Experience / Education
- 4 years of relevant experience in cyber security roles
- Bachelor’s or equivalent work experience as a Security Engineer
- Certification(s) such as CISSP, CISM, CompTIA Security+ or CompTIA CySA+ are preferred.
Knowledge / Skills / Abilities:
- Working knowledge of network, server and mobile security, with hands-on experience configuring, maintaining and troubleshooting security technologies such as SIEM, firewalls, access control lists (ACLs), IDS/IPS, data loss prevention and mobile device management tools.
- Practical experience administering and configuring endpoint detection and response (EDR) tools, maintaining endpoint protection policies and performing approved host isolation and remediation actions.
- Ability to analyze and correlate security alerts and logs, investigate cybersecurity incidents and recognize when escalation is required.
- Understanding of vulnerability assessment, risk-based prioritization, remediation tracking and validation of security fixes.
- Practical experience configuring and maintaining security controls in cloud environments such as Microsoft Azure or AWS, including secure cloud configurations, logging and security monitoring.
- Working knowledge of identity and access management, including multi-factor authentication, single sign-on, privileged access, account lifecycle management and access reviews.
- Knowledge of system hardening and secure configuration baselines for endpoints, servers and network devices, including the ability to identify configuration drift and implement and test corrective changes using established procedures.
- Knowledge of controls used to protect sensitive company information, including encryption, data masking and secure data handling, in accordance with established security policies and standards.
- Ability to develop and maintain scripts using PowerShell, Python or similar tools to automate security tasks, support investigations and improve reporting.
- Familiarity with security policies, standards and frameworks such as NIST, CIS or ISO 27001, including the ability to validate technical controls and gather evidence for audits.
- Ability to review proposed infrastructure, cloud configurations and technology changes before deployment, apply basic threat modeling techniques, identify security risks and recommend appropriate controls.
- Ability to maintain clear technical documentation and investigation records, prepare accurate security reports and operational metrics, and communicate findings and recommendations to technical and non-technical stakeholders.
- Ability to collaborate across teams, manage assigned tasks, meet agreed deadlines and identify issues that require guidance or a management decision.
- Working knowledge of network access control, segmentation and microsegmentation, including experience with Cisco Identity Services Engine (ISE) to support device authentication, authorization and network access policies that restrict unauthorized access and lateral movement.
- Practical experience configuring and maintaining DNS and web security tools such as Cisco Umbrella, including managing filtering policies, investigating blocked requests and troubleshooting access issues.
An Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, or protected veteran status and will not be discriminated against on the basis of disability
This job description does not state or imply that the above are the only duties and responsibilities assigned to this position. Employees holding this position will be required to perform any other job-related duties as requested by Management.