
Cloud Security Engineer
Enviva
公司概况
Enviva
美国马里兰州
2014年
商业模式
可再生能源
Enviva专注于生产和供应木质颗粒燃料,主要用于替代化石燃料,推动可持续能源的使用。他们的产品广泛应用于发电厂和工业设施,帮助客户减少碳足迹。
Enviva的收入主要来自于木质颗粒的销售,此外还包括与客户的长期供应合同。这些合同确保了稳定的收入流,并支持公司的可持续发展目标。
地点与地理
Enviva在美国多个州设有生产设施,主要集中在东南部地区。他们的产品不仅供应国内市场,还出口到欧洲和其他地区,支持全球可再生能源的转型。
公司文化
Enviva的使命是通过可再生能源的使用来推动全球的可持续发展。他们重视环境保护、社会责任和经济可行性,致力于为客户提供高质量的可再生能源解决方案。
Enviva提供一个包容和支持的工作环境,鼓励员工的创新和团队合作。他们相信多样性和包容性是推动公司成功的关键因素。
Enviva重视员工的职业发展,提供多种培训和发展机会,帮助员工提升技能和职业生涯。他们的目标是培养未来的领导者,推动公司和员工的共同成长。
活动与项目
Enviva正在进行多个项目,以扩大其生产能力和市场份额。他们最近在美国南部开设了新的生产设施,以满足日益增长的市场需求。
Enviva致力于技术创新,以提高木质颗粒的生产效率和可持续性。他们正在探索新的生产工艺和材料,以减少环境影响。
Enviva在其运营中实施严格的可持续实践,包括负责任的原材料采购和减少温室气体排放。他们的目标是实现碳中和,推动可再生能源的广泛应用。
职业机会
Enviva通常招聘工程师、生产操作员、环境健康与安全专家等职位。他们寻找具有创新精神和团队合作能力的人才,以支持公司的可持续发展目标。
Enviva为员工提供竞争力的薪酬和福利,包括健康保险、退休计划和职业发展支持。他们重视员工的工作与生活平衡,提供灵活的工作安排。
联系信息
最后更新于 2025-03-27 | 报告问题
Job Description
The Enviva team is driven by our shared vision for a renewable energy future. We are a fast-growing, purpose-driven, global energy company specializing in delivering sustainable wood bioenergy solutions. We are the world’s largest producer of sustainable wood pellets, which provide a low-carbon alternative to fossil fuels.
The Cyber Security Engineer reports to the Director of IT Infrastructure and Security and is responsible for leading security projects across the enterprise. This newly created position will be part of a high performing team and assist the Cyber Security Manager in driving the Enviva Cyber Security program, strategy, and road map to protect Enviva’s assets from security threats.
A successful candidate will be a resourceful self-starter capable of owning security solutions and platforms end-to-end and will work closely with the Director of IT Infrastructure and Security, the Infrastructure team, and Technology Solution Center resources to advance security initiatives and support corporate objectives.
Responsibilities
- Advance the Cyber Security road map and identify and lead security posture improvements
- Maintain and optimize security software and tools
- Evaluate capabilities and effectiveness of control environment and its individual controls and platforms and recommend required enhancements to the Cyber Security Manager
- Liaise with the Managed Detection and Response (MDR) services provider and ensure quality delivery through reporting and governance
- Investigate potential and confirmed security incidents, lead response efforts, lessons learned, and implementation of resulting proposed improvements
- Work with members of IT, application and system owners, and the business where required to remediate systems and applications with detected vulnerabilities.
- Work closely with peers in the Infrastructure team, the Infrastructure Architect, Application Development, to create and maintain a secure environment
- Consult with lines of business to guide best practices and offer solutions when the need arises
- Lead the threat and vulnerability management function leveraging vulnerability management tools and processes
Qualifications
- A Bachelor’s degree in Information Technology, Information Systems, Engineering, or a related field. Any combination of advanced course enrollment, certification and years of relevant work experience can be substituted
- 10+ years of experience in IT
- 4 years of IT security experience designing or building security solutions and supporting security incident response.
- Industry certifications, or demonstrated extracurricular participation in one or multiple security domains are required
- A diverse technical skill set with the desire to stay “up to speed” with the changing threat landscape, trends, and security solutions on the market
- Proficiency and experience in the below technical areas:
- Endpoint: OS hardening, endpoint management, endpoint protection/Anti-virus, disk encryption, USB protection
- Network: UTM, TCP/IP, SSL/TLS, proxy, content filtering
- Data: security implications of data-in-transit, at-rest, and in-use, DLP, DAG
- Identity: SSO, MFA, authentication and authorization logic
- Additional concepts: least privilege/least access, attack surface reduction, good knowledge of a wide range of applications, services, and protocols
- Demonstrated knowledge of tactics, techniques, and procedures (TTP’s) commonly used by threat actors and indicators of compromise (IoC’s)
- Awareness of cyber attack models- MITRE Att&ck, Cyber Kill Chain and how these translate to defense planning
- Ability to quickly assess risk impact from environment changes like implementation of new solutions or software, network design change or integration, and modification of system features
- Motivation and drive to “hunt” for threats or seek out optimization opportunities to improve effectiveness of controls
- Ability to maintain a people, process, technology view through design, build, and run phases of service and capability delivery
- Ability to handle multiple tasks, prioritize and meet deadlines
- Familiarity with regulatory and legal obligations:
- SOX
- ITGC
- Understanding of IT Security frameworks:
- NIST CSF
- CIS CSC
- Excellent written and verbal communication skills
- Able to lead or participate in Cyber Security incident response and investigations.
Preferred Qualifications - What Will Set You Apart
- Desired Certifications (or equivalent demonstrable experience):
- One of the below:
- Microsoft Certified Cyber Security Architect Expert
- Microsoft Certified Azure Security Engineer
- CompTIA Security+
- Plus SANS certification demonstrating specialized knowledge within a security domain
- Knowledge of PowerShell or other scripting languages
- One of the below:
Travel requirements
- Up to 10% domestic travel to Enviva facilities. Occasional international travel may be required depending on future business needs.
Working Conditions
- Normal office hours – however, could be longer hours when business requires. This position will assume a shared responsibility of ensuring applications are available 24x7x365.
- Willing and able to maintain strict adherence to safety rules and regulations, to include wearing safety equipment.
Physical Requirements
- Ability to safely and successfully perform the essential job functions consistent with the ADA and other federal, state and local standards, including meeting qualitative and/or quantitative productivity standards.
*This position does not offer visa sponsorship or support for work authorization
EEO Statement
Enviva is dedicated to the principles of equal employment opportunity (EEO) in any term, condition or privilege of employment. Enviva does not discriminate against applicants or employees on the basis of race, color, creed, religion, sex, national origin, age, physical or mental disability, ancestry, marital status, sexual orientation, gender identity or expression, veteran status, uniform service member, genetic information or any other status protected by law. Enviva complies with applicable state and local laws governing nondiscrimination in employment in every location in which we operate.
获取工作提醒
获取罗利,美国地区职位机会的工作提醒
关于这个角色
2025年8月11日
全职
公司
2025年8月11日
现场
- 罗利,美国
10+ years in IT, 4 years in IT security
UTC-05:00
靠近 罗利,美国 的类似工作
与朋友分享
形势严峻,谈话的时机已过。现在是采取行动的时候。 帮助朋友加快向可持续未来的转变。
分享这份工作 - Cloud Security Engineer - 给你的朋友们,帮助他们找到一份值得自豪的职业。