Senior Security Engineer

Tel Aviv, Israel

We are Sisense.

Sisense is the unified, collaborative data platform for professional data teams. We help thousands of data teams tackle increasingly complex data challenges, from ETL through to predictive analytics.

Our expectations for ourselves are ever increasing, and we're looking for someone to help us along that journey. If you love creating delightful user experiences for technical and non-technical users and delivering company-changing outcomes, this role is for you!

You will develop, design and implement security capabilities for the enterprise and shape the future of the technology environment in partnership with the IT team. While this role will primarily focus on IT Security (Configurations, SaaS security tooling and overall automation), there will be plenty of opportunity to expand into other areas of Security Operations (Vulnerability Management, Bug Bounty and Incident Response) and Security Governance (Policies, Compliance and Training)

WHY YOU SHOULD JOIN OUR INFORMATION SECURITY TEAM:

Customers trust us with their most important data. They use Sisense to query everything from revenue metrics to the personally identifiable information of their users. 

You will partner with IT to truly empower the employees at Sisense.  You'll be expected to design and deploy solutions that are both highly secure and highly functional while moving at the speed of the business. Enabling everyone at Sisense to keep moving fast while continuously increasing the strength of our security may be your greatest challenge.  While some capabilities are already in place that will need to be learned and maintained, there will be a great need to deploy new emerging security solutions to proactively and reactively protect our employees and customers. 

HOW YOU'LL RAMP

Within your first 30 days you'll…

  • Partner with the security team to understand the organizational mission, attack surface and helping define the appropriate risk-based security initiatives
  • Spend time with the IT and R&D customers to get up-to-speed on our technology stacks and current security controls 
  • Become educated on the endpoint management strategy for Windows and Mac
  • Assist with hardening practices for existing and emerging products
  • Support remediation of findings from vulnerability scanning efforts

By Day 30, you'll...

  • Have a solid fundamental understanding of our products, people, processes and technologies
  • Provide recommendations for identified opportunities from the current state processes
  • Work with key stakeholders to ensure compliance of Sisense's internal procedures and compliance goals (SOC2, HIPAA, ISO, GDPR, CCPA)
  • Identify the appropriate container security solution to better protect customers
  • Build strategy for deploying a Cloud Access Security Broker

By Day 60, you'll…

  • Drive security improvements for the enterprise VPN solution
  • Taken lead for endpoint protection and developing formal guidance for IT on how to better protect our employees
  • Evangelize better IT security practices throughout the company
  • Support and perform target risk assessments and audits to ensure process consistency
  • Support migration of previous acquired organizational IT tools and capabilities 

By Day 90, you'll...

  • Enhance enterprise collaboration tools to ensure appropriate security controls
  • Support External Penetration Testing efforts and assist with driving issues to closure 
  • Promote a security-first culture and ensure that all employees at Sisense are able to protect the organization from threats

WHAT YOU HAVE AND ACCOMPLISHED SO FAR:

  • Experience working as an IT Engineer or Security Engineer
  • Security mindset as a business enabler as part of the core security foundation of driving change with an effective communication style 
  • Hands-on experience in configuring and hardening cloud-based infrastructure (AWS, Google Cloud, Azure, etc.)
  • Ability to dissect new systems, product requirements, features to identify and develop security requirements
  • Basic understanding of security processes (Identify and Access Management, access management, incident management, data security, etc.)
  • Security certifications such as OSCP, CISSP, CEH, GWAPT, etc.

 

I'm In!