What You'll Do
Are you driven to protect systems, data, and people from evolving cyber threats while working closely with both technical and non-technical stakeholders? As a Cyber Security Engineer I, you'll play a key role in safeguarding the organization's technology environment by assessing risk, managing vulnerabilities, and advising on security best practices. You'll collaborate with Security Architecture on projects, provide trusted Information Security expertise across the firm, and help shape a strong, forward-looking security posture.
• Risk Assessment & Assurance - Perform security risk assessments for new technologies, IT initiatives, and third-party vendors; respond to security questionnaires, audits, and client assessments.
• Vulnerability Management - Monitor emerging threats and software vulnerabilities, coordinate triage and response efforts, and communicate risk insights to staff and leadership.
• Security Consulting & Expertise - Serve as a subject matter expert in Information Security, advising technical teams, non-technical management, and attorneys as needed.
• Technology Evaluation & Implementation - Assess and recommend security tools and solutions; plan and execute projects to implement or enhance security controls and technologies.
• Documentation & Standards - Create and maintain system, procedural, and support documentation; contribute to security policies, standards, processes, and guidelines.
• Issue & Exception Management - Support issues management activities, including exception handling and findings remediation.
• Strategic Contribution - Participate in long-term Information Security strategy, planning, and continuous improvement initiatives.
What You'll Bring
• Education - Bachelor's degree in Information Technology or a related field, or equivalent practical experience.
• Experience - Approximately three (3) years of hands-on experience in security assessments, vulnerability management, or a closely related area.
• Operating Systems & Infrastructure Knowledge - Experience conducting assessments in Windows and Unix environments, with a strong understanding of IT infrastructure and security controls.
• Cloud & Modern Technologies - Hands-on experience with cloud platforms, including Microsoft Azure Infrastructure as a Service (IaaS) and Software as a Service (SaaS).
• Security Frameworks & Standards - Working knowledge of security frameworks and technologies such as ISO 27001, National Institute of Standards and Technology (NIST), System and Organization Controls (SOC), and Standardized Information Gathering (SIG).
• Automation & Tooling - Exposure to scripting or automation using tools such as Python, PowerShell, and application programming interface (API) integrations.
• Security Domains Expertise - Familiarity with identity and access management (IAM), authentication technologies, vulnerability assessment and forensic tools, endpoint detection and response (EDR), encryption, intrusion detection and prevention systems (IDPS), firewalls, log correlation, anti-malware, web filtering, and email spam prevention.
• Communication & Collaboration - Ability to translate technical security concepts for non-technical audiences, paired with strong written, verbal, and interpersonal skills.
• Problem-Solving Mindset - A proactive, detail-oriented approach to researching and resolving complex security and networking challenges.
• Professional Certifications (Preferred) - Certified Information Systems Security Professional (CISSP), Certified Ethical Hacker (CEH), or Offensive Security Certified Professional (OSCP).
If you're excited to assess risk, strengthen security controls, and make a meaningful impact on how organizations stay secure in a rapidly changing threat landscape, we'd love to hear from you.
How to Apply
Thank you for your interest in Kirkland & Ellis LLP. To complete an application and submit your resume, please click "Apply Now."
Don't meet every job requirement? That's okay! If you're excited about this role but your experience doesn't perfectly fit every qualification, we encourage you to apply anyway. You may be just the right person for this role or others at Kirkland.