Job Summary:The Information Security Engineer supports the L11 New Product Introduction (NPI) project by designing, implementing, and maintaining information security solutions that protect products, systems, and manufacturing environments. This role collaborates with cross-functional engineering, IT, and product development teams to identify, assess, and mitigate cybersecurity risks while ensuring compliance with organizational policies, industry standards, and regulatory requirements. The engineer integrates security best practices throughout the product development lifecycle, conducts security assessments, supports vulnerability management and incident response activities, and implements security controls to enable the secure and successful launch of new products.
Duties and Responsibilities:- Evaluate and enhance the organization's cybersecurity posture by assessing existing security controls, identifying gaps, and implementing security best practices to protect systems, networks, applications, manufacturing environments, and sensitive information.
- Conduct security assessments, vulnerability scans, and risk analyses to identify potential threats and security weaknesses, and recommend and implement remediation measures to reduce organizational risk.
- Plan, coordinate, and support customer security audits, penetration tests, and security assessments by collaborating with internal stakeholders and external partners to validate security controls, ensure compliance with customer requirements, and remediate identified findings.
- Monitor, investigate, and respond to cybersecurity incidents by performing threat analysis, root cause investigations, containment, remediation, and recovery activities while maintaining and improving incident response processes.
- Monitor security events across networks, endpoints, cloud services, and enterprise systems using SIEM, EDR/XDR, and other security monitoring tools to detect, analyze, and respond to potential threats.
- Perform threat hunting and analyze security logs, alerts, and indicators of compromise to identify malicious activity and improve the organization's detection and response capabilities.
- Implement, configure, and maintain security technologies, including endpoint protection, identity security, vulnerability management, and network security solutions.
- Collaborate with engineering, IT, and product development teams to integrate security requirements and best practices throughout the New Product Introduction (NPI) lifecycle and support secure product releases.
- Ensure compliance with organizational security policies, customer security requirements, and applicable cybersecurity standards and regulatory frameworks by supporting audits, risk assessments, and documentation activities.
- Develop, maintain, and deliver information security awareness and training programs to educate employees on phishing, social engineering, password security, data protection, and other security best practices.
- Create and maintain security documentation, including policies, standards, procedures, risk assessments, incident reports, and technical implementation guides.
- Stay current on emerging cybersecurity threats, vulnerabilities, technologies, and industry best practices, and recommend improvements to strengthen the organization's overall security posture.
Education:- Bachelor's degree in Cybersecurity, Information Security, Computer Science, Information Technology, Computer Engineering, or a related technical field.
- Relevant cybersecurity certifications such as Security+, PenTest+, ISC2 CC, EHE are preferred.
Experience:- 1-2 years of foundational IT and networking experience
- 1-2 years of automation and application security experience
- 1-3 years of security operations and defense experience