> Markdown version of [/jobs/ext/571547-engineer-it-information-security-operations](https://www.wearedevelopers.com/jobs/ext/571547-engineer-it-information-security-operations). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Engineer, IT Information Security Operations - **Company:** PSKW LLC dba ConnectiveRx LLC - **Location:** Pittsburgh, PA, United States - **Experience:** Experienced - **Salary:** $103,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Amazon Web Services, Software System Penetration Testing, Cloud Computing Security, Cyber Security, Identity and Access Management, Networking Hardware, Intrusion Detection Systems, OSI Models, Network Security, Linux Security Modules, Log Analysis, Azure Active Directory, Phishing, Security Information and Event Management, TCP/IP, Software Vulnerability Management, Snort (Software), Office365, Firewalls (Computer Science), Network Server, Cisco - **Published:** June 12, 2026 - **Apply:** https://www.juju.com/job/00000000g7esj0 ## About the Role What we need from you: + Security focused degree and/or certifications a plus (e.g., BS/MS in Cybersecurity or related discipline, CISSP, CISA, etc) + 3+ years of Information Security / Cybersecurity experience + Strong knowledge of Information Security / Cybersecurity related technologies, processes, and tools. Minimum working knowledge of penetration testing, vulnerability management, SIEM/log analysis, TCP/IP, OSI Model, network security, endpoint security, identity and access control, Active Directory, Windows/Linux security, email security, DLP concepts, policy and governance, detection/monitoring, incident response, authentication concepts and asset discovery. + Network security concepts and products (e.g., firewall (Cisco, AWS Network Firewall), network (e.g., Cisco, Meraki), email (O365, Avanan), IDS/IPS (e.g., Snort, Suricata). Cisco Umbrella a plus). + Endpoint security products and concepts (e.g., malware protection, network protection, forensics, DLP, compliance. Bitdefender and Incydr a plus). + Security monitoring (SIEM), analysis and resolution of security events/alarms. AlienVault a plus. + Identity and access management concepts (e.g., Azure Active Directory, SSO, user access reviews). + Implementing NIST CSF, CIS top 20, SOC 2, PCI, HIPAA or related security frameworks. + Implementing Amazon AWS security tools and concepts. + Identifying assets (e.g., servers, network devices, applications), identifying network layouts and determining security risk and potential solutions. + Strong ability to monitor, test and validate that existing security controls and platforms are functioning as expected (e.g., process and technical auditing). + Strong analytical skills, detail oriented, ability to work autonomously or in groups toward a common goal, resourceful and able to make progress quickly and ability to build relationships, influence and educate on matters related to cybersecurity. ## Description The Information Security Operations Engineer will monitor, manage, and maintain the technologies and processes used to secure company information, systems and networks. The successful candidate must demonstrate a strong ability to manage and improve operational security functions, implement risk-based solutions, develop, and maintain security metrics, promote security best practices and training across the organization and partner with stakeholders from various IT and business teams. Focus areas will include managing security requests, conducting user access reviews, developing, and maintaining security documentation, network and endpoint security management, cloud security, vulnerability management, identity and access management, incident response, SIEM and log management and security monitoring and reporting. Additionally, the candidate will be responsible to contributing to internal control testing for client and regulatory audits (e.g., PCI, HIPAA, SOC1/2). Responsibilities What you will do: + Monitor and manage the Information Security request queue, including analysis and resolution of outstanding issues. + Manage endpoint and network security environments including overall health, policy modifications, troubleshooting/resolving issues and producing monthly health metrics for workstations, servers, and identities. + Work directly with the Information Security Team and Security Operations Center (SOC) to analyze and resolve security events/alerts. This includes some monitoring and management of the SIEM platform. + Manage and maintain Information Security training and awareness campaigns (e.g., training, phishing). Developing/monitoring campaigns, ensuring required training is complete, producing reports/metrics and recommending improvements to the current process. + Conduct internal security control testing. Includes gathering, uploading, and reviewing evidence within the GRC (Governance, Risk and Compliance) tool. Supporting PCI, SOC and related audits. + Other duties as assigned. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks)