Students! Find the fintech job of your dreams here.

Georgia Fintech Academy
Georgia Fintech Academy
28
companies
2,266
Jobs

Information Security Engineer II

NCR

NCR

IT
Atlanta, GA, USA
Posted on Thursday, April 4, 2024

About NCR VOYIX

NCR VOYIX Corporation (NYSE: VYX) is a leading global provider of digital commerce solutions for the retail, restaurant and banking industries. NCR VOYIX is headquartered in Atlanta, Georgia, with approximately 16,000 employees in 35 countries across the globe. For nearly 140 years, we have been the global leader in consumer transaction technologies, turning everyday consumer interactions into meaningful moments. Today, NCR VOYIX transforms the stores, restaurants and digital banking experiences with cloud-based, platform-led SaaS and services capabilities.

Not only are we the leader in the market segments we serve and the technology we deliver, but we create exceptional consumer experiences in partnership with the world’s leading retailers, restaurants and financial institutions. We leverage our expertise, R&D capabilities and unique platform to help navigate, simplify and run our customers’ technology systems.

Our customers are at the center of everything we do. Our mission is to enable stores, restaurants and financial institutions to exceed their goals – from customer satisfaction to revenue growth, to operational excellence, to reduced costs and profit growth. Our solutions empower our customers to succeed in today’s competitive landscape.

Our unique perspective brings innovative, industry-leading tech to all the moving parts of business across industries. NCR VOYIX has earned the trust of businesses large and small — from the best-known brands around the world to your local favorite around the corner.

This role is part of NCR’s Global Information Security team. This team is responsible for developing and implementing NCR’s corporate information security program. The primary goal of the program is to protect the confidentiality, integrity, and availability of information resources. Key information security functions and activities include architecture and design for NCR information security controls, developing and enforcing policies and standards, security awareness training, risk management, assessment, and testing, monitoring and metrics, incident management, and threat and vulnerability management.

The Information Security Engineer II shall be responsible for the day-to-day activities required to respond for both routine and high severity incidents and vulnerabilities identified. The Information Security Engineer II shall work in a collaborative manner with incident responders, key incident management team members, management, and other stakeholders to ensure security incidents are contained, eradicated, remediated and after-action review is held according to corporate policy. The Information Security Engineer II shall work in a collaborative manner with vulnerability coordinators and remediation team to make sure the vulnerabilities are remediated with patching and compensating controls. The Information Security Engineer II is expected to contribute to weekly status calls and is On-Call which includes working off hours/weekends and respond to ad-hoc requests as part of this position. The Information Security Engineer II will work with stakeholders and team members to assist with improving incident response processes that are aligned with the mission of the office of the CISO.

What You'll Do

  • As an active member of the team, monitor and process response for security events on a 24x7 basis.
  • Hands on experience in detailed research and analysis.
  • Triage, respond to and escalate security incidents.
  • Leverage automation and orchestration solutions to automate repetitive tasks.
  • Coordinate incident response activities across multiple independently managed environments and security teams.
  • Maintaining an in-depth knowledge of the cyber security industry, the competitive landscape and related industry developments to ensure our team continues to be thought leaders who innovate.
  • Experience with/exposure to Endpoint Security, Cloud Security, SIEM/Log Management, Mobile Security, Identity Security, Incident Response as well as other cyber security domains.
  • Utilize multiple security/threat intelligence tools and resources to understand threats.
  • Partner with internal and external teams to improve tool usage and workflow, as well as with the advanced threats and assessment team to mature monitoring and response capabilities.
  • Work alongside other security team members to hunt for and identify security issues generated from the network, including third-party relationships.
  • The ability or experience in developing security strategies for companies and/or governments and for overseeing the successful implementation and execution of these strategies.
  • Coordinate remediation activities for Zero days/High Severity vulnerabilities.
  • Other duties as assigned.

What You'll Need

  • 2 years of experience performing cyber incident response, cyber threat intelligence, and/or threat hunt operations.
  • Strong knowledge of network protocols, operating systems, applications, and web services in a manner that allows for the interaction of all as it relates to security and services.
  • 1-year hands on experience with Crowdstrike reviewing alerts and threat hunting.
  • Knowledge of Chronicle, Backstory a plus.
  • Experience with identifying anomalies through Tactics, Techniques, and Procedures and how they relate to the MITRE ATT&CK framework.
  • Familiarity with the CVSS scoring system for vulnerabilities.
  • Experience with Microsoft suite of host and cloud-based tools, such as Defender for Endpoint (MDE), Defender for Identity (MDI), Azure Sentinel, etc.
  • Experience analyzing various sources of Cyber Threat Intelligence (CTI) for TTP's, IOCs, and threat actor behavior to guide hunt operations.
  • In-depth knowledge of cybersecurity principles, best practices, and industry standards.
  • Ability to collaborate within a geographically distributed team of Incident Response Analysts and vulnerability remediation team.
  • Strong communication skills and ability to work in a collaborative atmosphere.
  • Strong attention to detail.
  • Ability to prioritize work with multiple, simultaneous work assignments.
  • Relevant certifications such as CISSP, CCSP, CrowdStrike and other revelation certifications are a plus.

Offers of employment are conditional upon passage of screening criteria applicable to the job

EEO Statement

Integrated into our shared values is NCR Voyix’s commitment to diversity and equal employment opportunity. All qualified applicants will receive consideration for employment without regard to sex, age, race, color, creed, religion, national origin, disability, sexual orientation, gender identity, veteran status, military service, genetic information, or any other characteristic or conduct protected by law. NCR Voyix is committed to being a globally inclusive company where all people are treated fairly, recognized for their individuality, promoted based on performance and encouraged to strive to reach their full potential. We believe in understanding and respecting differences among all people. Every individual at NCR Voyix has an ongoing responsibility to respect and support a globally diverse environment.

Statement to Third Party Agencies
To ALL recruitment agencies: NCR Voyix only accepts resumes from agencies on the preferred supplier list. Please do not forward resumes to our applicant tracking system, NCR Voyix employees, or any NCR Voyix facility. NCR Voyix is not responsible for any fees or charges associated with unsolicited resumes

“When applying for a job, please make sure to only open emails that you will receive during your application process that come from a @ncrvoyix.com email domain.”