Sinclair

Senior Information Security Engineer

Hunt Valley, Maryland · Hybrid · Posted today

Opens edyy.fa.us2.oraclecloud.com

Get a version of your resume written for this job.

Salary
Not listed
Job type
Full-time
Work mode
Hybrid
Source
Oracle (employer's hiring system)

Skills mentioned

SaaS

About the role

The Senior Information Security Engineer will support an enterprise security program including conducting deep-dive Third-Party Risk Management (TPRM) assessments, developing and delivering security awareness training campaigns, identifying, tracking, and coordinating vulnerability remediations based on threat intelligence feeds, performing litigation support and investigations, establishing policy enforcement processes, and engineering automations to improve time to deliver using Artificial Intelligence (AI) or automation platforms.

The applicant must have prior experience engineering security solutions with successful deployments in complex commercial enterprise environments. The candidate should have prior experience in a security operations or engineering role, with expertise conducting third-party, software, and vendor risk assessments. Additional required skills are, developing and enhancing security policies and standards, and hands-on knowledge of cloud (SaaS) and hybrid network infrastructure environments, establishing automations to improve accuracy and speed of outcomes, and performing disaster recovery (DR) /Continuity of Operations (COOP) assessments. The candidate will possess strong and polished communication skills, willingness and ability to present security topics to internal and external customers and thrive in a highly visible and fast-paced role. 

Responsibilities:

Process & Execution

  • Conduct high-quality and timely third-party/vendor/service provider/software risk assessments, with the ability to meet SLAs and communicate effectively with all stakeholders.
  • Contributes to the creation and maturation of information security policies and processes. 
  • Identifies opportunities to automate manual processes and successfully engineers and delivers on process improvements according to assigned timelines.
  • Develops and delivers Disaster Recovery and Continuity of Operations risk assessments to business units successfully establishing resiliency plans for the company. 
  • Assist with the governance of the enterprise Policy Exception process including stakeholder engagement, driving completion with internal teams, and providing balanced reports that will be visible to senior leaders.
  • Create, adapt, and enhance weekly metrics to measure program effectiveness.
  • Evaluate security architectures including the ability to identify risks, compensating controls, and mitigation plans.
  • Develop custom security awareness and phishing campaigns to elevate employee knowledge of current trends and threats to Sinclair.
  • Perform, and maintain litigation and data retention holds using eDiscovery and other actions to support Sinclair Legal requests.
  • Ability to multitask, prioritize, and remain organized with simultaneous assignments while remaining flexible and resilient. 
  • Maintain a high level of professionalism and integrity with the ability to effectively communicate with internal and external stakeholders. 
  • Ability to think strategically, plan methodically, and execute tactically.
  • Take ownership of personal and professional development needed to excel in the role.

Collaboration & Partnerships

  • Apply excellent communication skills to efficiently collaborate with company stakeholders and business partners.
  • Ability and prior experience delivering live training sessions to diverse audiences.
  • Evaluate and recommend new products, maintain knowledge of emerging technologies, and maximize value from existing tool sets to ensure return on investment. 
  • Demonstrate strong problem-solving skills by identifying gaps or issues and clearly formulating solutions.
  • Ensure compliance with Sinclair policies and standards by communicating requirements to internal stakeholders.
  • Proactively respond to information security tickets and requests according to team SLA.
  • Collaborate with third parties to remediate risks to effectively minimize attack surface.
  • Operating with a strong sense of teamwork and personal accountability.

Performance Improvement

  • Identify areas of improvement within the security team to maintain a level of excellence.
  • Design, document, and implement procedures for analyzing and evaluating risk. 
  • Proactively and effectively look for ways to improve and optimize processes and techniques. 
  • Research emerging technologies and provide options to leadership for problem solving. 
  • Champion collaboration amongst teams, quality execution on assignments, and take personal accountability for deliverables.
  • Thrive within fast-paced operational environment requiring priority adjustments, multi-tasking, and a high-level of communication skills.
  • Ability to self-motivate and go the extra mile to ensure team success. 
  • Maintain a positive and customer-oriented approach to daily operations.         
  • Comfortable working directly with other teams such as Legal, Privacy, and IT.

Qualifications:

  • Bachelor’s degree in Information Security, Information Technology, or related discipline. 
  • 7 years of relevant work experience or a combined background in the following areas: third-party risk management, security operations, security engineering, risk management, vulnerability management.
  • Experience with enterprise threat intelligence and third-party risk management platforms.
  • Demonstrated experience leveraging artificial intelligence (AI) and automation tools to streamline workflows, improve operational efficiency, and enhance decision-making.
  • Understanding of SOC-2, ISO-27001, and NIST SP 800 “series” frameworks with the ability to identify and mitigate control gaps.
  • Exceptional verbal and written communication skills with an ability to present complex information to audiences of varying subject knowledge. 
  • Solid technical background with the ability to understand network and systems architectures. 
  • Prior experience working in commercial multi-cloud provider environments.
  • Industry certification required in one of the following areas: (e.g., CISSP, CISM, CRISC, Security+, CISA, or equivalent).
  • Basic knowledge of current data privacy laws (CCPA/CPRA, GDPR).
  • Prior experience in the broadcast/media entertainment industries preferred.
  • Experience conducting litigation holds, retention requests, and eDiscovery is a big plus.
  • Commercial enterprise experience is required. 

Please note that this position is not eligible for visa sponsorship, including employer sponsorship for an H-1B visa, OPT-STEM employment, etc.

Sinclair is proud to be an equal opportunity employer and a drug free workplace. Employment practices will not be influenced or affected by virtue of an applicant's or employee's race, color, religion, sex (including pregnancy, gender identity, and sexual orientation), national origin, age, disability, genetic information, military or veteran status or any other characteristic protected by law.

About Sinclair:

Sinclair, Inc. (Nasdaq: SBGI) is a diversified media company and a leading provider of local news and sports. The Company owns, operates and/or provides services to 177 television stations in 79 markets affiliated with all major broadcast networks; owns Tennis Channel, the premium destination for tennis enthusiasts; and multicast networks CHARGE, Comet, ROAR and The Nest. Sinclair’s AMP Media produces a growing portfolio of digital content and original podcasts. Additional information about Sinclair can be found at www.sbgi.net.

 About the Team

The life-blood of our organization is our people. We have a compelling story, a goal-oriented culture, and we take really good care of people. How good? Here is a glimpse: great benefits, open-door policy, upward mobility and a strong desire to see you succeed. Ready to be part of a winning team? Let’s talk.

The base salary compensation range for this role is $93,000 to $124,000. Final compensation for this role will be determined by various factors such as a candidates’ relevant work experience, skills, certifications, and geographic location. Full time positions are eligible for benefits that include participation in a retirement plan, life and disability insurance, health, dental and vision plans, flexible spending accounts, sick leave, vacation time, personal time, parental leave and employee stock purchase plan.

Job ID or-edyy-fa-us2-oraclecloud-com-cx-2002-17346 · Original posting ↗