Sr Info Security Engineer - Information Security
MoneyGram Sr Info Security Engineer - Information Security
At MoneyGram, we connect the world by making cross-border money transfers seamless, affordable, and secure for everyone. We are seeking Senior Information Security Engineer. In this role, you will serve as a hands-on team member, working day-to-day across teams in security and IT operations ensuring the availability, confidentiality and integrity of IT systems by implementing security controls in the environment.
This role blends deep technical security expertise, Knowledge of common security tools and technologies such as EDR, SIEM, cloud security tools in AWS and GCP and vulnerability management tooling.
What you will get to do
Security tool implementation
Implement and configure security tools such as EDR, Email security, SOAR, and SIEM
Enable alert use cases in accordance with MITRE attack framework
Evaluate detection use cases for effectiveness and make changes accordingly
Evaluate control gaps and recommend technologies to fill them
Evaluate potential new tools and vendors.
Evolve security controls based on real world attack strategies
Incident Response
Monitor environments and respond to security detections
Work with security analysts to enrich detection data and confirm validity of incident
Prepare post incident reviews and brief security leadership on response actions
Cloud Security
Implement and maintain cloud visibility and scanning tools
Build and implement cloud environment scanning and detection methodology
Prioritize findings for remediation
Automation & Scripting
Identify repetitive tasks and automate for efficiency
Use scripting tools to aid in security tool implementation
Leverage API integrations to aid in pulling in tool data
Communications
Collaborate with peers across IT and security to plan remediation activities
Communicate program status to security leadership
Help foster a strong security culture where security is viewed as an enabler and not a blocker
Who you are
Bachelor’s degree in computer science or related field; or equivalent post high school education and/or work-related experience.
Preferred Certifications – CISSP, CCSP, AWS certified security, Azure Security Engineer
At least 3 years of experience in a security engineer role.
At least 3 years of experience with implementing SIEM and EDR.
Experience with tools such as Tenable, Qualys, Rapid 7, Carbon Black, CrowdStrike, Splunk, Torq, Darktrace, Abnormal, Proofpoint or Mimecast.
Background in vulnerability management including remediation prioritization.
Scripting experience with Bash, Python or PowerShell
Experience securing a regulated environment, PCI, GDPR, ect.
Strong bias toward AI-driven automation and scalable security solutions.
Experience with one or many of the following areas of security technologies:
Vulnerability management tooling.
EDR tooling
Email Security tooling
DLP technologies
Edge detection technologies
Cloud native security technologies.
SOAR and or hyper automation
SIEM technologies and use case enablement
Solid knowledge of security risks/threats to large organization systems and networks, and ability to address those threats.
Experience with scripting, programming, and AI-driven, automation technologies.
Experience with designing controls to meet regulatory compliance such as PCI, SOC, and SOX.
Strong problem-solving skills and ability to analyze and resolve problems.
Ability to translate complex technical information across all levels of the organization.
Strong relationship-building skills with business stakeholders.
Excellent interpersonal, communication, and presentation skills.