Boys Town is seeking a Threat Detection & Response Engineer. You will play a critical role in protecting the organization's systems, data, and mission. This position leads internal penetration testing initiatives and drives proactive threat detection and incident response efforts across the enterprise. The ideal candidate is an experienced cybersecurity professional with expertise in penetration testing, threat hunting, vulnerability management, security operations, and incident response. In this role, you will partner with technology and business leaders to identify and remediate cybersecurity risks, manage security testing engagements, and coordinate team exercises.
Position is on site.
MAJOR RESPONSIBILITIES & DUTIES:- Manages and executes a focused internally led penetration testing program, responding to requests from business and technology leaders.
- Prioritizes and schedules penetration tests, ensuring coverage across critical systems and infrastructure.
- Produces comprehensive risk reports and collaborates with the Governance, Risk, and Compliance (GRC) team to track and prioritize remediation efforts.
- Serves as the primary information security technical resource for vulnerability remediation efforts, coordinating with relevant stakeholders to address identified vulnerabilities promptly.
- Leads professional service engagements, such as PCI attestation and external penetration testing, ensuring compliance with independent third-party testing requirements.
- Coordinates and lead purple team exercises to evaluate and improve the organization's cybersecurity posture.
- Develops and oversees a Threat Hunting Program, leveraging Security Operations Center (SOC) capabilities and SIEM tools to proactively identify and mitigate threats.
- Establishes repeatable processes for SOC-led threat hunting activities, based on actual vulnerabilities and prioritized risks.
- Administers security technology tools for threat monitoring, detection, and alerting, ensuring optimal performance and effectiveness.
- Documents processes and procedures, making them repeatable and transferable to the SOC team where feasible.
- Acts as the Cyber Incident Commander during cybersecurity incidents, leading the SecOps response efforts and coordinating with cross-functional teams to contain and remediate threats.
- Provides expertise in digital forensics, technical security controls, and cybersecurity best practices, supporting GRC initiatives and fostering awareness and communication across the organization.
KNOWLEDGE, SKILLS, AND ABILITIES:- Strong understanding of cybersecurity frameworks, compliance requirements, and industry best practices.
- Proficiency in using security tools and technologies, including SIEM platforms, vulnerability scanners, and penetration testing tools.
- Excellent communication and interpersonal skills, with the ability to effectively collaborate with diverse stakeholders at all levels of the organization.
- Ability to work independently, prioritize tasks, and adapt to changing priorities in a fast-paced environment.
REQUIRED QUALIFICATIONS:
- Bachelor's degree in Computer Science, Information Security, or related field required.
- Minimum of 5 years of experience with increasing responsibility in information security or related field required.
- Proven experience in conducting penetration tests, vulnerability assessments, and incident response activities in a corporate environment required.
- On-call (continuously or rotationally) to provide support required.
PREFERRED QUALIFICATIONS:- Advanced certifications such as OSCP, CISSP, GIAC preferred.
- Other Duties: This job description incorporates the essential functions and duties required for this position. However, other duties may be required and assigned at times and as determined by a supervisor in order to meet the needs of the organization.
- Serves as a role model in carrying out activities and behaviors that reflect the values and principles of the Boys Town mission.
PHYSICAL REQUIREMENTS, EQUIPMENT USAGE, WORK ENVIRONMENT:- Position is relatively sedentary in a normal office administrative environment involving minimum exposure to physical risks. Will use office equipment such as a computer/laptop, monitor, keyboard, and a general workstation set-up.