Sr Lead Cybersecurity Program Manager

Centurylink Ashburn , VA 20147

Posted 2 weeks ago

CenturyLink (NYSE: CTL) at http://www.centurylink.com is a global communications and IT services company focused on connecting its customers to the power of the digital world. CenturyLink offers network and data systems management, big data analytics, managed security services, hosting, cloud, and IT consulting services. The company provides broadband, voice, video, advanced data and managed network services over a robust 265,000-route-mile U.S. fiber network and a 360,000-route-mile international transport network. Visit CenturyLink at http://www.centurylink.com/ for more information.

Job Summary

The Cyber Security Program Manager is the single point of contact for all technical, management, contracts, and personnel matters associated with service delivery. May direct additional program management staff in providing the necessary administrative and management expertise for effective program control and reporting. Is responsible for managing a team of cyber security engineers, analysts, forensic specialists, and other technical staff charged with cyber security defense of enterprise IT systems and networks. The scope of these responsibilities includes technical, quality, cost and schedule planning, management, execution, and reporting for a diverse range of information security technical and analytical projects and activities.

Job Description

  • Responsible for ensuring that the client's cyber defense protections are adequate and effective.

  • Provides recommendations to client leadership and technical management regarding current and future cyber security policy considerations and technologies, based on ongoing assessment of the evolving threat environment.

  • Monitor all operations and infrastructure.

  • Maintain all security tools and technology.

  • Monitor internal and external policy compliance.

  • Monitor regulation compliance if supporting a heavily regulated industry and are dealing with things like credit card, health care data, or other personally identifiable information.

  • Work with different departments in the company to reduce risk. Plans and conducts consultation with users, management, vendors, and technical staff to assess computing needs and system requirements that may affect the client's cyber security posture.

  • Planning and executing multi-faceted large scale and enterprise wide security projects in accordance with established policies, regulations, and cycle best practices.

  • Establishing clear roles, responsibilities, lines of authority, communications, and accountability among staff

  • Utilization of program and project management best practices. Identifying staff development and training needs and ensure that training, mentoring, and hands-on assistance is available to raise the talent/skill level of staff as appropriate

  • Creating and developing security assessment solutions.

  • Assist Pre-Sales with helping improve procedures and functions.

  • Assist with collecting customer business and technical requirements and determining recommended solution(s).

  • Build and review Statement of Work (SOWs) ensuring quality and accuracy

  • Align assessment opportunities with the correct delivery partners and ensuring scopes meet client needs while remaining cost effective

Qualifications

  • 8+ years of IT Security experience with Bachelor's Degree, or 6 +years experience with Master's Degree, or 12+ Years of experience as a Senior Network Engineer/Security Architect

  • Experience in Leading and Managing Projects and Program Management Life Cycles i.e., IT Portfolio Management

  • One or more of the following certifications: PMP, CISSP, CISM, GSEC, GCIH, or GSLC

  • Experience with CenturyLink systems and processes highly preferred

Education

Bachelors or Equivalent

Masters or Equivalent

Alternate Location: US-Virginia-Ashburn; US-Work From Home-Work At Home

Requisition # : 211234

This job may require successful completion of an online assessment. A brief description of the assessments can be viewed on our website at http://find.centurylink.jobs/testguides/

EEO Statement

We are committed to providing equal employment opportunities to all persons regardless of race, color, ancestry, citizenship, national origin, religion, veteran status, disability, genetic characteristic or information, age, gender, sexual orientation, gender identity, marital status, family status, pregnancy, or other legally protected status (collectively, "protected statuses"). We do not tolerate unlawful discrimination in any employment decisions, including recruiting, hiring, compensation, promotion, benefits, discipline, termination, job assignments or training.

Disclaimer

The above job definition information has been designed to indicate the general nature and level of work performed by employees within this classification. It is not designed to contain or be interpreted as a comprehensive inventory of all duties, responsibilities, and qualifications required of employees assigned to this job. Job duties and responsibilities are subject to change based on changing business needs and conditions.


