Information Security Engineer
Description
The Information Security Engineer will ensure the confidentiality, integrity, and availability of all IT assets within the Firm. This role involves both strategic oversight and hands-on security operations. Role and responsibilities: Security Operations & Incident Response • Participate in the Vulnerability Management Program, including asset scans, documentation, and reporting. • Research, prioritize, and remediate vulnerabilities in coordination with IT teams. • Manage the relationship with the Managed Threat Detection & Response vendor to ensure quality service. • Optimize SIEM alerting to reduce false positives, ensure comprehensive log ingestion, and strengthen detection capabilities. • Monitor and respond to SIEM (Security Information and Event Management) alerts, ensuring appropriate verbosity. • Conduct incident response and recovery exercises to enhance the Firm’s security posture. Security Governance & Compliance • Develop and validate controls, safeguards, and standards for the information security program. • Implement and document Firm security practices in alignment with policies and industry standards. • Monitor, track, and report key performance indicators (KPIs) for security program effectiveness. • Assess security program effectiveness, identifying gaps, and recommending improvements. • Conduct security evaluations for third-party vendors and facilitate access reviews. • Respond to due diligence questionnaires related to information security. Security Tools & Technology Management • Deploy, manage, and maintain security tools, ensuring alignment with security objectives. • Evaluate and recommend security solutions and vendors. • Assist with IT asset inventory control in coordination with other IT teams. • Stay current with emerging security threats, tools, and best practices. Collaboration & Continuous Improvement • Work cross-functionally to embed security into Firm processes and technology. • Educate employees on security best practices to enhance awareness and reduce risks. • Participate in Information Security and Governance projects, security initiatives, and third-party penetration testing. Requirements: Bachelor's degree in a technical, scientific, or quantitative field OR equivalent work experience in IT/security. 4+ years of experience in an Information Security or IT security operations Familiarity with security frameworks (e.g., NIST, ISO 27001, CIS), governance controls, MITRE ATT&CK. Hands-on experience with security tools such as SIEM, SOAR, EDR/AV, NAC, DLP, application control, email security, and vulnerability scanners. Industry certifications (e.g. CySA+, CEH, CISSP, etc) are a plus. Strong analytical, problem-solving, and communication skills. Ability to work in a fast-paced environment while managing multiple priorities. The anticipated salary range for this position is $ 100-120K. Actual salary will be based on a variety of factors including relevant experience, knowledge, skills and other factors permitted by law. A range of medical, dental, vision, retirement, paid time off, bonus and/or other benefits are available.