Earnbetter

Job Search Assistant

STAFF ENGINEER, SECURITY OPERATIONS

ACV Auctions • New York, NY 10001 • Posted today

Boost your interview chances in seconds

Tailored resume, cover letter, and cheat sheet

In-person • Full-time • $135,000-$204,000/yr • Senior Level

Job Highlights

Using AI ⚡ to summarize the original job post

The Staff Engineer, Security Operations at ACV Auctions is responsible for overseeing and maintaining the security infrastructure and operations of the organization. This role involves designing, implementing, and managing security systems, monitoring and analyzing security events, responding to security breaches, and collaborating with cross-functional teams to develop and enforce security policies and procedures. The position requires a deep understanding of security technologies and trends, as well as the ability to stay updated on the latest developments in the field.

Responsibilities

  • Actively and consistently support all efforts to simplify and enhance the customer experience.
  • Lead business use case analysis to implement identity and access management solutions.
  • Identify required attributes, customizing login pages and implement security policies.
  • Follow SDLC, change management and document the procedures on Trusted Identity solutions to meet compliance requirements.
  • Anticipate, identify, track and resolve technical issues.
  • Develop and implement repeatable processes for Access Management.
  • Lead the Trusted Identity team in implementing scalable access management and identity lifecycle processes.
  • Work closely with business, application, and solution owners to ensure user and role definitions and associated access rights are appropriately defined.
  • Lead role-based access control (RBAC) model and maintain role-based access control documentation for operational processes.
  • Create and implement automated processes that reduce manual efforts and increase overall efficiency and scalability.
  • Manage Security Alerts and provide Incident Response support services.
  • Develop and implement process improvement and operational management of Security Operations, Monitoring and Incident Response practices, processes and solutions.
  • Manage and maintain other security SaaS applications such as anti-phishing, EDR, or logging tools as required.
  • Lead employee trainings, such as creating webinars, create “how-to” tech articles, etc.
  • Perform other duties as assigned.

Qualifications

Required

  • Ability to read, write, speak and understand English.
  • Extensive and demonstrated experience in end-to-end deployment of identity and access management tools.
  • Knowledge of Security Domains, Compliance Requirements, and Risk Management Practices.
  • Knowledge of Identity concepts such as Privileged Account Management and Life Cycle Management.
  • Knowledge of AWS including but not limited to S3, Lambda, RDS, EC2 and AWS Security Center.
  • Knowledge of TCP/IP Networking including knowledge of Protocols and Services.
  • Overall understanding of the Security domain, compliance, business, risk, ops etc ALONG with its application to the business.
  • General understanding DevOps practices.
  • Understanding of building and making tools for our partners, how do we make something into a service?
  • Ability to read python code and writing basic scripts, or using Low Code / No Code SOAR tools.
  • Ability to build and implement security tools such as anti-phishing, EDR, or EMM/MDM tools.
  • Excellent communication, interpersonal and leadership skills, with the ability to interact with staff at all levels.
  • Proven ability to be agile and work effectively in a dynamic environment.
  • Demonstrated ability to perform under pressure and respond rapidly to emerging incidents and situations.
  • Excellent coordination, project management, and organization skills and comfortable with multi-tasking in a high-energy environment.

