| 
Did you know? 
Costco, the second largest retailer in the US, with operations in eight countries, needs technology leaders to join our IT division. We are in the midst of explosive worldwide growth and your IT skills can make an immediate contribution. With our rapid technology change and growth, we offer great career opportunities in a family atmosphere where our employees thrive. At Costco, the quality you see in our warehouses is reflected in every area of our business and we are widely recognized for our commitment to our employees. 
 
Description of position 
The role of every Information Security team member is to support the overarching values and business goals of Costco Wholesale as they relate to meeting legal, ethical and regulatory obligations; protecting member privacy; and maintaining a security technology environment for our operations. The Information Security Engineer provides consultative services, works with vendors for product consideration and recommendation, performs monitoring and auditing of information system activities, creates and maintains documentation related to policies, standards and procedures; and, mentors team members with lesser subject matter expertise. 
 
Tasks and responsibilities 
Perform the project manager role on security-related projectsAssess and/or design centralized user and configuration management systemsPerform and/or coordinate regular security assessments of existing or new infrastructurePerform duties necessary to assist in establishing practices and system configurations to ensure the safety of information systems assets and to protect information systems from intentional or inadvertent access or destructionWork with information systems custodians (i.e., department managers, user community and systems administrators) at different levels in the organization to understand their respective security needs and assist with implementing practices and procedures consistent with Costco’s Information Security PolicyAssist with monitoring and auditing of information systems activities and systems to confirm information security policy compliance and provide management with security policy compliance assessments and system monitoring reportsDevelop and maintain centralized information systems security standards, procedures, and guidelinesWork with stakeholders to provide security solutions that support their business requirementsIdentify, develop, and implement mechanisms to detect security incidents in order to enhance compliance with and support of security standards and procedures in place.Conduct security risk assessments on new products and systems, periodic security risk assessments on existing systems and identify and/or recommend appropriate security countermeasures and best practicesRespond to discovered security incidents by informing appropriate custodians, determining root cause, and identifying and executing remedial actions (if necessary) required to re-establish respective information system securityCoordinate activities or engagements with loss prevention, interact with legal and law enforcement as required 
Required skills, abilities, and certifications 
A Bachelor’s degree in Computer Science or a minimum of 6 years of information systems security or related data processing auditing experienceOne or more professional audit or security certifications such as CISA or CISSP (or equivalent experience)Ability to work effectively, independent of assistance or supervisionInnovative, creative, and extremely responsive, with a strong sense of urgencyWilling to share knowledge and assist others in understanding technical and business topicsWillingness to work outside of regular business hours as required which can include evenings, weekends and holidaysExperience with firewalls, routers, load balancers and DMZ silosWorking knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling)Demonstrated experience of “hands on” security knowledge of one or more of the following platforms: Windows or UNIX (preferably AIX)Ability to clearly communicate Information Security matters to executives, auditors, end users, and engineers, using appropriate language, examples, and toneExperience with tools such as NMAp, NetCat and EnumExperience with DNS, NTP and Citrix, TACACS, IDS, IPS and various SIEMSWorking knowledge of protocols such as TCP, UDP, SSL, FTP, SMTP, NetBIOS and DHCPWorking knowledge of HTML, CSS, JavaScript and WMLAt least one technical certification related to a major Costco platform (IBM, Microsoft or Cisco)Ability to interpret information security data and processes to identify potential compliance issuesAbility to quickly understand security systems in order to identify and validate security requirements 
Recommended skills and capabilities 
Experience with performing vulnerability scans and assessments as well as computer forensicsFamiliarity with SOA governance and policy management best practices |