Description
United's Digital Technology team is comprised of many talented individuals all working together with cutting-edge technology to build the best airline in the history of aviation. Our team designs, develops and maintains massively scaling technology solutions brought to life with innovative architectures, data analytics, and digital solutions.
Job overview and responsibilities
The Senior Manager - Product Cybersecurity is a technical leader responsible for managing a team of highly innovative cybersecurity engineers responsible for developing and maintaining end-to-end security architecture of United’s product(s) / application(s) / service(s). This person will create and implement a vision for security across all products within the United portfolio.
- Define, prioritize, allocate resources, track, and provide status reporting of work assignments, projects, and programs. Provides overall resource / project management for department, including matching people to projects, obtaining needed resources, etc.
- Monitors changes in legislation and compliance standards that affect assigned areas of responsibility and proactively acts to update standards, best practices and architectures based on this information.
- Manages, coordinates, and evaluates the work of assigned cybersecurity department to ensure the security, confidentiality, integrity & availability of United’s systems, products, and services.
- Works with cross functional teams to develop, document and implement cybersecurity standards, best practices, and architectures.
- Coordinates remediation of non-compliant items to meet applicable compliance standards and best practices.
- Manages the development and implementation of cybersecurity strategies.
- Maintains relationships with internal and external audit agencies to facilitate execution of audits.
This position is offered on local terms and conditions. Expatriate assignments and sponsorship for employment visas, even on a time-limited visa status, will not be awarded. This position is for United Airlines Business Services Pvt. Ltd - a wholly owned subsidiary of United Airlines Inc.
Qualifications What’s needed to succeed (Minimum Qualifications) :
Bachelor's degree in Computer Science, Engineering or Business Administration9+ years of IT and business / industry work experienceStrong and proven ability to communicate technical concepts to a non-technical audience and stakeholdersExperience with threat modeling or other risk identification techniques, and risk managementExperience managing teams to identify strategic and tactical riskExperience partnering and influencing cross functional teams to drive security improvementsExperience driving prioritization of security risks / vulnerabilities and ensuring that they are properly understood by the business and fixed and / or mitigatedStrong analytical and quantitative skills with the ability to use data and metrics to back up assumptions and recommendations and drive actionsExcellent oral and written communication skillsDemonstrated ability to convey complex technical subjects in a concise and direct mannerDemonstrated problem solving, critical thinking, logical structuring skills and a willingness to learn and stretch outside of your comfort zoneDemonstrated knowledge on threat landscape, security threat and vulnerability management, and security monitoring and analyticsMust be legally authorized to work in India for any employer without sponsorshipMust be fluent in English (written and spoken)Successful completion of interview required to meet job qualificationReliable, punctual attendance is an essential function of the positionWhat will help you propel from the pack (Preferred Qualifications) :
MS in Computer Science, Mathematics, Information Systems, or other related fieldOne or more of the following :Certified Ethical Hacker (CEH)GIAC Security Essentials (GSEC)Certified Information Security Manager (CISM)Comp TIA Security +Certified Information Systems Security Professional (CISSP)Certified Information Systems Auditor (CISA)Systems Security Certified Practitioner (SSCP)CompTIA Advanced Security Practitioner (CASP+)Offensive Security Certified Professional (OSCP)AWS Solution Architect Pro., Networking, and Security SpecializationsWorking knowledge and / or hands on experience with as many as possible of the following areas :Operating system & platform securityNetworking Security and an understanding of network and web related protocolsVoice over IP and unified communication securityStrong subject matter expertise in the fields of IT security and risk managementStrong knowledge of IT infrastructure security best practices, procedures, and standardsExperience with cloud native products and in-depth understanding microservice topologies and implementationsExpertise in application development and dev-ops security technologies and integrationDemonstrated ability to think strategically about business, product, and technical challengesExperience within the transformation of traditional data center security measures into industry adopted cloud technologiesProven ability to work with compliance frameworks and requirementsAbility to work in a fast-paced and Agile development environmentExperience providing training and mentorshipAbility to perform manual security code reviewsAbility to interpret dynamic / static analysis tools, and penetration test results