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Lead Cybersecurity Analyst

Visa

Posted 1 week ago

VIEW JOBS 3/13/2019 12:00:00 AM 2019-06-11T00:00 Visa operates the world's largest retail electronic payments network and is one of the most recognized global financial services brands. Visa facilitates global commerce through the transfer of value and information among financial institutions, merchants, consumers, businesses and government entities. We offer a range of branded payment product platforms, which our financial institution clients use to develop and offer credit, charge, deferred debit, prepaid and cash access programs to cardholders. Visa's card platforms provide consumers, businesses, merchants and government entities with a secure, convenient and reliable way to pay and be paid in 170 countries and territories. The Sr. Information Security Analyst will work as a member of Visa Cybersecurity's Ethical Hacking (Penetration testing) program. The objective of Visa's Penetration Testing program is to pro-actively identify weaknesses and shortcomings in Visa's security posture and recommend necessary controls and procedures to protect Visa adversarial threats. With this mission in mind, Visa's pentest team experts are pro-actively involved in engagements that simulate adversarial threats and attacks in a timely manner. The Sr. Information Security Analyst will be a key contributor for performing internal and external ethical hacks of Visa applications and systems. Pentest team members also help with design, development and recommendation of security solutions to protect Visa proprietary/confidential data and systems. The candidate will also assist with compliance objectives; provide guidance and direction for the logical protection of information systems assets to other functional units. Prepare reports regarding effectiveness of information security adherence and make recommendations for the adoption of new policies and procedures for Visa services. Responsibilities * Conduct high risk and sensitive ethical hacks of internally and externally hosted applications globally according to scope defined by the pentest team. * Subject matter expertise in web, mobile or network penetration testing with track record of end to end testing of complex systems. * Co-ordinate and execute system/network level pentests and ethical hacking exercises. * Pro-actively research and Identify network and system vulnerabilities and provide recommended counter measures or mitigating controls to reduce risk to an acceptable and manageable level. * Reviews results of network and application ethical hacks in order to determine severity of findings and to ensure proper remediation is applied. * Provide accurate and timely reporting of findings and proposed remediation and mitigations. * Technical support could include but not limited to the following: (1) Audit support & remediation, (2) Process Improvement, (3) Analysis & Reporting, (4) Cross Divisional Functional education, training and awareness, (5) Function/Methodology/Strategy advancement. * Provide technical support to senior management in identifying and streamlining new/existing protocols and tools used by the penetration testing team. * Mentor junior pentesters * Develop and automate scripts, tools and resources needed to advance ethical hacking capabilities around new and emerging technologies like mobile, cloud and embedded systems. * Actively involved in security research around new and emerging technologies. * Eight to Ten Years of progressive experience with increasing responsibility in Information Technology, Information Security and Compliance that includes a combination of technical and project leadership responsibilities * Expertise in performing advanced exploitation and post-exploitation attacks as part of ethical hacking exercises * Prior experience or expertise performing Red team exercises will be a plus * Experience in writing proof-of-concept exploits and creating custom payloads and modules for common ethical hacking frameworks and tools * Well versed in system exploits (e.g. Buffer Overflows, PTH attacks, windows authentication framework etc.), network exploitation (e.g. VLAN hopping) or web application exploitation * Well versed with security tools & frameworks like Metasploit, Core, Canvas etc. * Extensive understanding of cryptographic concepts and applied cryptography * Proficiency in one or more scripting language. E.g. Perl, Python, Shell Scripting etc. * Prior experience with exploit development or writing system modules in C & C++, a major advantage. Knowledge of high level programming languages an added bonus * Prior experience with reverse engineering, malware analysis and forensic tools will be an added advantage * Good interpersonal, facilitation, and demonstrated emerging leadership skills * Able to operate at an advanced level of written and spoken communication; write and speak effectively with impact * Good understanding of Ethernet, switched LAN and WAN environment and detailed understanding of layer 3 and layer 4 specifications, including IP, TCP, TCP/IP routing protocols and management of ACLs. All your information will be kept confidential according to EEO guidelines. Visa Ashburn VA

Sr Lead Cybersecurity Program Manager

Centurylink