Job Responsibilities
- [30%] Security Evaluation & Risk Management
- Perform risk assessments and identify vulnerabilities across systems and applications.
- Perform a variety of security assessments including; design reviews, customer security questionnaires, & tool reviews.
- Reproduce and validate security issues, recommending and implementing mitigations.
- Configure systems and infrastructure to enhance security posture.
- [25%] Incident Response & Forensics
- Assist with end-to-end incident response, including containment, remediation, and recovery.
- Conduct technical and forensic investigations into security issues.
- Coordinate with internal development teams, HR, Legal, and other stakeholders for incident handling and reporting.
- [20%] Security Automation & Monitoring
- Automate security testing and response workflows.
- Develop and manage security alerts, monitoring systems, and SIEM integrations.
- Monitor networks and systems for security breaches and ensure timely response.
- [15%] Security Training & Awareness
- Deliver security awareness training across the organization.
- Promote adoption of security standards, policies, and best practices.
- [10%] Research & Innovation
- Conduct proactive research on security trends, threats, and new solutions.
- Recommend and implement advanced strategies to improve organizational security.
Qualifications
- 3+ years of demonstrated experience in information security.
- Experience with penetration testing.
- Experience triaging and developing security alerts, automation, and front-line response.
- Experience implementing or managing a SIEM.
- Knowledge of firewalls, malware protection, intrusion detection, and content filtering tools.
- Knowledge of risk assessment, disaster recovery, and computer forensics technologies.
- Ability to communicate complex InfoSec topics to both technical and non-technical audiences.
- Experience planning, researching, and developing security policies, standards, and procedures.
- Preferred Qualifications
- BS degree in Computer Science, Computer Engineering, or equivalent experience.
- Security certifications such as CISSP, GISP, CISM, ISSAP, ISSEP, CEH, or CISA.