Overview:
Reporting to the Principal Security Architect, the Information Security Engineer is essential in implementing and maintaining the security measures to safeguard our technology infrastructure against potential threats. The ideal candidate will have a solid foundation in information security principles, be detail-oriented, and possess a strong technical aptitude.
Key Responsibilities:
- Establish comprehensive security hardening standards for operating systems, databases, networks, and applications to protect against vulnerabilities.
- Apply established security hardening standards across operating systems, databases, networks, and applications to enhance our security posture.
- Conduct configuration assessments to identify misconfigurations within the technology stack, working closely with relevant teams for timely remediation.
- Assist in security audits and compliance checks to ensure adherence to hardening standards and security best practices.
- Maintain up-to-date documentation of hardening procedures, standards, and security configurations.
- Work collaboratively with IT, DevOps, and software engineering teams to integrate security practices into the development and operational processes.
- Stay informed about the latest security threats, technologies, and best practices to suggest improvements to hardening standards and procedures.
- Contribute to the development and delivery of security training programs to increase security awareness across the organization.
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or related field, or equivalent experience.
- Security industry relevant certifications (e.g., CISSP, CSSP, GSEC, GCSA)
- 2+ years of experience in information security, specifically in implementing security controls and hardening technologies.
- Familiarity with security frameworks (e.g., NIST, CIS Benchmarks) and understanding of the current threat landscape.
- Experience creating secure templates for IaC tools like Terraform, ansible, and etc.
- Experience automating the enforcement of security standards, such as security configuration tools.
- Strong problem-solving skills and attention to detail.
- Excellent communication skills, with the ability to articulate technical information to non-technical audiences.
- A proactive approach to learning and staying updated on new technologies and security trends.
- Team-oriented mindset with a strong capability to work collaboratively across different departments.