Global IT Security Engineer
Job in
Pittsburgh, Allegheny County, Pennsylvania, 15289, USA
Listed on 2026-06-16
Listing for:
UGI Corporation
Full Time
position Listed on 2026-06-16
Job specializations:
-
IT/Tech
Cybersecurity, Systems Engineer, IT Consultant, Information Security
Job Description & How to Apply Below
Job Summary
The Global Cyber Security Engineer will lead the identification, assessment, and remediation of external attack surface and cloud security risks across the organization. This individual will work under the direction of the Global Manager – Cyber Security Threat Intelligence & Protection to drive the external and cloud exposure management program, conduct external penetration testing activities, manage attack surface management (ASM) tooling, and ensure cloud environments maintain a strong security posture.
The role also provides secondary support for network security, OT/ICS security, and identity and authentication functions in collaboration with other team members.
- Strong understanding of security and infrastructure architectures and technologies.
- Experience in developing, implementing, advancing, and supporting security tools and procedures.
- Demonstrated ability to troubleshoot with limited information.
- Own and drive the external exposure management program: manage attack surface management (ASM) tooling, continuously identify and prioritize externally exposed assets and vulnerabilities, develop remediation strategies, and track remediation through to closure with relevant IT and business stakeholders.
- Plan and coordinate external penetration testing with tooling and 3rd party engagements, including scoping, vendor management, results analysis, and remediation follow-up. Develop and maintain internal red team/pen test capabilities and tooling to assess the organization’s external attack surface on an ongoing basis.
- Assess and improve cloud security posture across various cloud environments. Identify misconfigurations, excessive exposure, and policy violations; partner with cloud and infrastructure teams to drive remediation.
- Contribute to cloud security architecture standards and guardrails.
- Interpret various federal, state, and industry frameworks for security, including but not limited to PCI DSS, SOX, ISO/IEC 27001, OWASP Top Ten, CIS Critical Security Controls, NIST, and advises management of any changes. Participate in security audits and assessments.
- Manage and optimize vulnerability management tooling (e.g., Insight
VM); analyze scan results, develop and maintain reporting and dashboards, and coordinate with IT teams on prioritization and remediation tracking. Interpret relevant security frameworks (PCI DSS, NIST, CIS Controls) and advise on compliance implications. - Provide secondary support for network security and OT/ICS security functions, including firewall rule review, network segmentation assessments, and OT-specific security architecture considerations. Serve as backup for identity and authentication platforms (e.g., RSA) as needed.
- Contribute to security governance activities including policy documentation, security audits, and compliance assessments. Support ongoing risk assessment processes and communicate findings to both technical and non-technical stakeholders.
- Develop and maintain comprehensive documentation related to security policies, procedures, and configurations.
- Collaborate effectively with other IT teams, business units, and vendors. Communicate security risks and recommendations to both technical and non-technical audiences.
- Stay up to date on the latest security threats, vulnerabilities, and technologies. Research and evaluate new security solutions to improve our security posture.
- Mentor junior security team members and provide technical guidance.
Skills and Abilities
- Advanced analytical and problem-solving skills.
- Strong interpersonal skills.
- Strong working knowledge of networking, routing, protocols, ports and services.
- Experience with attack surface management (ASM) platforms, vulnerability management tools (e.g., Insight
VM/Nexpose), external pen testing tools and frameworks (e.g., Metasploit, Burp Suite, NMAP, Wireshark), and cloud security posture management (CSPM) tools. - Hands‑on experience with penetration testing and/or red team concepts and methodologies (e.g., PTES, MITRE ATT&CK). Familiarity with automated pentesting platforms is a big plus.
- Working knowledge of Linux and Microsoft Windows operating…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
Search for further Jobs Here:
×