Engineer 3 - Cyber Security
Job Summary
This job ensures the integrity and security of the company's cyber infrastructure by designing robust system architecture. It also entails solving complex engineering challenges. It involves documenting technical processes, reporting outcomes, and recommending innovative solutions. The role supports project teams and influences engineering staff, while maintaining a comprehensive understanding of network protocols and security strategies. The position requires flexibility to work variable schedules, including nights and weekends, as necessary.Job Description
Position: Engineer 3 - Cyber Security
Experience: 5 years to 8 years
Job Location: Chennai Tamil Nadu
Live the Sky Values and demonstrate enthusiasm and a can-do attitude. • Demonstrate a passion for cyber security and have a positive outlook and approach to the work we do. • 5+ years' experience working within a security field or related discipline. Can be substituted for a relevant degree or equivalent qualification by related subjects such as technologies (e.g. MS IDAM experience), or any experience of compliance/regulatory frameworks (which may or may not by topics considered typical cyber security i.e. EECC, CCA, OFCOM or OSCR for example) • Strong skills in analytical, decision making, verbal and written communication capabilities. • Excellent teamwork skills to ensure we all collaborate, share and support one another. • Experience in Threat Modelling: • Strong understanding of threat modelling methodologies and frameworks, such as STRIDE, DREAD, or CAPEC. • Proficiency in conducting threat modelling exercises and identifying security vulnerabilities across various systems and applications. • Familiarity with industry best practices and standards related to threat modelling and security analysis. • Exposure to threat modelling tools and automation frameworks to enhance efficiency and accuracy. • Exposure with popular threat modelling tools, such as Microsoft Threat Modeling Tool, OWASP Threat Dragon, or ThreatModeler.
What you will do: • Proficient in managing your workload independently and familiarise yourself with industry business practices and procedures while taking ownership of your development pathway alongside your line manager and colleagues. • Work towards achieving a defined set of objectives identified between yourself and your line manager, tailored to your goals. • You will be able to perform an end-to-end threat model, using the STRIDE methodology, independently of any help. This means to organise, perform, document, engage stakeholders and follow up on the threat models taking place. • Develop and implement threat modelling methodologies and frameworks to assess our systems' security posture. • Conduct threat modelling exercises, utilizing tools and techniques to identify vulnerabilities and potential attack vectors. • Collaborate with stakeholders to integrate security controls and best practices into the software development lifecycle. • Recommend and design effective counter measures and risk mitigation strategies based on threat modelling findings. • Provide guidance and support to development teams on implementing security controls and addressing identified vulnerabilities. • Communicate effectively with stakeholders with varying levels of technical knowledge to explain security concepts. • Support external departments by providing early review of security implications and making necessary recommendations. • Engage with cyber stakeholders, the wider business, and external entities to facilitate and support the delivery of cyber services and initiatives. • Always look to improve your understanding and knowledge of the following. • Regulatory requirements on our business: TSA, PCI, SWIFT, GDPR (not an exhaustive list) • Architectural domains. DLP, CLOUD, IDAM, APP SW, LOGGING & MONITORING (not an exhaustive list) • Departments and their verticals. CONTENT, CUSTOMER, ISP, PRODUCT, DIGITAL, DATA (not an exhaustive list)
Responsibilities:
- Architecting secure system infrastructure within engineering projects, including the creation of design specifications
- Applying in-depth cybersecurity knowledge to solve complex development challenges and advance engineering objectives
- Documenting technical processes and results, and reporting findings to management with recommendations for innovative solutions
- Managing relationships with project groups and guiding less experienced cybersecurity staff
- Implementing cybersecurity measures for network infrastructure protection, adhering to secure routing protocols and best practices
- Conducting security assessments and audits to identify risks, and collaborating with teams to enhance organizational security posture
- Analyzing and responding to security incidents, leveraging technical expertise to mitigate impact on operations
- Maintaining current knowledge of cybersecurity trends and threats to inform strategic defenses and improve security measures
- Consistent exercise of independent judgment and discretion in matters of significance.
- Regular, consistent and punctual attendance. Must be able to work nights and weekends, variable schedule(s) as necessary.
- Other duties and responsibilities as assigned.
Employees at all levels are expected to:
- Understand our Operating Principles; make them the guidelines for how you do your job.
- Own the customer experience think and act in ways that put our customers first, give them seamless digital options at every touchpoint, and make them promoters of our products and services.
- Know your stuff be enthusiastic learners, users and advocates of our game-changing technology, products and services, especially our digital tools and experiences.
- Win as a team make big things happen by working together and being open to new ideas.
- Be an active part of the Net Promoter System a way of working that brings more employee and customer feedback into the company by joining huddles, making call backs and helping us elevate opportunities to do better for our customers.
- Drive results and growth.
- Support a culture of inclusion in how you work and lead.
- Do what's right for each other, our customers, investors and our communities.
Disclaimer: This information has been designed to indicate the general nature and level of work performed by employees in this role. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities and qualifications.
We believe that benefits should connect you to the support you need when it matters most, and should help you care for those who matter most. That's why we provide an array of options, expert guidance and always-on tools that are personalized to meet the needs of your reality—to help support you physically, financially and emotionally through the big milestones and in your everyday life.
Please visit the benefits summary on our careers site for more details.
Education
Bachelor's DegreeWhile possessing the stated degree is preferred, Comcast also may consider applicants who hold some combination of coursework and experience, or who have extensive related professional experience.Certifications (if applicable)
Relevant Work Experience
5-7 YearsComcast is an equal opportunity workplace. We will consider all qualified applicants for employment without regard to race, color, religion, age, sex, sexual orientation, gender identity, national origin, disability, veteran status, genetic information, or any other basis protected by applicable law.