34 Ofertas de Cissp en Costa Rica
Information Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Information Security Engineer – Santa Ana, Costa Rica
Does playing a vital role in business growth sound exciting to you? Would you like to work for a global company in Money Transfer that believes when money moves, better things can happen? Are you interested in joining a globally diverse organization where our unique contributions are recognized and celebrated, allowing each of us to thrive? Join Western Union as an Information Security Engineer.
Western Union powers your pursuit.
You'll provide technical support and operational oversight for cloud-based services, with a focus on Content Delivery Network (CDN) and Web Application Firewall (WAF) configurations. This role will involve working closely with enterprise customers, internal teams, and Akamai's infrastructure to ensure optimal performance, reliability, and security of cloud-based services. Monitors, evaluates, and maintains systems and procedures to safeguard internal information systems and databases and defines, implements, maintains information security practices and technologies to ensure appropriate protection of Western Union's data.
Role Responsibilities
Provide technical support for CDN and WAF configurations across enterprise-level cloud environments.
Troubleshoot performance, connectivity, and security issues related to web traffic delivery and protection.
Collaborate with internal teams and external stakeholders to ensure high availability and optimal performance of cloud services.
Monitor service health and proactively identify areas for improvement or risk mitigation.
Support incident response and contribute to post-incident reviews and root cause analyses. Document technical solutions and contribute to internal knowledge bases.
Stay current with industry trends and best practices in cloud networking and application security.
Research, recommend, and implement changes to enhance systems security. Educates and communicates security requirements and procedures to all users and new employees.
Act as a technical liaison for CDN/WAF cloud services, supporting enterprise-level clients. Troubleshoot and resolve complex issues related to CDN, DNS, HTTP/S, TCP/IP, and security configurations. Monitor and maintain service performance, proactively identifying and mitigating risks.
Collaborate with Vendor's Support, Network Operations, WU Cyber Fusion and Engineering teams. Also, mentor junior and SOC engineers and contribute to continuous improvement initiatives.
Role Requirements
Minimum bachelor's degree in computer science, or similar fields.
Five or more years in the information technology field.
At least two years of experience with WAF technologies, preferably Akamai WAF/Kona Site Defender, including hands-on experience.
Experience with other WAF platforms such as F5 ASM/Advanced WAF, Cloudflare, or Signal Sciences is a plus.
Experience with API security and bot mitigation strategies are preferred.
Ability to communicate technical security requirements to technical and non-technical personnel.
Relevant certifications such as GSEC, GCIH, or WAF/CDN vendor-specific certifications are not mandatory but considered a plus.
Ability to collaborate with technical and vendor personnel including cloud service providers.
We make financial services accessible to humans everywhere. Join us for what's next.
Western Union is positioned to become the world's most accessible financial services company —transforming lives and communities. We're a diverse and passionate customer-centric team of over 8,000 employees serving 200 countries and territories, reaching customers and receivers around the globe. More than moving money, we design easy-to-use products and services for our digital and physical financial ecosystem that help our customers move forward.
Just as we help our global customers prosper, we support our employees in achieving their professional aspirations. You'll have plenty of opportunities to learn new skills and build a career, as well as receive a great compensation package. If you're ready to help drive the future of financial services, it's time for Western Union. Learn more about our purpose and people at
Benefits
You will also have access to short-term incentives, multiple health insurance options, accident and life insurance, and access to best-in-class development platforms, to name a ). Please see the location-specific benefits below and note that your Recruiter may share additional role-specific benefits during your interview process or in an offer of employment.
Your Costa Rica- specific benefits include:
Asociación Solidarista
In house company doctor services
Transportation services options
Referral Program award
Pan American Medical and Life insurance
Cafeteria Discounts
Western Union values in-person collaboration, learning, and ideation whenever possible. We believe this creates value through common ways of working and supports the execution of enterprise objectives which will ultimately help us achieve our strategic goals. By connecting face-to-face, we are better able to learn from our peers, problem-solve together, and innovate.
Our Hybrid Work Model categorizes each role into one of three categories. Western Union has determined the category of this role to be Hybrid. This is defined as a flexible working arrangement that enables employees to divide their time between working from home and working from an office location. The expectation is to work from the office a minimum of three days a week.
We are passionate about diversity. Our commitment is to provide an inclusive culture that celebrates the unique backgrounds and perspectives of our global teams while reflecting the communities we serve. We do not discriminate based on race, color, national origin, religion, political affiliation, sex (including pregnancy), sexual orientation, gender identity, age, disability, marital status, or veteran status. The company will provide accommodation for applicants, including those with disabilities, during the recruitment process, following applicable laws.
