WAF Engineer, Cyber Defense Operations

2 weeks ago


Brossard, Quebec, Canada Royal Caribbean Group Full time

POSITION SUMMARY
The Cyber Defense Operations (CDO) Team is responsible for identifying and managing cyber risks and leading operational remediation projects for both ship and shore. For ships, the focus is to reduce risk to passenger, crew, and RCCL shipboard assets. The goal of the CDO Program is to provide cybersecurity architectural and engineering guidance on projects and strategies driven by shoreside business, marine operations, newbuild, and shipboard IT organizations to appropriately manage operational, regulatory, and safety risks as well as optimizing investments by reducing future remediation efforts.

The CDO WAF Engineer helps drive the execution of the CDO strategy and program initiatives at RCL. The role will partner with subject matter experts, peers and leaders across RCL shore and shipboard lines of business regarding cyber risks.The role will be an individual contributor providing cyber risk management and assurance expertise so that websites supporting RCL environments have been implemented and maintained, adhering to cybersecurity guidelines, and corporate information security standards.This position will assist the CDO manager by establishing WAF security baselines. This position will also help influence Digital, marketing, and sales areas to raise awareness of the cybersecurity website risk and their role in ensuring the overall safety of our brands that ultimately can impact passengers, crew, shoreside systems and maritime IT/OT/ET systems.

ESSENTIAL DUTIES AND RESPONSIBILITIES:

  • Manage and maintain the WAF rulesets for RCL websites
  • Publish a default OWASP top 10 WAF policy that all new websites must pass before being published to the Internet
  • Responsible for ensuring CDO WAF runbook's are updated and reviewed annually
  • Assist CDO leadership with the development and collection of accurate WAF metrics
  • Participate in planned normal call rotations and also 24/7 on-call rotations to resolve critical issues
  • Change Management - Ensure that outages & change requests are correctly documented, prioritized, and closed
  • Review and understand complex cyber guidelines (NIST) and regulations such as PCI, SOX, BIMCO Cybersecurity Guidelines for Ships, U.S. Coast Guard security requirements, and International Maritime Organization (IMO)
  • Contribute with a high degree of self-sufficiency and resourcefulness on individual and departmental performance objectives
  • High degree of motivation to maintain technical skills and cybersecurity knowledge relevant by seeking self-development opportunities such as industry certifications, investing time to learn new skills, and networking with peers in the security industry
  • Assist with Other CDO platforms that protect IT, and OT maritime cybersecurity technology
  • Leverage information security activities and technologies to raise cyber situational awareness and protection
  • Actively engage in liaison activities with industry associations, peer institutions, regulatory and contractual agencies/organizations, and IS information-sharing communities

QUALIFICATIONS:

  • Bachelor's degree or equivalent industry experience
  • 4+ years of experience in Information Security
  • 2+ years of experience with WAF platforms
  • Experience managing, monitoring and tuning Web Application Firewalls for critical web applications
  • Knowledge of Client Network configurations to ensure applications are configured to appropriately flow through the CDN platform ensuring application traffic flows appropriately to the application origins
  • Previous experience using Burp Suite is a plus
  • Demonstrated ability to perform independent analysis of complex problems
  • Broad IT knowledge, including hardware, virtualization, networking, architecture, common protocols, files systems and operating systems
  • An ability to communicate complex technical issues to English-speakers from many cultures
  • Must have competent verbal and written communication abilities; interpersonal collaborative skills; and the ability to communicate IS and risk-related concepts to technical and non-technical audiences
  • Ability to learn methodologies, tools, best practices and processes within specific areas of responsibility
  • Decision-making, reporting, communication, and skills
  • Prior experience with CMDB, Proxy, firewalls, or EDR systems is a plus
  • Industry certifications are a plus

Knowledge and Skills:

  • Demonstrates organizational skills and time management
  • Ability to manage multiple tasks / projects while ensuring deadlines are met
  • Displays sound judgment with a high level of integrity, ethics and ability to calmly, diplomatically and effectively deal with stressful situations
  • Able to formulate, communicate exceptions/findings and technical solutions
  • Demonstrate a degree of creativity with adept analytical and problem solving skills
  • Ability to identify remediation activities based on risk to the overall enterprise
  • May require travel (domestic and international) to perform shipboard cybersecurity work.
  • May require working United States business hours
  • Position is based in Manila, Philippines
Explore more InfoSec / Cybersecurity career opportunities

Find even more open roles in Ethical Hacking, Pen Testing, Security Engineering, Threat Research, Vulnerability Management, Cryptography, Digital Forensics and Cyber Security in general - ordered by popularity of job title or skills, toolset and products used - below.

#J-18808-Ljbffr

  • Brossard, Quebec, Canada Scotiabank Full time

    Senior Analyst, Cyber Security Control & Defense Requisition ID: 198872Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. As a Security Engineer under Cloud Platform Engineering, you will be responsible for working with a diverse team, leveraging i


  • Brossard, Quebec, Canada Prime Healthcare Full time

    Senior Cyber Security Advisor - SOC Incident Response Prime HealthcarePrime Healthcare is a significant health system with operations across multiple states in the US, boasting an extensive network of hospitals, outpatient facilities, and a large workforce dedicated to providing top-notch healthcare services.ResponsibilitiesLead and coordinate Computer...


  • Brossard, Quebec, Canada Revinate Full time

    Revinate Revinate empowers hoteliers to connect with guests using our Guest Data Platform and guest communication solutions to drive direct revenue. View company page Revinate is one of the largest and most innovative providers of direct revenue-generating solutions in the hospitality industry. Revinate's mission is to deliver hoteliers scalable direct...


