About this role
Job title: Database Security Engineer
About the Role The Database Security Engineer at AIG will design and implement security controls to protect sensitive data across databases, monitor activity, and partner with risk and compliance teams to ensure regulatory alignment. This role focuses on preventing data breaches and maintaining data integrity across the organization.
What You'll Do
- Design, develop, test, document, monitor, and implement database security solutions aligned with policies and procedures.
- Manage a database activity monitoring (DAM) platform for security and audit compliance, including policy creation, event and trend analysis, performance monitoring and infrastructure maintenance.
- Serve as a trusted security SME to business, operations, development, risk, and compliance teams.
- Develop and maintain database security standards, guidelines, and hardening practices for configurations, users, roles, and profiles.
- Refine and enhance existing controls, policies, standards, procedures, and guidelines to prevent the unauthorized use, release, modification, or destruction of data.
- Evaluate updates to database security controls by determining strengths/weaknesses and coordinate testing and implementation with affected partners.
- Identify weak links in information security products and determine how to mitigate the control deficiencies.
- Enhance preventive systems used to stop and/or deter security breaches.
- Evaluate database security patches from vendors and assess potential risk and work with stakeholders to address vulnerabilities.
- Work with database custodians at different levels of the organization to understand their respective security needs and assist with implementing practices and procedures consistent with the information security policy.
- Conduct and identify database security compliance issues and ensure that any non-compliance to security baseline configurations are identified, tracked and assigned to stakeholders for remediation.
- Work with internal and external auditors to demonstrate and provide evidence of security controls adherence to regulatory compliance.
What We're Looking For
- 5+ years of Database Security Engineer experience.
- Ability to understand security risks and controls, to analyze various methods of controlling information security problems, determine the strengths and weaknesses of each method and implement the best cost-justified solution.
- Detailed knowledge of major database platforms such as Oracle, SQL Server, MySQL, etc.
- Working knowledge of at least two or more operating systems and corresponding security systems in use at the Bank (Linux, Unix, Windows, etc.)
- Identify weak links in information security products and determine how to mitigate the control deficiencies.
- Maintain familiarity with industry trends and current security practices.
- Demonstrate ability to manage complex projects and prepare detailed task plans outlining all requirements.
- Evaluate business processes and application software affecting the integrity, functionality, and reliability of the network and systems.
- Passionate, positive and driven attitude with good communication and interpersonal skills; reliable time management and ability to convey technical findings in simple language.
- Proactive mindset and actions; aptitude to lead complex efforts with minimal supervision and to collaborate across the organization.
- Proven ability to work independently and as a team member.
- Flexibility to work in varying business functions and capabilities; adaptable to new and changing environments and able to handle multiple priorities.
Nice to Have
- Imperva Data Security and Data Risk Analytics (DRA) DAM platform experience; Imperva Data Security Specialist (IDSS) certification strongly preferred.
- In-depth working knowledge of databases and database technologies.
- Familiarity with AWS technologies and methods including RDS.
- Data protection, Database Firewall, Data Loss Prevention (DLP), Data Classification, Vulnerability detection and mitigation.
- Cybersecurity experience in regulated banking or financial environment; Top 10 banking experience strongly preferred.
- Information security, penetration testing and forensics, IT risk management, IS audit, GRC Tools & Processes.
About the Company At AIG, we value in-person collaboration as a vital part of our culture, which is why we ask our team members to be primarily in the office. This approach helps us work together.