Join TuSimple and help change the way the world moves. Together we're making freight transportation safer, more efficient, and more environmentally friendly.
We are TuSimple - a highly ambitious team with deep technical expertise and audacious vision. We are building products that will change the world. Our mission is to develop the world’s most advanced self-driving technologies specifically designed to meet the unique demands of heavy-duty trucks.
And we deliver. As the first AV to market, we are commercializing autonomous freight capacity that is safer, more efficient, and on-demand. In pursuit of our goals, we are looking for the best and brightest to join us on this exciting journey and be part of a fast-moving, highly execution-oriented team.
As a multi-national Artificial Intelligence Technology Company, we are at the epicenter of the Autonomous Vehicle Universe. Our breakthroughs are leading the industry in autonomous trucking.
While inventing the framework of Autonomous Driving, our current fleet of autonomous Trucks are helping communities receive much-needed supplies and medical equipment around the clock. Our people are some of the most talented engineers and contributors who are leaving behind a historic legacy.
TuSimple was founded half a decade ago with the goal of bringing the top minds in the world together to achieve the dream of a driverless truck solution. With a foundation in computer vision, algorithms, mapping, and Artificial Intelligence, TuSimple is working to create the first global commercially viable autonomous truck driving platform!
TuSimple’s Senior Information Security Analyst I is an experienced member of the Information Security office and works with stakeholders across the business to ensure the confidentiality, integrity, and availability of the organization’s systems and information. In this role the incumbent continuously monitors security technical controls and monitoring systems to ensure the business is safeguarded against internal and external threats. Additionally, the Senior Information Security Analyst I assists with/conducts routine audits, performs risk assessments, and plays a key role in incident response situations.
Acting as a champion for Information Security, the Senior Information Security Analyst I is a strong InfoSec advocate and helps promote information security awareness across the organization. The incumbent employs a proactive mindset but is also highly responsive when required to be reactive. They find gaps, solve problems, thrive under pressure, and have an unrelenting drive to achieve and maintain optimal levels of security.
- Researches required regulatory standards and the organization’s information systems to determine appropriate technical controls and technologies to fill security gaps.
- Conducts routine and AdHoc security assessments of IT infrastructure, enterprise applications, and production systems.
- Performs vulnerability scans, analysis, reporting and subsequent remediation actions.
- Performs weekly auditing/monitoring activities for anomalous or security relevant events.
- Monitors and tests the deployment of security infrastructure to ensure it’s full deployment and effectiveness.
- Engineers monitoring solutions using industry tools and technologies.
- Assists and coordinates in the management of all potential cybersecurity incidents.
- Conducts 3rd-party vendor risks assessments.
- Research, plan and implement solutions/technologies for data governance and data loss prevention (DLP).
- Performs routine monitoring/auditing of data governance practices and DLP events.
- Assists in the Installation, configuration, and deployment of cybersecurity infrastructure across workstations, servers and system platforms.
- Effectively carries out the compliance audit strategy and programs.
- Works with key stakeholders to identify and remediate cybersecurity risks in a timely fashion.
- Understands and disseminates the company’s compliance policies/procedures and applicable laws/regulations.
- Performs other duties and projects (i.e. SOX reviews) as may be necessary and assigned.
- Develops training programs to ensure adherence with compliance standards
- Establishes and maintains strong working relationships across the organization.
Experience & Skills Required
- 5+ years of related working experience in a cybersecurity role, combined with a relevant undergraduate degree OR 7+ years of related working experience in a cybersecurity role.
- Prior experience working with Security Information and Event Management (SIEM) tools or performing IT security auditing/monitoring in some capacity.
- Prior experience working with vulnerability scanning tools.
- Past experience with data loss prevention (DLP) technologies.
- Past experience with Windows and Linux command line interface (CLI).
- Strong working knowledge of operating systems and network security principles.
- Working knowledge and experience with access control systems like Single Sign On (SSO), Active Directory and other IAM systems.
- Working knowledge of Multifactor authentication (MFA) products. .
- Working knowledge and or experience with data governance practices (classification, marking, auditing/monitoring)
- Well developed skills that enable effective risk and issue detection, assessment and resolution.
- Ability to identify, troubleshoot, and resolve issues quickly and effectively.
- Understanding of industry standard IT compliance practices such as SOX, SOC2, HITRUST, ISO-27000, ISO-21434 or RMF.
- Ability to conduct advanced security auditing and monitoring.
- Ability to support audits for a publicly traded company and conduct third-party vendor risk assessments.
- Working knowledge of scripting (Powershell, VB, VBScript, Bash etc.).
- Understanding of and ability to use SQL or other query languages.
- 100% employer-paid healthcare premiums for you and your family
- Work visa sponsorship available
- Breakfast, lunch, and dinner served every day
- Full kitchens on every floor with unlimited snacks, drinks, special treats, fruits, meals, and more
- Gym membership reimbursement
- Learning/education budget
- Employer-paid life insurance
- Employer-paid long and short disability
TuSimple is an Equal Opportunity Employer. This company does not discriminate in employment and personnel practices on the basis of race, sex, age, handicap, religion, national origin, or any other basis prohibited by applicable law. Hiring, transferring and promotion practices are performed without regard to the above-listed items.