Information Technology Security Engineer
Colony Brands, Inc. · Monroe, WI · 2 days ago
On-siteInformation TechnologyFull-time
About the Role
SC Data Center, Inc., an affiliate of Colony Brands, Inc., is one of the world’s largest and most successful direct marketing catalog and e-Commerce companies. We are seeking an IT Security Engineer to promote and execute our information security programs, policies, and related regulatory compliance. This role operates within a lean team, requiring strong multi-tasking and a multi-faceted skillset. If you’re an IT professional with experience in process and procedure development for security—and prefer not to be restricted to a niche area—this position is for you.
Responsibilities
- Develop and implement a comprehensive information security program in collaboration with the IT Security team.
- Select and deploy technical controls to meet specific security requirements and define processes and standards to maintain security configurations.
- Define and promote information security policies, processes, and standards by designing secure technologies and monitoring compliance with company policies and applicable laws.
- Investigate and report security violations and incidents, advising on information security issues to ensure internal security controls are appropriate and operating as intended.
- Analyze information and processes to balance vulnerability levels with investment, personnel, and end-user capabilities.
- Serve as a subject matter expert to the business, providing security guidance.
- Partner with Project Teams to facilitate and implement new systems, policies, and processes.
- Coordinate with Managed Service SOC to centralize logging and identify security incidents or misconfigured security controls.
- Conduct responses to information security incidents, including forensic investigations as part of the Incident Response process.
- Prepare documentation, business notifications, and security alerts.
- Interact daily with employees on security alerts from EDR (Endpoint Detection & Response), SIEM (Security Incident & Event Management), phishing identification tools, and general service tickets.
- Research, recommend, and develop security and risk mitigation solutions.
Requirements
- Bachelor’s degree in MIS, Computer Sciences, Information Technology, or a related discipline.
- 3+ years of related business experience in information security engineering and policy/procedures.
- Broad and in-depth understanding of information security and information technology auditing.
- Commitment to continuous improvement and knowledge growth, staying current with security technologies.
- Documented ability to utilize security systems such as vulnerability scanners, logging software, Multi-Factor Authentication, SAML Federation, and experience with patch management processes.
- Experience with diverse desktop and server environments, networking, and operational security technologies both on-premise and in the Cloud (AWS preferred).
- Solid written and verbal communication skills at all comprehension levels; experience driving Security Awareness programs is desired.
Qualifications
- CISSP Certification is preferred.
- Experience working with small to mid-size companies is helpful.
- PCI, SOC1, Audit, and/or HIPAA experience is a plus.
Note: This position is not eligible for Visa Sponsorship.