LI-GGC #LI-HybridEstimated Job Posting End Date:
This application window is a good-faith estimate of the time that this posting will remain open. This posting will be promptly updated if the deadline is extended or the role is filled.
Senior Information Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Company Description
Experian is a global data and technology company, powering opportunities for people and businesses around the world. We help to redefine lending practices, uncover and prevent fraud, simplify healthcare, create marketing solutions, and gain deeper insights into the automotive market, all using our unique combination of data, analytics and software. We also assist millions of people to accomplish their financial goals and help them save time and money.
We operate across a range of markets, from financial services to healthcare, automotive, agribusiness, insurance, and many more industry segments.
We invest in people and new advanced technologies to unlock the power of data. As a FTSE 100 Index company listed on the London Stock Exchange (EXPN), we have a team of 22,500 people across 32 countries. Our corporate headquarters are in Dublin, Ireland. Learn more at
Job Description
As a part of Experian's Health Team Technology Team, you'll work in a team of technologists that focus on the security aspects of our application portfolio. This position is remote.
The Security Engineer / Analyst will be part of the Experian Health Department as an important member of the Product Security team reporting to the Sr. Director, Product Security. The Product Security team is responsible for the security of Experian's Health's products, including architecture and design, vulnerability remediation, and driving special security related projects.
You will support our security governance, risk, and compliance activities by working through different aspects of corporate systems and procedures and work closely with multiple BU Technology Leaders to ensure the classified, integrity, and availability of the Health BUs application (and supporting infrastructure).
Summary Of Primary Responsibilities
This role focuses on ensuring that business unit (BU) technology teams comply with Experian's security, risk, and compliance policies. The specialist acts as a subject matter expert (SME), providing technical and procedural guidance to stakeholders and supporting application deployments. Responsibilities include:
- Interpret and implement corporate security and compliance requirements.
- Conduct risk and security assessments to enhance BU technology.
- Collaborate with corporate groups (e.g., EGSO, EITS, Internal Audit).
- Lead vulnerability research, remediation planning, and coordination with technical teams. Promoting an Agile, innovative culture.
- Monitor and reporting on application security status and training gaps.
Qualifications
Years of Experience: 3 or more years (Advanced), 5+ years
Working knowledge of security, risk, and compliance processes and certifications (HIPAA, SOC2, PSA, Vulnerability Management, etc.)
- Talk through security processes to company partners and select third parties (internal and external auditors)
- Classified lead and occasional manage important projects related to security, risk, and compliance for the Health BU
- Professional cybersecurity relevant certifications such as Security+ (CompTIA), ISSMP or SSCP are important.
- Familiarity with NIST security and other industry standard 'norms' (e.g., ISO27001, ITIL)
Desired Skills
- Strong written and spoken communication skills. Be able to articulate technical subjects to a non-technical audience.
- Adjust partner communication to align with audience diversity.
- Strong information analysis and interpretation.
- Use available technology to enhance the effectiveness of deliverables and services.
- Experience with reporting tools
- Experience working with Cloud Environments.
- Experience with security reporting
- Experience in vulnerability remediation and management
- Experience with security best practices and industry standards
- Experience technical background in security, network, and/or application infrastructure
Additional Information
This is a permanent home-based role in Costa Rica. No Visa sponsorship or relocation available.**
Our benefits include: Medical, life and dental insurance, Asociación Solidarista, International Share Save Plan, Flex Work/Work from home, Paid time off, Annual Performance Bonus, Education Reimbursement, Family Bonding, Bereavement Leave, Referral Program, and more.
Experian is proud to be an Equal Opportunity and Affirmative Action employer. Our goal is to create a successful, inclusive and diverse team where people love their work and love working together. We believe that diversity, equity and inclusion is important to our purpose of creating a better tomorrow. We value the uniqueness and want you to bring your whole, authentic self to work. For us, this is The Power of YOU and it ensures that we live what we believe.
Experian Careers - Creating a better tomorrow together
Find out what its like to work for Experian by clicking here
This is a remote position.
Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Costa Rica
Company Overview
At Zuora, we do Modern Business. We're helping people subscribe to new ways of doing business that are better for people, companies and ultimately the planet. It's an approach resulting from the shift to the Subscription Economy that puts customers first by building recurring relationships instead of one-time product sales and focuses on sustainable growth. Through our leading expertise and multi-product suite, we are transforming all industries and working with the world's most innovative companies to monetize new business models, nurture subscriber relationships and optimize their digital experiences.
