This list contains only the countries for which job offers have been published in the selected language (e.g., in the French version, only job offers written in French are displayed, and in the English version, only those in English).
The Cybersecurity Principal Engineer will help ensure that our software, systems and infrastructure are designed and implemented to the highest security standards. Performs technical security assessments, code reviews and vulnerability testing to highlight risk and remediate associated findings while helping T-Mobile teams and partners improve security. Works closely with other T-Mobile Engineers to design and build proactive methods to enhance our security posture. This position serves as a subject matter expert which drives vision and results to enhance security posture within mobile device, IoT device, enterprise line of business applications, cloud, big data, Identity and core and carrier network technologies as well as and other business units as needed. Principal security advisor to cross-functional teams for the successful delivery of projects or services to enterprise customers.
Job Responsibility:
Optimizes cross-functional partnership to successfully address customer requirements
Leads / organizes large scale analysis efforts spanning multiple departments
Leads information security review of new technologies, designs, and remediation planning efforts
Collaborates with Engineering & Operations Teams to address security vulnerabilities
Proactively identifies process or technology improvements within existing legacy applications or infrastructure and seeks out remediation
Maintains visibility inside & outside of information security at the Executive (Director/Sr Director) level
Significant experience with the analysis of underlying technologies for threat identification, analysis, and thread model design
Proactively identifies areas that need to be developed and seeks out expertise in those areas
Leads security projects driven by groups both internal and external to info security
Mentors, peers and junior team members in security technologies, enterprise solution design, SDLC facilitation and effective customer interaction
Significant experience with implementation of various threat modeling approaches
Advanced understanding of IP/Security solutions & technologies applicable to the Wireless Network Architecture
Requirements:
Bachelor's Degree, Computer Science, or Information Technology (required)
7-10 years’ Experience with increasing responsibility with security related software and/or business process design (Required)
4-7 years’ Experience with the following: project/team lead, formal implementation SDLC, facilitation of cross-functional solution design teams
4-7 years’ Technical Project Management
Previous Leadership experience
Be subject matter expert in multiple security subject areas
Experience with high level design architecture, security technologies, networking, web services and SOA
Subject matter expert in all facets of network & information security, including Firewall policy design, SSL Certificate management, vulnerability analysis & mitigation
Significant knowledge of current technological trends and developments in the area of info security
Ability to create technical specification and requirements and work independently and with no direction/supervision
Strong verbal and communication skills with diverse cross functional groups
Always act with tact and integrity
Self-motivated and able to work under tight timelines
Strong problem solving / troubleshooting skills
Ability to plan, organize and prioritize tasks
In-depth knowledge of security best practices in large-scale environments
Strong presentation skills
Understanding load balancers (ex – A10, F5), firewalls (ex – CheckPoint), Venafi, MDM (ex - Mobile Iron), Cloud (ex - AWS, Azure), Malware Protection (ex -FireEye), Advanced Persistent Threats (ex - Damballa), Privileged Accounts (ex – CyberArk), SIEM (ex – ArcSight), Log & Event (ex – Splunk), Intrusion IDS/IPS (ex – Symantec), Cloud Platform (ex – PCF, Docker), Scanning (ex – Qualys), AppSec (ex - Veracode)
Expert understanding of T-Mobile’s network elements and how they work together (EIT, Engineering & 3rd Party)
Advance knowledge of Scripting tools (Python/Perl/Shell/HTML/PHP)
Knowledge of federal & compliance regulations e.g. SOX, PCI & CPNI
At least 18 years of age
Legally authorized to work in the United States
Nice to have:
CISSP and/or CCSK and/or CCSP and/or CISA/CISM certification a plus