Information Security Engineer

Posted 2 hours ago
Clinical Reference Laboratory
GENERAL STATEMENT OF RESPONSIBILITY: Identify, implement and monitor security systems and processes for the protection of the computer systems, networks and data.

Essential Functions

  • Coordinate and execute on IT security projects.
  • Identify and define system security requirements.
  • Assist with the development and documentation of Information Security standard operating procedures and policies ensuring best practices for the organization.
  • Develop strategies to respond to and recover from a security breach. Take a lead role in investigating security incidents, communicate information to management as quickly as possible to minimize risks and assist in root cause analysis.
  • Select, architect, operate and configure systems to protect data and information infrastructure, including firewalls, data encryption, network devices, Intrusion Prevention Systems, security appliances and software, etc.
  • Develop automated solutions for repeatable tasks.
  • Conduct periodic scans of the networks to identify vulnerabilities.
  • Conduct penetration testing to identity system weaknesses or process failures and help to remediate vulnerabilities.
  • Monitor the organizations networks and systems for security events.
  • Monitor computing environment and infrastructure logs, and network traffic for activities including but not limited to policy violations, abnormal behaviors, attacks, intrusions, best practice recommendations and security events.
  • Recommend and perform system hardening for OnPrem and Azure / AWS Cloud Environments.
  • Collaborate with internal resources to properly scope Identity and Access Management, configure roles and monitor for compliance.
  • Generate queries for correlation of logs and events using a SIEM solution.
  • Certificate and Key generation, issuance and management.
  • Assist with Data Classification within the environment and develop governance controls.
  • Assist in complying with SOC 2 Type 2 controls.
  • Help maintain high security standards within SDLC and CI/CD pipeline for development practices.
  • Develop strategy and coordination of disaster recovery and business continuity planning.
  • Maintain and protect the confidentiality of all CRL, CRL subsidiaries, legal entities and client information.
  • Comply with all applicable federal, state, and local safety and health regulations that would apply to this job.
  • Keep work area neat and clean.


Other duties as assigned.

Job Qualifications

EDUCATION: Bachelor’s Degree in Information Systems, Computer Science, Information Security or a related technical discipline, or the equivalent combination of education, professional training or work experience.

Experience

  • 8 years IT experience
  • 5 years of security specific experience with increasing responsibility
  • Qualifications to acquire CISSP (ISC2), GISCP (GIAC), GSLC (GIAC), or CSQE (ASQ) certification within 12 months of hire required.


Skills & Abilities

  • Direct experience with anti-virus software, intrusion detection, firewalls and content filtering
  • Knowledge of risk assessment tools, technologies and methods
  • Experience designing secure networks, systems and application architectures
  • Knowledge of disaster recovery, computer forensic tools, technologies and methods
  • Experience in the development, deployment and maintenance of security policies, procedures, standards and strategies.
  • Professional experience in a system administration role supporting multiple platforms and applications
  • Ability to communicate network security issues to peers and management
  • Ability to read and use the results of mobile code, malicious code, and anti-virus software
  • Experience in Azure and/or AWS Cloud environments and associated security toolsets
  • Experience managing security appliances e.g. F5, Firewalls, and SIEM solutions.
  • Familiarity with IPS / IDS
  • Experience with Web Security Proxies and Data DLP Solutions
  • Experience creating queries with Splunk or other SIEM solution
  • Knowledge of configuration and integration MFA solutions
  • Working knowledge of Security Solutions.
  • Understanding of the Encryption Protocols and managing high strength ciphers
  • Working knowledge and understanding of SOC, ISO27001, or similar certification standards.
  • Some scripting / Coding experience preferred: Bash, PowerShell, Java, .NET, Python, AWS CLI
  • Ability to be at work and on time
  • Ability and judgment to interact and communicate appropriately with other employees, clients and management


PHYSICAL REQUIREMENTS: The physical demands described here are representative of those that must be met to successfully perform the essential functions of this job. Reasonable accommodations may be available to enable qualified individuals with disabilities to perform the essential functions.

The Following Physical Attributes Are Required For This Position

  • Sitting for extended lengths of time
  • Close vision requirements due to computer work
  • Repetitive use of hands, fingers, wrists, and elbows for operating a computer and telephone
  • Light lifting, up to 10 pounds


EQUIPMENT: PC and communications equipment

OTHER: Overtime and weekend work as necessary according to workload and/or projects; occasional travel is required; this is an “on-call” position requiring the use of wireless phone for after-hours contact.

The employer shall, in its discretion, modify or adjust this position to meet the company’s changing needs.

This job description is not a contract and may be adjusted as deemed appropriate in the employer’s sole discretion.

  • denotes essential job function


An Equal Opportunity Employer

Pay Range: $95,000 - $180,000

Starting Pay Range: $95,000 - $115,000

Benefits For Full Time Employees

  • Medical, Dental, Vision
  • Life/AD&D
  • Supplemental Life/AD&D
  • Section 125 FSA Plan
  • 401(k)
  • Short and Long-Term Disability
  • Paid Time Off
  • Holidays
  • Tuition Reimbursement
Login to Apply Now

Recommended Jobs