The Team & Role
Zuora Security
is dedicated to safeguarding our cloud-based application ecosystem. Our teams are responsible for defending infrastructure, managing internal and external security services, and collaborating closely with engineering, customer support, and other departments to prioritize customer security. Operating on a
global follow-the-sun model
across the US, Beijing, and India, we provide
24/7/365 protection
for Zuora's SaaS products and platforms.
Within this, the
Infrastructure Security team
focuses on securing Zuora's foundational systems, services, and environments. We design and manage cloud-native infrastructure security controls, enabling safe, scalable operations while proactively protecting against modern threats. Our team values
innovation, automation, artificial intelligence, and close collaboration
to meet the demands of a rapidly expanding business.
This is an exciting time to join Zuora
— as our global infrastructure grows in scale and complexity, so does the opportunity to shape our security strategy and execution. In this role, you'll help design, implement, and manage robust security solutions while leveraging cutting-edge technologies like
AI-based security automation, cloud-native tooling, and proactive threat detection frameworks
. You'll play a critical role in safeguarding our infrastructure and enabling Zuora's secure growth.
This is a remote position
, so you'll work from wherever you're most productive, with occasional in-person office visits, events, or offsites. Of course, you're welcome to use our offices regularly if you're nearby.
What You'll Do
- Architect and implement automated, AI-driven security solutions to fortify our AWS Cloud infrastructure, improving operational efficiency and reducing risk.
- Provide technical leadership by designing, implementing, and optimizing security controls across both infrastructure and application environments.
- Collaborate cross-functionally with engineering, infrastructure, and operational teams to gather requirements and design practical, scalable security measures.
- Identify and address emerging threats through continuous monitoring, vulnerability assessments, penetration testing, and log analysis.
- Mentor and grow within a high-performing security team, sharing your expertise and contributing to a culture of continuous learning.
- Lead and participate in on-call rotations, ensuring 24/7/365 security coverage and effective, timely incident response as part of our global operations model.
- Work hands-on with modern security tools and platforms, including CSPM, CWPP, SOAR, EDR/XDR, IaC security, Kubernetes security, and AI/ML-based security automation — keeping your skills sharp in one of cybersecurity's fastest-evolving areas.
Education
What we're looking for
- Bachelor's degree in Computer Science, Information Security, or a related field (or equivalent practical experience). An advanced degree is a plus.
Experience
- Typically, 8+ years of progressive experience in security operations, infrastructure security, or a related field.
- 3–5 years of hands-on experience with AWS and Azure cloud security, including Infrastructure-as-Code software and tooling.
- Experience working with infrastructure supporting containerized applications (EKS, ECS, or similar).
- Experience developing and maintaining technical and procedural documentation and security policies.
- Proven experience in security incident handling, root cause analysis, and operational incident management.
- Practical experience using AI and automation in security workflows.
- Experience managing infrastructure vulnerability management programs.
- Familiarity with Agile methodologies applied to security engineering projects.
Technical Skills
- Strong understanding of security fundamentals, including system internals, cryptographic protocols, and attack surface reduction strategies.
- Proficiency in scripting languages such as Python, PowerShell, or Perl for automation.
- Hands-on experience with industry-standard security solutions like SIEM, SOAR, CSPM, DSPM, CDR, CWPP, etc.
- Solid knowledge of cloud security technologies, including IAM, encryption, key management, AWS GuardDuty, WAF, etc.
- Familiarity with web application security threats (e.g., OWASP Top 10) and mitigation strategies.
- Proficiency in Linux systems administration and troubleshooting.
Preferred Certifications
- AWS Certified Security Specialist, Azure Security Engineer Associate, or other relevant industry certifications.
Soft Skills
- Strong problem-solving and analytical skills.
- Excellent written and verbal communication abilities.
- Strong interpersonal skills for effective collaboration across diverse, distributed teams.
- Ability to adapt to fast-paced, changing environments and manage ambiguity.
- Proven leadership, mentorship, and team-building skills.
- Meticulous attention to detail, with the ability to prioritize and manage work under pressure.
#ZEOLife at Zuora
As an industry pioneer, our work is constantly evolving and challenging us in new ways that require us to think differently, iterate often and learn constantly—it's exciting. Our people, whom we refer to as "ZEOs" are empowered to take on a mindset of ownership and make a bigger impact here. Our teams collaborate deeply, exchange different ideas openly and together we're making what's next possible for our customers, community and the world.
As Part Of Our Commitment To Building An Inclusive, High-performance Culture Where ZEOs Feel Inspired, Connected And Valued, We Support ZEOs With
- Competitive compensation, variable bonus and performance reward opportunities, and retirement programs
- Medical, dental and vision insurance
- Generous, flexible time off
- Paid holidays, "wellness" days and company wide end of year break
- 6 months fully paid parental leave
- Learning & Development stipend
- Opportunities to volunteer and give back, including charitable donation match
- Free resources and support for your mental wellbeing
Specific benefits offerings may vary by country and can be viewed in more detail during your interview process.
