Aureon Consulting is seeking candidates for the following opportunity with one of our clients:
Sr. Security Engineer
Responsibilities will include:
- Senior Security Engineer will design, document, and deploy cyber security systems that will be used across the environment.
- Develop and carry out information security plans and policies.
- Provide design validation and troubleshooting for new technology and major changes within the environment.
- Define, document, and enforce standards, processes, procedures, and workflows within the team to better streamline the group as a whole.
- Ensure the confidentiality, integrity and availability of the data residing on or transmitted to/from/through the enterprise networks.
- Participate in defining best of class security practices for enterprise networks providing high-volume financial services transactions.
- Participate in maintenance windows where applicable.
- Collaborate with other technology groups and technology architects on product strategy discussions.
- Partner with the Cybersecurity Operations team to improve tool usage and workflow in maturation of monitoring and response capabilities.
- Develop or implement open-source/third-party tools to assist in detection, prevention and analysis of security threats.
- On-call resource for Incident Response and operational functions.
- Researches, develops, and keeps abreast of tools, techniques, and process improvements in support of cybersecurity threats and countermeasures. Maintain working knowledge of advanced threat detection as the industry evolves.
- Actively engages in the performance of Incident Response activities, including but not limited to, triage, escalation, conducting post-mortem and lessons learned review meetings, as well as remediation tracking.
- Leverage knowledge in multiple security disciplines, such as Windows, UNIX, Linux, data loss prevention (DLP), file integrity monitoring (FIM), endpoint controls, databases, wireless security, data networking and encryption, to offer solutions for a complex heterogeneous environment.
- Perform other duties as assigned.
- Responsible for reporting risks that are identified to the appropriate team and/or management. Additionally, responsible for managing, monitoring and reporting risks within the scope of your work area, to include, but not limited to Information Security risks.
Requirements for this role:
- Bachelor’s degree in computer science/related field or 5+ years equivalent work experience in Cybersecurity.
- 7 or more years of IT technical experience with 5+ years’ broad-based experience in security engineering.
- Specialized expertise in Google Cloud security is required.
- Minimum, 5+ years of security engineering experience in mid to large IT organization.
- Knowledge of PCI-DSS 3.2 is preferred.
- 5+ years of experience with SIEM deployment and log management.
- 5+ years of hands on and progressive information security design and implementation experience in a security engineering role preferred.
- Knowledge of ITIL best practices.
- Preferred security-related certifications (e.g. SSCP, ISSEP, ISSAP, CCSP, CCNP, MCSE, C|EH, OSCP, OSWE, GWEB, GPEN, CFCE, CHFI).
- CISSP required.
- PMP a plus.
- Ability to provide support in resolving IT security or related product issues as required.
- Ability to work independently in addition to working closely in a team environment.
- Demonstrates highly effective verbal/written communication skills with the ability to facilitate meetings, and influence.
- Exceptional planning, organization, communication, presentation, multi-tasking, prioritization, documentation, and business analysis skills.
- Has an excellent attention to detail, highly analytical and problem-solving mindset. Able to identify process improvement opportunities, separate key issues, consider alternatives or multiple solutions, and effectively make recommendations.
- Experience with network, server, and appliance secure configuration (hardening) using frameworks such as CIS, DISA, and NIST.
- Experience with Identity and Access Management (IdAM) solutions. Experience with Privileged Identity/Access Management (PIM/PAM), a plus.
- Excellent hands-on experience with firewalls (perimeter and web application). F5 ASM experienced preferred.
- Excellent experience and knowledge of TCP/IP protocols, network/packet analysis and intrusion detection/prevention.
- Excellent experience and knowledge of Data Loss Prevention (DLP) solutions.
- Excellent experience and knowledge of Azure security controls, including InTune, MDM, MAM, and Autopilot.
- Advanced experience with Anti-virus/Anti-malware products, and endpoint security control solutions, and URL filtering.
- Advanced experience with Vulnerability Management solutions.
- Advanced experience with scripting languages – PowerShell, Bash, etc.
- Demonstrated ability to identify and assess security patch and service pack releases and their associated impact, as well as an understanding of patch management systems.
- Experience working with a variety of security-related platforms and services, including: SIEM systems, Threat Intelligence platforms, Security Orchestration, Automation and Response (SOAR) solutions, Encryption technologies, File Integrity Monitoring (FIM), and other network and system monitoring tools.
- Experience troubleshooting security control related technologies and solutions.
- Experience with Public Key Cryptography (PKI) and deep understanding and knowledge of cryptography.
- Experience with NIST 800-53, NIST CSF, IS 27001, PCI-DSS and SOC standards. FFIEC, NCUA, GLBA a plus.
Does this sound like you? Do you have questions? Apply here to find out more!