Sr Manager, Penetration Testing & Research

Thermo Fisher Scientific Morrisville, NC

Company

Thermo Fisher Scientific

Location

Morrisville, NC

Type

Full Time

Job Description

Work Schedule
Standard (Mon-Fri)

Environmental Conditions
Office

Job Description

At Thermo Fisher Scientific, you'll join a curious team that shares your passion for exploration and discovery. We invest heavily in R&D and offer ample resources for you to make meaningful contributions to the world!

Location/Division Specific Information:

This position reports into the Senior Director, Product Security within Corporate Infrastructure & Security (CIS) and is based in Frederick, Maryland or Raleigh, North Carolina.

How will you make an impact?

Lead a distributed team focused on identifying and improving the security of our various products and internal systems. Make a meaningful difference for our customers, patients, and partners who rely on Thermo Fisher products. Join our team and make an impact!

Want more jobs like this?

Get jobs in Morrisville, NC delivered to your inbox every week.

By signing up, you agree to our Terms of Service & Privacy Policy.


Position Summary:

The Sr. Manager, Penetration Testing, is responsible for helping to secure the organization's products and assets globally. They will conduct research, testing, and validation of the products and platforms, as well as our internal environments throughout their development lifecycles. This role involves using robust solutions within the CIS program, focusing on testing, security awareness, education, vulnerability assessments, and risk evaluation. Continuous improvement is driven through our practical process improvement (PPI) methodology and will be instrumental in helping find a better way, every day.

Key Responsibilities:

  • Perform penetration testing activities and on products and/or infrastructure to resolve vulnerabilities, validate remediation, and reduce overall risk profiles.
  • Develop comprehensive mentorship for frequently encountered vulnerabilities and corresponding remediation strategies.
  • Build and improve existing methodologies for penetration testing, drawing from industry standards and mentorship provided by established agencies like CISA and the FDA.
  • Coordinate on security risk assessments for new and existing products through the pre- and post-market teams.
  • Build working partnerships with product development leaders and peers to drive secure development and integration of security features into all phases of product, firmware, software design processes and product development lifecycle.
  • Collaborate with architecture and development teams to develop shared security frameworks to enable consistent application of secure coding standard methodologies across the enterprise.
  • Educate key partners on program, risks, and importance of security in our products and environment.
  • Work with cross-functional teams to find and fix security issues in Thermo Fisher products and infrastructure. Use tools to send vulnerability information to the development team for fixing.
  • Mentor others in what constitutes secure product activities.
  • Coordinate/participate in and perform design reviews, peer reviews, and code reviews.
  • Ensure excellent consistency, documentation, and process across all programs.
  • Collaborate with other departments (e.g., Risk Management, Internal Audit, HR, Legal, etc.) to direct compliance issues to appropriate existing channels for investigation and resolution.
  • Creation of security bulletins to address new or evolving threats to the company's assets and products.
  • Travel up to 25% and on-call/after hours duties may be required.

Minimum Requirements/Qualifications:

  • Deep knowledge of IoT and digital device research methods, variables and parameters including analysis, testing and documentation.
  • Deep understanding of cryptography, authentication, authorization, network security protocols, and application security.
  • Strong exposure to application security standards including OWASP TOP 10, CSC 20, etc.
  • Familiarity with regulations and requirements surrounding medical devices and IoT such as FDA pre-market and post-market cybersecurity requirements.
  • Bachelor's Degree or equivalent experience in Information Assurance, Information Security, Management Information Systems, Risk Management, or Computer Science (Master's Degree or equivalent experience a plus) or a related field.
  • Relevant technical certificates a plus (OSCP, SANS, GIAC, etc).
  • 5+ years of related work experience with security consulting, product security, secure software development, risk assessment, and/or vulnerability management.
  • Strong interpersonal and documentation skills are a must.
  • Ability to explain and promote technical concepts.
  • Strong attention to detail and organization skills.
  • Excellent verbal and written communication skills and the ability to partner with a diverse group of executives, managers, and subject matter authorities.
  • The ideal candidate will have hands on experience in one or more of the following areas: Hardware System Integration, Signal and Power Integrity, RF Systems, Wi-Fi, Bluetooth, Wireless Communications, TCP/IP, Network and Application Penetration Testing.

Compensation and Benefits
The salary range estimated for this position based in Maryland is $143,000.00-$214,475.00.

This position may also be eligible to receive a variable annual bonus based on company, team, and/or individual performance results in accordance with company policy. We offer a comprehensive Total Rewards package that our U.S. colleagues and their families can count on, which includes:

  • A choice of national medical and dental plans, and a national vision plan, including health incentive programs
  • Employee assistance and family support programs, including commuter benefits and tuition reimbursement
  • At least 120 hours paid time off (PTO), 10 paid holidays annually, paid parental leave (3 weeks for bonding and 8 weeks for caregiver leave), accident and life insurance, and short- and long-term disability in accordance with company policy
  • Retirement and savings programs, such as our competitive 401(k) U.S. retirement savings plan
  • Employees' Stock Purchase Plan (ESPP) offers eligible colleagues the opportunity to purchase company stock at a discount

For more information on our benefits, please visit: https://jobs.thermofisher.com/global/en/total-rewards

Apply Now

Date Posted

12/19/2024

Views

0

Back to Job Listings ❤️Add To Job List Company Info View Company Reviews
Positive
Subjectivity Score: 0.8

Similar Jobs

Field Marketing Specialist (5- month Contract) - Endava

Views in the last 30 days - 0

Endava is seeking a Field Marketing Specialist with 45 years of marketing experience focusing on event planning 360 campaign management lead generatio...

View Details

Software Engineer II - The Walt Disney Company

Views in the last 30 days - 0

Disney Entertainment ESPN Technology is reimagining viewing experiences for beloved stories and transforming Disneys media business They are building...

View Details

Managing Consultant, Back of House Restaurant Technology - Point B

Views in the last 30 days - 0

Point B is a business innovation firm that specializes in transformation by combining advanced technologies and industry expertise They aim to help bu...

View Details

Managing Consultant, Front of House Restaurant Technology - Point B

Views in the last 30 days - 0

Point B is a business innovation firm that specializes in transformation by combining advanced technologies and industry expertise They aim to help bu...

View Details

Network Systems Engineer (Pre-Sales) - Arista Channels

Views in the last 30 days - 0

Arista Networks is a leading company in datadriven clienttocloud networking known for its innovation in cloud computing AI and softwaredefined network...

View Details

Lead Developer - Brightspeed

Views in the last 30 days - 0

Brightspeed is a company that aims to revolutionize internet connectivity in rural markets by upgrading copper to fiber optic technologies They are cu...

View Details