If you are currently an employee of Herc Rentals, please apply using this link: Herc Employee Career Portal Founded in 1965, Herc Rentals is one of the leading equipment rental suppliers in North America with trailing twelve month total revenues of nearly $3.5 billion as of December 31, 2024. Herc Rentals' parent company, known as Herc Holdings Inc., listed on the New York Stock Exchange on July 1, 2016, under the symbol "HRI." Herc Rentals serves customers through approximately 450+ locations and has approximately 7,700 employees in North America.
Job Purpose
The Cyber Security Architect I is a senior cyber security practitioner responsible for designing and implementing secure infrastructure solutions across on-premises and cloud environments, ensuring the confidentiality, integrity, and availability of the organization's information assets. This role will provide expert guidance on the secure deployment of infrastructure, as well as integration with existing systems and technologies. The successful candidate will have advanced knowledge of security development life cycle (SDLC) principles and will assist in the development of secure coding practices, scripting, and automation of security controls. Additionally, the Cyber Security Architect I will have experience with red, blue, and purple team activities, providing strategic threat modeling and vulnerability assessment expertise to inform security architecture and design. The goal of this role is to provide technical leadership and expertise in the design and implementation of secure systems, applications, and infrastructure, ensuring the organization's cybersecurity posture is aligned with industry best practices and emerging threats.
What you will do...
- As a Cyber Security Architect, you will have a key role in shaping the organization's cyber security strategy and architecture, and will be responsible for:
- Designing and implementing comprehensive security architectures for on-premises and cloud-based systems, applications, and infrastructure, to ensure the "CIA" triangle of Herc's systems
- Collaborating with cross-functional teams, including development, operations, and engineering, to integrate security into the development life cycle (SDLC) and ensure that security is a core component of all technology projects and initiatives.
- Develop and maintain a deep understanding of our threat landscape and using this knowledge to inform the development of strategic threat models, vulnerability assessments, and risk mitigation strategies.
- Lead the development and implementation of advanced security controls, including automation and orchestration of security processes, and the integration of security tools and technologies with existing systems and infrastructure.
- Provide expert guidance and advice on security-related matters, including compliance, risk management, and incident response, and serving as a subject matter expert on security architecture and engineering.
- Collaborate with the red, blue, and purple team activities to implement advanced threat simulation and vulnerability assessment exercises, and to develop and refine the organization's threat detection and response capabilities.
- Develop and maintain strategic relationships with key stakeholders, including executives, engineers, and external partners, to ensure that security is a core component of all business and technology initiatives.
- Mentor and help increase the abilities of others within the cyber security team and IT organization.
Requirements
- 7 - 10 years of working cyber security experience.
- Expertise in scripting languages such as Python, Bash, and PowerShell
- Expertise in Cyber Security Incident Response
- Expertise in securing Windows and Linux servers
- Experience in securing cloud solutions
- Very strong knowledge in cybersecurity solutions such as WebAuthN, Fido2, SAML, SSE/ZTNA types of solutions
- Strong GPO knowledge to provide system hardening recommendations.
- A naturally curious mindset, with a passion for learning and exploring new concepts and technologies
- Unquestionable integrity, with a strong commitment to ethics and a willingness to do what is right, even in challenging situations
- Excellent relationship-building skills, with the ability to collaborate and communicate effectively with colleagues across the cybersecurity team and other departments
- A strong ability to adapt to changing priorities and deadlines, with a flexible and agile approach to work
- Must undergo and pass a thorough background investigation, which includes a check of criminal records and a review of financial history to ensure responsible financial management.
Education:
Bachelor's degree or equivalent work experience. A CISSP, CASP+, OSCP, GWAPT or industry-recognized certification is strongly desired for this senior position.
Skills
- Advanced scripting skills in languages such as Python, Bash, and PowerShell, as well as the ability to develop complex scripts and automate security processes.
- Cloud security expertise, with strong knowledge of providers such as AWS, Azure, Google, and others, and experience in securing cloud-based systems and applications.
- Operating system security with expertise in securing Windows and Linux systems as well as hardening to promote a deny by default mindset.
- Strong knowledge of cybersecurity solutions such as WebAuthN, Fido2, SAML, SSE/ZTNA, and other advanced security technologies.
- Advanced understanding of GPOs, with the ability to provide system hardening recommendations and implement security configurations.
- Experience with threat modeling and vulnerability assessment tools and techniques, including participating and working with red, blue and purple teams.
- Knowledge of SDLC principles and practices, with experience in integrating security into the development life cycle.
- Familiarity with cybersecurity automation and orchestration.
- Experience with incident response and threat hunting, including knowledge of threat intel, incident response methodologies, and threat hunting tools and techniques.
- Understanding of compliance and risk management frameworks such as NIST, ISO 27001 and others.
- Excellent communication and collaboration skills, with the ability to work effectively with cross-functional teams, including development, operations, and engineering.
- Ability to mentor and lead others, with experience in developing and implementing security training programs and providing guidance and expertise to junior team members.
Req #: 62527 Pay Range: Based on Qualifications Please be advised that the actual salary offered for any position is subject to the company's sole discretion and may be influenced by various factors, including but not limited to the candidate's qualifications, experience, location, and overall fit for the role. Herc Rentals values its employees and provides excellent compensation and benefits packages which are not limited to the following. Keeping you healthy Medical, Dental, and Vision Coverage Life and disability insurance Flex spending and health savings accounts Virtual Health Visits 24 Hour Nurse Line Healthy Pregnancy Program Tobacco Cessation Program Weight Loss Program Building Your Financial Future 401(k) plan with company match Employee Stock Purchase Program Life & Work Harmony Paid Time Off (Holidays, Vacations, Sick Days) Paid parental leave. Military leave & support for those in the National Guard and Reserves Employee Assistance Program (EAP) Adoption Assistance Reimbursement Program Tuition Reimbursement Program Auto & Home Insurance Discounts Protecting You & Your Family Company Paid Life Insurance Supplemental Life Insurance Accidental Death & Dismemberment Insurance Company Paid Disability Insurance Supplemental Disability Insurance Group Legal Plan Critical Illness Insurance Accident Insurance Herc does not discriminate in employment based on the basis of race, creed, color, religion, sex, age, disability, national origin, marital status, sexual orientation, citizenship status, political affiliation, parental status, military service, or other non-merit factors.
|