Principal Cybersecurity Engineer
The Cybersecurity Engineering function is responsible for supporting the design and implementation of Security Architecture patterns into functioning platforms and systems within Comerica. This includes the engineering, deployment, and advanced support of critical control systems, security platforms, and associated workstreams or processes. The Cyber Engineering teams collaborate closely with peers within the Cyber Defense Organization and Technology teams to enable and support Comerica's systems.
The Principal Cybersecurity Engineer is accountable for the successful delivery of department-wide engineering efforts for distributed and complex systems. The role is focused on providing technical leadership in the application of security solutions and keeping in-touch with innovation in their target knowledge domain. The Principal Cybersecurity Engineer is expected to work directly with their Cybersecurity Engineering Manager to govern and guide junior members of staff in the proper execution of tactical objectives. They are recognized as platform and domain experts across the business with a demonstrated history of cross-functional partnership and solutions design. The role will be expected to exhibit strong execution of projects of high to very high complexity in partnership with their assigned project resources. The Principal Cybersecurity Engineer is expected to provide direct support as a delegate of their Cybersecurity Engineering Manager in the areas of Risk Management, Third-Party Risk Management, Model Risk Management, and Business Continuity and Disaster Recovery planning.
Position Responsibilities:
Cybersecurity Engineering
- Provide expert-level analysis, solutions, and implementation plans based on the strategic roadmaps of their target knowledge domain.
- Partner with Risk Coordinators, and Audit partners to ensure the continual success of function-level Audit requests and identify areas of improvement in Engineering principles.
- Perform pinnacle-level incident and security response support in coordination with their Cybersecurity Engineering Manager and junior staff members.
- Accountable to the delivery of risk issue or control gaps in conjunction with their Cybersecurity Engineering Manager and oversees the execution of strategic remediation plans.
- Participate in the strategic planning of their target knowledge domain in partnership with Cybersecurity Architecture and their Cybersecurity Engineering Manager.
- Ensure the continuous improvement of security platforms or tools within their target domain.
Communication and Collaboration
- Socialize and refine feedback on risk identification mechanisms, gap analysis processes, roadmap creation, and knowledge management for the Cyber Engineering teams.
- Provide oversight to resource management with vendors, operations members, and partnering with functional management to push continual improvement in all areas of their domain.
- Maintain effective relationships with Cybersecurity Architecture and assists with the refinement of proposed design patterns.
- Build relationships with key stakeholders across the business to develop security solutions for existing and new business problems.
- Coordinate complex changes necessary to support enhancements to Cyber Engineering services.
- Collaborate with other Engineering and Operations teams within both the Cyber and Technology organizations to troubleshoot and respond to events, as directed by business processes.
- Present strategic roadmaps, project deliverables, risk issue closures, and other materials to members of Snr. Management and the Business as needed.
Department Sustainability and Innovation
- Maintain a pulse on changes within their target domain and ensures that areas of innovation, or critical risks, are evaluated in partnership with Cyber Architecture and other Engineering leads.
- Coordinate with their Cybersecurity Engineering Manager to develop sustainable business processes, roadmaps, and complex system enhancements to reduce risk and administrative burden.
Planning and Administration
- Assist management with the growth and development of their junior staff as a key deliverable in their transition of knowledge and innovation.
- Identify & evaluate projects/programs/initiatives & design processes that enhance & rationalize existing and upcoming solutions.
- Review and propose alternate solutions to non-standard solutions if/as applicable to meet business & applications needs.
- Review, identify & manage requirements for moderate solutions and do a cost value, feasibility, and risk analysis as appropriate.
- Assist & provide guidance on complex/ large project/program planning phases & process. Direct and/or indirect management responsibility for large to enterprise size projects /programs/initiatives/services with high complexity across multiple functional area(s).
- Keep management informed of status of on activities through accurate, timely, and appropriate reporting.
- Actively participate in committees representing the department and/or planning unit.
- Keep abreast of leading-edge technologies in the Cybersecurity engineering space.
Position Qualifications:
- Bachelor's degree in computer science, engineering or in a technology related field OR equivalent through a combination of education and/or technology experience OR 12 years of technology experience
- 6 years of relevant work experience within Cybersecurity Engineering or Operations
- 6 years of Expertise in a combination of the following domains of knowledge: Network Engineering and Security, Endpoint Security or System Hardening, SIEM or Detection Engineering, Cloud Operations or Security Engineering, Fraud Detection and Analysis, Security Automation or Software Development, Data Engineering or Analytics, and Technical Risk Analysis
- 5 years of Experience partnering with Architecture and Design teams to develop strategic initiatives and translate those into highly effective enterprise systems
- 3 years of working within an Agile team targeting an iterative release method for infrastructure and security services
- 3 years of experience working with general automation tools and processes like Python, Bash, Powershell, Git, etc.
Licenses/Certifications:
- Preferred, CISSP (Certified Information Systems Security Professional) CISM, CySA+, or other Expert-level certifications
- Preferred, Certifications within relevant Engineering Domain: CCNP/CCDA, GDSA, GCIA, GMON, GCDA, CCSP, RHCE, GPPA, GSA, AWS - Security
Work Best Category: Category C - Days in the office will either be designated days or will vary week to week from 2-5 days
Hours: 8:00am - 5:00pm Monday - Friday
Salary: To Be Determined Based on Individual Experience
About Comerica We know our employees are critical to our overall success and we are dedicated to investing in their future. One of the ways we do this is to offer a comprehensive Total Rewards package designed to recognize and reward individual performance, as well support health, well-being, development and security for our colleagues and their family. Total Rewards consists of cash compensation, development and flexible benefit programs designed to meet individual needs today and in the future. Your salary will be commensurate with your work experience and our programs are reviewed regularly to ensure each remain competitive. We are proud to offer benefits such as health and welfare programs, strong retirement benefits, and generous paid time off programs. You and your eligible family members, including domestic partners and their children, can participate in medical, dental, and vision benefits, 401(k) and pension, income protection benefits such as life insurance, AD&D, and supplemental health programs to offset unexpected health care expenses. We also have a variety of time off programs for things like vacation, sick time, disability, and parental leave. Eligibility for some programs varies based on employment status and tenure.
Upon offer, Comerica conducts a comprehensive background and fingerprint check.
NMLS certification requirement: where applicable, a favorable background check screening, credit check, fingerprint check, and NMLS certification is required in accordance with the SAFE Act.
Comerica Incorporated (NYSE: CMA) is a financial services company headquartered in Dallas, Texas, and strategically aligned into three major business segments; the Commercial Bank, the Retail Bank, and Wealth Management. Comerica's colleagues focus on relationships, and helping people and businesses be successful. In addition to Texas, Comerica Bank locations can be found in Arizona, California, Florida and Michigan, with select businesses operating in several other states, as well as in Canada and Mexico.
Comerica is proud to be an Equal Opportunity Employer - veterans/individuals with disabilities, committed to workplace diversity.
|