Point your AI agent at freehire and let it find you a job.

Get the CLI →

Quest Diagnostics

NewBe an early applicant

Principal Engineer, IT Security

Discussion

Summary

A principal-level IT security engineer at Quest Diagnostics who drives vulnerability management, asset lifecycle/decommissioning, and security architecture reviews while reporting risk posture and metrics to senior leadership and the CIO. Day-to-day blends hands-on work with security tooling (scanning, SIEM, DLP, IDS) across cloud and datacenter environments with governance duties on the Security

We are seeking a Senior Security Engineer to champion the security, integrity, and compliance of our global infrastructure. In this high-visibility role, you will act as a strategic bridge between deep technical execution and executive-level governance, routinely interfacing with Senior Leadership and the CIO to present risk postures, security metrics, and SLA compliance. Balancing multi-disciplinary expertise across host and network security, with a sharp specialization in vulnerability management, you will drive critical initiatives to help drive a more robust asset management framework and lifecycle refresh programs (maintaining N/N-1 standards), and accelerate system decommissions to minimize our attack surface. You will also sit on our Security Review Board to assist with security architecture reviews for IT initiatives throughout the company.

On the operational front, you will provide direct assistance in maintaining an uncompromising, pristine security posture in both appearance and reality. This includes incorporating the outputs of various tools in our cloud and datacenter environments, establishing direct, collaborative relationships with Firewall and Infrastructure Operations teams, and prioritizing the remediation of confirmed vulnerabilities over potential ones to systematically reduce true risk. As a core representative on the Vulnerability Council, and Security Review Board (SRB), you will drive the security messaging, synthesizing SRB findings, vulnerability reporting and exception data into a unified, accurate narrative.

The Principle IT Security Engineer also must support the continual improvement of our IT security infrastructure. The person in this position will be a thought leader in the IT organization and considered a subject matter expert in multiple security-related areas as well as in the field of IT Security and or risk overall. This position requires advanced security expertise. Additionally, strong written and oral communication skills are important for this role. To maintain our security posture, this position may occasionally collaborate on after-hours or weekend response for high-priority security events.

Please note this is a hybrid opportunity (3 days in office & 2 days WFH). This position can be based in Secaucus, NJ or Schaumburg IL .

Pay Range: $160,000 - $170,000 / year

Salary offers are based on a wide range of factors including relevant skills, training, experience, education, and, where applicable, certifications obtained. Market and organizational factors are also considered. Successful candidates may be eligible to receive annual performance bonus compensation.

Benefits Information:

We are proud to offer best-in-class benefits and programs to support employees and their families in living healthy, happy lives. Our pay and benefit plans have been designed to promote employee health in all respects – physical, financial, and developmental. Depending on whether it is a part-time or full-time position, some of the benefits offered may include:

  • Day 1 Medical, supplemental health, dental & vision for FT employees who work 30+ hours
  • Best-in-class well-being programs
  • Annual, no-cost health assessment program Blueprint for Wellness®
  • healthyMINDS mental health program
  • Vacation and Health/Flex Time
  • 6 Holidays plus 1 "MyDay" off
  • FinFit financial coaching and services
  • 401(k) pre-tax and/or Roth IRA with company match up to 5% after 12 months of service
  • Employee stock purchase plan
  • Life and disability insurance, plus buy-up option
  • Flexible Spending Accounts
  • Annual incentive plans
  • Matching gifts program
  • Education assistance through MyQuest for Education
  • Career advancement opportunities
  • and so much more!
  • Develops security and or risk strategies and solutions to improve, augment and enhance the posture of IT Security at Quest Diagnostics.
  • Advise on and/or support a variety of security tools. These may include products and tools in various areas including: network vulnerability scanning, application vulnerability scanning; network and application access controls; intrusion detection systems; data loss prevention, security incident and event management (SIEM), etc.
  • Assists in the review and alignment of applicable IT security SOP’s.
  • Periodically reviews and updates corporate IT Security standards and procedures as required by such changes in technologies, business activities, corporate policies and/or regulations.
  • Work with IT leadership and the business to develop strategies and plans to enforce security requirements and address identified risks.
  • Is a subject matter expert in multiple areas of IT Security including the field of IT Security and or risk overall, and provides technical guidance on any IT projects.
  • Develops and maintains detailed knowledge of security products, tools, regulations, best practices, and trends.
  • Reports to IT management concerning risk, vulnerabilities and other security exposures, including misuse of information assets and noncompliance.
  • Plays a consultative role in security aspects of application development and lead security role in acquisition/merger projects to assess security requirements and controls and to ensure that security controls are implemented as planned.
  • Collaborates on critical IT projects to ensure that IT security issues are addressed throughout the project life cycle.
  • Fully understand security policies, standards, processes and procedures, and supports service-level agreements (SLAs) to ensure that security controls are managed and maintained.
  • Researches, evaluates and recommends IT and information-security-related hardware and software, including developing business cases for security investments.
  • Assumes highly visible technical project management role.
  • Manages relationships with key IT Security product and service vendors.
  • Provide oversight and expertise to assist in deployment, configuration, and maintenance of our suite of security tools.
  • Works closely with Enterprise Architecture in the overall design and implementation of security solutions.
  • When appropriate represents IT Security to Senior IT Management and customers

Required Work Experience:

  • Minimum 10 years’ experience with the implementation and support of an IT Security program including: aspects of security design and engineering; threat and vulnerability management; data protection; incident management and response; application security development, testing and assessments; and security management,
  • This person should be able to perform a variety of technical tasks, including, for example, the installation of security software, configuration of software, and problem determination and resolution.

Preferred Work Experience:

  • Minimum 10 years’ experience with the implementation and support of an IT Security program including: aspects of security design and engineering; threat and vulnerability management; data protection; incident management and response; application security development, testing and assessments; and security management.

Skills:

  • Demonstrated ability in defining and/or evaluating security requirements and relate them to appropriate security measures and controls.
  • Ability to interact with company personnel at all levels and across all business units and organizations, and to comprehend business imperatives.
  • Strong leadership abilities, with the capability to develop an IT security team and guide team members and to work with only minimal supervision.
  • Sound communications skills, including both oral and written, are important for the candidate to be successful in this role.
  • Creativity
  • Timely Decision Making
  • Peer Relationships
  • Problem Solving
  • Intellectual Horsepower
  • Decision Quality
  • Directing Others
  • Presentation Skills
  • Communication Skills

Education

  • Bachelor’s Degree B.A. or B.S. Degree or equivalent education and experience required (Preferred)
  • Master’s Degree Specialized education and/or training in information security highly desirable (Preferred)

Licenses and Certifications

  • Certified Information Systems Security Professional (CISSP) (Preferred)
  • GIAC Security Expert (GSE) (Preferred)
  • Systems Security Certified Practitioner (SSCP) (Preferred)

Skills

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available