Principal Cybersecurity Analyst
On-siteDurham, North Carolina, United States
Job Summary
Conduct risk determinations and develop plans to safeguard computer files against unauthorized modification or disclosure. Monitor virus reports to update protection systems, encrypt data transmissions, and erect firewalls to conceal confidential information. Execute tests of data processing systems and modify security files to incorporate new software or correct errors. Manage Intrusion Prevention Systems, Advanced Threat Protection, cloud security, and email security operational functions. Perform manual and automated penetration testing using Nmap, Nessus, and Burpsuite to identify vulnerabilities and validate controls. Engage in incident handling including threat discovery, triage, containment, recovery, and remediation plan coordination using Splunk, Wireshark, and Crowdstrike. This role requires a Bachelor's or Master's degree in a technical field with five or three years of experience, respectively, and involves onsite presence as Fidelity transitions to a full-time onsite working model.
Required Qualifications
- Bachelor's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent)
- Five (5) years of experience as a Principal Cybersecurity Analyst (or closely related occupation) designing and implementing perimeter security defense solutions to protect enterprise networks from external threats, unauthorized access, and DDoS attacks, in on premises and Cloud environments
- Master's degree in Computer Science, Engineering, Information Technology, Information Systems, or a closely related field (or foreign education equivalent)
- Three (3) years of experience as a Principal Cybersecurity Analyst (or closely related occupation) designing and implementing perimeter security defense solutions to protect enterprise networks from external threats, unauthorized access, and DDoS attacks, in on premises and Cloud environments
- Demonstrated Expertise (DE) designing enterprise networks requiring security using secure routing protocols (RIPv2 and OSPF), encryption protocols (IPSec and SSL or TSL), and robust firewalls and access control implementation
- Demonstrated Expertise (DE) performing manual and penetration testing, using Nmap, Dirbuster, and Metasploit to secure enterprise network from unauthorized access
- Demonstrated Expertise (DE) performing automated penetration testing using Nessus, Qualys, and Burpsuite to identify vulnerabilities, analyze traffic, and validate security controls
- Demonstrated Expertise (DE) maintaining security systems (Cisco ASA, Juniper SRX, or Check Point Firewalls), intrusion detection and prevention systems, force point proxy servers, and log management tools (Spunk, Qradar, and Sevone) to monitor and troubleshoot network traffic
- Demonstrated Expertise (DE) engaging in incident handling -- threat discovery, triage, containment, recovery, and remediation plan coordination -- using Splunk, Wireshark, Crowdstrike, Sentinelone, and Servicenow to ensure rapid response and resolution
- Valid driver's license (implied by onsite working model requirement)
- No criminal history (implied by Fidelity's hiring restrictions under Securities Exchange Act of 1934, Investment Advisers Act of 1940, Investment Company Act of 1940, ERISA, state laws, and FINRA rules)
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.