TITLE: Security Engineer
TERM: Direct Hire
ESSENTIAL DUTIES AND RESPONSIBILITIES:
Our client is seeking a Security Engineer for a direct hire opportunity. This individual will play a key role as a subject matter expert in helping to lead and manage Company's security tools and key service providers that are used to support the company’s overall security and data privacy programs.
This role will provide security architectural advice and guidance related to all Company existing and new systems that are used to support our restaurants, ecommerce platform (Web & Mobile) and corporate applications. These systems comprise of on premise systems, as well as cloud and third-party platforms (Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS)).
The security engineer will provide thought leadership and guidance in helping to shape Company’s security capabilities and influencing the overall security program.
- The ongoing integration of information security architecture with business strategies and privacy requirements
- Threat and Vulnerability management process oversight and communicate threat and vulnerability observations clearly to leaders and subject matter experts properly relaying risk factors. Drive finding through remediation.
- Partner with business and IT to ensure that risks are clearly articulated in a manner that is understood by business and technology audiences
- Initiate, facilitate, and promote activities to create information security awareness within the company.
- Develop security metrics and produce security reporting including dashboards.
- Assist in coordinating stakeholders across Company to socialize and drive change regarding IT security and risk management
- Apply leading-edge principles, theories, and concepts to the development, maintenance, and implementation of information security standards, procedures, and guidelines.
- Investigate any misuse or improper actions relating to IT, security, or compliance activities.
- Familiar with Incident Response processes and incident response tabletop exercise.
- Research and implement new technologies as required to support the ever-changing security landscape
RESPONSIBILITIES:
In this role, the Security Engineer will be responsible for providing configuration management and ongoing support of Company’s vulnerability management and Anti-phishing programs. In addition to this, the role will provide technical leadership and oversight in the management of our Security Partners responsible for providing Company’s Security Information and Event Management (SIEM) and Endpoint Detection and Response platforms.
This role will provide level 2/ level 3 operational support and investigation of security related events and incidents. Helping to drive issues through remediation and incorporating the learnings back into its systems and processes.
The security engineer will work with cross functional teams at all levels to help educate them on security requirements, provide technical leadership of security tools, and to help drive security tool adoption and promote security awareness.
The security engineer will participate in system and process audits to ensure ongoing compliance (SOX, PCI) and adherence to Company’s Information Security Policies and Standards. This role will also participate in performing risk assessments on current internal systems, as well as assess the security controls of current and proposed vendors in alignment with Company’s information security policies and standards.
- Understanding of information security architecture and ethical hacking
- Advanced understanding of network protocols
- Proven experience in designing and deploying enterprise security services such as Identity and Access Management, Privileged Access Management, Certificate and Key Management, Data Protection, and Vulnerability Management
- Experienced in API architecture and implementation, with API security hardening, security assessment and monitoring experience preferred
- Strong knowledge of security best practices for web application design, development, and testing techniques preferred
- Previous professional experience with enterprise SIEM is required (IBM QRadar preferred)
- Experience with PCI and audits is preferred
- Knowledge of SANS 20 Security Controls, NIST-CSF, SOC 2 Type II, ISO 27001/02 etc.
- Ability to explain detailed findings to non-technical professionals
- Excellent report writing and presentation skills
- Able to work independently but also as part of a team
- Flexibility to change direction and manage conflicting demands
- Outstanding organizational and data analytics skills
- Comfortable working multiple projects
WHO YOU ARE:
- HUMBLE: You feel there is always opportunity to further your personal and professional growth. You have a bachelor’s degree in accounting, along with awesome written and verbal communication skills.
- HUNGRY: You continue to pursue excellence, particularly in fast-paced, deadline-driven environments.
- SMART: You have CISSP, GCIH, GWAPT, a Native Cloud Security certification (AWS or GCP), or similar experience. Additional certification like ITIL, PMP a plus