FabFitFun
Hybrid

Principal Information Security Engineer

Sorry, this job was removed at 4:11 a.m. (PST) on Tuesday, April 27, 2021
Find out who's hiring in Greater LA Area.
See all Cybersecurity + IT jobs in Greater LA Area
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

Principal Information Security Engineer

FabFitFun is one of the best places to work in Los Angeles and its amazing success has been achieved due to our amazing business initiatives (over 2 million members), dedicated leadership, inclusive corporate culture, and career growth opportunities.  Guided by our company values, FFF seeks to maintain a work culture that encourages innovation, rewards creativity, values teamwork, and supports inclusion and equity.  The company endeavors to foster confidence, effectiveness, and success for all employees who work with these values every day.

We are looking for a Principal-level Security Engineer to join our Security Engineering team. The ideal candidate will participate and lead efforts to create new security designs based on current business needs, capacity increases, and customer growth. You will play a pivotal role improving security across all aspects of the FabFitFun infrastructure.

What You’ll Do:

  • Manage security incidents as Incident Commander: determining direction of investigations, incident exit criteria, and update cadence.
  • Conduct host/network, forensics & log analysis in support of incident response investigations
  • Identify attacker tools, tactics, and procedures (TTPs) to develop indicators of compromise
  • Hunt FabFitFun networks for indicators of compromise, looking for evidence of a compromise
  • Preserve and analyze data from a diverse set of data sources, including attack patterns and bad actors identified by FabFitFun's CX team
  • Work with cross functional teams to contain and remediate security incidents related to breach and compromise.
  • Provide feedback across engineering, product and IT teams about accuracy and quality of security detections, controls and remediations
  • Identify areas of opportunity, and drive improvements to the incident response process and technology directly impacting the team
  • Work with partner teams including: PR, HR, Legal, Compliance, Investigations, Engineering, and external partners including AWS, Google and other strategic technology providers to further FabFitFun’s information security maturity
  • Support mentoring and technical development for engineering, product and IT teams
  • Identify areas of opportunity, and drive improvements to information security processes and technologies
  • Be a voice of security within FabFitFun, championing best practices and promoting a “secure business” environment

What You’ll Bring:

  • 4+ years experience with incident management, cross team coordination, and management update cadences for multi-day incidents.
  • 3+ years of experience with common actor attack vectors and tracing IOC/IOA through SIEMs, EDR, raw logs, and other telemetry.
  • Previous experience with actor tactics, techniques and procedures (TTP), and following lateral movement (i.e. Mitre ATT&CK framework).
  • Previous experience with one or more of these environments: cloud, physical, production, e-commerce and business environments.
  • Previous experience with understanding the impact chain for security decisions and remediation impact downstream
  • Ability to apply NIST CSF, PCI DSS, SOX and other relevant standards to inform and execute information security functions
  • Ability to monitor and secure AWS / public cloud infrastructure environments
  • Ability to monitor and secure SaaS platforms
  • Ability to participate in occasional on-call activities during cybersecurity incident investigations.
  • Ability to develop scripts and/or automation tools in programming languages such as Java or Python a plus
  • Ability to develop scripts to ingest log data from IaaS/PaaS/SaaS platforms into log aggregators / SIEMs such as AWS GuardDuty, Amazon Detective, or Splunk/SumoLogic/Chronicle a plus
  • BA/BS degree in Information Security, CyberSecurity, Computer Science, or other related technical disciplines, or equivalent practical experience
  • Must be able to travel domestically (USA) and Internationally (UKI, SE Asia) up to 15% of the time once global travel resumes (maybe 2x/year)

What You'll Get:

  • Amazing benefits including medical, dental, vision, FSA
  • Matching 401k and equity incentives
  • The​​ opportunity​ ​to​ ​work​ ​in​ ​a​ ​collaborative environment​ ​full​ ​of​​ bright, driven, and happy​ ​people​
  • Be a part of one of the fastest growing companies in the US that is revolutionizing eCommerce
  • Open/Flexible PTO policy - we trust our employees to manage their time!
  • Free FabFitFun subscription and quarterly credit in the Add-Ons store
  • Monthly cell phone reimbursement
  • Monthly work from home stipend while the company is temporarily remote
See More
Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.

What are FabFitFun Perks + Benefits

FabFitFun Benefits Overview

Amazing benefits including medical, dental, vision (+ Pet insurance!)
401K & Matching
Open/Flexible PTO policy - we trust our employees to manage their time
Donation matching program
Free FabFitFun subscription and quarterly credit in our e-commerce Add-Ons store
Monthly cell phone stipend

Culture
Volunteer in local community
Partners with nonprofits
Each of our seasonal boxes partners with a charity/nonprofit organization.
Open door policy
OKR operational model
Team based strategic planning
Open office floor plan
Flexible work schedule
Diversity
Highly diverse management team
Mandated unconscious bias training
Hiring practices that promote diversity
Health Insurance & Wellness Benefits
Flexible Spending Account (FSA)
Disability insurance
Dental insurance
Vision insurance
Health insurance
Life insurance
Pet insurance
Covered through Nationwide - 90%
Mental health benefits
Financial & Retirement
401(K)
401(K) matching
Company equity
Charitable contribution matching
Partner with BrightFunds to allow the company to match up to $500 per employee annually for approved donations and organizations
Child Care & Parental Leave Benefits
Generous parental leave
Family medical leave
Return-to-work program post parental leave
Vacation & Time Off Benefits
Unlimited vacation policy
Generous PTO
Paid holidays
Paid sick days
Office Perks
Commuter benefits
Company-sponsored outings
Free snacks and drinks
Stocked kitchen with amazing snacks that suit both looking for something healthy or a sweet treat in the afternoon. Kombucha & cold brew also on tap!
Some meals provided
Catered lunch weekly on Tuesday! Supplemental Catered meals also available throughout the month
Company-sponsored happy hours
Onsite office parking
Paid parking available for all of our employees
Pet friendly
Dog friendly office and right across the street from the West Hollywood dog park! You will find bowls and treats throughout the office.
Relocation assistance
Fitness stipend
You will have access to our online digital streaming platform (FabFitFun TV) that hosts a library of online fitness classes from top studies. Also hosted fitness classes every quarter in nearby gyms.
Home-office stipend for remote employees
Professional Development Benefits
Job training & conferences
Lunch and learns
Promote from within
Online course subscriptions available

Additional Perks + Benefits

Generous compensation package and extensive benefits. 12 weeks’ paid parental leave. Free FabFitFun subscription and tons of beauty freebies! Daily impact on personalizing the FabFitFun member experience.

More Jobs at FabFitFun

Easy Apply
By clicking Apply Now you agree to share your profile information with the hiring company.
Learn more about FabFitFunFind similar jobs like this