Location & Work Arrangements
Organizations and teams at Zuora are empowered to design efficient and flexible ways of working, being intentional about scheduling, communication, and collaboration strategies that help us achieve our best results. In our dynamic, globally distributed company, this means balancing flexibility and responsibility — flexibility to live our lives to the fullest, and responsibility to each other, to our customers, and to our shareholders. For most roles, we offer the flexibility to work both remotely and at Zuora offices.
Our Commitment to an Inclusive Workplace
Think, be and do you At Zuora, different perspectives, experiences and contributions matter. Everyone counts. Zuora is proud to be an Equal Opportunity Employer committed to creating an inclusive environment for all.
Zuora does not discriminate on the basis of, and considers individuals seeking employment with Zuora without regards to, race, religion, color, national origin, sex (including pregnancy, childbirth, reproductive health decisions, or related medical conditions), sexual orientation, gender identity, gender expression, age, status as a protected veteran, status as an individual with a disability, genetic information, political views or activity, or other applicable legally protected characteristics.
We encourage candidates from all backgrounds to apply. Applicants in need of special assistance or accommodation during the interview process or in accessing our website may contact us by sending an email to
Product Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Datasite is where deals are made. We provide the data rooms and SaaS technology used in M&A and other high-value transactions, to deliver projects in more than 170 countries. Carrying that success into the future is all about you. Your useful skills, your unusual experience, your unique ideas. Everyone here brings something unexpected. What's yours? Invest your talents in us, and we'll return the compliment.
Job Description
As a Product Security Engineer, leverage your expertise in identifying and mitigating security vulnerabilities, collaborating with cross-functional teams, and implementing robust security measures. With a strong foundation in web application security, authentication technologies, and development skills, you'll ensure our products remain secure and resilient against emerging threats. If you're passionate about security and thrive in a dynamic environment, this is the perfect opportunity to make a significant impact
Duties And Responsibilities
- Implement and maintain product security capabilities into the Secure SDLC.
- Define baseline requirements and build integrations into the CI/CD to enable detection and prevention of misconfigurations and vulnerabilities.
- Perform code reviews focused on potential security risks and collaborate with engineering to remediate.
- Support the growth of the Product Security program to include establishing security pillars targeting key focus areas within the product lifecycle.
- Develop automation to scale security capabilities integrated into Datasite processes.
- Define security best practices relevant to our technology stack.
- Support security incident response processes for the Security Operations team.
Qualifications
Education
- Required: Bachelor's Degree in Computer Science, Cybersecurity, or similar technical degree.
- Highly Preferred: Certifications relevant to product security or software development. (i.e. CSSLP, OSWE, CKS)
Experience
- Required: 2+ years in software development or product security
- Strong understanding of core software security principles and OWASP Top 10.
- Experience identifying and mitigating security vulnerabilities.
- Familiarity with application security tools such as web proxies, or fuzzers.
- Proficient in programming languages such as Java, JavaScript, and Python.
- Understanding of cloud principles and experience working with a major cloud provider.
- Familiarity with DevOps practices, CI/CD and containerization.
- Experience with Microservices architecture and MVC design pattern.
- Experience performing code reviews, identifying software bugs or security risks.
- Knowledge of networking principles and web protocols.
- Understanding of Agile methodologies and experience working with Agile teams.
- Experience collaborating as a team player in a cross-functional environment.
- Strong critical thinking and problem-solving skills.
Additional Requirements
- Must be consistently available during core business hours of Monday – Friday, 8:00am - 5:00pm Central, to assist with global coverage.
- This is a hybrid role (100% remote is not available), our employees work on average 2-3 days per week in our Heredia office. Also, we require (1) in-person interview in Costa Rica.
As a global organization, Datasite knows that diverse perspectives are essential to our success. We're committed to maintaining a diverse workforce to serve our customers around the world. Datasite is an equal opportunity employer (EEO) and furthers the principles of EEO through Affirmative Action.
Firewall Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
In this position, you will be responsible for the day-to-day provisioning/delivery and support of a complex security environment – in a global multi-data center setting.
Firewalls in the environment include mostly Palo Alto and CheckPoint, some Cisco ASA firewalls as well.
Responsibilities
:
- Working off governance approved customer requests to create and implement firewall policies for acceptable use of company resources.
- Providing technical help for customers encountering difficulties with their connectivity as it relates to firewalls.
