Share Email Opening
Title

Principal Security Architect  

Description

U.S. News & World Report is a multifaceted digital media company dedicated to helping citizens, consumers, business leaders and policy officials make important decisions in their lives. We publish independent reporting, rankings, data journalism and advice that has earned the trust of our readers and users for nearly 90 years. Our platforms on usnews.com include Education, Health, Money, Travel, Cars, News and 360 Reviews.

We reach more than 40 million people monthly during moments when they are most in need of expert advice and motivated to act on that advice directly on our platforms. Our signature franchises include our “Best” series of consumer guides on colleges, graduate schools, hospitals, diets, cars, financial services and more. These guides provide an easy-to-digest list for consumers to better understand and compare when making their decisions. We continue to publish annual guides of the authoritative Best Colleges and Best Hospitals rankings on our website and in print. And our U.S. News Live flagship conferences highlight important national conversations including Healthcare of Tomorrow and Healthiest Communities.

Your role in helping us shape the future:

U.S. News empowers everyone to thrive. We have a diverse environment, with Linux, and macOS X, and Windows machines living side-by-side. The majority of our development effort involves building & maintaining web applications on Python & Java.

Our applications support just about every aspect of company operations, including content management for the usnews.com website, data ranking products such as Best Colleges/Grad schools and Best Hospitals, and other business applications.

U.S. News & World Report is looking for a Security Architect to set and implement the company security program with the goals to attain high availability and maintain data integrity and confidentiality. As a Security Architect, you will play a key role deciding the risk management posture of the company as well as to improve the detection, prevention and remediation tooling, and readiness of the staff. We offer a casual work environment. Our offices are in the Georgetown neighborhood of Washington, D.C.

Are you up to the challenge?

  • Lead major security projects

  • Hands-on infrastructure as code deployments to deploy tooling for monitoring, scanning, access management, patching, key rotations, web application firewalls, bot management among others

  • Automation for remediation of security events

  • Respond and remediate security incidents and provide solutions to detect, prevent or mitigate similar issues in the future

  • Identify and protect sensitive company information

  • Endpoint Protection

  • Implement and communicate security policies, standards and response procedures

  • Stay up to date with new cyber security attack trends and techniques

  • Contribute ideas to improve our risk management program, security roadmap, tooling and security processes

 
Position Requirements

You should definitely have:

  • Solid understanding of modern web-based application development and underlying technologies

  • Experience designing and maintaining production-ready workloads using software-defined cloud infrastructure, especially security policies and access control (AWS, GCP, etc.)

  • At least 2 years working in a development, operations, or similar support role, and at least 4 years in a security-focused position

  • Experience working on a multi-person software development team with robust deployment tooling

  • Bachelor’s degree in Cybersecurity, Computer Science or related field

It would be nice if you had:

  • Web Application Firewall technologies (e.g. AWS WAF, Akamai WAF)

  • Bot mitigation protection technologies is a plus (AWS SiteShield, Akamai BotManager)

  • API security management

  • Understanding of data management for PII, PHI, etc.

  • Languages/frameworks, such as Python, Java, Javascript/Node.js or Ruby

  • Working with Linux based systems (Debian, CentOS, or RHEL)

  • Familiarity with security standards and benchmarks (e.g. NIST, PCI, CIS, OWASP)

  • Endpoint Protection technologies (Sophos, Crowdtrike, Fireye, Cynet, Nessus)

  • Strong oral and written communications skills

  • CI and orchestration systems (e.g. Jenkins)

  • Containerization & Orchestration experience (e.g. Docker, Kubernetes, ECS)

  • Configuration Management Experience (e.g. Puppet, Chef, Docker)

  • CISSP certification 

What it’s like to work with us:

  • Talent is our best asset!

  • We invest in people with passion and potential who understand U.S. News’ dedication to our consumers.

  • Entrepreneurial, mission-driven culture with core values of quality and integrity

  • Focus on fostering personal and professional growth

  • Competitive benefits including paid vacation time, medical, tuition reimbursement, and training

  • Collaborative Work Environment ~ Fun, diverse, inclusive and ambitious co-workers

  • We are offering a competitive salary and comprehensive benefits package that includes healthcare, dental, and 401(k) plan.

 
Full-Time/Part-Time Full-Time  
Number of Openings 1  
About the Organization U.S. News & World Report is a publisher of news and information that empowers people to make better, more informed decisions about important issues affecting their lives.  
EOE Statement We are an equal employment opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, disability status, protected veteran status or any other characteristic protected by law.  
Tags  

This position is currently not accepting applications.

To search for an open position, please go to http://USNewsandWorldReport.appone.com



WE ALSO RECOMMEND

Other Jobs Within Same Category
AI Software Developer in Washington, DC
Posted on: 4/23/2024
[Apply Now]

Senior Software Developer, Money (Wealth) in Washington, DC
Posted on: 4/5/2024
[Apply Now]

Senior Backend Developer, Python in Washington, DC
Posted on: 3/13/2024
[Apply Now]

DevOps Engineer in Washington, DC
Posted on: 3/12/2024
[Apply Now]

Software Developer Summer 2024 Intern in Washington, DC
Posted on: 2/21/2024
[Apply Now]


Other Jobs Within 60 Miles
Editorial Summer 2024 Intern, Branded Content in Washington, DC
Posted on: 1/31/2024
[Apply Now]

Communications Summer 2024 Intern in Washington, DC
Posted on: 2/2/2024
[Apply Now]

Business Intelligence Analyst in Washington, DC
Posted on: 12/7/2023
[Apply Now]

Maternity Outreach and Communications 2024 Summer Intern in Washington, DC
Posted on: 1/31/2024
[Apply Now]

Digital Producer, Autos in Washington, DC
Posted on: 3/8/2024
[Apply Now]



Follow us See who works here:
 


AppOne.comTM   ©1999-2021 HR Services, Inc.
Click here for technical assistance.