Your Mission & Key ResponsibilitiesThe Information Security Engineer is responsible for all tasks and work efforts as a part of SRM's cybersecurity program - from design through implementation, monitoring, and continuous improvement.
- Become a valuable member of the information security team, fostering a culture of collaboration, and accountability.
- Collaborate with system and network engineers to align network infrastructure with Microsoft Entra ID (Azure AD), Active Directory, and identity-based access controls.
- Implement solutions in support of cybersecurity policies, standards, and procedures in alignment with industry best practice.
- Implement security controls across network, system, application, and cloud infrastructures (Azure, OCI, O365).
- Collaborate with IT leadership to integrate security into all technology projects, ensuring secure configuration, and deployment practices.
- Perform vulnerability management and remediation activities, prioritizing mitigation efforts based on business impact.
- Perform enterprise security operations and incident response activities, leveraging SIEM, threat intelligence, analytics, and MSSP SOC to detect and mitigate risks, participate in periodic threat assessments and penetration testing, and post-incident reviews to strengthen organizational resilience.
- Define and track risk metrics on key cybersecurity performance indicators (KPIs) including health, incidents, and strategic initiatives and provide executive reports to the Director of Information Security & Compliance, CIO and IT leadership.
- Evaluate emerging threats and technologies, recommending appropriate security solutions through demonstrations, pilots and proof-of-concept/value work efforts.
- Collaborate across IT disciplines (systems, networking, applications) to ensure end-to-end resilience, visibility, and alignment of security priorities with operational needs.
- Other duties as assigned by the Director of Information Security & Compliance.
What Sets You Apart- Associate and/or Bachelor's degree in Computer Science, Information Technology, or equivalent professional certification(s).
- 3+ years of experience in information security engineering or related infrastructure roles.
- Strong technical foundation in network, system, and cloud security, including firewalls, SIEM, endpoint protection, and identity management.
- Deep understanding of various security suites for endpoint management and security (Defender, Entra ID, Intune, SentinelOne, Avanon, Azure Security Center and similar).
- Experience with two or more of these focus areas: Incident Response, Vulnerability Management, Network Security, Application Security, and Cloud Security.
- Strong analytical, problem-solving, and critical thinking skills.
- Excellent communication and interpersonal skills.
- Relevant certifications such as CISSP, Security+, PenTest+ or CySA+.
- Experience with Zero Trust architecture and/or cloud-native security solutions.
- Knowledge of data loss prevention (DLP), MFA, SIEM/SOAR, and endpoint detection and response (EDR) platforms.
- Familiarity with network monitoring and analysis tools.
- Demonstrated ability to work collaboratively with system engineers, application teams, and field personnel.
- Contribute to team knowledge sharing, mentoring, and continuous improvement initiatives.
- Familiarity with infrastructure-as-code and automation tools (Ansible, Terraform) would be preferred.
- Experience in Zero Trust, SD-WAN, or network segmentation strategies would be preferred.
- Experience in developing and maintaining automation scripts using PowerShell, Python, or Bash for provisioning and maintenance tasks would be preferred.