Security Automation Engineer -Architect

20 Mar 2025

Vacancy expired!

Overview

Security Automation Engineer -Architect

Our Team: At BNY Mellon, Cyber Security is a top priority for both technology and the business Our Information Security Division is on constant alert using their creativity and knowledge of cybersecurity, technology, and business processes to develop and deliver solutions. In this fast-paced environment, we collaborate to respond to current risks while identifying and anticipating future threats. Our cyber capabilities encompass the full spectrum of services from Cyber Operations (SOC, Cyber Threat Intelligence, Vulnerability Management, Cyber Incident Response, Penetration Testing & Red Teaming, Cyber Analytics & Fraud, and Insider threat) to Cyber Architecture and Engineering (Network, Platform, Cloud, and Applications Security). We provide a robust set of cyber services that provide full scope protection and response capabilities across the BNY Mellon enterprise. We drive an understanding of cybersecurity risk and the steps that must be taken to create and maintain a secure environment that drives innovation

The Role: As a Security Automation Engineer / Architect, you will be responsible to partner with our DevOps teams to design, test and build detective, responsive and preventative controls to ensure a secure coding platform. You will need to work directly with business stakeholders, technical staff, and project teams to identify, analyze, design, test, and implement new systems or improvements to existing systems and associated procedures.

Key Responsibilities:
  • Review system and software releases for new functionality and test to optimize existing systems, processes, and integrations accordingly
  • Propose, develop, implement and maintain automation of security controls to support DevSecOps methodologies.
  • Provision, deploy and maintain security tools in collaboration with the application development teams.
  • Research current trends in DevOps tools in order to design best in class DevSecOps. Orchestrate multiple Proof of Concept initiatives to insure the AppSec team remains on the cutting edge of vulnerability prevention, detection and remediation.
  • Design, deploy, administer, monitor, and enhance the Application Security DevOps Framework.
  • Act as an authority on your domain expertise; combining expert-level proficiency with the ability to communicate clearly and collaborate to turn broad requirements into deliverable work items
  • Diagnose and resolve issues while identifying recurring problems or processes that can be remediated through automation
  • Troubleshoot system functional and operational issues as well as maintain the system operations at all times
  • Produce, maintain and update knowledge base documentation, runbooks, and SOPs
  • Identify and take advantage of opportunities to train and mentor various members of the Application Security team.
  • Perform and provide progress on project deliverables, tasks, and milestones, as well as provide project documentation such as, architecture diagrams, and runbooks
  • Act as a primary point of contact for system outages and escalations
  • Take initiative to develop unique projects in which you get to research new technology, solve more complex problems, perform POCs
  • Work with leadership to gather ROI and complete whitepapers to justify purchase approval
  • Work with team members to schedule and report upon the execution of testing and validation efforts as part of a formal release ITIL Change Management process
  • Represent team recommendations to leadership, demonstrate influence over governance bodies, and coach on communicating technical issues, impact, and risk mitigation strategies in business terminology that non-technical resources can understand
  • Build strong relationships and influence with vendors, business and technology leaders
  • Keep ahead of emerging trends, understand business area opportunities and challenges, process or system impacts to all related business or systems areas when designing recommended solutions to achieve business objectives
  • Perform other duties as assigned
  • Solid understanding of computing and network concepts and troubleshooting skills.
  • The utmost passion for technology and a thirst for knowledge and growth
  • Ability to work well within a team; good interpersonal relational and collaboration skills
  • Knowledge of downstream integrations to gauge the impact of changes, triage and remedy incidents, and scope level of effort for new initiatives
  • Knowledge of virtualization technologies
  • Have hands-on experience in grooming/mentoring individuals and being the bar raiser in the team
  • Demonstrated attention to detail with the ability to design and develop solutions to meet business needs creatively
  • Customer Service focused approach to interactions with business partners and employee user community
  • Strong organizational and time management skills
  • Demonstrated success in a fast-paced, high-performance, and deadline-driven engineering team
  • Ability to handle escalations and friendly resolution of the most complex hardware and software problems
  • Ability to learn quickly and use new complex technical concepts and resolve issues in a rapidly changing environment
  • Ability to discuss complex technical concepts with technical staff, stakeholders, and business executives in a simple, straightforward manner
  • Familiar with current security protection, encryption, monitoring/auditing, and remediation techniques with the proven ability to oversee solutions for the network, servers, databases, and the desktop
  • Familiar with disaster recovery, business continuity, and high availability concepts
  • Working knowledge of Windows and Linux operating systems and administrative functions (Ops Support)
  • Working knowledge of SDLC or CI/CD pipeline tools such as GitHub, Jenkins, Sonarqube, Selenium, Docker, Chef, Puppet, JIRA, etc.
  • Experience working with technologies such as Ansible, Stackstorm, Terraform, GitLab, Docker, VMWare
  • Working knowledge of secure code testing tools using static code analysis, dynamic analysis and Interactive Application Security Testing.
  • Ability to work independently to assess and address system issues
  • Experience managing 3rd party hardware and software vendors and providers

Qualifications: Required:
  • A minimum of 8 years- experience in IT
  • 5 years being responsible for application development of DevOps platforms or similar Enterprise wide services utilizing Python and or Java.
  • Bachelor's degree in a related discipline or equivalent combination of education and experience required
Preferred

:
  • Application security experience
  • CCSP and/or CSSLP certification
  • Experience working on an Agile team
  • Working knowledge of security frameworks such as NIST and ISO 27000

Employer Description:

For over 230 years, the people of BNY Mellon have been at the forefront of finance, expanding the financial markets while supporting investors throughout the investment lifecycle. BNY Mellon can act as a single point of contact for clients looking to create, trade, hold, manage, service, distribute or restructure investments and safeguards nearly one-fifth of the world's financial assets. BNY Mellon remains one of the safest, most trusted and admired companies. Every day our employees make their mark by helping clients better manage and service their financial assets around the world. Whether providing financial services for institutions, corporations or individual investors, clients count on the people of BNY Mellon across time zones and in 35 countries and more than 100 markets. It's the collective ambition, innovative thinking and exceptionally focused client service paired with a commitment to doing what is right that continues to set us apart. Make your mark: bnymellon.com/careers.

EEO Statement:

BNY Mellon is an Equal Employment Opportunity/Affirmative Action Employer. Minorities/Females/Individuals With Disabilities/Protected Veterans. Our ambition is to build the best global team - one that is representative and inclusive of the diverse talent, clients and communities we work with and serve - and to empower our team to do their best work. We support wellbeing and a balanced life, and offer a range of family-friendly, inclusive employment policies and employee forums.

  • ID: #49505985
  • State: Florida Orlando 32801 Orlando USA
  • City: Orlando
  • Salary: USD TBD TBD
  • Job type: Permanent
  • Showed: 2023-03-20
  • Deadline: 2023-05-18
  • Category: Security