Global IT Security Engineer

UGI Utilities, Inc.

Pennsylvania

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

UGI Utilities, Inc. is seeking a Global Cyber Security Engineer to lead external attack surface management and cloud security across the organization. You will drive ASM tooling, coordinate external pentesting, and oversee remediation with IT and business stakeholders.

The role also supports network security, OT/ICS security, and identity management, working with various teams to strengthen security posture and governance. Travel may be required within PA and surrounding areas.

Qualifications

  • BS degree in CS/InfoSec or related field required.
  • 4+ years of information security experience preferred.
  • Certifications (e.g., CISSP, CISM, CEH) desirable.

Responsibilities

  • Own external exposure management: ASM tooling and remediation tracking.
  • Coordinate external penetration testing and red team capabilities.
  • Improve cloud security posture across multiple environments.
  • Contribute to cloud security standards and guardrails.
  • Interpret PCI DSS, NIST, CIS Controls and advise on compliance.
  • Manage vulnerability tooling, reporting, and remediation prioritization.
  • Provide backup for network/OT/ICS security tasks and IAM platforms.
  • Document security policies and support risk assessments.
  • Communicate risks to technical and non-technical stakeholders.

Skills

Attack surface management
Penetration testing
Cloud security
Vulnerability management
Networking security architectures
Scripting: PowerShell/Python
SDLC security / DevSecOps

Education

Bachelor's degree in Computer Science or Information Security

Tools

InsightVM
Nexpose
Metasploit
Burp Suite
NMAP

Job description

Job Summary

The Global Cyber Security Engineer will lead the identification, assessment, and remediation of external attack surface and cloud security risks across the organization. This individual will work under the direction of the Global Manager – Cyber Security Threat Intelligence & Protection to drive the external and cloud exposure management program, conduct external penetration testing activities, manage attack surface management (ASM) tooling, and ensure cloud environments maintain a strong security posture. The role also provides secondary support for network security, OT/ICS security, and identity and authentication functions in collaboration with other team members.

Key Characteristics
  • Strong understanding of security and infrastructure architectures and technologies.
  • Experience in developing, implementing, advancing, and supporting security tools and procedures.
  • Demonstrated ability to troubleshoot with limited information.
Duties and Responsibilities
  • Own and drive the external exposure management program: manage attack surface management (ASM) tooling, continuously identify and prioritize externally exposed assets and vulnerabilities, develop remediation strategies, and track remediation through to closure with relevant IT and business stakeholders.
  • Plan and coordinate external penetration testing with tooling and 3rd party engagements, including scoping, vendor management, results analysis, and remediation follow-up. Develop and maintain internal red team/pen test capabilities and tooling to assess the organization’s external attack surface on an ongoing basis.
  • Assess and improve cloud security posture across various cloud environments. Identify misconfigurations, excessive exposure, and policy violations; partner with cloud and infrastructure teams to drive remediation.
  • Contribute to cloud security architecture standards and guardrails.
  • Interpret various federal, state, and industry frameworks for security, including but not limited to PCI DSS, SOX, ISO/IEC 27001, OWASP Top Ten, CIS Critical Security Controls, NIST, and advises management of any changes. Participate in security audits and assessments.
  • Manage and optimize vulnerability management tooling (e.g., InsightVM); analyze scan results, develop and maintain reporting and dashboards, and coordinate with IT teams on prioritization and remediation tracking. Interpret relevant security frameworks (PCI DSS, NIST, CIS Controls) and advise on compliance implications.
  • Provide secondary support for network security and OT/ICS security functions, including firewall rule review, network segmentation assessments, and OT-specific security architecture considerations. Serve as backup for identity and authentication platforms (e.g., RSA) as needed.
  • Contribute to security governance activities including policy documentation, security audits, and compliance assessments. Support ongoing risk assessment processes and communicate findings to both technical and non-technical stakeholders.
  • Develop and maintain comprehensive documentation related to security policies, procedures, and configurations.
  • Collaborate effectively with other IT teams, business units, and vendors. Communicate security risks and recommendations to both technical and non-technical audiences.
  • Stay up to date on the latest security threats, vulnerabilities, and technologies. Research and evaluate new security solutions to improve our security posture.
  • Mentor junior security team members and provide technical guidance.
Knowledge, Skills and Abilities
  • Advanced analytical and problem-solving skills.
  • Strong interpersonal skills.
  • Strong working knowledge of networking, routing, protocols, ports and services.
  • Experience with attack surface management (ASM) platforms, vulnerability management tools (e.g., InsightVM/Nexpose), external pen testing tools and frameworks (e.g., Metasploit, Burp Suite, NMAP, Wireshark), and cloud security posture management (CSPM) tools.
  • Hands‑on experience with penetration testing and/or red team concepts and methodologies (e.g., PTES, MITRE ATT&CK). Familiarity with automated pentesting platforms is a big plus.
  • Working knowledge of Linux and Microsoft Windows operating systems, Active Directory, and server / endpoint skills and experience.
  • Demonstrated experience in conducting security assessments.
  • Familiarity with OT/ICS security concepts and environments, including network segmentation, industrial protocols, asset visibility, and OT‑specific threat considerations (e.g., Purdue model, IEC 62443).
  • Understanding of identity and authentication platforms and their security implications, including MFA, token‑based authentication, and privileged access management (e.g., RSA, PAM solutions).
  • Strong working knowledge of various cloud computing environments, including cloud‑native security services, IAM, and common cloud misconfigurations and exposure patterns.
  • Experience with scripting languages (e.g., PowerShell, Python, Bash) is a plus. Familiarity with SDLC security testing concepts and application security (OWASP, SAST/DAST) is a plus.
  • Excellent oral and written communication skills.
  • Ability to follow established processes and guidelines for Change Management, Release Management, Problem and Incident management.
  • Collaborator with strong organizational skills, a positive attitude and customer service orientation.
  • Innovative thinker who can see the big picture while remaining attentive to the details.
  • Experience with MS productivity tools (Word, Excel, PowerPoint, Visio).
Education and Experience
  • Bachelor's degree in Computer Science, Information Security, or a related field, preferred.
  • A minimum four years of experience in Information Security. Previous general IT systems and networking background strongly preferred.
  • Relevant security certifications (e.g., CISSP, CISM, CEH, CompTIA Security+) are highly desirable.
Working Conditions
  • Normal office environment
  • May require travel
  • May require on‑call responsibilities
  • Must be in driving distance to the Pennsylvania offices (Valley Forge, Denver and Wyomissing)
  • Must have a conducive work from home environment to be productive