- Following and adhering to all PCI compliance requirements around the firewall process.
- Automation skills and familiarity with scripting technology a plus.
Basic Qualifications for Consideration
:
- 5+ years relevant technical experience.
- At least 2-4 years' experience working in a progressive information security operations or engineering group.
- 3+ years' experience in a large complex Palo Alto and Checkpoint environment
- Proven hands-on experience with firewalls and knowledge of IP networking and network security including: Intrusion Detection, DMZ, encryption, IPSec, PKI, VPNs, MPLS/VPN, Site to Site VPN tunnels, SSL/VPN, proxy services, and DNS
- Cisco ASA experience
- Splunk Experience
- Network routing, switching, packet analysis
- PCI DSS compliance knowledge
- Change Management and ITIL familiarity
- Prior experience with network security & related applications, tools and solutions
- Deep understanding of network routing and switching architecture, design and troubleshooting
- Experience supporting 24x7x365 high availability solutions in large complex data center environments
- Exceptional planning, organization, communication, presentation, multi-tasking, prioritization & business analysis skills.
- Ability to work independently in addition to working closely in a team environment.
- Needs strong ability to multi-task and work effectively in a distributed and matrix-oriented environment
- Excellent networking troubleshooting skills
Preferred Skills, Experience, and Education:
- Bachelor of Science in Information Technology, Management Information Systems or Risk Management OR
- High School Diploma with 4+ years relevant work experience.
- Checkpoint VSX and Provider 1 experience, CCSA preferred.
- CISSP certification preferred
- Palo Alto ACE, PCNSE preferred.
- Certs in CompTIA Network+ or CCNA
- AWS or Azure Experience
- WAF exposure
- Tufin management experience
- CISSP
IT Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Meet the Team
Cisco is going through transformation and to support that initiative, IT Security its own major transformation. We are working to embrace/migrate/deploy industry the best tools, industry protocols/standards, and helping to own the way in making Cisco the best Security company in the world.
Identity is at the heart of a companywide transformation that is key to Cisco's future success, making this a very exciting time to join our IT Security Team. We are in the process of extending our identity border to enable Cisco and adopt Zero Trust and the broader use of Cloud, and to help accelerate these transitions we are looking a confident Security Engineer with Directory and Privileged Identity skills to be part of our growing team.
While understanding and operating our sophisticated enterprise environment we'll look to you to recommend and implement automation of our services shifting to a self-service model, as well as explore and implement new Directory and Identity technologies. We look forward to your creativity in moving our internally hosted solutions to industry leading solutions which will support our transformation journey
What You Will Do
The Mid-Level IT Security Engineer will be responsible for the implementation, support and management of the IAM systems. The ideal candidate will have a proven background in identity management solutions, access control policies, ability to respond and resolve issues within Service Level Agreements (SLA) and a deep understanding of IT security standard methodologies. This role is important in ensuring that the right individuals have access to the right resources at the right times and for the right reasons.
Your Impact
Develop and Migrate and maintain identity governance frameworks to ensure user access is stays in sync with regulatory requirements and company policies.
Implement and handle IAM systems, including provisioning, deprovisioning, and access reviews.
Resolve issues raised by users of the platform within SLAs using standard operating procedures following ITIL framework.
Configure and maintain Single Sign-On (SSO) and Multi-Factor Authentication (MFA) systems.
Work closely with IT, HR, Risk and Compliance and other business units to ensure detailed integration of IAM solutions.
Conduct regular audits of user access and permissions to ensure compliance with established policies.
Respond to and investigate security incidents related to unauthorized access.
Build and maintain documentation for IAM processes and policies.
Deliver training and support to users on IAM procedures and standard methodologies.
Stay up-to-date with emerging security threats, IAM technologies, and industry trends.
Collaborate with team members to improve overall security posture.
Minimum Qualifications
- Bachelor's degree or equivalent experience in Information Security, Computer Science, or a related field.
- Demonstrated ability in IT security, with a focus on identity governance and access management, supporting Enterprise user platforms.
- Solid experience with implementing and maintaining IGA systems like Sailpoint (IIQ and/or ISC).
- Solid experience working in AWS or other public cloud platforms and Knowledge of directory services, LDAP, and Active Directory.
- Working experience demonstrable experience with IAM tools and platforms (e.g., Okta, Azure AD, SailPoint, Duo, Ping Identity) and solid grasp of compliance frameworks such as GDPR, HIPAA, SOX, and NIST.
Preferred Qualifications
- Experience with programming and scripting languages Java, NodeJS, PowerShell, Python is preferred.
- Certifications on Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CISM), Certified Identity and Access Manager (CIAM) is preferred.
