Cybersecurity Analyst

Role Summary:

This position will be part of our Cybersecurity department, which is responsible for assuring that security principles and company security policies are adhered to in the design and delivery of systems and software. The Cybersecurity Analyst is responsible for leading a coordinated effort to assess and audit VWGoA applications, internally and externally. This role will also coordinate penetration tests and third party cybersecurity assessments.​ ​

  • Assessing applications with the designated IT and Business owners to meet VW security requirements, internally and externally, following the documented Application Security Assessment (ASA) process​ • Managing and organizing the documentation for ASAs​
  • Setting up and leading meetings between the Business and IT owners to conduct interviews for ASAs​ • Gathering evidence for applications based on ASA control measures, third party assessments and penetration tests​ • Coordinating penetration tests for applications and ensuring that identified findings are remediated prior to approval/launch​ • Ensuring known vulnerabilities are identified and documented for applications​
  • Performing and/or supporting cybersecurity assessments of third parties that are a part of applications through the review of third party cybersecurity questions, participation in third party interviews, and review of third party documentation​
  • Managing assessment activities and associated timelines persuade to both business and IT need in an urgent but business-like manner​ ​

Technical Experience​

5+ years of professional experience in information technology, with at least 2 years of experience directly in an Cybersecurity role.​

Education:​

  • Required: Bachelor’s Degree or a combination of formal education and work experience equaling a Bachelor’s Degree​
  • Desired: Bachelor’s Degree in Information Security, Technology or Computer Science​

Unique Skills:​

  • Cybersecurity Certification (Certified Information Security System Professional (CISSP) certification or equivalent)​
  • Broad understanding of computer networking, technology, and customer service with a security focus​
  • Understanding of common web application security concepts, such as the OWASP Top 10, and their practical implementation​
  • Experience with industry cybersecurity frameworks (eg. NIST 800-53 or equivalent)​
  • Operational knowledge and skills related to conducting industry standard application security assessments​
  • Experience gathering evidence to verify cybersecurity control implementation​
  • Strong verbal and written communications skills, with an ability to express complex technical concepts in business terms to multiple different audiences​
  • Ability to inform, educate and influence business and IT employees to support goals and initiatives of the

Cybersecurity Department​

  • Analytical and conceptual thinking – using logic and reason, creative and strategic​
  • Integration – joining people, processes or system​
  • Excellent planning, organization, and time management skill​
  • Ability to work independently with minimal supervision

Technical Architect (Office 365)

Description:

Under the general supervision of the Manager, IT Workplace Solutions for Volkswagen Group of America, the Office Solutions Architect is responsible for the Office 365 Environment as it relates to business solutions, user productivity, and security/compliance. This will focus on the End Userspace, but will cover all Office 365 Solutions and supporting environments.​​

This role will focus on the potential solutions available within Office 365, determine what would provide benefit to our company and environment, and work to implement these solutions in a way that will meet our security and compliance policies.​

Role Responsibilities​

  • Lead the collaborative effort in designing, building and implementing Office 365 business initiatives​
  • Research and evaluate upcoming changes to Office 365 in order to determine user, security and legal impact. Coordinate decisions among multiple teams as needed​
  • Become familiar with responsibilities of our business units in order to recommend solutions as new functionality is released
  • ​Monitor and communicate to stakeholders the performance of the services​
  • Participate in gathering and analysis of business requirements for software capabilities​
  • Interface with the Global Architects and Support Organizations
  • ​Establish the governance model for O365 suite of applications working with other IT&S groups
  • ​Perform analysis to ensure continuous improvement of all services and systems​
  • Ensures that all support processes are well documented and process is being followed, and is auditable​
  • Provide architectural design for all future system deployments
  • ​Informs management of critical issues that may affect systems​
  • Work with the Enterprise Operations Center (EOC) to maintain appropriate levels of monitoring and alerting​
  • Identify opportunities to transition repeatable, operational activities to lower level operation teams​

Would need to be able to travel at least 1 or 2X per quarter to the Auburn Hills facility.

  • Experience with scripting languages like bash, Groovy.
  • ​Experience with Service mesh .​
  • Experience with Vault.​
  • CKA/CKS Certification a plus.