It Security Engineer

Achilles
Municipality of Burgos, Spain
2 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours
Languages
English, Spanish
Experience level
Senior

Job location

Municipality of Burgos, Spain

Tech stack

Software System Penetration Testing
Azure
Computer Security
Domain-Based Message Authentication Reporting and Conformance (DMARC)
DNS
Intrusion Detection Systems
Virtual Private Networks (VPN)
Network Security
Network Architecture
Network Monitoring
Routing
Network Protocols
PCI Data Security Standards
Powershell
Azure
Security Information and Event Management
TCP/IP
Information Security Management System
Cloud Platform System
Firewalls (Computer Science)
Microsoft InTune
Cybercrime
Qualys
Vulnerability Analysis

Job description

pAs an IT Security Engineer, you will be responsible for protecting systems, networks and data from cyber threats and ensuring compliance with security standards.Identification of vulnerabilities, responding to security incidents and conducting regular assessments of the Achilles security posture./ppbr/ppResults Responsibilities /ppbr/ppSecurity Operations /pullibThreat Monitoring: /b Monitor network traffic for suspicious activity, detect and respond to potential threats, and provide recommendations for mitigation./lilibSecurity Audits: /b Conduct internal audits of Achilles teams to ensure ISO *****, SOC 2 Type 2 and ENS requirements are met./lilibFirewall and VPN Management: /b Configure and manage firewalls, VPNs, and related network security devices to ensure optimal protection./lilibCollaboration: /b Work with other IT teams to ensure security is embedded in infrastructure designs and processes./lilibPatch Management: /b Ensure timely updates and patches to network devices to mitigate vulnerabilities./lilibDocumentation: /b Maintain detailed documentation of network configurations, security incidents, and changes made to systems./li /ulpbr/ppInformation Security /pullibCompliance and Audits: /b Ensuring that the organisation complies with ISO ***** requirements and other related standards.Preparing for internal and external audits./lilibIncident Management: /b Handling security incidents and breaches, ensuring proper reporting and analysis.Ensuring that corrective actions from security incidents are implemented and that lessons learned are incorporated into future improvements./lilibVendor and Third- /bParty Management: Ensuring that third-party vendors and service providers comply with the organisation's security policies and ISO *****, SOC 2 Type 2 and ENS requirements./lilibContinuous Improvement: /b Monitoring the effectiveness of the ISMS and implementing improvements as needed./lilibCollaboration: /b Working closely with IT, legal, compliance, and other departments to ensure a unified approach to security.Collaborating on the integration of ISO *****, SOC 2 Type 2 and ENS requirements into broader IT or business processes./li /ulpPersonal Development /pulliTaking personal responsibility for skills development, particularly to enhance security capabilities./liliActively participating in the performance management process and taking responsibility for delivering agreed objectives./li /ulpRelationships /pulliManage and develop relationships with third party providers and internal stakeholders /liliBeing a security 'go to person'./li /ul pPERSON SPECIFICATION /ppbr/ppKnowledge /pulliUnderstanding of ISO ***** principles, threat modelling, vulnerability assessments, and risk treatment methodologies./liliDeep understanding of network security principles (e.g., firewalls, VPNs, intrusion detection systems, SIEM), and network protocols./liliKnowledge of encryption methods, access control mechanisms, and endpoint security tools./liliKnowledge of compliance frameworks (ISO *****, SOC 2, ENS, PCI DSS) and best practices./liliKnowledge and experience with securing cloud environments (Azure)./liliKnowledge of network architectures./li /ulpbr/ppExperience /pulliMinimum of 5 years of experience in IT Security, with a proven track record in a similar role./liliTechnical skills: /liliStrong understanding of network protocols, including TCP/IP, DNS, routing, and switching./liliExperience of security toolsets (Mimecast Portal and DMARC, Sophos Central, Qualys, Duo, Taegis XDR, Microsoft Entra ID, Copilot and InTune)./li /ulpbr/pulliSoft skills: /liliStrong problem-solving and analytical skills./liliExcellent communication skills, both verbal and written./liliAbility to work both independently and collaboratively in a fast-paced environment./liliPreferred skills: /liliExperience in conducting penetration testing and threat hunting./liliScripting experience (PowerShell) for automation of security tasks./li /ulpQualifications /pulliIT Diploma level or equivalent experience./liliISO ***** Lead Auditor desirable./liliCISSP, CEH, CCNA Security, or other relevant security certifications are highly desirable./liliFluent in English and Spanish, with the ability to communicate effectively in both written and spoken form./li /ulpbr/ppCompetencies /ppDecision Making /pulliIdentifies and evaluates the range of options open to them /liliArticulates the assumptions made and the risks involved in decisions taken /liliAnalyses information carefully to identify facts, patterns, trends and missing data that may impact on a decision /liliCommunicates decisions clearly to those who are affected /li /ulpAchieving Results /pulliFocuses on performance outcomes despite uncertain or difficult circumstances /liliActively links own efforts to those of others within the team to avoid overlap, rework or delays /liliSpots opportunities to deliver beyond expectations, where this would help others perform more effectively /liliSets own targets and objectives with clear reference to how these contribute to the departmental business plan /li /ulpManaging Change /pulliResponds constructively and quickly to shifting goalposts or changing requirements /liliCopes effectively with rapid change or increased demands /liliReprioritises own work or the work of the team in response to external pressures /liliIs flexible in their approach; adapts their working style to suit the needs of the situation /li /ulpDrive Motivation /pulliAddresses multiple demands without losing focus or energy /liliIncreases efforts in the face of difficulties or obstacles and recovers quickly after setbacks /liliRemains calm and focused during stressful or challenging situations; concentrates only on things they can control or influence /liliEncourages others during challenging times with their positive, can-do attitude /li /ulpCreative Capacity /pulliUses initiative to resolve recurring problems in own role or team /liliTakes calculated risks to improve own performance /liliTries out new ways of working /liliAllocates time to identifying and resolving the root causes of problems /li /ulpbr/p

