Information Security Engineer

Job not on LinkedIn

🕒 April 1

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of eTrepid Inc.

eTrepid Inc.

11 - 50 employees

📋 Compliance

🔐 Security

IT • Compliance • Security

eTrepid Inc. is a provider of advanced IT solutions dedicated to digital fortification. The company specializes in compliance, security, and cloud services, offering tailored solutions for businesses to achieve goals such as CMMC and HIPAA compliance. eTrepid supports organizations with IT and security management, featuring services like ThreatKrusher, continuous compliance, security awareness training, and 24/7 security monitoring. With over 10 years of expertise and partnerships across multiple states, eTrepid specializes in enhancing business operations through secure and efficient technology solutions. Their accredited experts provide services to meet the unique needs of their clients, ensuring optimum security and compliance.

📋 Description

• Participate in all aspects of planning, deploying, documenting, monitoring, & maintaining the layered security to protect the confidentiality, integrity, and availability within the corporate and client facing infrastructures. • Focus on protecting system boundaries, keeping systems and infrastructure hardened against attacks and securing highly sensitive data, along with securing user and computer identities. • Perform engineering, tuning, and provide guidance of network security controls & hardening including IDS/IPS, Web Filtering, Cloud Technologies, Email/Spam, and Firewalls. • Perform engineering, tuning, and guidance to the Information Security Team for incident response & SIEM management. • Experienced in cloud security and compliance for Azure and AWS. • Manage and support Identity and Access Management. • Support the investigation and resolution of security incidents. • Perform Security User Awareness Training and Phishing campaigns. • Perform vulnerability management as well as support penetration testing and remediation. • Perform engineering, tuning, & provide guidance of mobile & endpoint security controls & hardening including AV, Endpoint Detection & Response, DLP, & encryption. • Translate security controls and requirements into system specification requirements. • Perform 3rd party vendor risk management assessments. • Plan, develop, and enhance security standards, requirements gathering, and engineer security solutions across the risk and technology portfolio. • Assist in designing computer security architecture and develop detailed cyber security designs. • Engineer, implement and monitor security measures for the protection of computer systems, storage, infrastructure, and cloud applications. • Define system security requirements, identify vulnerabilities, and coordinate remediation plans. • Support and coordinate risk assessments and security evaluations for vendors deploying solutions either on premise or in the cloud. • Participate in proof of concepts and other technical evaluations of technologies, designs and solutions and provide recommendations. • Plan and coordinate the deployment of security and vulnerability patching to all computer systems. • Prepare and document standard operating procedures and standards. • Develop technical solutions and select and implement new security tools to help mitigate security vulnerabilities and automate repeatable tasks. • Write comprehensive reports including assessment-based findings, outcomes, and propositions for further system security enhancement. • Plan/automate/deploy new infrastructure and security capabilities. • Participate in security awareness trainings, webinars, and podcasts designed as a Subject Matter Expert (SME). • Adept at Presenting in-person and virtual to customers, partners, and executives.

🎯 Requirements

• BS degree in Computer Science, Information Systems or equivalent experience preferred. • CISSP certification required. • Industry certifications preferred: CISA, CISM, CEH, GIAC, or equivalent. • 8+ years of relevant experience focusing on security analysis. • 3+ years of experience performing Network Security with expertise configuring Firewalls, Network IDPS systems, Data-Loss Prevention (DLP), VPN, Proxy/Web content filtering, WAF, NAC, Zero-Trust, GRE/IPSec, and/or Network segmentation. • Experience managing and configuring Vulnerability Management tools, Cloud Security (including CASB & M365), Identity and Access Management tools, and/or Multi-Factor authentication. • 3+ years of experience performing Endpoint Security with expertise configuring AV and/or MDR/EDR solutions, hardening Windows Server and Workstation OS, and/or MDM and Mobility. • Experience performing SIEM management and tuning, incident response, forensics, playbook development, and/or SOAR tools. • Ability to employ procedures, methods, and tools for identifying, representing, and formally assessing the important aspects of alternative decisions (options) to make an optimum (e.g. best possible) decision. • Experience with IT governance and/or risk. • Strong knowledge of network & infrastructure security architecture. • Experience working with Linux and Windows operating systems. • Experience with Microsoft Azure, IaaS, PaaS, SaaS, NaaS platforms. • Detailed and thorough knowledge of incident analysis and response concepts and techniques, including incident tracking process, root cause, lessons learned and process improvements. • Knowledge of compliance standards and security frameworks (COBIT, NIST, HIPAA, ISO27001/2, OWASP, PCI) • Knowledge of security regulations, frameworks and security requirements that impact SMB market (GLBA, HIPAA, PCI, NIST 800-171, NIST 800-53, NIST -CSF, CMMC) • Excellent analytical and problem-solving skills with the ability to work under pressure. • High level of personal integrity, with the ability to professionally handle confidential matters while leveraging the appropriate level of judgment. • Strong interpersonal and communication skills. • Ability to work well under stressful environments. • Ability to work extended hours and weekends when required.

🏖️ Benefits

• Employees can work remotely

Apply Now

Similar Jobs

🕒 April 1

Red Cup IT

11 - 50

🔒 Cybersecurity

☁️ SaaS

Security Engineer designing and maintaining systems to protect organizations from cyber threats. Collaborating with teams for security in applications and networks.

AWS

Cloud

Cyber Security

Firewalls

Python

SDLC

Terraform

🕒 April 1

Red Cup IT

11 - 50

🔒 Cybersecurity

☁️ SaaS

CMMC Security Engineer ensuring cybersecurity compliance and protecting Controlled Unclassified Information. Leading vulnerability assessments and supporting incident response in the Defense Industrial Base sector.

Azure

Cloud

Cyber Security

🕒 April 1

Digital Forge

11 - 50

🔒 Cybersecurity

📋 Compliance

Cybersecurity and Compliance Professional supporting IS027K, HITRUST, HIPAA, and NIST services. Performing vulnerability testing, risk assessments, and policy writing.

Cyber Security

🕒 April 1

ProSidian Consulting

11 - 50

⚡ Energy

🏢 Enterprise

Providing IT System Lifecycle Development and Management Support Services for the FDA's CFSAN. Seeking Small Business sources for technical and management services.

Cloud

🕒 April 1

Symmetry Systems

11 - 50

🔒 Cybersecurity

🏢 Enterprise

☁️ SaaS

Product Security Engineer shaping security architecture for Symmetry Systems' Data+AI Security platform. Collaborating with engineering teams to implement security features and best practices.

AWS

Azure

Cloud

Cyber Security

Google Cloud Platform