  • Brossard, Quebec, Canada Scotiabank Full time

    We are looking for a dynamic and experienced Lead Network Security Engineer to join our team. As the Lead Network Security Engineer, you will be responsible for providing technical leadership and strategic direction in the design, implementation, and management of network security solutions and platforms. You will play a pivotal role in protecting...


  • Brossard, Quebec, Canada Prime Healthcare Full time

    Senior Cyber Security Advisor - SOC Incident Response Prime Healthcare Prime Healthcare is the fifth largest for-profit health system in the United States operating 44 hospitals in 14 states, more than 300 outpatient locations, and nearly 45,000 employees and affiliated physicians dedicated to providing the... View company page Prime Healthcare is an...


  • Brossard, Quebec, Canada Telstra Full time

    Join Australia's largest mobile network, view our plans for NBN broadband internet, mobile phones, 5G & on demand streaming services. We're Australia's leading telecommunications and technology company. We're all about providing the best experience and delivering the best tech on the best network. As a Senior Security Engineer, you will be responsible for...


  • Brossard, Quebec, Canada Scotiabank Full time

    Requisition ID: 197488Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Purpose of JobThis position is responsible for leading and conducting risk based information and cyber security audit assessments of medium to high complexity following the Bank's Audit Methodology.Key AccountabilitiesExecution:Plan and...


  • Brossard, Quebec, Canada Teck Resources Full time

    Teck Resources Teck is Canada's largest diversified mining company and is committed to responsible development. It has major business units focused on copper, metallurgical coal, zinc, gold and energy. Shares are listed on the TSX under the symbols TECK.A and... View company page As Canada's largest diversified mining company, Teck is committed to...


  • Brossard, Quebec, Canada Scotiabank Full time

    Senior Analyst, Cyber Security IntelligenceRequisition ID: 194733Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture.Reporting to the Senior Manager of CTI, the Cyber Threat Intelligence Associate will provide technical expertise and analysis for the proactive and reactive responses to information security...


  • Brossard, Quebec, Canada Scotiabank Full time

    Requisition ID: 198839 Join a purpose driven winning team, committed to results, in an inclusive and high-performing culture. We are looking for a dynamic and experienced Lead Network Security Engineer to join our team. As the Lead Network Security Engineer, you will be responsible for providing technical leadership and strategic direction in the design,...


  • Brossard, Quebec, Canada Magna International Full time

    Analyst, Cyber Security & Information Governance Magna International Magna. Forward. For all. Explore how Magna ́s advancements in mobility help build a better world for everyone and everything. View company page About usWe see a future where everyone can live and move without limitations. That's why we are developing technologies, systems and concepts...


  • Brossard, Quebec, Canada Prime Healthcare Full time

    Senior Cyber Security Advisor - SOC Incident Response Prime Healthcare Prime Healthcare is the fifth largest for-profit health system in the United States operating 44 hospitals in 14 states, more than 300 outpatient locations, and nearly 45,000 employees and affiliated physicians dedicated to pro


  • Brossard, Quebec, Canada BMO Full time

    We are seeking a highly skilled Senior Cloud Security Specialist with expertise in securing cloud platforms, particularly AWS and Azure. The ideal candidate will have hands-on experience in cloud security and a deep understanding of various aspects including Identity and Access Management, Data Protection, Infrastructure Security, Logging and Monitoring,...


  • Brossard, Quebec, Canada CIBC Full time

    Bank on your terms with CIBC – whether it's in person, over the phone or online, CIBC has you covered. We're building a relationship-oriented bank for the modern world. The Senior Consultant, Risk and Governance will help execute on the approach to risk governance across technology and endorse stakeholder engagement by managing and delivering on key Risk...


  • Brossard, Quebec, Canada Precision Drilling Full time

    If you are an experienced Cyber Security Analyst professional looking to enjoy a work-life balance, then please read on.Precision Drilling has a hybrid opening for a Cyber Security Analyst eager for fresh challenges and development toward potential future career growth as our business continues to innovate and grow.Working for Precision Drilling means being...

  • Security Analyst

    2 weeks ago


    Brossard, Quebec, Canada GoSecure Full time

    The Security Analyst specialist is a member of GoSecure's MSD Services team. He provide technical consulting service in network security, such as Firewall technology, Antispam or EDR. Also provides expertise in security operations and technical support to various customers. As part of managed security contracts, the Security Analyst configure managed...


  • Brossard, Quebec, Canada Philips Full time

    Line of Service Internal Firm Services Industry/Sector IFS - Information Technology (IT) Management Level Senior Associate Job Description & Summary A career in Global Information Security, within Internal Firm Services, will provide you with the opportunity to develop and support our internal security technologies and services across the entire global...


  • Brossard, Quebec, Canada Clarivate Full time

    Senior Cyber Security Analyst, IAM Onboarding (GCS) Clarivate Clarivate is a global leader in providing trusted insights and analytics. Our vision is to improve the way the world creates, protects, and advances innovation. View company page The ideal candidate is passionate about information security for Identity Access Management capabilities across...


  • Brossard, Quebec, Canada SC Johnson Full time

    SC Johnson is a family company dedicated to innovative, high-quality products, excellence in the workplace and a long-term commitment to the environment and the communities in which it operates. The Global Information Security (GIS) Engineer will help designing and implementing enterprise security solutions.This role will assist the Global Information...


  • Brossard, Quebec, Canada SC Johnson Full time

    Associate Manager, BPT Infrastructure & Ops (Security Engineer) SC Johnson SC Johnson is a family company dedicated to innovative, high-quality products, excellence in the workplace and a long-term commitment to the environment and the communities in which it operates. Based in the USA, the company is one of the... View company page The Global Information...