OverviewResponsibilities & QualificationsJOB OVERVIEWThe Information Security Engineer is responsible for the maturing of IT security programs to meet security requirements related to function, protection, assurance, risk management, and compliance. This individual will be responsible for documenting, testing and maturing a comprehensive information security program to protect all aspects of business and application assets across the organization.
ESSENTIAL JOB FUNCTIONS- Facilitate architecture, design, implementation, deployment, and operational discussions to ensure HIPAA and PCI compliant technology solutions.
- Validate current security standards against industry best practices and provide recommendations for improvements.
- Use vulnerability management tools to identify and prioritize risks across the enterprise.
- Research, evaluate, design, test, recommend and plan the implementation of new or updated information security technologies.
- Document and validate business procedures against published policies.
- Define security configuration and operations standards for security systems and applications, including policy assessment and compliance tools, network security appliances, and host-based security systems.
- Play an advisory role in application development or acquisition projects to assess security requirements and controls and to ensure that security controls are implemented as planned. Complete remediation activities and initiate actions to ensure that compliance and security gaps are successfully addressed.
- Research and assess new threats and security alerts and recommend remedial actions.
- Develop plans for security systems by evaluating network and security technologies; developing requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related security and network devices
- Interface with the Project Management teams to ensure security services are met in all phases of the SDLC.
- Business continuity and disaster recovery validation against SLA definitions.
- Support compliance and financial audit requests.
QUALIFICATIONSRequired- 3 to 5 years of experience in IT, with a minimum of one year in security architecture.
- Experience conducting disaster recovery, business continuity, incident response exercises.
- In-depth experience implementing security solutions.
- Knowledgeable in the design and implementation of security architectures that enable well integrated transactional, collaborative and analytical systems.
- In depth knowledge of information security regulations such as, FISMA, HIPAA, HITECH, PSQIA, Gramm-Leach-Bliley, SOX.
- In depth knowledge CIS, NIST, and ISO 27001 standards.
- Ability to perform vulnerability scans and provide remediation. Tenable Nessus experience a plus.
- Experience with EDR solutions.
- Experience with integrating, updating, and tuning a SIEM.
- In depth knowledge of Microsoft on prem and cloud environments including all security blades. Purview and Intune experience is a plus
- Experience with maintaining AV and endpoint encryption suite.
- Exceptional interpersonal skills, including teamwork, facilitation and negotiation.
- Must be able to work independently with minimal supervision.
- Ability to perform network forensics and resolve IDS alerts.
- Ability to rapidly comprehend the functions and capabilities of new technologies.
- Strong knowledge in Windows and Network administration.
- Ability to perform system hardening.
Preferred- Certifications: CISSP, OSCP, CISA preferred
- Known publications in the security field (blogs, recorded presentations, or news articles)
- Having writing organization policies from scratch
Other Requirements- Must be able to always adhere to confidentiality standards and professional boundaries.
- Attention to detail.
- Time Management.
- Ability to remain calm and professional in stressful situations
- Strong commitment to excellence.
- Effective problem-solving and conflict resolution.
- Excellent organization and communication skills.
- Quick-thinking and astute decision-making skills.
Physical Requirements- Must be able to travel
- Must be able to lift 50 pounds
- Prolonged walking, standing, bending, kneeling, reaching, twisting
- Must be able to sit and climb stairs
- Must have visual and hearing acuity
DrivingA valid driver's license and an acceptable Motor Vehicle Record (MVR) may be required.
AgeMust be 18 years or older
LanguageMust be able to speak, write, read, and understand English.
Work EnvironmentPerforms duties during agency operating hours in either an office, remote or hybrid work environment.
Must be able to function in a wide variety of environments which may involve exposure to allergens and other various conditions.
OTHER DUTIESPlease note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
TOTAL REWARDSComprehensive medical, dental, and vision coverage; a 401(k) matching program; and an Employee Stock Purchase Plan (ESPP)
Career Path: Opportunities for advancemen
Headhunters and recruitment agencies may not submit resumes/CVs through this website or directly to managers. Aveanna does not accept unsolicited headhunter, and agency resumes and will not pay fees to any third-party agency or company that does not have a signed agreement with Aveanna.