Full Job Description

If you are looking for a career at a dynamic company with a people-first mindset and a deep culture of growth and autonomy, ACV is the right place for you! Competitive compensation packages and learning and development opportunities, ACV has what you need to advance to the next level in your career. We will continue to raise the bar every day by investing in our people and technology to help our customers succeed. We hire people who share our passion, bring innovative ideas to the table, and enjoy a collaborative atmosphere. Who we are: ACV is a technology company that has revolutionized how dealers buy and sell cars online. We are transforming the automotive industry. ACV Auctions Inc. (ACV), has applied innovation and user-designed, data driven applications and solutions. We are building the most trusted and efficient digital marketplace with datasolutions for sourcing, selling and managing used vehicles with transparency and comprehensive insights that were once unimaginable. We are disruptors of the industry and we wantyou to join us on our journey. ACV’s network of brands includes ACV Auctions, ACV Transportation, ClearCar, MAX Digital and ACV Capital within its Marketplace Products, as well as, True360 and Data Services. At ACV we focus on the Health, Physical, Financial, Social and Emotional Wellness of our Teammates and to support this we offer: Multiple medical plans including a high deductible health plan that costs $0 out of your paycheck Company-sponsored (paid) Short-Term Disability, Long-Term Disability, and Life Insurance Comprehensive optional benefits such as Dental, Vision, Supplemental Life/AD&D, Legal/ID Protection, and Accident and Critical Illness Insurance Generous paid time off options, including vacation time, sick days, Company holidays, floating holidays, parental leave, bereavement leave, jury duty leave, voting leave, and other forms of paid leave as required by applicable law or regulation Employee Stock Purchase Program with additional opportunities to earn stock in the Company Retirement planning through the Company’s 401(k)Who we are looking for:The Staff Engineer, Security Operations is responsible for overseeing and maintaining the security infrastructure and operations of an organization. They design, implement, and manage security systems, including firewalls, intrusion detection systems, and access control systems. They monitor and analyze security events and incidents, respond to security breaches, and conduct vulnerability assessments and penetration testing. The Staff Engineer collaborates with cross-functional teams to develop and enforce security policies and procedures and provides guidance and support to junior engineers. They stay updated on the latest security technologies and trends to ensure the organization's security posture remains strong.What you will do:Actively and consistently support all efforts to simplify and enhance the customer experience.Lead business use case analysis to implement identity and access management solutionsIdentify required attributes, customizing login pages and implement security policiesFollow SDLC, change management and document the procedures on Trusted Identity solutions to meet compliance requirementsAnticipate, identify, track and resolve technical issuesDevelop and implement repeatable processes for Access ManagementLead the Trusted Identity team in implementing scalable access management and identity lifecycle processesWork closely with business, application, and solution owners to ensure user and role definitions and associated access rights are appropriatelyLead role-based access control (RBAC) model and maintain role-based access control documentation for operational processesCreate and implement automated processes that reduce manual efforts and increase overall efficiency and scalabilityManage Security Alerts and provide Incident Response support services, it's not expected someone knows everything but this person should be able to identify and perform triage to resolve a Security IncidentDevelop and implement process improvement and operational management of Security Operations, Monitoring and Incident Response practices, processes and solutionsManage and maintain other security SaaS applications such as anti-phishing, EDR, or logging tools as requireLead employee trainings, such as creating webinars, create “how-to” tech articles, etcPerform other duties as assignedWhat you will need:Ability to read, write, speak and understand English.Extensive and demonstrated experience in end-to-end deployment of identity and access management toolsKnowledge of Security Domains, Compliance Requirements, and Risk Management PracticesKnowledge of Identity concepts such as Privileged Account Management and Life Cycle ManagementKnowledge of AWS including but not limited to S3, Lambda, RDS, EC2 and AWS Security CenterKnowledge of TCP/IP Networking including knowledge of Protocols and ServicesOverall understanding of the Security domain, compliance, business, risk, ops etc ALONG with its application to the businessGeneral understanding DevOps practicesUnderstanding of building and making tools for our partners, how do we make something into a service? Ability to read python code and writing basic scripts, or using Low Code / No Code SOAR toolsAbility to build and implement security tools such as anti-phishing, EDR, or EMM/MDM toolsExcellent communication, interpersonal and leadership skills, with the ability to interact with staff at all levels.Proven ability to be agile and work effectively in a dynamic environment.Demonstrated ability to perform under pressure and respond rapidly to emerging incidents and situations.Excellent coordination, project management, and organization skills and comfortable with multi-tasking in a high-energy environment.Compensation: $135,000.00 - $204,000.00 annually. Please note that final compensation will be determined based upon the applicant's relevant experience, skillset, location, business needs, market demands, and other factors as permitted by law.No immigration or work visa sponsorship will be provided for this position.Our Values Trust & Transparency | People First | Positive Experiences | Calm Persistence | Never Settling At ACV, we are committed to an inclusive culture in which every individual is welcomed and empowered to celebrate their true selves. We achieve this by fostering a work environment of acceptance and understanding that is free from discrimination. ACV is committed to being an equal opportunity employer regardless of sex, race, creed, color, religion, marital status, national origin, age, pregnancy, sexual orientation, gender, gender identity, gender expression, genetic information, disability, military status, status as a veteran, or any other protected characteristic. We also consider qualified applicants regardless of criminal histories, consistent with legal requirements. If you have a disability or special need that requires reasonable accommodation, please let us know.For information on our collection and use of your personal information, please see our Privacy Notice.