The Security Operations Engineer is responsible for the development, design, and implementation of secure solutions and processes for the corporation and sub-entities. They identify, implement, support and maintain tool-driven and highly automated solutions to deliver key security management processes using existing tool sets and/or identify new tools as innovations in security are realized. They develop corporate governance in support of MAR, FINRA and other compliance/governance policies/procedures following NIST/Hi-Trust best practices. They are responsible for ensuring that the software development lifecycle (SDLC) follows security best practices and adhering to secure coding principles by facilitating the scanning and testing of software applications against security risks/vulnerabilities before release.
The Security Operations Engineer leads Security Operation integrations between various security technologies and business software within existing infrastructure platforms (e.g. on premises, cloud, and hybrid). Work closely with various technology, project, and business teams to engineer and implement security controls with a focus on Security Operations. Provide mentoring for other project teams or individual team members regarding security concepts. Enable the business to achieve goals in a secure manner. Respond to, resolve, and escalate security incidents to all appropriate parties. Report unresolved security exposures, misuse of resources, and noncompliance situations using defined escalation processes.
The Security Operations Engineer builds security utilities and tools for internal use that enables high speed and wide scale security and identity solutions, monitoring and coverage. Evaluate and recommend use of machine learning, artificial intelligence, and data analytic services to enable action based decisions. With an emphasis on securing systems, applications, third-party connections, identities, service providers and ancillary systems, the security engineer is responsible for securing business-to-business initiatives, third-party relationships, outsourced solutions and vendors. Considered a highly knowledgeable individual, the security engineer is expected to implement, monitor and manage secure solutions that address modern day issues.
Skillsets:
40%
20%
20%
10%
10%
Additional Workday Skillset:
Workday Responsibilities - Designs, implements, and maintains Workday security architecture, including security groups, domain security policies, business process security configuration, and advanced access control models. Engineers automated identity governance and lifecycle integrations between Workday and enterprise IAM platforms, enabling secure provisioning, deprovisioning, SSO, compliance reporting, access certification, segregation of duties enforcement, and audit readiness.
Expert experience with Workday Security administration and architecture, including security groups, domain security policies, business process security, role-based access controls, and segregation of duties controls.
Experience designing and supporting Workday integrations with IAM, IGA, PAM, SSO, and provisioning platforms.
Experience implementing SAML, OAuth, and related authentication and authorization technologies within Workday environments.
Experience supporting Workday security audit, compliance, governance, and identity lifecycle management requirements.
#AFC
American Fidelity is a financial services organization subject to regulatory compliance requirements including MAR and FINRA regulations. The company operates across multiple infrastructure platforms including on-premises, cloud, and hybrid environments. They focus on secure software development lifecycle practices and governance frameworks aligned with NIST and Hi-Trust standards. American Fidelity maintains business-to-business initiatives and manages third-party vendor relationships with emphasis on security controls and compliance.