Information Security Engineer

IT AssociatesUnited States
Full TimeOn-siteJuniorLimited info disclosed
35 views0 applications

Description

The Information Security Engineer will ensure the confidentiality, integrity, and availability of all IT assets within the Firm. This role involves both strategic oversight and hands-on security operations. Role and responsibilities: Security Operations & Incident Response • Participate in the Vulnerability Management Program, including asset scans, documentation, and reporting. • Research, prioritize, and remediate vulnerabilities in coordination with IT teams. • Manage the relationship with the Managed Threat Detection & Response vendor to ensure quality service. • Optimize SIEM alerting to reduce false positives, ensure comprehensive log ingestion, and strengthen detection capabilities. • Monitor and respond to SIEM (Security Information and Event Management) alerts, ensuring appropriate verbosity. • Conduct incident response and recovery exercises to enhance the Firm’s security posture. Security Governance & Compliance • Develop and validate controls, safeguards, and standards for the information security program. • Implement and document Firm security practices in alignment with policies and industry standards. • Monitor, track, and report key performance indicators (KPIs) for security program effectiveness. • Assess security program effectiveness, identifying gaps, and recommending improvements. • Conduct security evaluations for third-party vendors and facilitate access reviews. • Respond to due diligence questionnaires related to information security. Security Tools & Technology Management • Deploy, manage, and maintain security tools, ensuring alignment with security objectives. • Evaluate and recommend security solutions and vendors. • Assist with IT asset inventory control in coordination with other IT teams. • Stay current with emerging security threats, tools, and best practices. Collaboration & Continuous Improvement • Work cross-functionally to embed security into Firm processes and technology. • Educate employees on security best practices to enhance awareness and reduce risks. • Participate in Information Security and Governance projects, security initiatives, and third-party penetration testing. Requirements: Bachelor's degree in a technical, scientific, or quantitative field OR equivalent work experience in IT/security. 4+ years of experience in an Information Security or IT security operations Familiarity with security frameworks (e.g., NIST, ISO 27001, CIS), governance controls, MITRE ATT&CK. Hands-on experience with security tools such as SIEM, SOAR, EDR/AV, NAC, DLP, application control, email security, and vulnerability scanners. Industry certifications (e.g. CySA+, CEH, CISSP, etc) are a plus. Strong analytical, problem-solving, and communication skills. Ability to work in a fast-paced environment while managing multiple priorities. The anticipated salary range for this position is $ 100-120K. Actual salary will be based on a variety of factors including relevant experience, knowledge, skills and other factors permitted by law. A range of medical, dental, vision, retirement, paid time off, bonus and/or other benefits are available.