Security Engineer I
Columbia Bank New Jersey · Fair Lawn, NJ · 3 wk ago
On-siteInformation TechnologyFull-time
Columbia Bank is seeking a Security Engineer to oversee day-to-day security operations, serving as a technical operations subject matter expert. This role ensures the proper maintenance of security controls, threat detection, incident response, and remediation.
Responsibilities
- Security Operations: Execute, enhance, and document security operations processes. Support one or more security practice areas and assess platforms and practices for improvement.
- Incident Response Support: Review security events, perform investigations, and escalate matters to resolution. Collaborate with technology and business teams as needed.
- Security Platform Management: Monitor, troubleshoot, tune, and upgrade security platforms. Assist in implementing and operationalizing new security solutions. Coordinate with internal and external resources.
- Analytical Responsibility: Develop and analyze security-related content (reports, alerts, dashboards, metrics) to drive actionable insights and follow-through on action plans.
- Project Management: Assist in managing small to medium-sized projects according to project schedules.
- Professional Development: Stay current with industry trends, threats, and advancements in cybersecurity. Commit to ongoing education and training.
- Other Duties: Perform additional job-related tasks as assigned, including:
- Conduct daily vulnerability assessments and risk evaluations on assets.
- Prioritize vulnerabilities and establish remediation timelines.
- Develop standard operating procedures for security solutions, incident responses, and escalation processes.
- Communicate security warnings, awareness materials, and best practices to end-users.
- Create performance metrics, trend data, and customized reports for Risk, IT, and Information Security teams.
- Analyze security events, alerts, and notifications from security tools.
- Investigate incidents and collaborate with the CISO and business units on threat response.
- Coordinate risk mitigation and service outage resolution with internal and external resources.
Requirements
- Bachelor’s degree in an IT-related discipline (required).
- At least 5 years of experience in information technology, security, or risk management.
- 3+ years in an information security role.
- 1+ years of engineering experience.
- Relevant certifications or advanced degrees may substitute for experience.
- Knowledge of one or more security practice areas, including:
- Security architecture, identity and access management, asset management.
- Vulnerability management, threat detection and response, endpoint security.
- Network security, cloud security, web/email/data security, threat intelligence.
- Configuration management.
- Experience with:
- Log analysis, packet flow, TCP/UDP traffic, firewall technologies.
- IDS technologies (e.g., Snort rules), proxy technologies, antivirus/spam/spyware solutions.
- Scripting languages and automation methodologies.
- Intrusion detection methodologies for host and network-based threats.
- Cybersecurity frameworks, regulatory requirements, and industry best practices.
- Technical risk assessments.
- Deep knowledge of computer networking concepts, protocols, and network security methodologies.
- Commitment to ongoing professional education and certification in cybersecurity.
Benefits
- Contributory medical, dental, vision, and prescription coverage.
- Bonus programs.
- Employee Stock Option Program (ESOP).
- Life insurance, long-term disability, and accidental death and dismemberment (LTD & AD&D).
- Paid Time Off (PTO), including personal, vacation, and sick time.
- Bank holidays.
- 401(k) retirement plan eligibility.
Schedule
This role is eligible for a hybrid schedule: 3 days in the office and 2 days remote, based on business needs. This arrangement may change without notice.