Cybersecurity Engineer

Visa Visa · Fintech · Austin, TX

Cybersecurity Engineer at Visa focused on supporting and managing security engineering processes and testing efforts. Responsibilities include performing penetration tests, SSDLC code reviews, assisting with design reviews, supervising security governance, creating reports, and managing security findings and exceptions.

What you'd actually do

  1. Perform Discovery Penetration Tests of Web Applications and APIs
  2. Perform SSDLC Code reviews
  3. Supervise all Security Governance activities for VAS
  4. Create and disseminate reports (weekly, monthly, ad-hoc) as required to management and executive management
  5. Coordinate scheduling and execution of security tests, including CheckMarx, BlackDuck, and PEN tests

Skills

Required

  • 8+ years of relevant work experience with a Bachelor’s Degree or at least 5 years of experience with an Advanced Degree (e.g. Masters, MBA, JD, MD) or 2 years of work experience with a PhD, OR 11+ years of relevant work experience.
  • Strong Security background
  • Pentest process knowledge
  • SSDLC process understanding knowledge
  • Minimum 5-8 years of experience working as an IT auditor or in IT-audit environment
  • 3-5 years Project Management experience
  • Strong analytical and problem solving skills
  • Excellent written and verbal communication and interpersonal skills
  • Ability to work independently with minimum supervision and handle multiple simultaneous projects with deadlines
  • Extremely detail oriented, conscientious, thorough and accurate
  • Expert with MS Office applications (Excel, PowerPoint, Word), SharePoint, document control systems.
  • Ability to collaborate in a professional manner with varying levels of management
  • Advanced knowledge of Cobit, FFIEC, Sarbanes-Oxley, PCI-DSS, SSAE 16, NIST
  • Knowledge of OWASP top 10, SANS top 20 Critical Security Controls
  • Ability to influence process and control alterations in the environment requires ability to influence and advise colleagues
  • Knowledge and understanding of Finding Management to include Exception Management
  • Knowledge of Visa organization and systems
  • Experienced Pen testing background
  • Experience in SSDLC Testing and review
  • Experience in Open-Source Vulnerability Management
  • Experience with Penetration testing
  • Mobile Secure Development Best Practices
  • Knowledge of Mobile security Best Practices
  • Knowledge and background on Mobile security evaluating tools and processes

What the JD emphasized

  • Must use independent judgment and latitude in deciding that artifacts provided to audit are appropriate, within the scope, and delivered on time to the auditing body.
  • Individual will function with minimal daily guidance from management.
  • Candidate will interface with varying levels within the organization, including Directors and Executive Management.