🪄 Skills: Cloud ComputingCybersecurityMicrosoft Active DirectoryLinuxCompliance
Requirements:
A Bachelor's degree or higher in Computer Science, Electrical Engineering, Information Assurance, Network Security Computer Engineering or a related field, or equivalent experience
5+ years of Information Security / Cybersecurity experience
Strong knowledge of Information Security / Cybersecurity related technologies, processes, and tools.
Working knowledge of Office 365 security concepts, policies, settings, alerting, audit logging, security and compliance center, cloud app security and investigations is required.
Experience identifying assets (e.g. servers, network devices, applications), identifying network layouts and determining security risk and potential solutions.
Security focused degree and/or certifications a plus (e.g. BS/MS in Cybersecurity or related discipline, CEH, OCSP, CISSP, CISA, CompTIA Security+, etc.)
Familiar with network security concepts and products (e.g. firewall (Palo Alto, Cisco), network (e.g. Cisco, Meraki), email (O365). Cisco Umbrella a major plus).
Familiar with endpoint security products and concepts (e.g. malware protection, network protection, forensics, DLP, compliance. Bitdefender a plus).
Familiar with security monitoring (SIEM), analysis and resolution of security events/alarms (AlienVault a plus).
Familiar with identity and access management concepts (e.g. Azure Active Directory, SSO, user access reviews).
HIPAA and healthcare experience a plus
Understanding of SDLC process is a plus
Excellent oral and written communication skills.
Responsibilities:
Monitor and manage the Information Security request queue, including analysis and resolution of outstanding issues and process improvement.
Manage endpoint and network security environments including overall health, policy modifications, troubleshooting/resolving issues and producing monthly health metrics for workstations, servers, and identities.
Work directly with the Security Operations Center (SOC) to analyze and resolve security events/alerts.
Work directly with Information Security Engineering and Governance, Risk and Compliance (GRC) resources as needed to investigate and resolve issues.
Supports and manages the vulnerability management platforms for infrastructure and application scanning.
Conduct internal security control testing.
Supporting PCI, SOC1/2, HIPAA, and client security assessments.
Manage and maintain Information Security training and awareness campaigns (e.g. training, phishing).