Planned Parenthood

Associate Director, Information Security Engineer

Planned Parenthood • $125K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree with 5+ years of industry experience
  • Experience with SIEM platforms, preferably Splunk
  • Strong understanding of compliance standards (e.g., PCI, HIPAA, NIST)
  • Proficiency in multiple operating systems such as UNIX, Linux, and Windows
  • Experience with network/system IDS/IPS and vulnerability assessment tools
  • Ability to work independently and make critical decisions during escalated events
  • Commitment to Planned Parenthood's mission in Sexual and Reproductive Health

Responsibilities

  • Manage 24/7 security monitoring and threat analysis using SIEM
  • Filter and refine security events to improve monitoring processes
  • Conduct investigations on security events and ensure proper assignment
  • Handle Tier II security event escalations with thorough documentation
  • Create and maintain SOPs for Information Security Operations
  • Assist in vulnerability assessments and collaborate with IT Ops
  • Support incident response tasks as assigned by management

Benefits

  • Engagement with a mission-driven organization
  • Opportunity to work with cutting-edge security tools and technologies
  • Supportive team environment with guidance from management and vendors
  • Chance to contribute to impactful security implementations
  • Professional development opportunities in the security domain
Full Job Description
The Office of Information Security provides the strategy and implementation of the information security program that safeguards the data entrusted to Planned Parenthood by its patients, supporters, donors, and staff.

Purpose:

The Security Engineer manages Information Technology security protections with the goal of protecting PPFA from and reducing the impact of security incidents and system compromises for the organization. This position provides security monitoring, event investigation and analysis, and countermeasure proposals on a 24x7 basis along with providing support and guidance to Tier I Analysts, will provide technical assistance for Tier II & III incidents as assigned, and is responsible to directly interface with the InfoSec Operations Team, Managed Security Service Provider (MSSP) and IT Managed Service Provider (MSP) as it relates to security event architecture, collection, management, reporting, and alerting within PPFA's SIEM Platforms.

Engagement:

The Security Engineer will engage with InfoSecOps, InfoSec, ITOps/MSP, the MSSP, ATS and staff within both PPFA and Affiliates.

Delivery:

The Security Engineer will deliver by identifying, implementing, and maintaining Information Security toolsets, primarily focused on SIEM, to protect the organization; interfacing with IT Ops to ensure proper security event logging setup; and, where applicable, supporting the Information Security SIEM management needs of PPFA and Affiliates.

Act as a Subject Matter Expert for PPFA's SIEM (currently Splunk) and be able to configure, manage, operate, and administer the platform from a managed SIEM perspective.
  • SIEM Security Monitoring - Provide security monitoring and threat/risk analysis in a 24/7 environment.
  • SIEM Event Filtering - Monitor & ensure established processes for event identification are followed, and, where required, make recommendations for new or refined event filtering, ensuring all updates are completed.
  • SIEM Event Investigation & Assignment - Monitor & ensure established processes are followed for collecting relevant data and performing the necessary levels of analysis on that data. Ensure events are assigned appropriately.
  • Tier II Event Escalations - Follow an established process for handling Tier II escalations, identifying the source of the escalation (MSSP, MSP, Affiliate, or other) and the appropriate triage and documentation processes.
  • Creating and maintaining Standard Operating Procedures (SOPs) for the Information Security Ops group, and providing recommendations on security process improvements
  • Support and engage on complex security tool-specific tasks with the assistance and guidance of management, vendor & MSSP resources
  • Assist in Vulnerability Assessments setup, scanning, analysis, and remediations, working with IT Ops staff and corporate vendors as needed in correcting errors and alerts as found with the IT infrastructure systems.
  • Assist in IR incidents as assigned by management
  • All other duties as assigned


Knowledge, Skills and Abilities (KSAs):

  • Bachelor's degree and 5+ years of industry experience
  • Passion for working on newer technologies and exploring the security domain.
  • Independent decision-making capabilities, especially in identifying analysis tracks for escalated events, analysis assignments, and escalation decisions ranging from a base Tier I event to Incident Response-level remediations.
  • Experience in compliance requirements and industry standards like PCI, HIPAA, ISO 27001, NIST, CSF, MITRE ATT&CK, ITIL, COBIT, Sarbanes-Oxley, and SANS 20.
  • UNIX, AIX & Solaris, Linux, Windows Server Operating Systems
  • Network/System Intrusion Detection or Prevention Systems (IDS/IPS)
  • Security Information and Event Management (SIEM)
  • Vulnerability scanner/Penetration testing systems
  • Wireless Networking
  • Switches/Routers, Firewalls (basic configuration)
  • TCP/IP networking, VPN, VLAN, NAT, and security concepts
  • Software & Hardware Asset Management
  • Security threat and attack countermeasures
  • Experience conducting forensic analytical studies and investigations
  • Flexibility and ability to adapt to quickly changing priorities and ambiguous situations
  • A deep commitment to Planned Parenthood's mission of promoting Sexual and Reproductive Health


$125,000 - $130,000 a year

Travel:(0-10% travel as needed)

About Planned Parenthood

Planned Parenthood is a non-profit organization that provides reproductive health care in the United States and globally. It is the largest provider of reproductive health services in the United States, with over 600 health centers nationwide. Planned Parenthood offers a range of services, including birth control, cancer screenings, STI testing and treatment, and abortion services. The organization was founded in 1916 and is headquartered in New York City.
Learn more about Planned Parenthood
Size
12,000 employees
Industry
Net Income
$11 million
5 Year Trend
+10%
Revenue
$1.2 billion

Similar Jobs

More Jobs at Planned Parenthood

More Information Technology Jobs

Find similar Associate Director, Information Security Engineer jobs: