The Senior Security Engineer helps to design, develop and implement security changes and enhancements to the company environments. Responsibilities include: - Design, document, test, maintain, and provide issue resolution recommendations for enterprise security solutions related to networking, cryptography, cloud, authentication and directory services, email, internet, applications, and endpoint security - Provide security consulting for internal clients to ensure conformity with corporate information, security policy, and standards - Lead or participate in computer security incident response activities - Identify security vulnerabilities and issues, perform risk assessments, and evaluate remediation alternatives - Collaborate and consult with peers, colleagues and managers to resolve issues and achieve goals - Determining appropriate security measures and creating policies and procedures that monitor and control access to system resources and data. - Update security standards as necessary - Prevention, detection, containment and correction of security breaches - Oversees the establishment, implementation and adherence to policies and procedures that guide and support the provision of information security services - Conducts risk assessments and risk analysis to help the organization develop security standards and procedures that support strategic, tactical and operational objectives on a cost-effective basis - Makes recommendations on appropriate personnel, physical and technical security controls - Participates in resolving problems with security violations - Certifies that IT systems meet predetermined security requirements - Strives to maintain high system availability - Works with vendors, IT associates, and user departments to enhance information security - Participate in after hours on-call rotation
Qualifications - This is a senior level position suited for an individual who has a strong Information Security background. - B.S. degree in Computer Science, Computer Engineering and 4 years’ experience OR 6 – 8 years of relevant Information Security experience with at least 3 years in a Security Engineer role. - Works well in a team environment and independently - Strong analytical and problem solving skills - Relevant Information Security Certifications (CISSP, CISA, CNE, GISA, etc.) are preferred - Excellent listening, verbal and technical writing skills
Skills Needed: - Advanced Level knowledge of Security Architecture for both infrastructure components (networks and servers) as well as applications and data. - Experience working with log management, security monitoring, vulnerability management and security incident/event management tools - Ability to manage platform level security controls for Microsoft Windows, Unix etc. (access controls and hardening). - Knowledge of application and web services security. - Familiar with Identity and Access Management methodology and implementation. - Knowledge of relevant Information Security state and federal regulations and compliance require
Concentrix
OLX Group
Erie Insurance Group
Gamma
Lime