Trean Insurance Group, Inc.

Security Engineer

Trean Insurance Group, Inc. • $100K — $115K *
Information Technology
Less than 5 years of experience
Job Overview by Ladders

Qualifications

  • Bachelor's degree in Cybersecurity, IT, Computer Science, or related field, or equivalent experience.
  • 2-4 years of experience in cybersecurity or security operations.
  • Experience in security operations activities like alert triage and incident investigation.
  • Knowledge of current cybersecurity threats and attack techniques.
  • Strong analytical and problem-solving skills with the ability to assess risk.

Responsibilities

  • Monitor and investigate security alerts and suspicious activity.
  • Analyze cybersecurity events and perform incident triage and recovery activities.
  • Manage full incident response lifecycle including investigation and documentation.
  • Review security alerts and ensure timely investigation and remediation recommendations.
  • Perform risk assessments and provide recommendations to mitigate risks.
  • Research emerging threats and recommend improvements to security controls.
  • Contribute to process improvements in cybersecurity operations and incident response.

Benefits

  • Hybrid work model requiring onsite presence three days per week.
  • Professional office environment and standard office equipment usage.
  • Full-time position with comprehensive benefits.
Full Job Description
POSITION SUMMARY:

**Please note: Trean will not sponsor applicants for work visas.**

The Security Engineer is responsible for the day-to-day execution of the organization's cybersecurity operations program. This role serves as a hands-on member of the cybersecurity team, reviewing security alerts, investigating incidents, analyzing security events, managing security-related requests, conducting risk assessments, and identifying opportunities to strengthen security controls and processes.

The ideal candidate has experience in security operations and incident response and is seeking an opportunity to expand their skills and responsibilities across risk management, vulnerability management, security process improvement, and cybersecurity operations.

The Security Engineer must possess strong technical and analytical skills, maintain awareness of the evolving cybersecurity threat landscape, and understand modern attack techniques including ransomware, phishing, business email compromise, identity-based attacks, cloud security threats, and emerging risks associated with artificial intelligence. Success in this role requires the ability to evaluate risks, recommend practical security improvements, and contribute to the continuous evolution of the organization's cybersecurity capabilities.

RESPONSIBILITIES:
  • Monitor and investigate security alerts and suspicious activity across the enterprise environment.
  • Analyze suspected cybersecurity events and perform triage, containment, eradication, and recovery activities.
  • Manage cybersecurity incidents through the full incident response lifecycle, including investigation, documentation, escalation, and post-incident review.
  • Serve as the primary reviewer and analyst for security alerts, security-related requests, security incidents, and risk assessments, ensuring timely investigation, documentation, remediation recommendations, and follow-through.
  • Review, analyze, and resolve security-related tickets, requests, and reported security concerns.
  • Perform application, vendor, infrastructure, and technology risk assessments and provide recommendations to mitigate identified risks.
  • Review security questionnaires, technology implementations, and proposed business or technology changes to identify security risks and control gaps.
  • Assess security vulnerabilities, system misconfigurations, and control weaknesses and work with stakeholders to drive remediation efforts.
  • Research emerging cyber threats, attacker tactics, techniques, and procedures (TTPs), and recommend improvements to security controls and defenses.
  • Develop and maintain security procedures, response playbooks, technical documentation, and operational standards.
  • Identify opportunities to improve cybersecurity processes, incident response workflows, ticket handling procedures, and operational efficiency.
  • Recommend and implement enhancements to security controls, monitoring capabilities, and security processes based on lessons learned, risk assessments, and emerging threats.
  • Participate in projects and technology initiatives to ensure security requirements and risks are appropriately considered.
  • Support the evaluation and secure adoption of emerging technologies, including artificial intelligence solutions, within the organization.


Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
  • 2-4 years of experience in cybersecurity, security operations, incident response, or a related information security role.
  • Demonstrated experience performing day-to-day security operations activities, including alert triage, incident investigation, security ticket review, remediation tracking, and resolution of security-related requests.
  • Experience supporting or participating in cybersecurity incident response activities, including investigation, containment, eradication, recovery, and documentation.
  • Experience conducting or participating in technology, application, vendor, or cybersecurity risk assessments.
  • Experience identifying security vulnerabilities, control weaknesses, and recommendations for remediation.
  • Knowledge of current cybersecurity threats, attack techniques, defensive security principles, and industry best practices.
  • Understanding of information security concepts including identity and access management, endpoint security, vulnerability management, security monitoring, and incident response.
  • Strong analytical and problem-solving skills with the ability to assess risk, prioritize work, and recommend practical solutions.
  • Ability to assess, prioritize, and manage multiple security events, incidents, assessments, and requests in a fast-paced environment.
  • Ability to learn new technologies, evaluate security risks, and recommend process and security control improvements.
  • Strong written and verbal communication skills with the ability to document findings and communicate technical information to both technical and non-technical audiences.
  • Ability to work independently, exercise sound judgment, and collaborate effectively with cross-functional teams.
  • Ability to work in a hybrid work environment with a minimum onsite presence of three days per week at a designated company office location.
  • Demonstrated integrity, trustworthiness, and the ability to maintain strict confidentiality when handling sensitive company, customer, employee, and cybersecurity-related information.


PREFERRED QUALIFICATIONS
  • Experience conducting application, vendor, or technology risk assessments.
  • Experience supporting security engineering initiatives and implementation of security controls.
  • Security certifications such as Security+, CySA+, SSCP, GSEC, GCIH, or equivalent.
  • Experience working in a regulated industry such as insurance, financial services, healthcare, or a similar environment.
  • Experience identifying opportunities to improve security processes, workflows, and operational effectiveness.
  • Exposure to cloud security, identity and access management, artificial intelligence technologies, or security automation.
  • Experience reviewing vendor security questionnaires, technology implementations, or application security assessments.


IDEAL CANDIDATE
  • Currently works in a security operations, SOC, or cybersecurity analyst role.
  • Reviews security alerts, investigates incidents, and manages security-related tickets as part of their daily responsibilities.
  • Has participated in risk assessments, security reviews, vendor reviews, or vulnerability management activities and is ready to take ownership of those activities.
  • Demonstrates strong analytical thinking, attention to detail, and sound judgment.
  • Maintains a high level of integrity and discretion when handling sensitive and confidential information.
  • Is eager to expand their technical skills, contribute to security improvements, and grow into a more senior cybersecurity role over time.


WORKING CONDITIONS

This position is located in a professional office environment. This role routinely uses standard office equipment and requires the physical demands of a normal office position with some light lifting. This is a full-time position with benefits. This position follows Trean's hybrid work model and requires a minimum onsite presence of three days per week at a designated company office location.

Salary Description

$100,000-$115,000

About Trean Insurance Group, Inc.

Trean Insurance Group, Inc. is a specialty insurance company that provides insurance products and services to the property and casualty market. The company offers a range of insurance products, including workers' compensation, commercial auto, general liability, and other specialty insurance products. Trean Insurance Group serves small to medium-sized businesses in various industries, including construction, transportation, healthcare, and retail. The company was founded in 1996 and is headquartered in St. Louis Park, Minnesota.
Learn more about Trean Insurance Group, Inc.
Size
200 employees
Market Cap
$306.3 million
Industry
NASDAQ

Similar Jobs

More Jobs at Trean Insurance Group, Inc.

More Information Technology Jobs

Find similar Security Engineer jobs: