About this role
Description
**This position is a range posting. Final grade level and position will be determined based on skillset and experience.**
We deliver our customers peace of mind every day by helping them protect what they value most. Our passion for placing the customer at the center of everything we do is driving a transformational shift at Liberty Mutual.
The Global Cybersecurity Team within Threat Defense and Response is actively searching for an experienced Information Cybersecurity Engineer to support the 3rd Party Security Team. In this role you will provide technical expertise and support to clients, IT management, and staff in risk assessments, solution evaluation, and mitigation plans for appropriate information security processes, procedures, and products. The team’s primary focus is the protection of Liberty’s 3rd party ecosystem, which includes full life cycle management of all third parties.
The Cybersecurity Engineer will be working with many sectors of the company, including but not limited to Privacy, Legal, CSOC, Business Continuity, TPRM, etc. The Cybersecurity Engineer will assess the adequacy of security controls, evaluate threats and vulnerabilities, qualitatively calculate the level of current and residual risk, and communicate these risks to IT and business teams. The analyst must have the ability to convey technology and security concepts to application teams and have technical knowledge and/or experience in security, networking, systems administration, database administration, public cloud or another technical domain.
Proficiency in a risk management framework and conducting risk assessments in a regulated environment is desired. Maintaining a current understanding of the latest security threats, trends and technologies is a crucial component of the position. Experience specific to incident response is highly desirable.
Responsibilities:
- Participates in all activities related to third party lifecycle management, including but not limited to, participating in investigations through cross-functional teams to support closure of investigations, acting as a SME for all parties related to Cyber/IT exposure
- Performs risk assessments on third parties to identify their risk exposure to Liberty Mutual. Works with the third parties to strengthen their security posture through formal risk treatment.
- Work with teams within the TDR (Threat Defense & Response) dept
- Informs technology SME’s and other Engineers on risk exposure.
- Provides consultative services to identify and ensure that security issues are understood and addressed
- Researches and assesses new threats and security alerts and recommends remedial action.
- Maintain an awareness of Liberty Mutual’s security policies, frameworks and regulations pertaining to information security.
- Monitoring the overall security posture of the third party eco-system.
- Serves as an established team member supporting security projects or subprojects of increasing complexity. Identifies possible process improvements that address functional and technology gaps within a single business process of moderate complexity.
- Analyzes and prepares moderate to complex technology enabled recommendations to address gaps within a single business process. Proficient understanding of and makes connections to potential impact on business strategy.
Qualifications
- Bachelors in technical or business discipline or related experience,
- 1-3 years professional experience (grade 14) or 5+ years professional experience (grade 15)
- Must be detail-oriented and be flexible as incidents are unable to be predicted
- Understanding third party risk management, including privacy and business continuity and resiliency topics
- Experienced incident handler highly desirable
- Ability to handle complex scenarios and work with empathy with stakeholders during cyber event investigations
- Knowledge of risk assessment practices or IT controls and testing strategies is a plus
- Knowledge of cybersecurity control, program, and risk frameworks such as CIS Controls, NIST CSF, FAIR, NIST RMF, and ISO 27001 is a plus
- Already has security certifications, or is willing to obtain certification within 12 months of hiring
- Collaboration, prioritization, and adaptability skills required.
- Basic proficiency of operational framework capabilities to include dimensional and lateral thinking, architectural analysis, business analysis and financial disciplines, data integration and analysis, and computational thinking.
- Intermediate proficiency across security and compliance, social networking, application delivery, mobile competency, system and technology integration, system software infrastructure, and workplace adaptability.
Employees may apply for a new role after completing 12 months of employment in their current position.
Employees should review all role requirements and apply only for positions for which they are eligible. Hiring processes may vary by country, including differences in procedures, requirements, and timelines. For country-specific details, please consult your local recruiting / HR team.
## Travel
10%