Sony Corporation of America, located in New York, NY, is the U.S. headquarters of Sony Group Corporation, based in Tokyo, Japan. Sony's principal U.S. businesses include Sony Electronics Inc., Sony Interactive Entertainment LLC, Sony Music Entertainment, Sony Music Publishing and Sony Pictures Entertainment Inc. With some 900 million Sony devices in hands and homes worldwide today, a vast array of Sony movies, television shows and music, and the PlayStation Network, Sony creates and delivers more entertainment experiences to more people than anyone else on earth. To learn more: www.sony.com/en. POSITION SUMMARY Sony Corporation of America (SCA), is seeking a Principal Engineer, Vulnerability Management to join the Corporate Information Security Division in Reston, VA. This position will report to the Senior Manager, Vulnerability Management, and be a part of the team responsible for establishing a unified approach to vulnerability reporting to secure Sony's information assets, services, and the products that depend on them, building trust with customers and stakeholders, and protecting the privacy of Sony's customers and employees. JOB RESPONSIBILITIES
Leads the resolution of security challenges, drawing upon the expertise of relevant security subject matter experts for strategic technical guidance and engaging with internal stakeholders, as needed. Advise/Aids in defining and establishing the best practices for vulnerability assessment processes and solutions within the security teams. Propose and/or build solutions/capabilities within the scope of Vulnerability Management to further improve the Vulnerability Management Program (e.g., automation, data analysis, process development) Lead key projects such as vulnerability prioritization to remediate critical key vulnerabilities (and help with reporting via GISO Monthly Sync). Automate existing manual processes to create improved processes and faster delivery across ITD teams. Partner with application and infrastructure owners to provide consulting on vulnerability remediation to allow them to appropriately remediate large highly complex vulnerabilities within the SLA (service level agreement) and reduce risk. Perform vulnerability assessments and common baseline control scans across the environment and report on Key Risks Indicators (KRIs). Create presentations based off KRI materials and keep Management informed of them. Contributes highly innovative ideas and may lead large cross-functional teams, exercising independent judgment to solve unique and complex problems impacting the business. Implement new, and iterate on existing technology, to help identify and mitigate security issues. Maintain awareness of the latest emerging threats and exploitation vectors and provide awareness to internal teams, leadership, and Sony Group company stakeholders on changes to the cyber threat landscape. Support projects to improve data collection, interpretation processes and initiatives regarding threat intelligence and information security. Prepare detailed analysis reports, products, cyber threat assessments, and briefings of security incidents and related intelligence for GSIRT and its stakeholders. Honesty, trustworthiness and ethical conduct are material requirements for the responsibilities outlined above
QUALIFICATIONS FOR POSITION
Your qualifications and experience should include:
Minimum of seven (7) years of experience in information security Bachelor's degree in an appropriate field, such as information technology or management, or equivalent experience Expert-level knowledge of information security vulnerability concepts Experience using threat intelligence tools and management platforms to identify, analyze and track cyber threats. Extensive knowledge of how vulnerabilities work and associated remediation techniques Deep understanding of network defense principles, common attack vectors, and attacker techniques Exceptional communication and advocacy skills, both verbal and written, with the ability to express complex and technical issues in clear and concise language Experience with scripting and automating processes Knowledge of the MITRE ATT&CK Framework, Cyber Kill Chain, Diamond Model of Intrusion Analysis, or other relevant network defense and intelligence frameworks preferred. Ability to exercise prudent judgment and discretion Ability to negotiate compromise between diverse parties with competing equities Ability to work independently in unstructured situations Ability to manage multiple projects simultaneously that involve key stakeholders across a globally-distributed and federated enterprise Ability to travel internationally as required, up to 15% All candidates must be authorized to work in the USA
In addition to competitive pay and benefits, we offer an environment and culture that promotes Diversity, Equity, and Inclusion. We are committed to creating an inclusive employee experience for you to thrive as part of Sony's purpose to "fill the world with emotion through the power of creativity and technology".
SCA offers benefits-eligible employees (generally regular employees scheduled to work 20 or more hours a week) a comprehensive benefits program that offers coverage and support for employees and their family's physical, emotional, and financial well-being.
Comprehensive medical, prescription drug, dental, and vision coverage with coverage for spouses/domestic partners and child dependents, including access to a Health Savings Account (HSA) and Flexible Spending Account (FSA) Employee assistance plan and comprehensive behavioral health benefits Fertility benefits, including surrogacy, and adoption assistance programs Basic and supplemental life insurance for employees as well as supplemental life insurance coverage for their spouses/domestic partners and children Voluntary benefits such as group legal, identity theft protection, accident, and hospital indemnity insurance Short-term & long-term disability plans Paid parental and caregiver leave 401(k) Plan with pre-tax, Roth, and after-tax options and company match with immediate vesting Education assistance and student loan programs
Flexible Work Arrangements, including remote and hybrid work schedules Time off to include vacation, paid holidays, sick leave, Summer Fridays (early release), and a winter break between Christmas and New Year's Day (based on business needs) Referral bonuses (subject to eligibility) Matching gift program A wide variety of employee business resource groups (EBRGs) Special discounts on Sony products, offered exclusively to Sony employees Employee stock purchase plan (Sony covers commissions and fees for your Sony stock purchases made through after-tax payroll deductions) Annual incentive bonus
The anticipated annual base salary for this position is $185,000 to $205,000. In addition to the annual base salary, this role has an annual bonus target of 17%. This range does not include any other compensation components or other benefits that an individual may be eligible for. The actual base salary offered depends on a variety of factors, which may include as applicable, the qualifications of the individual applicant for the position, years of relevant experience, specific and unique skills, level of education attained, certifications or other professional licenses held, and the location in which the applicant lives and/or from which they will be performing the job. #LI-SC1 Sony is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religious creed, sex (including pregnancy), gender, national origin, citizenship, ancestry, age, physical or mental disability, military status, status as a veteran or disabled veteran, sexual orientation, gender identity or expression, marital or family status, genetic information, medical condition, or any other basis protected by applicable federal, state, or local law, ordinance, or regulation. Disability Accommodation for Applicants to Sony Corporation of America Sony Corporation of America provides reasonable accommodation for qualified individuals with disabilities and disabled veterans in job application procedures. For reasonable accommodation requests, please contact us by email at careers@sonyusa.com or by mail to: Sony Corporation of America, Human Resources Department, 25 Madison Avenue, New York, NY 10010. Please indicate the position you are applying for.
EEO is the Law EEO is the Law Supplement Right to Work (English/Spanish) E-Verify Participation (English/Spanish)
While SCA does not require employees to be vaccinated against COVID-19, there are certain Sony offices that require employees to be vaccinated in order to enter. If you will be located at or travel to those offices, you will be required to be fully vaccinated to enter. The Company will consider requests for reasonable accommodations for documented medical reasons and for sincerely held religious beliefs in accordance with applicable law. Please do not include proof of vaccination status or any indication of a possible request for a vaccination accommodation when submitting your application materials. If applicable, the Company will follow up with you directly to request proof of vaccination and to discuss any potential accommodations.
|