If you are currently an employee of Herc Rentals, please apply using this link: Herc Employee Career Portal Founded in 1965, Herc Rentals is one of the leading equipment rental suppliers in North America with 2024 total revenues reaching approximately $3.6 billion. Herc Rentals' parent company, known as Herc Holdings Inc., listed on the New York Stock Exchange on July 1, 2016, under the symbol "HRI." Herc Rentals serves customers through approximately 450+ locations and has about 7,600 employees in North America as of March 31, 2025.
Job Purpose
We are seeking a highly experienced Senior Cyber Security Architect to join our team. The successful candidate will possess a unique blend of cloud architecture expertise, cybersecurity penetration testing experience, and leadership skills to mentor our cybersecurity team. This individual will play a critical role in developing and implementing our cybersecurity program, performing architecture reviews, and providing consultative guidance to secure our systems and applications. This individual will be a working cybersecurity expert and will be required to architect secure systems and solutions.
What you will do...
- Conduct system exploits and security testing for web applications, servers, and desktops to identify vulnerabilities and provide recommendations for remediation and hardening.
- Develop and implement a comprehensive cyber security program to protect our organization's assets and data.
- Strong VISIO, Draw.io, or other diagraming tools with the ability to create robust logical diagrams.
- Perform architecture reviews to ensure the security and integrity of our systems and applications, and provide guidance on secure design principles and best practices.
- Collaborate with technical owners to secure products and services, providing cyber security consulting expertise and guidance on secure development lifecycle practices.
- Utilize automated penetration/breach attack simulation products to identify vulnerabilities and weaknesses, and provide recommendations for remediation.
- Perform threat hunting activities to detect and respond to potential security threats.
- Design and implement automation scripts and tools to streamline cyber security processes and improve efficiency.
- Strong knowledge in SIEM technologies to help data science team build high fidelity alerts.
- Mentor and lead our cyber security team, providing guidance and expertise to help them develop their skills and knowledge.
- Stay up-to-date with emerging threats, technologies, and trends in cyber security, and apply this knowledge to improve our organization's cyber security posture.
Requirements
- 8+ years of experience in cyber security, with a focus on cloud architecture, penetration testing, and security consulting.
- 5 years' experience conducting comprehensive security assessments of web applications and APIs, simulating real-world attacks using tools such as Burp Suite, ZAP, and Postman to identify and exploit vulnerabilities (e.g., SQL injection, XSS, CSRF).
- 5 years' experience performing penetration testing and red team exercises on systems, networks, and applications using tools like Metasploit and Cobalt Strike, delivering actionable remediation strategies and recommendations to enhance overall security posture.
- Strong knowledge of system exploitation and security testing methodologies, including web application security testing and vulnerability assessment.
- Strong understanding of the Windows, Linux and Macintosh operating systems relevant to hardening (Registry, configs, stigs)
- Experience with automated penetration/breach attack simulation products (such as Pentera, Horizon3, Cimulate, AttackIQ, Verodin)
- Strong understanding of cloud security architecture, including AWS, Azure, or Google Cloud Platform.
- Experience with cyber security frameworks and standards, such as NIST, ISO 27001, or PCI-DSS.
- Strong leadership and mentoring skills, with the ability to lead and guide a team of cyber security professionals.
Preferred Qualifications
- Advanced degree in Computer Science, Cyber Security, or a related field.
- Industry-recognized certifications, such as OSCP, CEH, or CISSP.
- Experience with security orchestration, automation, and response (SOAR) tools.
- Familiarity with DevSecOps practices and tools, such as Jenkins, Docker, or Kubernetes.
- Experience with threat intelligence platforms and threat hunting tools.
- Excellent communication and interpersonal skills, with the ability to communicate complex technical concepts to non-technical stakeholders.
Req #: 62527 Pay Range: Based on Qualifications Please be advised that the actual salary offered for any position is subject to the company's sole discretion and may be influenced by various factors, including but not limited to the candidate's qualifications, experience, location, and overall fit for the role. Herc Rentals values its employees and provides excellent compensation and benefits packages which are not limited to the following. Keeping you healthy Medical, Dental, and Vision Coverage Life and disability insurance Flex spending and health savings accounts Virtual Health Visits 24 Hour Nurse Line Healthy Pregnancy Program Tobacco Cessation Program Weight Loss Program Building Your Financial Future 401(k) plan with company match Employee Stock Purchase Program Life & Work Harmony Paid Time Off (Holidays, Vacations, Sick Days) Paid parental leave. Military leave & support for those in the National Guard and Reserves Employee Assistance Program (EAP) Adoption Assistance Reimbursement Program Tuition Reimbursement Program Auto & Home Insurance Discounts Protecting You & Your Family Company Paid Life Insurance Supplemental Life Insurance Accidental Death & Dismemberment Insurance Company Paid Disability Insurance Supplemental Disability Insurance Group Legal Plan Critical Illness Insurance Accident Insurance Herc does not discriminate in employment based on the basis of race, creed, color, religion, sex, age, disability, national origin, marital status, sexual orientation, citizenship status, political affiliation, parental status, military service, or other non-merit factors.
|