At Cisco, we're revolutionizing how data and infrastructure connect and protect organizations in the AI era – and beyond. We've been innovating fearlessly for 40 years to create solutions that power how humans and technology work together across the physical and digital worlds. These solutions provide customers with unparalleled security, visibility, and insights across the entire digital footprint. Simply put – we power the future.
Fueled by the depth and breadth of our technology, we experiment and create meaningful solutions. Add to that our worldwide network of doers and experts, and you'll see that the opportunities to grow and build are limitless. We work as a team, collaborating with empathy to make really big things happen on a global scale. Because our solutions are everywhere, our impact is everywhere.
We are Cisco, and our power starts with you.
Cyber Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
-
The successful candidate will be a critical link between the Cyber Security and Digital IT delivery teams, closely supporting the rate of deployment while managing strategic security and business risks. You will be providing expertise and undertaking risk assessments on numerous sprints, prioritising and managing multiple work streams at any one time. You will work with the wider Cyber security team and engage their knowledge where appropriate.
What you will be doing:
- Provide guidance and help to IT delivery teams in regards to security solutions to enable faster delivery of secure IT Systems
- Collaborating with IT development teams and other teams working closely in a DevOps and Agile development process. Support the Secure SDLC ensuring developers are coding in-line with security standards, practices and industry best-practice
- Responsible for undertaking application security risk assessments as part of development projects. This entails using a threat modeling methodology to identify threats which could affect the Confidentiality, Integrity and Availability of the data and components in scope.
- Own driving the remediation of security issues (defects), or supporting other risk treatment methods as needed (e.g. risk acceptance)
- Providing support for automated application security tooling working with Cyber Security as necessary
- Challenge and create new ways to meet security controls which are more effective in DevOps and Agile ways of working, by helping IT delivery teams adopt a "shift left" approach to managing security
- Overseeing effectiveness of controls to ensure compliance with Information Security policies and standards.
- Work closely with delivery teams to develop and monitor security risk remediation programme activities and actions to ensure delivery within acceptable timelines
- Focusing on Technology top security risks and threats, including new/emerging top risks, to ensure they are fully understood and that controls that mitigate these risks (key controls) are effective, efficient and where possible automated
- Responsible for embedding risk and control management framework
- Role model a positive internal security risk and control culture across Digital IT delivery teams and help shape the climate, tone and environment in which people work
What you will bring to the role:
- Proficient in application security testing of Web, Mobile (Android and iOS), and API etc.
- Ability to assess and identify any possible vulnerabilities in technology being developed prior to implementation
- Expertise in application Security Testing DAST; experienced in web application, API Security, and mobile application security testing in conformance to various industry standards like OWASP top 10, SANS top 25 etc.
- Good to have knowledge on programming and scripting skills in languages like Java, JavaScript, Angular, Spring Boot, Kotlin, and Swift etc.
- Expert level knowledge of tools like Burp Suite, IBM appscan (standard and source), HP Fortify, Postman, SoapUI, Checkmarx, Contrast etc. to perform the security testing
- Consistently display positive leadership behaviours related to the management and mitigation of risk, including notification and escalation of any concerns and ensuring timely action in relation to points raised by audit, 2LoD and external regulators
- The jobholder will adopt the Group Compliance Policy by escalating any identified compliance risk in liaison with, Global Compliance Officer, Area Compliance Officer or Local Compliance Officer. The term 'compliance' embraces all relevant financial services laws, rules and codes with which the business has to comply
This will be achieved by adhering to all relevant processes/procedures and by liaising with Compliance department about new business initiatives at the earliest opportunity. Also and when applicable, by ensuring adequate resources are in place and training is provided, fostering a compliance culture and optimising relations with regulators
Role relevant qualifications, i.e. professional certifications in Information Security (CRISC, CISSP, CISA, OSCP, GIAC GPEN, GIAC GMOB) is desirable but not essential
- Strong grasp of application security tooling, and experience of driving automation within the delivery environment
Sé el primero en saberlo
Acerca de lo último Cissp Empleos en Costa Rica !
Cloud Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
About the Role
As a
Cloud Security Engineer
, you will play a key role in securing our client's expanding cloud environment. You'll support the safe adoption of cloud technologies and help shape the future of their cloud security program. The ideal candidate brings hands-on technical expertise, a deep understanding of modern cloud platforms, and a passion for building secure, scalable, and resilient solutions. You'll collaborate cross-functionally with infrastructure, DevOps, and application teams to embed security throughout the cloud lifecycle—from design to deployment and beyond.
Key Responsibilities
- Design and implement cloud security controls across IaaS, PaaS, and SaaS environments to ensure data and service confidentiality, integrity, and availability.
