Information Security Engineer II

VEIC

$90K — $100K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • 3+ years in information security operations/engineering or equivalent experience
  • Proficient in Microsoft 365 security services like Defender for Endpoint
  • Knowledge of core infrastructure tech: Windows, Linux, networking
  • Experience with scripting languages like PowerShell or Python
  • Strong understanding of security technologies such as firewalls and WAFs

Responsibilities

  • Independently monitor and respond to security alerts and incidents
  • Coordinate containment and recovery efforts for security incidents
  • Engineers, implements, and maintains information security technologies
  • Handle security projects from design to operational handoff
  • Collaborate with IT on improving processes and technologies
  • Promote security best practices organization-wide

Benefits

  • Flexible work arrangements to support work-life balance
  • Commitment to continuous learning and professional development
  • Ergonomic assessments and accommodations provided
  • Promotional opportunities through active company culture
  • Supportive team environment encouraging information security engagement
Full Job Description
Information Security Engineer II VEIC is seeking a dedicated Information Security Engineer II. This position is a generalist role focused on blue team security operations and security engineering. The Engineer II independently monitors, triages, investigates, and responds to information security incidents and engineers, implements, and maintains the information security technologies used by VEIC to ensure confidentiality, integrity, and availability of company data and information systems, consistent with VEIC's information security policies, guidelines, standards, and controls. The Information Security Engineer II operates with a moderate degree of autonomy, owning security engineering projects from design through implementation and taking an active, hands-on role in responding to security incidents. The Engineer II works closely with the Manager, Information Security as a day-to-day partner on investigations, digital forensics, governance, and policy-related initiatives. The Information Security Engineer II advises the Information Security Team on emerging vulnerabilities and newly identified risks to company systems and takes a proactive approach to continually assessing the security of company systems throughout their lifecycle. This role provides recommendations to strengthen security controls and adapt to evolving threats and vulnerabilities. The Information Security Engineer II promotes a culture of information security across the organization. Essential Functions - Lead Independently monitors, triages, and responds to security alerts and incidents across the security stack, escalating and documenting activities as appropriate. - Coordinates response efforts for security incidents, including containment, eradication, and recovery activities. - Engineers, implements, and maintains information security technologies, including SIEM content, detection rules, data onboarding, and automation. - Owns security engineering projects end-to-end, from scoping and design through implementation and operational handoff, with minimal oversight. - Serves as a point of contact within Information Technology for information security technologies, processes, and procedures. - Works closely with Information Technology colleagues on technology and process improvement initiatives. - Partners with teams across the organization to support the security of the technologies and systems they use, extending beyond the core IT environment. - Maintains a strong working knowledge of VEIC's IT systems and their business value. - Collaborates with internal stakeholders, providing support and guidance on issues of moderate to high complexity. - Proactively identifies and escalates security issues, risks, and operational performance concerns. - Performs investigative tasks of moderate complexity and partners with the Manager, Information Security on digital forensics and other investigative efforts. - Works closely with the Manager, Information Security on governance and policy activities, including policy maintenance, control reviews, and audit evidence collection. - Advises business units across the organization on cyber risk, helping ensure processes remain both practical and secure. - Collaborates with technologists across the organization, providing guidance on security best practices. - Explores and develops security automation capabilities, including AI-assisted tools, to enhance security operations. - Provides training and guidance to VEIC staff and teams on information security risks in support of organizational and departmental initiatives. - Promotes a culture of information security across the organization. - Supports the work of other VEIC staff as necessary to achieve organizational goals and objectives. - Performs administrative tasks, reporting, and stakeholder communications as needed. - Participates in on-call and after-hours response activities as needed for security incidents, including on-site response for events requiring a physical presence. - Other duties as assigned. Knowledge and Experience - Strong personal commitment to the mission, vision, goals, and values of VEIC. - Strong professional interest in and commitment to the information security field. - Strong understanding of information security concepts and principles. - 3 or more years of experience in information security operations and/or security engineering within a professional environment, or an equivalent combination of education and experience from which comparable knowledge and skills have been acquired. - Demonstrated proficiency in securing and administering Microsoft 365 security products, including Defender for Endpoint, Purview, Entra ID, and Intune. - Proficiency with core infrastructure technologies, including enterprise operating systems such as Windows and Linux, TCP/IP networking, storage systems, virtualization, and containerization. - Proficiency in scripting or programming languages such as PowerShell and Python. - Working knowledge of security technologies including vulnerability scanning, event log management, endpoint security, firewalls, and web application firewalls. - Working knowledge of cloud technologies and concepts. - Experience with Splunk, including Splunk Enterprise Security (ES), is a plus. - Experience with Proofpoint email security products is a plus. - Familiarity with digital forensics tools, techniques, and procedures. - Familiarity with physical security concepts and practices. - Familiarity with offensive security concepts is a plus. - Familiarity with Mac Endpoint security is a plus. - Demonstrated ability to work independently and manage projects from initiation through completion. - Strong interpersonal, written, and verbal communication skills, with a customer service-oriented approach. - Strong analytical, critical thinking, and problem-solving skills. - Ability to remain organized, detail-oriented, and accurate while managing multiple tasks and competing priorities in a dynamic, fast-paced environment. - Ability to communicate complex technical concepts to non-technical audiences in a clear and user-friendly manner. - Commitment to continuous learning and professional development. - Possess, or be willing to obtain, an entry- to mid-level information security certification such as CompTIA Security+, CySA+, or GSEC within the first six months of employment. Work Environment and Physical Requirements This position primarily involves desk-based work with extensive collaboration and communication responsibilities. Physical requirements include: - Ability to remain stationary at a workstation for extended periods (typically 6-8 hours per day with regular breaks) - Regular use of computer, keyboard, mouse, and telephone/headset requiring fine motor skills and repetitive hand/wrist movements - Visual acuity to view digital screens, documents, and presentations for prolonged periods - Verbal communication abilities are sufficient for clear articulation during in-person and virtual meetings, presentations, and discussions - Auditory capabilities to participate effectively in conversations, conference calls, and virtual collaboration sessions - Cognitive focus for simultaneous management of multiple communication streams, projects, and stakeholder relationships - Occasional movement between meeting spaces, collaboration areas, and individual workstations - Minimal lifting requirements (typically under 15 pounds) for office supplies, equipment, or materials VEIC provides ergonomic assessments and appropriate accommodation to support team members in this collaborative environment, if needed. Our commitment to wellness includes encouraging regular movement breaks and supporting flexible work arrangements that promote sustainable productivity aligned with our core values. Travel Requirements No Travel Required This position does not require regular travel. Occasional in-person attendance at company events or meetings (typically 0-2 times per year) may be encouraged, but participation is often optional or available virtually. $90,000 - $100,000 a year

Similar Jobs

More Jobs at VEIC

More Information Technology Jobs

Find similar Information Security Engineer II jobs: