The posting
Job Description:
NOTE: This role is based in New York City and encourages a minimum of two days per week in the SoHo office. Some roles or teams may require additional in-office attendance if the essential functions of the role require it.
THE OPPORTUNITY
The Principal Security Engineer will be part of the Scholastic Security organization and report to the Executive Director of Information Security and Compliance. This role will work closely with the CISO and the SVP of Technology Operations to proactively identify, assess, and reduce security risk across Scholastic’s network, systems, applications, and third-party ecosystem. The position is responsible for assessing information risk, identifying vulnerabilities, facilitating remediation, documenting mitigation options, monitoring remediation progress, and reporting findings and recommendations. The Principal Security Engineer will also support IT audits, risk assessments, regulatory compliance, vulnerability assessments, third-party risk management activities, and weekly project status reporting.
YOUR RESPONSIBILITIES
- Design and implement security architecture and controls across cloud, network, endpoint, and application environments.
- Work closely with team members to enhance, implement, and configure scalable security technologies and improve detection and response capabilities.
- Lead engineering efforts to build, tune, and scale security tooling, including SIEM, EDR, vulnerability management, identity and access management, TPRM and secrets management platforms.
- Work closely with the SOC to review, develop, and maintain incident response playbooks.
- Serve as an escalation point for SOC incidents, providing technical guidance and support during investigation and response activities.
- Develop metrics and KPIs that demonstrate security posture, control effectiveness, and tooling consolidation progress.
- Automate security controls and evidence collection to support audit and compliance programs, including SOX IT General Controls, PCI DSS, SOC 2.
- Ensure CIS benchmark controls are applied, configurations are maintained across the enterprise, continuous monitoring is performed, and remediation plans are developed for identified gaps.
- Continuously improve the security framework, methodology, standards, and system of internal controls
- Lead and assist in security risk assessments for systems and applications
- Address questions from internal and external audits and examinations
- Develop policies, procedures, and standards that meet existing and newly developed policy and regulatory requirements, including SOX, PCI, and Privacy
- Research business and technical challenges and provide solution recommendations to mitigate risk and improve our security posture
- Perform security reviews, identify gaps in security architecture, and develop a security risk management plan
- Serve as a project lead within IT security projects
- Provide advice on project costs, design concepts, or design changes
- Define and document how the implementation of a new system, or interfaces between systems, impacts the security posture of the current environment
- Drive and deliver Enterprise security roadmap and initiatives
- Conduct a cybersecurity incident response tabletop exercise at least annually.
- Identifies opportunities to reduce risk and documents remediation options regarding acceptance or mitigation of risk scenarios
- Investigate security incidents and lead incident response activities, including minimizing impact, performing technical and forensic analysis, determining root cause, and assessing the extent of damage.
- Build tools and automation scripts that enable developers to consume security services delivered by the Security Engineering and Automation team.
- Monitor emerging threats, vulnerabilities, and industry best practices to inform risk decisions and security roadmap priorities.
- Develop metrics/KPIs to show security posture and tools consolidation
- Develop and maintain documentation, runbooks, and standards for security engineering practices.
- Track emerging threats, vulnerabilities, and industry best practices, and translate relevant developments into actionable recommendations for leadership.
- Mentor and provide technical leadership to other security analysts, engineers, and contribute to hiring and skill development.
About Scholastic
For more than 100 years, Scholastic Corporation (NASDAQ: SCHL) has been meeting children where they are – at school, at home and in their communities – by creating quality content and experiences, all beginning with literacy. Scholastic delivers stories, characters, and learning moments that empower all kids to become lifelong readers and learners through bestselling children’s books, literacy- and knowledge-building resources for schools including classroom magazines, and award-winning, entertaining children's media. As the world's largest publisher and distributor of children's books through school-based book clubs and book fairs, classroom libraries, school and public libraries, retail, and online, and with a global reach into more than 135 countries, Scholastic encourages the personal and intellectual growth of all children, while nurturing a lifelong relationship with reading, themselves, and the world around them. Learn more at www.scholastic.com.
Some benefits that we offer:
- Full suite of health and wellness benefits (including a $0 deductible Medical Plan)
- Retirement Savings Plan 401(k) with options for both Roth and Traditional Contributions
- Tuition-Free programs for undergraduate and graduate degrees
- Generous Parental Leave Program
- Employee Stock Purchase Plan (ESPP) with opportunity for discounted stock at a 15% discount
Thank you for your consideration in choosing Scholastic.
#LI-MV1
Qualifications
HOW YOU CAN FIT
- A bachelor's degree in information systems, engineering, or equivalent work experience
- Candidates with the following certifications are preferred: ISC2, SANS, ISACA, or other recognized security professional credentialing organizations
- Minimum 10+ years of experience in designing and implementing security solutions, including IAM, EDR, MDM, SIEM, KMS, and PAM
- 5+ years of experience in a Security Operations Center or Continuous Monitoring role
- 5+ years working and supporting Incident Response functions
- Hands-on experience with software development languages and technologies, including Java, C#, C++, JavaScript, and HTML.
- Strong hands-on infrastructure security skills, including IDS/IPS, firewalls, SIEM, server and operating system hardening, malware detection, physical security, and encryption for data in transit and at rest across file systems, databases, and other data persistence mechanisms.
- Experience managing application security testing tools, including SAST, DAST, and open-source vulnerability scanning.
- Experience implementing SOX, PCI, NIST CSF, CIS Controls, and SANS Controls is required.
- Excellent written and verbal communication skills — including the ability to effectively communicate security- and risk-related concepts to technical and non-technical audiences — and strong interpersonal and collaborative skills
- Ability to operate with minimal supervision as a self-starter who can identify and resolve problems, manage multiple priorities, deliver results, and meet deadlines.
- Knowledge of tactics, techniques, and procedures that are leveraged to perform recon, which can be used to gain persistence, move laterally, or exfiltrate data
- In-depth knowledge and understanding of information risk concepts and principles as a means of relating business needs to security controls, excellent understanding of information security concepts, protocols, industry best practices, and strategies
- Ability to work in a highly fast-paced environment with high expectations
Time Type:
Full time
Job Type:
Regular
Job Family Group:
Information Technology
Location Region/State:
New York
Compensation Range:
Annual Salary: 165,000.00 - 185,000.00
EEO Statement:
Scholastic is an Equal Opportunity Employer. Our policy is clear: there shall be no discrimination on the basis of race, religion, color, sex, pregnancy, national origin, marital status, sexual orientation, gender identity or expression, age, non-disqualifying physical or mental disability, or status as a disabled veteran or Vietnam veteran. Those factors shall not influence the determination of qualifications for a job or other opportunity within the company. Further, all personnel actions (such as compensation, tuition aid, benefits, transfers, promotions, and dismissals, company-sponsored training, social and recreational programs) shall be administered without discrimination.
EEO is the Law Poster
EEO Scholastic Policy Statement
Pay Transparency Provision



