Senior Infrastructure Security Engineer
Pennsylvania Staffing - Phila, Pennsylvania, United States, 19117
Work at Pennsylvania Staffing
Overview
- View job
Overview
Sporttrade, Inc. Full-time position located in Philadelphia, PA. The Senior Infrastructure Security Engineer performs the following key responsibilities: Maintain a deep understanding of Sporttrade's product offerings, how they work, and how they could be attacked or abused by users and threat actors alike. Configure and manage solutions for SAST and SCA to detect and remediate vulnerabilities and ensure regulatory compliance with GLI-33 standards. Implement and maintain a Software Bill of Materials (SBOM) for web applications, GKE container images, and on-premise environments. Implement and manage an IDS/IPS to monitor network traffic across on-premise and cloud-based infrastructure. Configure and troubleshoot security and networking capabilities on Linux-based operating systems using systemd and app-armor. Work with Sporttrade's Product and Engineering teams to manage publishing of mobile apps using Apple App Store Connect and Google Play Console. Engage with external security resources for annual pentests of infrastructure and mobile applications according to GLI and other Gaming Regulatory standards. Manage and maintain Crowdstrike agents and policies across user devices, on-prem hardware and cloud environments for EDR and patch management capabilities. Own and execute the vulnerability and patch management plan across on-premise and cloud environments. Manage and oversee deployment of solutions for user access and identity management using Okta and Zscaler to prevent threats from BEC, credential theft, etc. Requirements for the position: Bachelor's degree in Computer Science or closely related technical field (or foreign degree equivalent) and two (2) years of relevant experience. Employer will accept part-time equivalent experience. Telecommuting allowed within commuting distance of reporting office in Philadelphia, PA (main data center). Occasional rotating weekend/evening on-call work is required. Domestic travel required up to 10% of time to setup data center hardware at new sites based on business expansion. Must have at least two (2) years of experience with each of the following: Securing systems according to the GLI-33 Event Wagering Systems Standard. Exploiting vulnerabilities in 3 of the following: web applications; Cloud Environments (GCP/AWS); Linux based OS; or macOS workstations. Administering and managing solutions in: Okta, Kandji, Zscaler, Google Workspace, and Microsoft 365. Hands-on experience with full lifecycle datacenter operations (rack and stack of hardware, network deployment and configuration, and off-hours troubleshooting. Must have at least one (1) year of experience with each of the following: Managing the mobile application release management process through Apple App Store Connect and Google Play Console. On-premise hardware, including: Dell PowerEdge, Arista, Opengear, Cisco, and FortiGate. Interested applicants can apply online.