JOB SUMMARY:The Sr IT Security Engineer is responsible for designing and deploying information security technologies to directly support the organization's efforts in securing the company's information and enforcing directives as mandated by regulations and NTS policy. Focuses on hardening internal processes and systems against internal and external security penetration and attacks. This role is client-focused, working in conjunction with Professional Services and Outsourcing functions. Responsible for the day-to-day activities with the 24x7x365 SOC, resolving threats, virus, malware, Phishing, and failed logins. Working with the SOC and IT Teams to remediate events and alarms discovered by the SOC. Ability to do in-depth discovery on the source of a threat, isolate and resolve the threat. Responsible to mature the existing O365 E5 Security and management tools to improve the security model.
JOB RESPONSIBILITIES:- Responsible for the planning, design and build of security architectures. Advanced configuration to mature the monitoring and managing the security posture. Design roadmap to leverage existing tools and improve capability and security.
- Oversees the implementation of network and computer security and ensures compliance with corporate cybersecurity policies and procedures. Focused on procedures and evidence for audit.
- Monitors cybersecurity requirements for local area networks (LANs), wide area networks (WANs), virtual private networks (VPNs), routers, firewalls, and related network devices. Focused on end user systems, logins, MFA, remote access, Security Awareness training and communicating with the end user to resolve issues
- Performs security assessments of applications and systems using penetration and vulnerability testing and risk analysis. Manage overall project plan and strategy for penetration and vulnerability testing remediation plan. Work directly with the IT Dept. and Business to remediate the risk. Manage and track the risk register.
- Configures / installs firewall and intrusion detection systems. Provide strategy and plan to Implements software fixes/Hardware (patches/fixes/updates) to remove system vulnerabilities. Stay current on active threats in the wild and provide advanced notification on potential threats. Implement technology to reduce the threat surface from these potential threats.
- Responds immediately to cybersecurity-related incidents and provides a thorough post-event analysis. Investigates intrusion incidents and conducts forensic investigations and documents RCA and manages communications to the IT Teams and Business.
JOB REQUIREMENTS:- Advanced capability in troubleshooting, isolating, and escalating security threats
- Advanced understanding in defining and applying industry security standards
- Proven track record on working with other departments on security risks and mitigation
- Ability to document process, procedures, and technical diagrams
- Ability to perform security threat hunting, managing alarms and events
- Advanced security threat detection with tools, isolation skills, resolution and tracking security events
- Knowledge of Microsoft M365 E3/E5 and Microsoft Advanced Security Suite of Tools, best practices
- Knowledge of NIST 800-171 and CMMC L3 - Documentation / Process / Procedures
- Knowledge with KnowBe4 or other Security Awareness training tools and programs
- Knowledge on scripting language for data collection
- Knowledge of networking and technical knowledge and understanding of security concepts (e.g., Application, Web and Network Security, Identity and Access Management, Vulnerability Management, Encryption, security protocols)
- Must possess superior analytical and problem-solving skills; be action-oriented and decisive
- Excellent written and verbal communication skills, as well as interpersonal skills including the ability to articulate to both technical and non-technical audiences
- Demonstrate leadership to the team
EDUCATION AND EXPERIENCE:- BS degree in Information Security, Information Systems or Computer Science required
- Security+ certification is a plus, CCISP or equivalent
- 5+ years of experience in IT cyber security
WORKING CONDITIONS:Test lab with exposure to sudden, loud noises
PHYSICAL REQUIREMENTS:While performing the duties of this job, the employee is occasionally required to stand; walk; sit; climb stairs; balance; stoop; kneel; crouch or crawl; talk or hear; taste or smell. The employee must occasionally lift and/or move up to 25 pounds. Specific vision abilities required by the job include close vision, distance vision, color vision, peripheral vision, depth perception and the ability to adjust focus.