Job Overview:
As a member of the Information Security Program Team, the Information Security Engineer is responsible for participating in all aspects of planning, deploying, documenting, monitoring, & maintaining the layered security to protect the confidentiality, integrity, and availability within the corporate and client facing infrastructures. This position will focus on protecting system boundaries, keeping systems and infrastructure hardened against attacks and securing highly sensitive data, along with securing user and computer identities.
Key Responsibilities:
- Perform engineering, tuning, and provide guidance of network security controls & hardening including IDS/IPS, Web Filtering, Cloud Technologies, Email/Spam, and Firewalls.
- Perform engineering, tuning, and guidance to the Information Security Team for incident response & SIEM management.
- Experienced in cloud security and compliance for Azure and AWS.
- Manage and support Identity and Access Management.
- Support the investigation and resolution of security incidents.
- Perform Security User Awareness Training and Phishing campaigns.
- Perform vulnerability management as well as support penetration testing and remediation.
- Perform engineering, tuning, & provide guidance of mobile & endpoint security controls & hardening including AV, Endpoint Detection & Response, DLP, & encryption.
- Translate security controls and requirements into system specification requirements.
- Perform 3rd party vendor risk management assessments.
- Plan, develop, and enhance security standards, requirements gathering, and engineer security solutions across the risk and technology portfolio.
- Assist in designing computer security architecture and develop detailed cyber security designs.
- Engineer, implement and monitor security measures for the protection of computer systems, storage, infrastructure, and cloud applications.
- Define system security requirements, identify vulnerabilities, and coordinate remediation plans.
- Support and coordinate risk assessments and security evaluations for vendors deploying solutions either on premise or in the cloud.
- Participate in proof of concepts and other technical evaluations of technologies, designs and solutions and provide recommendations.
- Plan and coordinate the deployment of security and vulnerability patching to all computer systems.
- Prepare and document standard operating procedures and standards.
- Develop technical solutions and select and implement new security tools to help mitigate security vulnerabilities and automate repeatable tasks.
- Write comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement.
- Plan/automate/deploy new infrastructure and security capabilities.
- Participates in secur