IT Info Security Specialist/Sr
Work from corporate office in Erie, PA.
Pay
Salary range: $79,191 – $126,500. Actual salary depends on role level, scope, complexity, skills, education, training, credentials, geographic location, and experience. Position may be eligible for an annual bonus payment.
Benefits
- Premier health, prescription, dental, and vision benefits for you and your dependents, with coverage beginning your first day of work and low employee contributions to premiums (ERIE currently pays up to 97% of monthly premium costs).
- Traditional pension plan (vested after five years of service).
- 401(k) with up to 4% company match.
- Paid time off: vacation, personal days, sick days, bereavement days, and parental leave.
- Career development: tuition reimbursement for higher education and industry designations.
- Additional benefits:
- Company-paid basic life insurance and short- and long-term disability insurance.
- Orthodontic coverage for children and adults.
- Adoption assistance and fertility/infertility coverage.
- Well-being programs.
- Paid volunteer hours and dollar-for-dollar matching of charitable gifts.
About the Role
Working independently or as part of a team, you will contribute to the planning, implementation, and management of the Information Security program to safeguard ERIE’s digital assets. You will implement and maintain security systems and procedures to govern, identify, protect, detect, respond to, and recover from cybersecurity risks, threats, vulnerabilities, and incidents. The role involves assignments of moderate complexity within the Information Security portfolio with minimal guidance, focusing on one or more of the following disciplines: Application Security (AppSec), Cloud Security (CloudSec), Governance/Risk/Compliance (GRC), Identity & Access Management (IAM), Security Operations (SecOps), or Vulnerability Management.
The hiring manager may also consider candidates for a Senior IT Info Security Specialist. The level offered will depend on the depth and breadth of the selected candidate’s experience and qualifications.
Responsibilities
- Installs, configures, administers, and analyzes information security technologies, controls, and practices to maintain the confidentiality, integrity, and availability of ERIE's information systems and data assets.
- Continuously detects, logs, monitors, alerts, and reports on information security controls, exceptions, vulnerabilities, threats, risks, and incidents.
- Executes actions to protect assets, detect vulnerabilities or threats, and respond to and recover from incidents.
- Develops and manages relationships with diverse stakeholders at multiple levels. Partners with cross-functional risk assurance, IT, and business teams to implement, align, and ensure compliance with security measures.
- Ensures security measures align with industry standards, best practices, and regulations. Measures and improves the operating rhythm of Information Security and the risk posture of ERIE.
- Advances Information Security controls through maturity assessments, process and automation improvements, policies/standards/procedures, and capability development.
- Develops and presents reports, metrics, dashboards, and evidence to stakeholders, including leadership and corporate officers.
- Provides support to end-users on security-related issues and communicates effectively to influence stakeholders through oral and written communications.
- Provides discipline-specific knowledge to support security awareness and outreach, ensuring best practices are understood and followed enterprise-wide.
- Remains current on industry best practices, standards, frameworks, regulations, and emerging security threats. Makes recommendations for improving the company’s security posture and shares knowledge with others.
The first seven duties listed are essential functions of the job. Regular and predictable attendance is required. For certain positions, including leadership roles, regular and predictable onsite presence may also be required based on business needs.
Preferred Experience and Skills
- Experience with application security practices, secure development methodologies, and vulnerability management processes.
- Familiarity with securing applications, APIs, and related platforms across cloud and on-premises environments.
- Software development experience or experience in a closely related role supporting software delivery.
- Experience with security assessments, tool evaluations, remediation support, developer education, and reporting to strengthen application security capabilities.
Qualifications
- Bachelor’s degree in a relevant field and 2 years of related experience; or
- Associate degree in a relevant field and 4 years of related experience; or
- High School diploma or equivalent and 6 years of related experience.
Completion of a relevant IT-career preparation program approved by ERIE’s Human Resources and IT Talent Optimization Departments may be considered if the degree is unrelated and/or experience is less than required. Relevant certifications and/or military training/service may also be considered for equivalent education/experience.
- Foundational knowledge and skill in at least one Information Security discipline and one IT domain (analysis, engineering, system administration).
- Experience with IT delivery or operational methodologies (Agile, SDLC, ITIL) is preferred.
- Critical thinking skills and an analytical mindset.
- Persuasive communication and interpersonal skills, with the ability to convey technical concepts to non-technical stakeholders.
- Ability to participate in on-call rotations and work outside regular business hours to support cyber event and incident handling may be required.
Physical Requirements
- Ability to move over 50 lbs using lifting aide equipment (rarely).
- Climbing/accessing heights (rarely).
- Driving (rarely).
- Lifting/moving 0–20 lbs (occasionally).
- Lifting/moving 20–50 lbs (rarely).
- Manual keying/data entry/computer use (frequent, 50–80%).
- Pushing/pulling/moving objects or equipment with wheels (rarely).