UGI Utilities, Inc is an Equal Opportunity Employer. The Company does not discriminate on the basis of race, color, sex, national origin, disability, age, gender identity, sexual orientation, veteran status, or any other legally protected class in its practices.

Successful applicants shall be required to pass a pre-employment drug screen as a condition of employment, and if hired, shall be subject to substance abuse testing in accordance with UGI policies.

As a federal contractor that engages in safety-sensitive work, UGI cannot permit employees in certain positions to use medical marijuana, even if prescribed by an authorized physician. Similarly, applicants for such positions who are actively using medical marijuana may be denied hire on that basis.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Global IT Security Engineer
Global IT Security Engineer

UGI Corporation • Pennsylvania

On-site
USD 90,000 - 115,000
Global IT Security Engineer
Global IT Security Engineer

UGI Corporation • Denver

Hybrid
USD 90,000 - 120,000
Equal Opportunity Employer
Drug-free workplace policies
Cybersecurity Senior GRC Analyst
Cybersecurity Senior GRC Analyst

UGI Utilities, Inc. • Pennsylvania

On-site
USD 85,000 - 110,000
Competitive compensation plan
Comprehensive benefits
Upward mobility opportunities
+1
Cybersecurity Senior GRC Analyst
Cybersecurity Senior GRC Analyst

UGI Corporation • Denver

On-site
USD 80,000 - 100,000
Competitive total compensation plan
Comprehensive benefits
Work life balance
Global IT Security Engineer: External & Cloud Risk
Global IT Security Engineer: External & Cloud Risk

UGI Utilities, Inc. • Pennsylvania

Hybrid
USD 120,000 - 180,000
Cybersecurity Operations Project Lead
Cybersecurity Operations Project Lead

UGI Corporation • Philadelphia

On-site
USD 90,000 - 120,000
Generous health and welfare benefits
401K with company match
Tuition reimbursement
+2
Cybersecurity Operations Project Lead
Cybersecurity Operations Project Lead

UGI Corporation • Pennsylvania

On-site
USD 90,000 - 120,000
Medical, Vision, and Dental Plans
401K with a generous company match
Tuition Reimbursement
+2
Cybersecurity Operations Project Lead
Cybersecurity Operations Project Lead

UGI Corporation • King of Prussia (PA)

On-site
USD 90,000 - 120,000
Medical, Vision, and Dental Plans
401K with company match
Tuition Reimbursement
+2
GRC Security Analyst II
GRC Security Analyst II

Aqua America, Inc. • Bryn Mawr (PA)

On-site
USD 80,000 - 100,000
Equal Opportunity Employer
Accommodation for individuals with disabilities
Safety & Health Admin II
Safety & Health Admin II

UGI Utilities, Inc. • Kingston

On-site
USD 70,000 - 90,000