- Collaborate with infrastructure, DevOps, and application teams to integrate security into cloud architectures and CI/CD pipelines.
- Monitor and respond to cloud security events using tools such as Microsoft Defender for Cloud.
- Evaluate and enhance identity and access management (IAM) practices, including privileged access, conditional access, and Just-In-Time access.
- Conduct security assessments and threat modeling for cloud workloads; identify gaps and lead remediation efforts.
- Define and enforce cloud security policies, standards, and best practices aligned with industry frameworks (e.g., NIST, CIS, CSA CCM).
- Lead or support incident response efforts for cloud-related security incidents, including investigation, containment, and post-incident analysis.
- Continuously assess cloud configurations for misconfigurations or non-compliance using native or third-party tools.
- Support data protection initiatives including encryption, DLP, key management, and secure cloud storage.
- Stay up to date on emerging threats, tools, and regulatory requirements related to cloud computing and advise on necessary changes to security posture.
Qualifications
Education:
- Bachelor's degree in Cybersecurity, Information Technology, or a related field (relevant certifications may be considered in lieu of formal education).
Preferred Certifications:
- Microsoft Certified Cybersecurity Architect Expert
- Azure Security Engineer Associate
- AWS Certified Security – Specialty
- (ISC)² Certified Cloud Security Professional (CCSP)
Experience:
- Minimum 5 years of experience in one or more cybersecurity domains.
- At least 3 years focused specifically on cloud security across platforms such as Microsoft Azure, AWS, or GCP (Azure experience preferred).
Technical Expertise:
- Strong understanding of cloud security principles:
- Identity and access management (IAM)
- Network security (NSGs, firewalls, segmentation)
- Data protection (encryption, tokenization, key management)
- Threat detection and incident response
- Familiarity with:
- Cloud-native security tools (e.g., Microsoft Defender for Cloud, AWS GuardDuty, GCP Security Command Center)
- SIEM integration and cloud log analysis
- DevSecOps practices and CI/CD pipeline security
- Compliance frameworks such as NIST, ISO 27001, CIS Benchmarks, CSA CCM
Soft Skills:
- Excellent written and verbal communication skills.
- Strong interpersonal skills and ability to thrive in a fast-paced, collaborative environment.
Leadership Attributes
Our client values the following leadership principles:
- Embrace Diversity and Inclusion:
Welcome diverse perspectives, foster transparency, and promote inclusivity. - Seek to Listen:
Actively listen to others to reach the best solutions and make strong decisions. - Always Learn:
Continuously strive for improvement and challenge the status quo. - Be Authentic:
Demonstrate honesty, energy, and resilience in everything you do. - Win Together:
Collaborate effectively, align goals, and communicate across teams to succeed as one.
Network Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
This job is with Thermo Fisher Scientific, an inclusive employer and a member of myGwork – the largest global platform for the LGBTQ+ business community. Please do not contact the recruiter directly.
Work Schedule
Standard (Mon-Fri)
Environmental Conditions
Office
Job Description
When you join us at Thermo Fisher Scientific, you'll be part of a hard-working, driven team that shares your passion for exploration and discovery. With annual revenues of approximately $40 billion and the most significant investment in R&D in the industry, we give our over 100,000 colleagues the resources and chances to create meaningful contributions to the world.
Location/Division Specific Information
Discover Impactful Work: The Network Security Engineer has global responsibility for supporting solutions crafted to protect, detect, and alert to security threats in our enterprise network environment.
A Day in the Life
- Communicates and engages with the SOC on security incidents related to network security events
- Oversees management of security posture for network security platforms such as firewalls, web content filtering, etc
- Maintains enterprise firewall policy rule base and support the business during technical troubleshooting and support efforts
- Documents organizational change requests to support planned maintenance events
- Work closely with our vendors to mitigate threats and vulnerabilities
- Resolves security violations and inefficiencies by conducting periodic audits
Keys to Success
- Ensure documentation and processes are well defined so that the engineered solutions are understood and repeatable
- Maintaining, updating, configuring, monitoring firewalls, virtual private networks, content filtering, intrusion detection, log management, and security policies
- Identify and implement IT industry standards to improve the organization's security posture
- Maintaining technical knowledge by attending educational workshops; reviewing publications
Education
- Bachelor's Degree in cybersecurity, computer science, systems engineering, or related field. Equivalent work experience is accepted
- Four years of related work experience in cybersecurity
- Certifications are not required but encouraged: Certified Information Systems Security Professional, CompTIA Network+, Security+, or related certifications
Experience
- At least two years of experience in zero-trust security framework, user identity and device management, architectur
- Strong organization skills, leading sophisticated project
- Excellent written and verbal communication skills
Knowledge, Skills, Abilities
- Demonstrates knowledge of firewalls, F5s, VPNs, and cloud technologies
- Monitoring web security gateways, perimeter security, network access controls, and endpoint security
- Maintaining & implementing SOPs for Network Security
- Knowledge of various packet analyzers to perform packet captures
- Safeguards information system assets by identifying and solving potential and actual security problems
Thermo Fisher Scientific Inc. is an equal opportunity employer. We value diversity and are committed to creating an inclusive environment for all employees. We believe that by embracing individual differences, we can drive innovation and achieve even greater success.
