Garmin
Website:
garmin.com
Job details:
POSITION SUMMARY:
The Cyber Security Engineer is responsible for leading and executing advanced offensive security assessments, penetration testing, and red team operations to identify and mitigate critical security vulnerabilities and weaknesses in complex computer systems, networks, applications, and infrastructure. This role requires expert-level knowledge of security principles, advanced hacking techniques, and cutting-edge security tools and methodologies.
ESSENTIAL FUNCTIONS:
- Serve as a trusted advisor to other cybersecurity teams and to Garmin business segments on multiple domains in cybersecurity.
- Collaborate across a team of highly skilled security professionals, promoting knowledge transfer, skill development, and a culture of continuous learning and improvement.
- Identify opportunities to enhance tool integrations and workflows through automation and scripting, leveraging APIs provided by security tools.
- Contribute to project and program planning by estimating and coordinating assigned work, and maintain accurate, timely status updates on overall progress.
- Design and develop complex, integrated solutions to meet business requirements and enhance the performance of Garmin’s security systems.
- Contribute to the team roadmap and priorities.
- Participate in the evaluation and adoption of emerging security technologies to improve threat detection, prevention, and response.
- Conduct ethical hacking and penetration testing activities, including red team operations, to identify and exploit critical security vulnerabilities and weaknesses.
- Design and implement complex attack scenarios, leveraging advanced techniques such as exploit development, reverse engineering, and advanced persistent threats (APTs).
- Utilize and develop custom security testing tools, scripts, and automation frameworks to enhance the effectiveness and efficiency of security assessments.
- Perform in-depth security assessments, including advanced network and application security testing, wireless security testing, mobile security testing, and cloud security testing.
- Analyze and document findings from security assessments, providing detailed reports and actionable recommendations for remediation and risk mitigation.
- Collaborate with security teams, developers, and stakeholders to communicate critical security risks and advocate for secure coding practices and robust security controls.
- Stay up-to-date with the latest security trends, vulnerabilities, attack vectors, and emerging threats to ensure the effectiveness of security testing methodologies.
- Participate in security research and knowledge-sharing activities to contribute to the advancement of offensive security practices.
- Ensure compliance with ethical hacking guidelines, legal requirements, and industry best practices during security assessments.
OTHER RESPONSIBILITIES:
- Demonstrate understanding of Garmin's business model, including Engineering, Operations, Finance, Sales, and Marketing
- Participate in team discussions and meetings.
- Demonstrate professional maturity through giving and receiving constructive feedback.
- Collaborate effectively and resolve conflicts.
- Coordinate changes across business segments, IT, and Cyber teams, minimizing service disruption.
- Perform other duties as necessary.
Certifications (Preferred):
- Must-have: OSCP
- Nice-to-have: CEH, OSEP, OSWE, CRTP, PNPT, eWPTX, Red Team-focused certifications
EDUCATION EXPERIENCE AND SKILLS REQUIRED:
- Bachelor of Science Degree in Computer Science, Information Technology, Management Information Systems, Cybersecurity or another relevant field AND a minimum of 2 years relevant experience OR equivalent combination of education and relevant experience.
- Communicate effectively with team members and stakeholders through strong verbal, written, and interpersonal skills.
- Contribute positively to a collaborative, team-focused environment.
- Proactively solves moderately complex problems with a strong, solutions-oriented mindset and a track record of delivering effective resolutions.
- Manages time, priorities, and follow-up tasks independently.
- Consistently delivers well-organized, high-quality documentation aligned with team expectations.
- Understands core information technology services such as networking, storage, databases, and web-based services.
- Hands-on experience in offensive security, penetration testing, and ethical hacking.
- Expert-level knowledge of security principles, advanced hacking techniques, security tools and methodologies.
- Programming and scripting skills, with the ability to develop custom security tools and automation frameworks.
- In-depth understanding of network protocols, operating systems, application architectures, and security controls.
- Experience using advanced security testing tools and frameworks (e.g., Metasploit, Cobalt Strike, Burp Suite).
- Strong analytical and problem-solving skills with the ability to think like an advanced attacker.
- Ability to work independently and lead security assessments and red team operations.
Click on Apply to know more.