What are the responsibilities and job description for the Senior Information Security Engineer position at KOHLS?
About the Role
As Senior Information Security Engineer, you will design, build, and run core security solutions that support all information security capabilities and products. You will also provide operational support to security-related Kohl’s Technology processes, including firewall rule request approvals, proxy allow/deny listing and application allow/deny listing.
What You’ll Do
Provide architectural design, engineering maintenance and application administration for the Information Security tool suite
Research, test and advise on new technology and security requirements
Design, develop, test, deploy and iteratively improve product capabilities and features in collaboration with designers, product managers and other engineers on the product team
Leverage critical thinking, experimentation, data and industry best practices to achieve desired business outcomes
Develop high-quality applications that are secure, easy to operate, difficult to break, and extremely observable with measurable results
Oversee all technical aspects of the product application lifecycle, including code, infrastructure, data, security, and CICD
Contribute to product engineering and software standard
Expand experience across domains within the role
Additional tasks may be assigned
What Skills You Have
Required
Deep experience designing and operating enterprise Identity and Access Management (IAM) platforms, including Single Sign-On (SSO), Multi-Factor Authentication (MFA), federation, and modern authentication protocols such as SAML 2.0, OAuth 2.0, OpenID Connect (OIDC), and related identity standards
Hands-on experience implementing and supporting enterprise secrets management and machine identity solutions, including credential lifecycle management, privileged access patterns, application authentication, certificate management, and secrets automation at scale
Experience with Identity Governance and Administration (IGA) platforms, including identity lifecycle management, access request and approval workflows, birthright and role-based access provisioning, certification campaigns, segregation of duties, and compliance reporting
Experience with complex application troubleshooting, performance tuning and integration platforms or frameworks
Background in integrating with large SaaS systems, migrating on-prem systems to cloud solutions and developing integration frameworks
Ability to execute integration testing strategies
Preferred
Experience as a software developer