Don't miss this ambitious opportunity to join a leading global company and make a significant impact on our team. Apply now and be part of our success story
Network Security Engineer
Hoy
Trabajo visto
Descripción Del Trabajo
Cloud Network & Security Engineer:-
Experience: 5+ years
Location: Costa Rica and Mexico
We are seeking a
Cloud Network & Security Engineer
to join a global consultancy team supporting a Fortune 50 enterprise client. This role is dedicated to modernizing and supporting a massive hub-and-spoke
multi-cloud network infrastructure
, with emphasis on
firewalls, load balancers, and secure connectivity
across Azure, AWS, and GCP.
As a member of the
Enterprise Cloud Network & Security Team
, you will help design, deploy, and support cloud-native and hybrid network security solutions. You will also contribute to
automation and orchestration efforts
, enabling scalability, governance, and compliance in one of the world's largest enterprise IT environments. This position requires a hands-on engineer with a strong networking and cloud background, coupled with the ability to collaborate across
security, DevOps, and application teams
.
Key Responsibilities
- Implement, maintain, and support next-generation
cloud and hybrid firewalls
(cloud-native and vendor-based) and
application delivery/load balancer solutions
. - Deploy, upgrade, and troubleshoot multi-cloud network security infrastructure including:
- Firewalls (Palo Alto, Check Point, cloud-native)
- Load balancers (cloud-native, F5)
- Hybrid cloud connectivity (VPN, ExpressRoute, Direct Connect)
- Secure remote access and site-to-site VPN solutions
- Support
automation of firewall, load balancer, and network security operations
through scripting and Infrastructure as Code (IaC). - Integrate automation workflows with enterprise DevOps toolsets (GitHub Actions, Azure DevOps, Terraform, CloudFormation, etc.).
- Collaborate with enterprise security, infrastructure, and application teams to deliver
standardized, compliant, and scalable network security solutions
. - Participate in incident response, troubleshooting, and on-call rotations for critical network security services.
- Stay current on
emerging technologies and automation practices
in multi-cloud security and networking.
Required Qualifications
- Bachelor's degree in Computer Science, Engineering, or related field (or equivalent experience).
- 3+ years of professional experience
in network and security engineering roles. - 1+ years of hands-on experience
with at least one major public cloud (Azure, AWS, or GCP). - At least one
cloud certification
(Azure, AWS, or GCP). - Demonstrated experience with:
- Firewall implementation, configuration, and troubleshooting.
- Load balancer implementation and support (cloud-native or F5).
- Cloud networking concepts: VPC/VNet design, routing, VPNs, hybrid cloud connectivity.
- Proficiency in
English communication
(written and verbal). - Familiarity with
AI-driven monitoring and automation tools
.
Preferred Qualifications
- Multiple cloud certifications across Azure, AWS, or GCP.
- Hands-on experience with
Palo Alto firewalls
(Panorama, Prisma) and/or
Check Point firewalls
. - Experience supporting
cloud-native load balancers
(Azure ALB/AGW, AWS ALB/NLB, GCP Load Balancer) and
F5 LTM/GTM
in enterprise environments. - Familiarity with
automation and scripting tools
(PowerShell, Python, Bash, Postman, REST APIs). - Experience with
Infrastructure-as-Code
frameworks (Terraform, ARM/Bicep, CloudFormation). - Exposure to
DevSecOps practices
for securing network infrastructure as part of CI/CD pipelines. - Knowledge of enterprise-scale, hub-and-spoke multi-cloud architectures.
Why Work With Us
- Be part of a
global consultancy team
supporting one of the world's largest and most complex enterprise cloud infrastructures. - Opportunity to contribute to
multi-cloud automation and modernization initiatives
at scale. - Collaborate with
industry-leading network, security, and cloud experts
. - Gain exposure to
emerging technologies
and AI-driven automation in enterprise network security. - Deliver impact across
Azure, AWS, GCP, and hybrid environments
at Fortune 50 scale.