Requirements

li /ulpbr/ppExperience /pulliMinimum of 5 years of experience in IT Security, with a proven track record in a similar role. /liliTechnical skills: /liliStrong understanding of network protocols, including TCP/IP, DNS, routing, and switching. /liliExperience of security toolsets (Mimecast Portal and DMARC, Sophos Central, Qualys, Duo, Taegis XDR, Microsoft Entra ID, Copilot and InTune). /li /ulpbr/pulliSoft skills: /liliStrong problem-solving and analytical skills. /liliExcellent communication skills, both verbal and written. /liliAbility to work both independently and collaboratively in a fast-paced environment. /liliPreferred skills: /liliExperience in conducting penetration testing and threat hunting. /liliScripting experience (PowerShell) for automation of security tasks. /li /ulpQualifications /pulliIT Diploma level or equivalent experience. /liliISO ***** Lead Auditor desirable. /liliCISSP, CEH, CCNA Security, or other relevant security certifications are highly desirable. /liliFluent in English and Spanish, with the ability to communicate effectively in both written and spoken form. /li /ulpbr/ppCompetencies /ppDecision Making /pulliIdentifies and evaluates the range of options open to them /liliArticulates the assumptions made and the risks involved in decisions taken /liliAnalyses information carefully to identify facts, patterns, trends and missing data that may impact on a decision /liliCommunicates decisions clearly to those who are affected /li /ulpAchieving Results /pulliFocuses on performance outcomes despite uncertain or difficult circumstances /liliActively links own efforts to those of others within the team to avoid overlap, rework or delays /liliSpots opportunities to deliver beyond expectations, where this would help others perform more effectively /liliSets own targets and objectives with clear reference to how these contribute to the departmental business plan /li /ulpManaging Change /pulliResponds constructively and quickly to shifting goalposts or changing requirements /liliCopes effectively with rapid change or increased demands /liliReprioritises own work or the work of the team in response to external pressures /liliIs flexible in their approach; adapts their working style to suit the needs of the situation /li /ulpDrive Motivation /pulliAddresses multiple demands without losing focus or energy /liliIncreases efforts in the face of difficulties or obstacles and recovers quickly after setbacks /liliRemains calm and focused during stressful or challenging situations; concentrates only on things they can control or influence /liliEncourages others during challenging times with their positive, can-do attitude /li /ulpCreative Capacity /pulliUses initiative to resolve recurring problems in own role or team /liliTakes calculated risks to improve own performance /liliTries out new ways of working /liliAllocates time to identifying and resolving the root causes of problems /li /ulpbr/p

Apply for this position