Cybersecurity Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
The Security Engineer oversees and provides direction, and development for the security assessment and vulnerability management programs. He/She will work with leadership to determine proper security configurations. This position is hands-on and includes performing security risk assessments on new and current technologies, analysis and reporting on vulnerabilities as part of the overall vulnerability management function, collaboration with Security Architecture on projects, and consulting to provide subject matter expertise. Essential Functions:
- Perform security assessments on hardware/software (on premise and cloud) technologies and third parties (e.g., vendors and service providers).
- Manage and mature the security assessment and vulnerability management programs. Create and maintain system, metrics, procedural and support documentation.
- Collect information and assess emerging threats including software vulnerabilities. Coordinate the triage of and response to vulnerability information. Disseminate this information regularly to firm staff and management as appropriate.
- Provide input into the strategic decisions that affect the functional area of responsibility and participate in long-term strategy and planning for Information Security.
- Subject matter expert for Information Security, consulting to technical and non-technical management, and attorneys as necessary.
- Contribute to the development and maintenance of security policies, standards, processes and guidelines.
- Lead and mentor the security engineering team.
- Participate in issues management (exception and findings requests) as needed.
Requirements
- Education, Work Experience, Skills
- Six (6) years of direct work experience in security assessments, vulnerability management, or similar.
- 4-year college degree in information technology or equivalent experience.
- Experience with assessments in Windows and Unix is required.
- Knowledge of IT security controls and IT infrastructure is required.
- Experience with cloud technologies such as Microsoft Azure IaaS and SaaS is required.
- Strong knowledge on Security frameworks and technologies such as ISO 27001, NIST, SOC, SIG… is required.
- Scripting/automation experience such as Python, PowerShell and API integrations is preferred.
- Outstanding communication (verbal, written, visualization and listening) skills.
- Self-starter who can work independently as well as in a team setting.
- Interest in understanding customer perspective to aid in the development of the right solution.
- Commitment to delivering quality solutions.
- Ability to communicate technical topics to a non-technical audience.
- The ability to research and solve complex security and networking challenges.
- Demonstrated personal skills to effectively cooperate and communicate with business partners.
- Creative problem solving, analytical, industry knowledge, project management and communication.
Technologies/Software
- Hands on experience of cloud capabilities, controls, and implementation.
- Hands on experience of security administration and role based security controls.
- Hands on experience of authentication technologies and their interaction with different platforms, both on-site and remote.
- Hands on experience of vulnerability assessment and forensic tools.
- Hands on experience of vulnerability assessment and forensic tools of Identity & Access Management technologies.
- Knowledge of security technology capabilities.
- Knowledge of anti-malware technologies.
- Knowledge of Intrusion Detection and Intrusion Prevention technical capabilities.
- Knowledge of both client and server firewalling technologies and their configuration and administration.
- Knowledge of security systems log correlation and analysis.
- Knowledge of data encryption technologies.
- Knowledge of Endpoint Detection and Response tools.
- Knowledge of web filtering and email SPAM prevention techniques.
Certifications
- Cloud security certifications, Certified Ethical Hacker (CEH), Offensive Security Certified Professional (OSCP) are preferred.
Skills: Analysis Skills, Application Programming Interface (API), Authentication, Cloud Computing, Communication Skills, Computer Security, Consulting, Content Filtering Software, Cryptography, Firewalls, ISO (International Organization for Standardization), Identity Data Management, Information Technology & Information Systems, Information/Data Security (InfoSec), Infrastructure as a Service (IaaS), Internet Security, Interpersonal Skills, Intrusion Detection and Prevention (IDP), Leadership, Malware, Mentoring, Metrics, Microsoft Windows Azure, Microsoft Windows Operating System, People Management, Presentation/Verbal Skills, Problem Solving Skills, Project/Program Management, Python Programming/Scripting Language, Research Skills, Risk Analysis, Scripting (Scripting Languages), Security Analysis, Security Architecture, Security Monitoring, Software as a Service (SaaS), Spam Filtering, Strategic Planning, Support Documentation, Systems Maintenance, Technical Consulting, Technical Leadership, Technology Analysis, U.S. National Institute of Standards and Technology (NIST), Unix Operating Systems, Windows PowerShell
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Understanding and Mitigating Common Web Vulnerabilities
What Are The Top Skills Required For Azure Developers?
Dev Digest 134 - Where pixels sing?
Best Paying Jobs in Technology