Database Protection - Cyber Security Senior
At Freddie Mac, our mission of Making Home Possible is what motivates us, and it’s at the core of everything we do. Since our charter in 1970, we have made home possible for more than 90 million families across the country. Join an organization where your work contributes to a greater purpose.
Position Overview:
We are seeking a Data Protection Senior to join the Data Protection team within the Information Security Engineering department of the Information Technology Division. The engineer is responsible for providing administration and operations support of various Data Protection security tools. Read on to learn more about this exciting opportunity!
**This position has an on-call requirement. **
Our Impact:
We reduce information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac.
Your Impact:
In this role, you will help fulfill the Information Security department’s vision of reducing information risk by ensuring and enhancing the Confidentiality, Availability, and Integrity of Information systems at Freddie Mac. You will work towards the development and delivery of our technical solutions related to Data Protection. You will build, develop, and maintain relationships with internal and external customers, and vendors to formulate remediation solutions for issues related with Information Security.
Security Administration and Operations
Install, configure and troubleshoot Data Protection software including agent-based software installations on Windows and Unix servers.
Apply patches and upgrades to clients, administrative tools, and utilities on a regular basis.
Perform daily monitoring for integrity and availability of appliances, management servers, systems and processes which may also include:
Reviewing system and application logs, and verifying services and jobs are running as expected.
Establishing and maintaining operational, configuration and other process/procedures to ensure effectiveness of new and existing detective and preventative configuration policies.
Where possible, incorporating automated monitoring/alerting.
Provide management support relating to IT Security Audit, including providing evidence, artifacts and solutions.
Provide support to the Cyber Security Operations Center and Threat Detection Teams with recommendations and handling of their requests.
Coordinate with other infrastructure, engineering, and application project/support teams to ensure new policies/assets are deployed.
Ensure that any issues impacting tools and systems are resolved quickly and effectively without adversely impacting the affected business systems.
Augment production support team to ensure 24/7 coverage and operations. Responsibilities sometimes require working evenings and weekends, sometimes with little to no advanced notice.
Ensure system supporting Data Protection services comply with Baseline Security Configurations and address identified vulnerabilities.
Understand and advocate IT Security standards, reference architectures.
Demonstrate an understanding of malware, threats, vulnerabilities and the complete effect these could have in the environment.
Communicate effectively with clients to identify needs and evaluate alternative technical solutions and strategies.
Develop SOP’s and Runbooks to promote successful operations, ensuring documents are regularly reviewed/certified to be current/accurate.
Ensure processes reflect our technical obligations of system uptime and performance.
Presentation of metrics and other attributes to convey accomplishments.
Effectively provide regular status updates and accomplishments to leadership.
Qualifications:
5-7 years of IT Security experience with expertise in Linux and Windows platforms.
Proficient in scripting (Python, BASH, PowerShell, Ansible) and understanding cryptographic primitives.
Strong collaboration skills to deliver and enhance Data Protection services across IT and business lines.
Experience evaluating and implementing automation to help streamline processes and procedures while remaining compliant with existing controls.
A strong understanding of Data Encryption, Data Tokenization, Data Masking, Security Configuration Management Database, Database Activity Monitoring, File Integrity Monitoring, Unauthorized Change Monitoring, SaaS security solutions and cloud client security.
Familiarity with industry security regulations/frameworks (MITRE, CIS CSC, SOX, NIST, IANA, RFCs, IETF).
Experience in testing/maintaining SOX controls and Change Management processes.
3-5+ years in security tools administration, with a focus on Data Protection technologies.
Knowledgeable in Java, JSON, XML, YAML, OOP, and design patterns.
Strong skills in debugging, troubleshooting, and using source code repository tools (e.g., GIT).
Foundation in Secure Software Lifecycle and Vulnerability Management.
Familiarity with TCP/IP, TLS, security protocols, and ITIL activities (Incident/Problem Management).
Security certifications preferred.
Keys to Success in this Role:
Proactive, self-motivated problem solver with innovative thinking.
Strong team collaborator with excellent mentorship and communication skills.
Clear communicator with internal and external stakeholders.
Eager to learn new technologies and improve processes.
Detail-oriented with a focus on impactful changes.
Familiar with ITIL guidelines; prioritizes work with a risk-based approach.
Adaptable to change while achieving objectives.
Manages product lifecycle, ensuring timely upgrades and testing.
Guides junior team members and collaborates across teams.
Knowledgeable in network ports, protocols, and firewalls.
Current Freddie Mac employees please apply through the internal career site.
We consider all applicants for all positions without regard to gender, race, color, religion, national origin, age, marital status, veteran status, sexual orientation, gender identity/expression, physical and mental disability, pregnancy, ethnicity, genetic information or any other protected categories under applicable federal, state or local laws. We will ensure that individuals are provided reasonable accommodation to participate in the job application or interview process, to perform essential job functions, and to receive other benefits and privileges of employment. Please contact us to request accommodation.
A safe and secure environment is critical to Freddie Mac’s business. This includes employee commitment to our acceptable use policy, applying a vigilance-first approach to work, supporting regulatory mandates, and using best practices to protect Freddie Mac from potential threats and risk. Employees exercise this responsibility by executing against policies and procedures and adhering to privacy & security obligations as required via training programs.
CA Applicants: Qualified applications with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.
Notice to External Search Firms: Freddie Mac partners with BountyJobs for contingency search business through outside firms. Resumes received outside the BountyJobs system will be considered unsolicited and Freddie Mac will not be obligated to pay a placement fee. If interested in learning more, please visit www.BountyJobs.com and register with our referral code: MAC.
Time-type:Full timeFLSA Status:ExemptFreddie Mac offers a comprehensive total rewards package to include competitive compensation and market-leading benefit programs. Information on these benefit programs is available on our Careers site.
This position has an annualized market-based salary range of $126,000 - $190,000 and is eligible to participate in the annual incentive program. The final salary offered will generally fall within this range and is dependent on various factors including but not limited to the responsibilities of the position, experience, skill set, internal pay equity and other relevant qualifications of the applicant.