Information Security Engineer - Threat and Vulnerability Management

Faegre Drinker Biddle & Reath LLP

$121K — $137K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in cybersecurity, information systems, or related field, or equivalent experience
  • 4+ years of relevant information security experience; Master's degree can substitute for one year
  • Hands-on experience with vulnerability management and threat assessments
  • Familiarity with vulnerability scanning tools like Tenable, Rapid7, or Qualys
  • Knowledge of security fundamentals across applications, operating systems, and networks
  • Experience with incident response and cyber threat intelligence analysis
  • Ability to communicate security risks and recommendations clearly to various audiences

Responsibilities

  • Conduct ongoing vulnerability assessments across various environments including cloud and on-premises
  • Prioritize assessment findings with a risk-based approach and communicate remediation strategies
  • Maintain a current threat profile for the firm, tracking relevant threat actors and campaigns
  • Monitor intelligence feeds for signs of compromise and potential threats to the firm
  • Translate threat intelligence into actionable measures and brief relevant stakeholders
  • Test for emerging threats, including new AI attack strategies
  • Engage in special projects and additional tasks as assigned

Benefits

  • Flexible working environment
  • Engagement in firm-sponsored volunteer events
  • Personalized wellness programming
  • Opportunity to work alongside experts in the field
  • Diverse health plan options including dental and vision
  • Generous paid time off
Full Job Description
Job Description Summary:
Faegre Drinker has an opportunity for an Information Security Engineer - Threat & Vulnerability Management to work with our Technology& Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm's threat and vulnerability management program. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

Job Description:

What you would do:
  • Conducts ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments using the firm's vulnerability scanning platform
  • Prioritizes findings using a risk-based approach that considers exploitability, threat intelligence, asset criticality, and exposure, and presents clear remediation recommendations to system owners and the Director
  • Maintains a current threat profile for the firm, tracking threat actors, campaigns, and tactics targeting law firms, professional services, and the firm's clients and industries
  • Monitors threat intelligence feeds, information sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or its clients
  • Translates threat intelligence into action, including prioritizing vulnerabilities under active exploitation, recommending new detections, and briefing the Director and peers on emerging threats
  • Executes prompt injection and cross-client data isolation test cases as directed, and brings threat intelligence on emerging AI attack techniques into the testing program
  • Special projects and other duties as assigned


What is expected:
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment


What we offer:
  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off


The anticipated initial salary for someone who is hired into this position is $121,800 - $137,700.

Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law. This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insurance; and a 401(k) plan.

What is required:
  • Bachelor's degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Four years or more of relevant information security experience. A Master's degree in cybersecurity or a related field may be considered in lieu of one year of experience
  • Hands-on experience with vulnerability management or threat and vulnerability assessment, including scanning, analysis, and risk-based prioritization of findings
  • Experience with vulnerability scanning platforms such as Tenable, Rapid7, Qualys, or equivalent
  • Working knowledge of application, operating system, and network security fundamentals, including common monitoring tools
  • Experience with incident response, digital forensics, and cyber threat intelligence in an operational environment, including analysis of threat actor tactics and indicators of compromise
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports


Apply now if you are ready to join the Faegre Drinker team!

Similar Jobs

More Jobs at Faegre Drinker Biddle & Reath LLP

More Information Technology Jobs

Find similar Information Security Engineer - Threat and Vulnerability Management jobs: