Sr. Security Engineer

Insight Global
Schiller Park, IL, United States
about 1 month ago
Apply on jobs.insightglobal.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
1 year minimum
Compensation
$85,280.0 - $106,080.0
Working hours
Regular working hours

Tech stack

Proxy Servers Systems Engineering Cloud Computing Security Cyber Security Computer Networks Information Leak Prevention Data Loss Domain Name System Security Extensions Identity and Access Management Intrusion Detection Systems Phishing Runbook
+6 more
Security Information and Event Management Data Streaming System Availability Firewalls (Computer Science) Information Technology Blue Team (Cyber Security)

Job description

The Security Team is responsible for securing Encore’s infrastructure to ensure the confidentiality, integrity, and availability of systems and resources. The Security Operations Engineer works to prevent, detect, and respond to security events while also supporting the operation, maintenance, and continuous improvement of Encore’s security platforms and controls.

This role works closely with systems engineers, network engineers, application teams, and senior security engineers to maintain Encore’s global security posture. The Security Operations Engineer I monitors emerging threats, investigates security events, supports security tool deployments and enhancements, and coordinates with internal teams to reduce risk and improve resilience., Security Monitoring and Detection

  • Monitor security alerts, network traffic, and user risk/activity to identify and respond to potential security incidents.
  • Monitor data flows and user activities to detect and help prevent potential data loss.
  • Perform triage and initial investigation of security events and suspicious activity.
  • Identify false positives, tune detections under guidance, and recommend improvements.

Security Incident Management

  • Execute incident response activities according to documented playbooks and procedures.
  • Document incidents, findings, root causes, and remediation actions.
  • Investigate security events, categorize incidents, and escalate critical or complex issues as appropriate.
  • Assist with root cause analysis and participate in post-incident reviews.
  • Support containment, eradication, and recovery efforts during incidents.

Security Platform Operations

  • Support the operation, monitoring, and health of security platforms including SIEM, EDR/MDR, email security, DNS security, identity protection, and DLP.
  • Assist with SIEM onboarding, log parsing, tuning, and alert optimization.
  • Assist with configuration, testing, and deployment of new security tools and capabilities.
  • Participate in security platform upgrades, changes, and maintenance activities.
  • Follow change management processes for security system updates and enhancements.
  • Assist in troubleshooting security product issues and integration failures.

Reporting and Communication

  • Generate clear and concise incident reports, findings, and analysis summaries.
  • Communicate security risks, incidents, and recommended actions to stakeholders as appropriate.
  • Collaborate with cross-functional teams to align security operations with organizational objectives.
  • Contribute to documentation, runbooks, playbooks, and operational procedures.
  • Perform other duties as assigned.

Requirements

  • 1-3 years of general IT experience (help desk or desktop support) .
  • 1-3 years of incident response experience.
  • 1-3 years of experience with: DNS security, Endpoint Detection and Response, Phishing Analysis, Email Security, Data Loss Prevention, Security Awareness Training, Identity Protection, Cloud Security.
  • Proficient in security operations, understanding of Blue Team and incident response tactics.
  • Familiarity with security technologies and tools: including IDS/IPS, firewalls, proxies, SIEM, EDR.
  • Outstanding communication and analytical skills.
  • Understanding of regulatory compliance and risk management frameworks.
  • Logical thinking ability to translate security requirements into precise plans to mitigate risk.
  • Relevant security certifications.

Benefits & conditions

Benefit packages for this role will start on the 1st day of employment and include medical, dental, and vision insurance, as well as HSA, FSA, and DCFSA account options, and 401k retirement account access with employer matching. Employees in this role are also entitled to paid sick leave and/or other paid time off as provided by applicable law.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on jobs.insightglobal.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

50 sec

Repurposing retired smartphones into servers and mitigating data loss

Chris Heilmann +1 · LIVE

1:29 min

Evaluating phishing emails that leverage artificial time constraints

Mauro Verderosa · LIVE

2:50 min

Introduction and the value of runbooks

Hila Fish · World Congress 2023

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

41 sec

Massive client data loss and bio-digital storage

Chris Heilmann +1 · LIVE

Videos

See all

Related articles

See all