Principal Information Security Engineer

American Sugar Refining, Inc.
West Palm Beach, FL, United States
5 days ago
Apply on jobs.localjobnetwork.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
8 years minimum
Working hours
Regular working hours

Tech stack

Business Software Business Systems Software as a Service Cloud Computing Cloud Computing Security Cyber Security Information Systems Computer Networks Databases Data Centers Software Design Documents Multi-Factor Authentication
+28 more
Identity and Access Management IT Management Information Technology Operations Intrusion Detection and Prevention Intrusion Detection Systems Virtual Private Networks (VPN) Information Systems Security Architecture Professional Network Security Routing Network Segmentation Remote Access Technology Zero Trust Network Access Security Information and Event Management Single Sign-On Systems Integration Technical Data Management Systems Virtual Local Area Networks Software Vulnerability Management Network Access Control Cloud Platform System In-Plane Switching (IPS) Software Security HybridCloud Firewalls (Computer Science) Information Technology Hardware Infrastructure Network Server Vulnerability Analysis

Job description

The Principal IT Security Engineer reports to the Sr. Manager of Information Security and serves as the technical lead for securing the company’s enterprise IT environment across data centers, cloud platforms, corporate networks, endpoints, and business applications. The role emphasizes enterprise security engineering, network and identity architecture, and the protection of the systems and data that run the business, with awareness of how corporate IT interfaces with plant and OT environments where those boundaries intersect.

The primary focus is to design, implement, and operate security controls for complex, hybrid, and cloud-first environments, with a strong emphasis on Zero Trust, microsegmentation, secure connectivity, identity, and defense-in-depth. This role partners closely with infrastructure, cloud, application, and operations teams to advance the security architecture and drive execution of the 1-3 year enterprise security and segmentation roadmap., * Design, implement, and operate enterprise security controls across endpoints, servers, business applications, data, cloud and on-prem infrastructure, mobile, and networking, including firewalls, IDS/IPS, secure remote access, VPN, ZTNA, and network access control.

  • Lead the design and rollout of network microsegmentation and zone-based architectures using technologies such as identity-based segmentation, VLANs, next-generation firewalls, and policy-based controls across on-premises and cloud environments.
  • Function as a Subject Matter Expert (SME) for security integrations and authentication elements, including firewall and network security, conditional access, VPN, Zero Trust network architecture, SSO federation, MFA, and email security solutions.
  • Engineer and maintain secure connectivity between corporate IT and plant networks where those environments interconnect, applying least-privilege and defense-in-depth principles at the IT/OT boundary.
  • Collaborate with network, infrastructure, cloud, and application teams to design and review security architectures for new and existing business systems, SaaS platforms, and infrastructure services.
  • Implement and administer security tools and platforms across endpoints, servers, network, identity, and cloud environments, including EDR, SIEM/SOC integrations, vulnerability management, and secure remote access solutions.
  • Perform security engineering and threat modeling for enterprise systems and integrations, identifying and mitigating risks introduced by new connectivity, vendors, and technologies.
  • Develop, test, and maintain incident detection and response playbooks for enterprise security events, supporting the SOC and IT operations teams during investigations and recovery efforts.
  • Drive vulnerability management for network, infrastructure, and platform components and coordinate safe remediation activities across production business systems.
  • Contribute to and maintain security standards, reference architectures, and configuration baselines for data centers, cloud environments, corporate networks, and identity platforms.
  • Create, manage, and update Standard Operating Procedures, and coordinate cross-team communications and activities that improve and sustain operational security functions.
  • Provide mentorship and technical guidance to infrastructure, operations, and security team members on security best practices and secure design principles.
  • Stay current on threats and trends affecting enterprise IT environments and evaluate new solutions that support segmentation, identity, visibility, and protection objectives.
  • Implement, configure, and operate application allowlisting / default-deny Zero Trust endpoint tooling (e.g., ThreatLocker, AppLocker, Airlock, or equivalent), including policy design, ringfencing, exception governance, and integration with EDR and SIEM.

Requirements

  • Eight (8) or more years of hands-on experience as an Information Security Engineer or Network Security Engineer in enterprise environments.
  • Significant experience designing and operating enterprise security controls such as firewalls, segmentation, VPN/ZTNA, NAC, EDR, and SIEM platforms at scale.
  • Proven experience planning and executing network segmentation or microsegmentation programs, including firewall-based segmentation, SDN, or identity-based segmentation.
  • Broad security experience in heterogeneous environments spanning diverse applications, systems, databases, SaaS solutions, and hybrid cloud and on-premises platforms.
  • Working familiarity with manufacturing or plant environments and the IT/OT boundary is a plus.
  • Demonstrated experience implementing and configuring application allowlisting / default-deny Zero Trust endpoint tooling (e.g., ThreatLocker, AppLocker, Airlock, or equivalent) in enterprise environments., * Bachelor’s degree in Information Systems, Computer Science, Engineering, or a related field, or equivalent experience.
  • In lieu of a Bachelor’s degree, eight (8) or more years of relevant professional experience will be considered.
  • Relevant certifications preferred, including CISSP, CCNP Security, CCSP, or comparable enterprise security and network-focused certifications.

ESSENTIAL CAPABILITIES

  • Strong expertise in network security, routing and switching fundamentals, firewalls, secure remote access, and segmentation or microsegmentation technologies.
  • Experience designing and implementing Zero Trust-aligned architectures, including identity-aware access controls and least-privilege network policies.
  • Expert understanding of cloud and on-premises security, identity and access management, multi-factor authentication, SSO federation, and related security protocols.
  • Strong expertise with cloud security and firewall technologies, and a working understanding of security architecture models and application security.
  • Demonstrated knowledge of common adversary tactics, techniques, and procedures (TTPs) and relevant network defense and intelligence frameworks.
  • Ability to collect, analyze, and interpret technical data from multiple tools, including firewalls, SIEM platforms, EDR solutions, and vulnerability scanners, and produce clear, actionable recommendations.
  • Awareness of how corporate IT environments interface with plant and OT systems, sufficient to design safe connectivity and segmentation at that boundary.
  • Ability to create clear, concise documentation for IT leadership, business stakeholders, and technical teams, including architecture and design documents for new and pre-existing solutions.
  • Strong communication, collaboration, and leadership skills, with the ability to influence cross-functional teams and drive alignment on critical security decisions and policies.

About the company

Florida Crystals Corporation is a fully integrated cane sugar company. Florida Crystals regeneratively farms sugarcane and rice in South Florida, where it owns two sugar mills, a sugar refinery, a packaging and distribution center, Florida’s only rice mill, a compost facility, and one of the largest renewable power plants of its kind in the U.S., which uses sugarcane fiber to generate eco-friendly energy that powers its sugar operations. Florida Crystals owns one of the largest Regenerative Organic Certified farms in the U.S. and its Florida Crystals products are the only ROC sugar grown and milled sugar in the country. Florida Crystals owns ASR Group International, Inc., a holding company that conducts operations through its subsidiaries. The ASR Group family of companies make up the world’s largest refiner and marketer of cane sugar. Florida Crystals is headquartered in West Palm Beach, Florida. Learn more at www.FloridaCrystalsCorp.com.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.localjobnetwork.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:04 min

Database evolution and the funding behind vector databases

Erik Bamberg · LIVE

2:04 min

Enhancing network privacy with routing fees and onion routing

Andreas M Antonopoulos · LIVE

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:01 min

Managing application isolation via pluggable database models

Wei Hu Wei Hu · World Congress 2022

1:51 min

Overview of the three Google Maps routing applications

Germán Álvarez · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

Videos

See all

Related articles

See all