Group Cyber Security Specialist
IJW Whiskey Company · Shelbyville, KY · 3 wk ago
EngineeringFull-time
About the role
A proactive and detail-oriented Cyber Security Specialist to safeguard the organization’s systems, networks, and data from evolving cyber threats. This role combines strong technical expertise with sound judgment, a continuous improvement mindset, and the ability to collaborate effectively across departments.
Responsibilities
- Security Monitoring and Incident Response
- Monitor, analyze, and respond to security alerts and events using SIEM and other security monitoring tools.
- Investigate suspicious activity, contain threats, and lead incident response efforts.
- Perform root cause analysis and implement corrective and preventive actions.
- Develop, maintain, and periodically test incident response plans and playbooks.
- Document incidents, response actions, and lessons learned.
- Risk Assessment and Vulnerability Management
- Conduct regular vulnerability scans and coordinate penetration testing activities.
- Identify, assess, and prioritize security risks; recommend and track remediation efforts.
- Perform security audits and support compliance assessments.
- Ensure patch management processes are effectively implemented and maintained.
- Continuously evaluate emerging threats and recommend mitigation strategies.
- Security Controls and Implementation
- Implement, configure, and maintain firewalls, IDS/IPS, endpoint protection, EDR solutions, and other security technologies.
- Manage identity and access controls, enforcing least privilege and zero-trust principles where applicable.
- Design and maintain secure network architectures and system configurations.
- Oversee encryption standards and data protection controls for data at rest and in transit.
- Participate in security reviews for new systems, applications, and infrastructure changes.
- Policy & Compliance
- Develop, update, and enforce cybersecurity policies, standards, and procedures.
- Ensure compliance with applicable regulatory and industry standards.
- Support internal and external audits and remediation of findings.
- Contribute to business continuity and disaster recovery planning efforts.
- Awareness & Training
- Deliver cybersecurity awareness training and promote a security-first culture.
- Provide guidance on secure system configuration and secure development practices.
- Partner with IT and business stakeholders to integrate security into operational processes.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or related field (or equivalent experience).
- 10+ years of experience in cybersecurity or IT Security Role.
- Knowledge of network security, firewalls, VPNs, IDS/IPS, and endpoint security.
- Experience with security tools (SIEM, vulnerability scanners, EDR solutions).
- CISSP, CISM, or CISA certification.
- Deep understanding of Microsoft 365 security requirements.