral and written communication.
Data-driven and risk-based analytical skills to successfully assess, formulate, and present technical solutions.
Ability to work independently and collaboratively with local and remote OCC employees, vendors, and consultants.
Must possess critical OCC values, including (but not limited to) collaboration, credibility, trust, and adaptability.
Technical Skills:
Must have expertise in at least one of the following areas, as well as general knowledge in at least one additional area:
Network Security: solid understanding of the OSI model, common network protocols, next-generation firewalls and policy, intrusion prevention and detection, remote access solutions, ability to read and understand network traffic captures, etc.
Internet Security: Common layer 7 protocols (HTTP, SFTP, websockets, RTC, SMTP, etc.), forward and reverse proxies, cloud access security brokers, email security gateways and cloud API-based solutions, protocol tunneling, common web servers (Nginx, Apache, IIS) and OWASP, etc.
Systems Security: Operating systems (including NT, Linux, Unix, and mobile OS distributions), kernel modification, service/daemon hardening, file systems and registry, system authentication protocols, domain services, privileged access, application sandboxing, containerization, cloud and on-premises endpoint management, etc.
Identity Security: Domain services and identity-as-a-service platforms, authentication protocols and suites (NTLM, LDAP, Kerberos, SAML, OIDC, etc.), multi-factor authentication and password-less platforms and technologies, role-based access control and entitlements, etc.
Cloud Security: solid understanding of cloud infrastructure concepts, experience in Amazon Web Services, Microsoft Azure, and/or Google Cloud Platform, infrastructure-as-code and automation, DevSecOps concepts and tooling, etc.
Database Security: solid understanding of common database technologies on-premises and in the cloud (MSSQL, MySQL/MariaDB, Oracle, MongoDB, DB2), data field hardening and encryption, access controls, high-availability, etc.
Familiarity with
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s