Live Nation Entertainment is the world’s leading live entertainment company, and they are seeking a Director of Cyber Security Engineering. This role involves managing a global team of security engineers, implementing security technologies, and ensuring risk management principles are incorporated in new solutions and existing systems.
Responsibilities:
- Manage and adapt the growing needs of a global team of security engineers to continuously meet the needs of the business and the Cyber Security program; from both the technical and the professional requirements that arise
- Create, maintain, and promote sets of standard operating procedures for strategic and operational roadmaps pertaining to the day-to-day as well as long term security operations management
- Ensure risk management principles are incorporated in new solutions and changes to existing systems, processes, and workflows
- Implement and maintain defensive security technologies such as SIEM, logging, IDS, vulnerability scanners, and others, for use in threat hunting, incident response, triage analysis, reporting, and documentation
- Ensure system uptime of a diverse range of operating systems and technologies
- Develop, grow, and manage a diverse group of engineers tasked with ensuring good cyber security practices
Requirements:
- Bachelor's Degree in Computer Science, Information Technology, a closely related discipline, or an information security management certification (CASP, CISSP, CIPM, or equivalent) with at least 7 years of relevant professional experience or relevant work experience
- 2-4 years of people and team management experience required
- Information Security Certification (Security+, SSCP, GSEC)
- Technology-specific Certifications (AWS, Windows, Linux, Tenable, Zscaler, CrowdStrike, etc.). Agile Project Management Certification (CSM, CSD, or beyond)
- Knowledge to diagnose root cause of issues with security tooling such as vulnerability scanners, IDS, network proxies, SIEM, IAM/PAM, and DNS
- Knowledge to diagnose root cause of issues with AWS's Core Services such as EC2, S3, VPCs, Security Groups, CloudTrail, CloudWatch, CloudFormation, SQS, and IAM
- Knowledge to teach team members to deploy and configure computer operating systems and virtualization, such as Windows, MacOS, Linux, Hypervisors, and Docker
- Knowledge of networking concepts such as DNS, DHCP, VLANs, CIDR Ranges, Proxies, Firewalls, ACLs, and packet analysis
- Knowledge of endpoint detection and response (EDR) and other tools on the endpoint for security purposes
- Experience with different scripting, programming, and automation techniques such as Ansible, bash, chef, PowerShell, Python, cronjobs, and AWS lambda
- Technical knowledge on computer security operational security, threat actors, attack vectors, vulnerabilities, CVEs, and threat actor techniques
- Experience working with SIEM platforms and log management systems, including concepts such as big data management & analysis, dashboarding, data parsing, log message formatting, and data aggregation
- Working knowledge of encryption, password management, certificates, multi-factor authentication, and other means of keeping data secure both in transit and at rest
- Eagerness not only to learn, but to also teach, new methodologies, tools, and platforms for technical and security operations