Lead Information Security Engineer at Nasdaq

Toronto, Ontario, Canada

Nasdaq Logo
Not SpecifiedCompensation
Senior (5 to 8 years), Expert & Leadership (9+ years)Experience Level
Full TimeJob Type
UnknownVisa
Financial Services, TechnologyIndustries

Requirements

  • Degree in Computer Science, Information Systems, or related discipline, or equivalent work experience
  • At least 10 years of experience
  • One or more of the following certifications: MCSE; GIAC (GSEC, GCFW, GCIA, GCIH, GISO, GSNA, GCFA, GSLC); GPEN, CISA, CISSP, CCSP
  • Experience with application security tools in DAST, SAST, and Web Application Penetration Testing

Responsibilities

  • Designs, develops, modifies, adapts, and implements short- and long-term solutions to support IT needs for new and existing applications, systems architecture, network systems, and applications infrastructure
  • Reviews system requirements and business processes; codes, tests, debugs, and architects on-premise and cloud-based software solutions
  • Performs penetration testing, Red Teaming, and risk assessments for cloud-based and on-premise systems
  • Serves as Information Security primary point of contact for a Google cloud-based technology project
  • Designs, develops, implements, and solves problems with various information systems security software ensuring resolution
  • Tests and validates solutions to remediate exploitable conditions on applications
  • Evaluates software fixes (patches) to address sophisticated system vulnerabilities (e.g., viruses, SQL injection, cross-site scripting, buffer overflows, parameter tampering, hidden field manipulation, cookie poisoning, Web services manipulation)
  • Conducts security assessments of complex systems, networks, and applications using penetration tests, ethical hacking tools, and risk assessment/mediation methodologies to evaluate vulnerabilities
  • Prepares status reports on security matters to develop security risk analysis scenarios and response procedures
  • Reviews security designs for complex environments
  • Supports regulatory compliance initiatives related to industry regulations
  • Works with teams across organizations involved in the project to deliver information security related tasks

Skills

Key technologies and capabilities for this role

Penetration TestingRed TeamingRisk AssessmentsGoogle CloudEthical HackingSQL InjectionCross-Site ScriptingBuffer OverflowParameter TamperingRegulatory ComplianceSecurity ArchitectureVulnerability Assessment

Questions & Answers

Common questions about this position

What is the salary for the Lead Information Security Engineer position?

This information is not specified in the job description.

Is this a remote position or what is the location requirement?

This information is not specified in the job description.

What certifications are required for this role?

Candidates must have completed one or more of the following: MCSE certification; GIAC, GSEC, GCFW, GCIA, GCIH, GISO, GSNA, GCFA, GSLC; GPEN, CISA, CISSP, CCSP certifications, plus experience with DAST, SAST, and Web Application Penetration Testing.

What experience level is needed for this position?

At least 10 years of experience is required, along with a degree in Computer Science, Information Systems, or related discipline, or equivalent work experience.

What does Nasdaq's company culture emphasize for applicants?

Nasdaq encourages applications from diverse candidates regardless of age, color, disability, national origin, ancestry, race, religion, gender, sexual orientation, gender identity, veteran status, or other protected statuses, with accommodations for individuals with disabilities.

Nasdaq

Operates electronic stock exchange and financial services

About Nasdaq

Nasdaq operates one of the largest electronic stock exchanges in the world, providing a platform for buying and selling securities. It caters to a wide range of clients, including individual and institutional investors, as well as corporations. Nasdaq offers various financial products and services, such as the Nasdaq Smart Portfolio, which uses advanced analytics to help investors optimize their stock portfolios. Additionally, Nasdaq supports non-financial marketplaces and is recognized for its efforts in sustainable investment practices. The company earns revenue through transaction and listing fees, along with subscription services for its products. Nasdaq aims for global expansion and innovation, with nearly 40 offices around the world.

New York City, New YorkHeadquarters
1971Year Founded
$9,370.5MTotal Funding
IPOCompany Stage
Data & Analytics, Fintech, Financial ServicesIndustries
5,001-10,000Employees

Risks

Adenza acquisition's high price may affect shareholder confidence and stock performance.
Integration of Metrio's ESG software may face challenges, delaying expected benefits.
Nasdaq's secondary stock offering could lead to stock dilution, affecting shareholder value.

Differentiation

Nasdaq operates one of the world's largest electronic stock exchanges.
Nasdaq offers advanced analytics through its Smart Portfolio for investment optimization.
Nasdaq is a pioneer in sustainable investment practices with a focus on ESG solutions.

Upsides

Nasdaq's acquisition of Adenza expands its financial technology capabilities.
Nasdaq's secondary stock offering could provide capital for strategic investments.
Nasdaq Private Market's Series B financing indicates strong investor confidence.

Land your dream remote job 3x faster with AI