Principal Security Engineer
Role details
Job location
Tech stack
Job description
The Principal Security Engineer will be responsible for designing and implementing robust security solutions. This role involves performing security reviews, identifying gaps in security architecture, and developing a security risk management plan. The engineer will define and document how new systems or interfaces impact the security posture of the current environment and will plan, design, test, and enhance operational security and resiliency., * Design and implement security solutions to protect data and systems.
- Perform security reviews and identify gaps in security architecture.
- Develop and maintain a security risk management plan.
- Define and document the security impact of new systems and interfaces.
- Evaluate security architectures and designs to determine the adequacy of security controls.
- Plan, design, test, and enhance the operational security and resiliency of computers, VoIP, network infrastructure, backups, and network-connected medical devices.
Requirements
Education: A Bachelor's Degree in Computer Science, Information Security, or a related field is required. A combination of relevant education and experience may be considered in lieu of a degree.
Experience: 10 years of experience in Information Security and 10 years of experience in systems administration, architecting, developing, and designing complex systems and networking are required. Experience with cloud security principles and practices (e.g., AWS, Azure, Google Cloud Platform) and securing virtualized environments is also required.
Technical Skills: A demonstrated understanding of cybersecurity principles, best practices, and industry standards such as ISO 27001, NIST, and CIS Controls is required. This includes an understanding of encryption methodologies, network architecture, protocols, and security technologies (firewalls, IDS/IPS, VPN, SIEM, endpoint protection), and proficiency in security frameworks like MITRE ATT&CK and the Cyber Kill Chain.
Preferred Qualifications
- Master's Degree in Computer Science, Management, or a related field.
- CISSP - Cert Info Sys Security Prof or GSE - GIAC Security Essentials certification.
- Background in a healthcare environment.
- Experience with Bio-Med / IoT, or SCADA systems preferred.
- Strong documentation skills.