Overview:
The Security Engineer is responsible for ensuring the secure and resilient architecture of the organization’s IT infrastructure. This role involves maintaining system integrity, supporting operational efficiency, and implementing robust security measures.
Key Responsibilities:
- Reports to the Director of Security Operations
- Design and maintain secure, scalable, and reliable system architectures to support the organization’s digital assets.
- Collaborate with the Security Operations Analyst to integrate security tools into the IT infrastructure effectively.
- Apply Threat and Vulnerability Management (TVM) practices to assess and mitigate risks, enhancing the security posture.
- Ensure the reliability and performance of security services, continuously improving operational outcomes.
- Troubleshoot and resolve security system issues, working towards continuous system improvement.
- Implement and manage security tools, including firewalls, IDS/IPS, WAF, IAM, RBAC, Zscaler, Crowdstrike, Delinea, JAMF, and Intune.
- Develop and maintain security policies and procedures to ensure compliance with industry standards and regulatory requirements.
- Conduct regular security audits and assessments to identify vulnerabilities and recommend appropriate mitigation strategies.
- Collaborate with other IT teams to ensure the secure configuration and maintenance of cloud platforms (AWS, Azure, GCP).
- Participate in the design and implementation of secure network architectures.
- Provide technical guidance and mentorship to junior security team members.
- Stay updated with the latest security trends, threats, and technologies to continuously improve the organization’s security posture.
- Lead and participate in incident response activities, ensuring quick and effective resolution of security incidents.
- Participate in On Call rotation as necessary.
Qualifications:
- Bachelor’s degree in Computer Science, Information Security, or a related technical field, or equivalent practical experience.
- 5+ years of experience in IT security or system administration, with a focus on security engineering.
- Strong understanding of security principles, tools, and technologies (e.g., firewalls, IDS/IPS, vulnerability management, WAF, IAM, RBAC, Zscaler, Crowdstrike, Delinea, JAMF, Intune).
- Experience with cloud platforms and services (AWS, Azure, GCP) is highly desirable.
- Proficiency in conducting threat and vulnerability assessments and implementing mitigation strategies.
- Excellent problem-solving skills and the ability to work independently.
- Strong analytical skills and attention to detail.
- Effective communication and teamwork skills, with the ability to collaborate across departments and present technical information to non-technical stakeholders.
- Certifications such as Security, SSCP or CEH, or similar are a plus.
- Ability to manage multiple tasks and projects simultaneously in a fast-paced environment.
- Commitment to continuous learning and improvement in the field of cybersecurity.