Cyber Security Engineer
- Full-time
Company Description
Avery Dennison Corporation (NYSE: AVY) is a global materials science and digital identification solutions company that provides branding and information labeling solutions, including pressure-sensitive materials, radio-frequency identification (RFID) inlays and tags, and a variety of converted products and solutions. The company designs and manufactures a wide range of labeling and functional materials that enhance branded packaging, carry or display information that connects the physical and the digital, and improve customers’ product performance. The company serves an array of industries worldwide, including home and personal care, apparel, e-commerce, logistics, food and grocery, pharmaceuticals and automotive. The company employs approximately 36,000 employees in more than 50 countries. Reported sales in 2022 were $9.0 billion. Learn more at www.averydennison.com.
At Avery Dennison, some of the great benefits we provide are:
- Health & Wellness benefits starting on day 1 of employment
- Paid parental leave
- 401K eligibility
- Tuition reimbursement
- Flexible work arrangements
- Employee Assistance Program eligibility / Health Advocate
- Paid vacation and Paid holidays
Job Description
What You’ll Do:
- Identify, minimize and lead both internal and perimeter attack surface to Avery Dennison’s IT environment
- Manage and support vulnerability management (“VM”) tool sets including:
- a CSPM - Cloud Security Posture Management platform
- a SAST - Static Application Security Tool and two enterprise vulnerability scanning platforms
- Scope of the VM tool set management include:
- Test and deploy new features and capabilities
- Manage access and permission of users, groups and roles
- Educate and advise internal partners to demonstrate VM tool sets for self service
- Maintain overall health status of the tool sets, solve issues and errors.
- Configure and update tool sets routinely to reflect IT infrastructure and organizational changes
- Ensure scan queue are scheduled, and jobs are performed without failure
- Perform review of security findings of on-premise infrastructure and multi-cloud environments.
- Prioritize vulnerabilities, and assign tasks to appropriate owners for remediation of vulnerabilities
- Carry out remediation SLAs and advance per Avery Dennison IT security policies and guidelines
- Educate and advise internal partners on high risk and/or high priority security vulnerabilities
- Set up and continue to grow automated scanning, ensuring maximum coverage through scanning
- Work with multiple teams and organizations, translate security and vulnerability requirements into business context
Role Location
#LI-Remote - Work from home 5 days per week
Pay Range: $82,425-$123,000
The salary range above represents what Avery Dennison reasonably expects to pay for this position as of the date of this posting. The actual salary will vary within the range, and in extraordinary circumstances may be above or below the range, based on various factors including but not limited to a candidate’s relevant skills, experience, education, and location.
Qualifications
- Bachelor's degree in information systems, information security, computer science, engineering or similar technical field of study and 4+ years of professional experience in information security, networking and/or systems administration; OR 5+ years of professional experience in information security in lieu of a degree
- 3+ years of experience implementing, and/or maintaining vulnerability and configuration management technologies in an enterprise level environment
- Experience with Linux, Windows, and Mac system internals and configuration management tools
Preferred Skills and Experience
- Experience with on-premise and cloud vulnerability management products. Examples:
- CSPM: Sysdig, Lacework, Wiz, Aqua Security or similar
- SAST: Veracode, CheckMarx, Synopsys, SonarCube or similar
- Vulnerability Scanner: Qualys, Rapid7, Tenable or similar
- Knowledge of SDLC, modern application development processes and tools.
- Knowledge of cloud computing technologies (IaaS, PaaS) kubernetes and containerization technologies.
- Knowledge of IT infrastructure design including identity and access management, Active Directory, firewall, and proxy.
- Ability to learn and master cyber security platforms and technologies - through provided resources, documentation and training
- Independent research and analytical skills on cyber security concepts, knowledge, and specific vendor technologies.
- Strong communication skills with internal partners - both written and verbal
- Ability to work with vendors to diagnose and solve problems, and consult on design and configurations
- Familiar with security best practices for Windows, Linux, and Mac OS, and secured networking design
- Experience in analyzing & validating vulnerabilities to most effectively prioritize the most critical vulnerabilities
Additional Information
All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, sexual orientation, gender identity, disability, protected veteran status or other protected status. EEOE/M/F/Vet/Disabled. All your information will be kept confidential according to EEO guidelines. If you require accommodations to view or apply for a job, alternative methods are available to submit an application. Please contact (440)534-6000 or [email protected] to discuss reasonable accommodations.
By clicking the link above or any third-party link within this posting, you are leaving this site and going to a third-party website where the third-party website's terms and privacy policy apply