Dealer Tire is a family-owned, international distributor of tires and parts established in 1918 in Cleveland, OH. They are seeking an Information Security Engineer responsible for managing vendor risk assessments, developing security automation processes, and providing security guidance for compliance issues.
Responsibilities:
- Performing vendor risk assessments for new vendors and reviewing the risk of current vendors
- Maintaining our matrix of 3rd party vendor to features
- Includes evaluation of AI vendors and AI workloads: data flows, the model and data supply chain, and agentic and MCP integrations
- Evaluate alerting processes and systems and develop security automation processes
- Includes using AI-based engineering tools, such as AI coding assistants and MCP servers, to build security automation, along with detection engineering and the secure design of AI-enabled systems
- Policy & Runbook development, incident reporting, pen testing analysis
- Includes AI review patterns and AI usage telemetry; technical AI risk findings feed the Governance and Policy impact assessments and AI compliance program
- Build out new monitoring capabilities, developing alerts, integrate new feeds
- Includes shadow-AI discovery and monitoring of AI tool usage and egress
- Provide security guidance for compliance issues such as OWASP development practices, privacy protection, network security practices, and security framework compliance
- Includes secure-by-design guidance for teams building with AI, aligned to the OWASP Top 10 for LLM and Agentic Applications and MITRE ATLAS
- Configure technologies such as security information and event management, artificial intelligence and machine learning, intrusion detection and prevention, and various anti-malware solutions to allow for monitoring of computer systems
- Investigate security breaches and incidents
- Determine if event requires further action and escalation
- Assist other teams within IT during incidents, document steps taken and lessons learned
- Provide technical security guidance for compliance issues such as OWASP development practices, privacy protection, network security practices, and security framework compliance to projects and teams
- Analyze current vulnerability management systems for effectiveness and make recommendations to maintain and improve accuracy and scalability of systems
- Evaluate new vendors and products for security risks and compliance with security policies
- Develop security automation processes to improve security posture
- Research new security threats and solutions
- Stay current with IT security news and developments in the field
Requirements:
- Bachelor's degree in computer science, information security, information systems or other related field is required and/or equivalent of 3-5 years of information security work experience with exposure to infrastructure/network and multiplatform environments
- Advanced skills in scripting and automation tools like Powershell and Bash
- Demonstrated knowledge of security issues, techniques, and implications across the most popular computer, cloud, and IaaS platforms
- Working knowledge of AI and large language model security concepts, including prompt injection and the data-as-code trust boundary, authorization for autonomous and agentic systems, and the AI model and data supply chain
- Familiarity with AI security frameworks such as the OWASP Top 10 for LLM and Agentic Applications, the NIST AI Risk Management Framework, and MITRE ATLAS
- Ability to work independently as well as a team
- Professional security certification, such as a Certified Information Systems Security Professional (CISSP), CompTIA Security+, SANS Cybersecurity Certification, Certified Information Systems Auditor (CISA) or other similar credentials
- AI security credentials are a plus