Full Job Description
What You Do.
DUTIES: Responsible for leading the protection of the organization's IT and OT identities, assets, and data, both on-premises and in the cloud, through proactive security monitoring, vulnerability and risk management, administration of critical security infrastructure, and participation in incident response activities. Key responsibilities include: 1) leading monitoring of security tools and systems for anomalies and threats; 2) leading incident response activities such as event triage, investigation, containment, remediation, and root-cause analysis; 3) configuring vulnerability management platforms, performing scans on systems and networks, tracking remediation, configure malware protection, and reporting on risk posture; 4) developing security metrics, KPI/KRI reporting, and risk-related documentation; 5) assessing risks for new and existing technologies, identifying potential impacts, and proposing control improvements; 6) configuring and administering firewalls, network access controls, endpoint security, cloud and data security, identity and email security, and web filtering systems; 7) installing, configuring, and maintaining security hardware and software following best practices, while leading the optimization of security tool configurations and system hardening efforts; 8) supporting the administration of the Security Awareness & Training platform, including designing and executing phishing simulations and training campaigns; 9) developing advanced scripting skills in Python and PowerShell to support threat hunting, automation, and reporting; 10) designing, building, and implementing security solutions; 11) researching emerging technologies and threats and recommending product or service evaluations; 12) developing process improvements; 13) organizing and leading tasks within larger projects, supporting planning and execution, and monitoring project performance metrics and alignment with Statements of Work; and 14) collaborating closely with senior team members, cross-functional partners, and external vendors to ensure the confidentiality, integrity, and availability of company systems and data.
Qualifications
MINIMUM REQUIREMENTS: This position requires a Bachelor's degree or equivalent in Computer Science, Information Security, Cybersecurity, or a related field and 5 years related (progressive, post-baccalaureate) experience in cybersecurity, information technology, information security, or IT system administration. Must also have demonstrated experience (which may have been gained concurrently) with each of the following: (1) Designing, implementing, and managing Secure Access Service Edge (SASE) architectures, including integration of Zero Trust Network Access (ZTNA), Secure Web Gateway (SWG), Cloud Access Security Broker (CASB), and SD-WAN technologies to secure hybrid and remote workforces; (2) Working with network security, including network segmentation, secure protocol implementation, intrusion prevention systems (IPS), and advanced threat detection across LAN/WAN and cloud environments; (3) Working with cloud-native security tools (e.g., AWS Security Hub, Azure Defender, Google Chronicle) and securing multi-cloud environments; (4) Using AI/ML-based threat detection tools and platforms, including anomaly detection and behavior analytics and conducting proactive threat hunting using tools such as MITRE ATT&CK, YARA rules, and threat intelligence platforms; and (5) Working with Security Frameworks such as NIST CSF or CIS controls. 10% domestic travel required to visit different locations and attend conferences. Full-time, position located in Plymouth, WI. May work remotely up to one day per week. Please apply online at careers.sargento.com/us/en. Ref#SRENT005063
Visa sponsorship is not available for this position.