Information Security Engineer
TBC Corporation Lake Park, Florida, United States
Transportation, Logistics, Supply Chain and Storage · 1,001-5,000 employees
About the role
The Security Engineer will establish and maintain cloud security standards while identifying and remediating risks across cloud and on-prem environments. They will also partner with DevOps and application teams to embed security into delivery pipelines and support threat detection and response efforts.
What they look for
Requirements
Candidates must have a bachelor's degree in Cybersecurity, Computer Science, or a related field. A minimum of 3-5 years of hands-on experience in security engineering or cloud operations is required.
Benefits
Full description
Compensation Data
Company Overview
For more than 70 years, TBC Corporation has been a leader in the mobility industry and one of North America’s largest marketers and distributors of automotive replacement tires through wholesale operations. Additionally, TBC responds to the needs of consumers in search of total car care at nearly 470 franchised tire and automotive service centers under the award-winning Big O Tires® brand. TBC is headquartered in Palm Beach Gardens, Florida.
With $5 billion in revenue and more than 3,000 employees in the U.S. and Mexico, TBC markets on a wholesale basis to regional tire chains and distributors serving independent tire dealers and with proprietary brands of tires specializing in passenger, commercial, farm and specialty tires. In 2005, TBC Corp. was purchased by Sumitomo Corporation of America (SCOA). SCOA is the largest subsidiary of Sumitomo Corporation, one of Japan’s major integrated trading and investment business enterprises. In 2018, Michelin, the largest tire manufacturer in Europe, invested in the company which is now a 50:50, privately held joint venture between Sumitomo and Michelin.
Our values are the foundation of our work, how we interact with each other, and the strategies we employ to fulfill our purpose. These are the practices we use every day – in everything we do:
- Integrity - We act honestly because nothing is more important than our reputation.
- Teamwork - We are better together.
- People-Focused - We put people first – our Associates, customers, franchisees, and partners – and cultivate a respectful, collaborative, and inclusive culture, top to bottom, inside and out.
- Accountability - We own our actions and decisions; we do what we say we are going to do.
- Leave Everything Better - We innovate to improve everything we touch, and we take actions now to protect the future.
Description
This position will be part of our information security operations engineering team with a primary focus on securing TBC Corporation’s cloud environments. This team provides secure configuration, security foundations, risk management, and operational security expertise across cloud and on-prem platforms, applications, infrastructure, and business technology initiatives. The team is responsible for identifying and reducing risk, strengthening identity and access controls, operationalizing cloud-native and third-party security solutions, supporting secure architecture decisions, responding to security events, and partnering with technology teams to embed security into cloud operations and delivery practices.
The Security Engineer will serve as a cybersecurity subject matter expert and support other TBC Corporation security and technology professionals by applying cloud security standards to improve the security posture of enterprise operations within TBC Corporation.
Responsibilities
- Establish and maintain cloud security standards, guardrails, and secure configuration practices that support cloud security foundations, compliance expectations, and enterprise risk reduction.
- Identify, assess, prioritize, and remediate cloud risks including misconfigurations, excessive permissions, exposed services, unmanaged assets, vulnerable workloads, and insecure data storage.
- Design, review, and improve cloud identity and access controls, including least privilege, privileged access, service accounts, service principals, workload identities, MFA, conditional access, and access review practices.
- Deploy, manage, tune, and operationalize cloud-native and third-party security platforms, including CSPM, CNAPP, vulnerability management, SIEM, workload protection, and data protection solutions.
- Support threat detection and response in enterprise environments by analyzing logs, identity events, workload telemetry, posture findings, vulnerabilities, and security alerts, and by recommending control improvements.
Additional Responsibilities
- Support secure AI enablement by assessing risks associated with AI tools, cloud-based and private AI services, data usage, model access, third-party integrations, and business use cases, and by recommending practical safeguards that align with security and compliance expectations.
- Partner with application, platform, and DevOps teams to embed DevSecOps practices into cloud delivery pipelines, including secure design reviews, automated security testing, vulnerability remediation, secrets protection, infrastructure-as-code security, and release governance.
- Partner with security, infrastructure, application, DevOps, audit, and operations teams to embed cloud security into projects, improve processes, document standards, and communicate security posture and remediation progress.
- Other duties as assigned.
Continued Responsibilities
- Framework, CIS Benchmarks, ISO 27001, and PCI-DSS as applied to cloud environments.
- Provide support for cloud security projects and audit activity, including but not limited to JSOX, PCI, ISO, and internal security assessments.
- Analyze cloud security logs, identity events, posture findings, vulnerability data, and security alerts.
- Investigate and remediate cloud security incidents, risky configurations, identity exposures, and control gaps; implement preventative measures as appropriate.
- Assist with the creation, review, updating, implementation, and documentation of cloud architecture, security architecture, data flow diagrams, and control mappings.
- Familiarity with cloud networking, firewalls, private connectivity, segmentation, encryption, key management, logging, monitoring, and secure data storage patterns.
Added Responsibilities
Qualifications
- Bachelor’s degree in Cybersecurity, Computer Science, or a related field (or equivalent experience).
- 3-5 years of hands-on experience in security engineering, cloud security, cloud operations, infrastructure security, or a related role.
- Strong conceptual understanding of cloud security foundations, information security theory, shared responsibility, defense-in-depth, identity-centric security, and risk-based control design.
- Strong multi-tasking and analytical/troubleshooting skills
- Experience meeting with IT, cloud operations, application, DevOps, and management teams to discuss and resolve business concerns related to cloud security and risk.
- Proficient in MS-Office suite of products
- Aptitude to prioritize and load balance multiple sensitive projects concurrently
- Professional certifications from ISACA, (ISC)2, SANS, Microsoft, AWS, Google Cloud, or other cloud security certification providers preferred.
- 5+ years of relevant information technology, infrastructure, cloud operations, or information security experience preferred.
- Experience with cloud-native security platforms and capabilities such as Microsoft Defender for Cloud, Azure Policy, AWS Security Hub, GuardDuty, CloudTrail, Config, Google Cloud Security Command Center, or equivalent services.
- Strong experience identifying cloud risk, prioritizing remediation, and operationalizing cloud security solutions using CSPM, CNAPP, vulnerability management, SIEM, SOAR, and ticketing or workflow platforms.
- Experience with cloud identity and access management, including RBAC, least privilege, privileged access, service principals, managed identities, service accounts, conditional access, MFA, and access reviews.
- Perform other cloud security and information security projects / duties as assigned.
- Bilingual in Spanish /English is a plus
Benefits
- Market competitive compensation
- 401(k) and Roth with company match. Immediate 100% vesting
- Comprehensive benefits including medical, dental and vision
- Company paid short term disability and employer subsidized long term disability
- Company paid life insurance
- Discounted tire purchasing
- Tuition reimbursement
- Employee assistance program
- Generous paid vacation and paid time off
- Customizable voluntary benefits
- and More!!!
Similar roles
-
CYS - Cybersecurity Researcher - TP
Leonardo Rome, Lazio, Italy · €36K–€59K/yr
-
Application Security Engineer
AbbVie North Chicago, Illinois, United States · $84K–$162K/yr
-
Senior Cybersecurity Engineer
Bluestaq US External Colorado Springs, Colorado, United States · $100K–$155K/yr
-
Cybersecurity Support Specialist
Nooks Arlington, Virginia, United States · $90K–$115K/yr
-
Campus Undergraduate Full-Time Associate - 2027 Cybersecurity Analyst, Enterprise Technology Services- Sunrise, FL
American Express Sunrise, Florida, United States · $78K–$125K/yr
-
Account Manager, Public Relations (Cybersecurity)
Highwire San Francisco, California, United States · $80K–$105K/yr