Lead Information Security Engineer
BigCommerce is disrupting the e-commerce industry as the SaaS leader for fast-growing, mid-market businesses. We enable our customers to build intuitive and engaging stores to support every stage of their growth.
BigCommerce is growing our cybersecurity team. You will influence the culture and direction moving forward.
As the BigCommerce e-commerce SaaS platform handles information at a large scale, we need to anticipate and protect against attackers targeting BigCommerce or our customers. As a Lead Information Security Engineer, you will perform realistic offensive security exercises to simulate real attacks, to test and improve our detection and response capabilities, and to identify how attackers could infiltrate and move inside our infrastructure.
You will work closely with team members and affected product teams to improve our detection capabilities and design defense-in-depth controls that limit attackers' ability to move inside our network. Whether working on our Google Cloud systems, researching the latest in computer technology or keeping BigCommerce internal systems humming, BigCommerce customers rely on us to keep things running. We're back-end experts: protecting privacy and ensuring the security of our platform
We are looking for a full-time Lead Information Security Engineer, who wants to make an impact at every level of society through protecting more than 60,000 merchants sitting on the BigCommerce e-commerce SaaS platform. By protecting our merchants you will be powering innovators, creative thinkers, entrepreneurs and business owners around the world to be successful at each stage of their business.
The Lead Information Security Engineer will direct the work of the Information Security Operations Team. In this role, they will monitor, analyze, and detect Cyber vulnerabilities, events and incidents within information systems and networks. Lead Cyber Defense efforts to maintain our security toolsets, establish a framework by which cyber risk can be measured and quantified. Conduct multiple-disciplined penetration tests. Development of domain or problem-specific tools that leverage identified vulnerabilities, research on the latest exploitation techniques and threat vectors, and design and configuration of representative test environments. They will support various training events and mentor others.
Their main mission is to lead the Information Security Operations team to excellence in their efforts to protect the BigCommerce platform and BigCommerce customers and employees from cyber threats.
What you’ll do:
- Evangelize security within BigCommerce
- Protect BigCommerce Merchants, their Shopper, and the company
- Seamlessly improve Bigcommerce security posture with minimal impact to our employees daily operations
- Assess security on existing infrastructures
- Respond to information security incidents, providing technical expertise and conduct forensics
- Reduce time-to-detect and time-to-remediate by driving the automation of security event management, vulnerability assessment, and intelligence correlation
- Provide security guidance and experience to Engineering teams
- Provide domain expertise regarding security events that impact applications and network design
- Mentoring team members in best practice around information security standards
- Design secure information systems that protect company data, empower users and drive business growth
- Regular and ongoing pen testing of BigCommerce’s changing environment
- Utilize data to help generate insights into threats, and build solutions.
Who you are:
- Bachelor's degree in CS, EE or MIS; or equivalent experience
- 7 + years of Experience in security engineering, system and network security, cloud security, authentication and security protocols, cryptography, and application security
- Passion for Information Security
- Experience using various penetration testing tools (such as, BurpSuite, Metasploit, Nessus, etc.) on Windows and Linux
- Have supported PCI, ISO 27001 , and SOX audits
- Develops scripts, tools, methodologies and best practices to improve team capabilities
- Knowledge of security testing standards and practices (is a must)
- Proficient in Identity Management best practices
- Scripting skills (i.e. Python / Perl / Ruby, shell scripting) a significant plus
- Experience in using network protocol analyzers and sniffers, as well as the ability to decipher packet captures
- Excellent verbal and written communication
- Proven ability to work effectively with stakeholders, staff, vendors, and external consultants
- Exceptional ability to provide a high level of support with a customer first attitude
- Exceptional ability to seek out opportunities to increase internal client satisfaction and deepen client relationships
- Passionate about technology, strong desire to make our environment better
- Strong sense of ownership, urgency, and drive
- A desire to help and train users so they better understand the solutions we offer
- Presentation Experience, Conferences, White Papers, Bug bounties are most Welcome
- Desired but not mandatory, Relevant information security certifications OSCP, OSCE, SANS GCIA, SANS GCIH, SANS GPEN, SANS GCFA and CISSP
Diversity & Inclusion at BigCommerce
We have the opportunity to build not only a great business, but a great company, with soul. Our beliefs and commitment to diversity and inclusion are a central part of achieving that.
Our dedication to diversity and inclusion is grounded in two things: a moral belief in the dignity, value, and potential of every individual, and a practical belief that diverse, inclusive teams will create the best outcomes for our customers, partners, employees, and company. We welcome everyone to be a part of our journey.