Jobs and Careers
SO

Senior Cybersecurity Engineer

Sound Transit
United Statesfull_timeVerifiedPosted 13 Sept 2024
💰 $195,000/yr($100,000/yr$195,000/yr)

About the role

Salary range is $100k to $195k, with a midpoint of $145k.  New hires typically receive between minimum and midpoint, however, we may go slightly higher based on experience, internal equity and market.

Sound Transit also offers a competitive benefits package with a wide range of offerings, including:

  • Health Benefits: We offer two choices of medical plans, a dental plan, and a vision plan all at no cost for employee coverage; comprehensive benefits for employees and eligible dependents, including a spouse or domestic partner.
  • Long-Term Disability and Life Insurance.
  • Employee Assistance Program.
  • Retirement Plans: 401a – 10% of employee contribution with a 12% match by Sound Transit; 457b – up to IRS maximum (employee only contribution).
  • Paid Time Off: Employees accrue 25 days of paid time off annually with increases at four, eight and twelve years of service. Employees at the director level and up accrue additional days. We also observe 12 paid holidays and provide up to 2 paid floating holidays and up to 2 paid volunteer days per year.
  • Parental Leave: 12 weeks of parental leave for new parents.
  • Pet Insurance.
  • ORCA Card: All full-time employees will receive an ORCA card at no cost.
  • Tuition Reimbursement: Sound Transit will pay up to $5,000 annually for approved tuition expenses.
  • Inclusive Reproductive Health Support Services.
  • Compensation Practices: We offer competitive salaries based on market rates and internal equity. In addition to compensation and benefits, you’ll find that we provide work-life balance, opportunities for professional development and recognition from your colleagues.

GENERAL PURPOSE: 

Under general direction, the Senior Cybersecurity Engineer performs at a senior professional level supporting the operation of the technical controls outlined by the Agency’s Information Security Program for its corporate IT infrastructure; evaluates, designs, builds, and documents security solutions; evaluates proposed projects and activities to identify information security risks and available mitigating controls; evaluates systems for compliance with internal policies and standards, as well as applicable regulatory frameworks, recommending solutions to address any gaps; and acts as primary handler in the execution of the incident response plan for IT.

ESSENTIAL FUNCTIONS:

The following duties are a representative summary of the primary duties and responsibilities. Incumbent(s) may not be required to perform all duties listed and may be required to perform additional, position-specific duties.

  • Identifies and assesses technology-related risks to information security associated with current and prospective technology solutions; and recommends appropriate mitigating controls. 
  • Develops technical standards to interpret and implement applicable information security policies and controls; evaluates any prospective technology solution for adherence to documented agency standards, policies, and regulatory responsibilities. 
  • Collaborates with other IT engineering and administration disciplines to ensure security best practices are incorporated into design, implementation, and sustainment of systems and services within the enterprise. 
  • Assesses and classifies any identified system vulnerabilities in accordance with pre-defined risk criteria; advises and consults with internal customers on risk assessment, threat modeling, and mitigation of vulnerabilities. 
  • Develops Incident Response dashboard and metrics; leads information security incident investigation and response efforts; conducts computer and network forensic investigations in support of incident response activities; performs root-cause analysis when incidents occur and prepare incident reports. 
  • Evaluates, implements, and supports security-focused tools and services required to support information security controls. 
  • Assists in promoting a culture of information security at Sound Transit. 
  • Conducts regular security reviews of both software and processes. Reviews and creates threat models and recommends security enhancements consistent with information security strategy and evolving threats. 
  • Interacts with penetration testers and other external vendors as needed. 
  • Keeps up to date on latest information security trends, “best practices”, threats, and countermeasures. 
  • Reviews log-based data, both in raw form and utilizing SIEM or

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Sound Transit

View company profile →