Summary
What you’ll impact
The IT Security Engineer II at the organization will enhance and continuously improve the organization’s cybersecurity posture while safeguarding data, systems, and resources. The role involves developing and executing security strategy, managing policies, conducting compliance audits, leading incident response, and mentoring junior staff. The position is hybrid, may include a 24/7 on-call rotation, and requires strong leadership, project management, and communication skills.
Responsibilities
What you'll do
- Identify threats and vulnerabilities. Conduct complex security incident reviews and investigations. Lead security incident response and recovery processes and activities.
- Architect, design and implement security technologies and process as directed by leadership, and in collaboration with departmental colleagues and business and application owners.
- Manage, administer, monitor, and support 2-3 security applications. Troubleshoot and resolve problems related to cybersecurity technologies. Drive and automate operational use of said technologies to reduce risk and deliver value to the organization. Cross train team members on operational processes.
- Measure and report on enterprise security capabilities using automated and manual tools.
- Develop and maintain security policies, standards and standard operating procedures. Socialize security strategies, standards, policies, procedures, communications, and awareness efforts with IT and business partners. Create short and long-term security application capability strategies and business case documents.
- Participate in reviews of new or existing systems to ensure security requirements are satisfied, including performing various types of risk and impact assessments, before and after implementation.
- Develop, maintain, audit, and enhance enterprise security controls.
- Contribute to security awareness training and communications collateral.
- Respond to and assist with audits, assessments and compliance requests.
- Assist with system-wide compliance of the HIPAA Security and Privacy rules, Payment Card Industry (PCI) standards, and other appropriate standards and audit requirements.
- Participate in an on-call rotation with peers to address any incidents as they are assigned.
- Execute all other duties as assigned.
Requirements
What you’ll bring
- Education: Bachelor’s Degree, or equivalent, in a technical discipline, or a corresponding educational background with professional-level security certifications relevant to the role.
- Certification: One advanced, professional, or expert-level security certification preferred.
- Experience: Minimum three (3) years of mid-level Cybersecurity experience at an analyst or engineer level.
- Previous experience leading, supporting, managing, and administering at least one security application.
- Previous experience leading security projects and initiatives.
- Ability to work independently with minimal oversight on a broad range of security projects and initiatives.
- Demonstrated in-depth knowledge of information security principles, practices, solutions, and capabilities.
- Demonstrated understanding of advanced security incident investigation techniques.
- Intermediate understanding of threats and risks.
- Intermediate-level knowledge of network, application, and systems security architecture.
- Significant experience documenting, designing, and implementing desktop, server, network, database, cloud, and application security controls.
- Significant experience with hardware and software asset inventory; configuration management; security posture and exposure management; threat detection; vulnerability identification and remediation; identity protection; incident response; security operations; and security orchestration, automation, and response (SOAR) capabilities.
- Experience with common security testing methods and tool sets such as email security, data loss prevention (DLP), vulnerability management, system hardening, intrusion detection/prevention systems (IDS/IPS), security incident and event management (SIEM), endpoint/extended detection and response (EDR/XDR), anti-malware, proxy tools, identity security services, cloud security posture management (CSPM), and cloud-native application protection platforms (CNAPP).
- Leadership and project management skills.
- Proven communication, customer service, and organization skills.
- Previous experience with HIPAA, NIST, and project management.