Information Security Engineer

Insight Global
Fountain Valley, CA, United States
9 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Working hours
Regular working hours

Tech stack

Microsoft Access JavaScript (Programming Language) Application Programming Interfaces (APIs) Artificial Intelligence Amazon Web Services Proxy Servers ARM Architecture Automation of Tests Microsoft Azure Cloud Computing Cloud Computing Security Cloud Engineering
+41 more
Cyber Security Computer Programming System Configuration Continuous Integration Domain Name System (DNS) Hypertext Transfer Protocols (HTTP) Identity and Access Management JSON Python (Programming Language) Network Security Machine Learning Microsoft Security Essentials Routing Windows PowerShell Role-Based Access Control Microsoft Copilot Security Information and Event Management Systems Integration TCP/IP Software Vulnerability Management Scripting Retrieval-Augmented Generation Large Language Models Software Troubleshooting Generative AI Firewalls (Computer Science) Agentic-AI Git Tanium Platform Expertise AI Platforms Kubernetes Palo Alto Networks Cortex XSOAR Platform Restful APIs Terraform Webhooks Software Version Control Devsecops Serverless Computing Security Orchestration, Automation & Response Vulnerability Analysis

Job description

The Information Security Engineer II is responsible for the engineering, architecture, implementation, integration, optimization, and ongoing improvement of enterprise information security technologies. This position is a hands-on security engineering role focused on designing and enhancing security capabilities across the organization’s cybersecurity technology portfolio. The Engineer will work closely with Information Security, Infrastructure, Cloud, IAM, Network, Application, and other technology teams to develop secure, scalable, and automated solutions. A significant focus of this position will be security orchestration and automation using Palo Alto Cortex XSOAR, including the development and maintenance of playbooks, integrations, automations, and workflows. The position will also support the organization’s growing Artificial Intelligence Security program, including evaluating and engineering controls to protect the use of Generative AI, Large Language Models, AI-enabled applications, AI agents, and emerging AI technologies. This is not a primary Security Operations Center or incident-response position. However, the Engineer must understand the security incident response lifecycle and be capable of engineering technologies, integrations, workflows, and automations that support detection, investigation, containment, remediation, and recovery activities., A SOC Analyst An incident queue analyst A primary incident responder A help-desk or desktop-support engineer A vulnerability scanning operator A firewall-rule administrator The Engineer may assist with complex security events or investigations when engineering expertise is required, but the primary responsibility of the role is to design, build, automate, integrate, architect, and improve security capabilities.

Requirements

Required Technical Skills Experience in cybersecurity engineering, security architecture, information security, infrastructure security, or a related technical discipline. Hands-on experience implementing, integrating, configuring, or supporting enterprise cybersecurity technologies. Hands-on experience with security orchestration, automation, and response technologies, preferably Palo Alto Cortex XSOAR. Demonstrated experience developing or modifying security automation workflows and playbooks. Experience integrating technologies using REST APIs, JSON, webhooks, or similar integration technologies. Working knowledge of scripting or programming, preferably: Python PowerShell JavaScript or similar scripting languages Understanding of enterprise networking concepts including TCP/IP, DNS, HTTP/HTTPS, firewalls, proxies, routing, segmentation, and network security controls. Understanding of endpoint security concepts and technologies. Understanding of identity and access management concepts including authentication, authorization, MFA, privileged access, and least privilege. Understanding of vulnerability management and security configuration concepts. Ability to troubleshoot complex technical issues across multiple systems and security platforms. Ability to create technical documentation, architecture diagrams, implementation procedures, and operational documentation. Security Operations Knowledge Although this position is not responsible for primary incident-response operations, candidates must understand the security incident response lifecycle, including: Preparation Detection and Analysis Containment Eradication Recovery Post-Incident Activities / Lessons Learned The Engineer should understand how cybersecurity technologies and automation can support each stage of the incident lifecycle. Required AI Security Knowledge Candidates should demonstrate knowledge of emerging AI and Generative AI security concepts.

Experience may include securing or evaluating

Generative AI platforms Large Language Models AI applications AI agents Copilot-style technologies AI APIs and integrations Retrieval-Augmented Generation architectures Enterprise AI platforms Candidates should understand common AI security concerns including prompt injection, sensitive data exposure, excessive agency, insecure output handling, AI application access controls, and third-party AI risks. Deep AI development or machine-learning engineering experience is not required, but candidates should demonstrate a strong interest in AI Security and the ability to rapidly develop expertise in emerging AI technologies. The following qualifications are highly desirable but are not required. Cloud Security Experience securing AWS and/or Microsoft Azure environments. Experience with Cloud Security Posture Management or Cloud-Native Application Protection Platforms. Experience with platforms such as Wiz or comparable cloud security technologies. Understanding of cloud IAM, workloads, containers, Kubernetes, serverless technologies, and cloud-native security controls. Familiarity with Infrastructure as Code technologies such as Terraform. Familiarity with security within CI/CD and DevSecOps environments. Security Automation Advanced Cortex XSOAR playbook development experience. Development of custom XSOAR integrations or automation scripts. Python development experience. Experience working with REST APIs and API authentication. Experience using Git or other version-control systems. Experience developing reusable automation components and security engineering frameworks. Security Technology Experience

Experience with one or more technologies such as

Palo Alto Cortex XSOAR Palo Alto Cortex XDR Palo Alto Networks Next-Generation Firewalls Prisma Access Wiz Tanium Proofpoint BeyondTrust Claroty Recorded Future Microsoft security technologies AWS security technologies Azure security technologies SIEM, SOAR, EDR, NDR, CSPM, CNAPP, ITDR, PAM, or vulnerability-management platforms Experience with these specific products is preferred but equivalent experience with comparable enterprise security platforms is acceptable.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Loading talks and stories from around this role…