Security Engineer I
About the Role
The Security Engineer is responsible for providing daily operational information security support to the Nordic Global client’s enterprise. This position supports cybersecurity initiatives throughout the enterprise and acts as a resource for local system markets, facilities, departments, and units on technical cybersecurity matters. The role involves close collaboration with cybersecurity teammates, the Infrastructure Services staff, and the Internal Audit department.
You will conduct and document investigations of suspect or potential security breaches, policy and standards violations, and compromises across the enterprise, including audits of complex computer applications and technological solutions. The role requires recognizing security risks and making appropriate recommendations to governance bodies, as well as identifying and analyzing information to support cybersecurity objectives.
Responsibilities
- Operate, maintain, and troubleshoot cybersecurity technologies.
- Recognize cybersecurity risks and make appropriate recommendations for addressing them.
- Analyze and recommend secure technical solutions for network/system connections to individuals, contractors, vendors, and business partners.
- Implement, support, and evaluate cybersecurity-focused tools and services.
- Administer and analyze data from network security devices and services to prevent security threats and reduce risk.
- Provide periodic security reporting.
- Work closely with IT teams and third-party vendors to identify and provide secure IT solutions.
- Assist in developing and implementing security policies and procedures involving network security architecture, network access, and monitoring.
- Adhere to all policies defined by management related to change control, security, and separation of duties.
- Perform system implementations and significant changes to existing systems to ensure compliance requirements and critical risks are adequately addressed.
- Remain current with cybersecurity trends and threats, identifying those that pose risks to systems and developing appropriate responses.
- Develop change management requests related to security technologies.
- Other duties as assigned.
Requirements
- Generally requires a Bachelor's degree and 3 years of related experience, or 6 years of related experience with no degree.
- 3 years of combined relevant work experience in cybersecurity, information technology, and/or information security operations.
- Experience with cybersecurity toolsets such as: CyberArk, Securelink, Crowdstrike, Nessus, Palo Alto, Varonis, and Windows Defender suite.
Skills
- Skill in applying and incorporating information technologies into proposed solutions.
- Skill in designing the integration of hardware and software solutions.
- Skill in determining how a security system should work (including its resilience and dependability capabilities) and how changes in conditions, operations, or the environment will affect these outcomes.
- Skill in applying cybersecurity and privacy principles to organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Basic/fundamental knowledge of computer networking concepts and protocols, and network security methodologies.
- Basic/fundamental knowledge of risk management processes (e.g., methods for assessing and mitigating risk).
- Basic/fundamental knowledge of laws, regulations, policies, and ethics as they relate to cybersecurity and privacy.
- Basic/fundamental knowledge of cybersecurity and privacy principles.
- Basic/fundamental knowledge of cyber threats and vulnerabilities.
- Basic/fundamental knowledge of specific operational impacts of cybersecurity lapses.
- Basic/fundamental knowledge of cybersecurity and privacy principles and organizational requirements (relevant to confidentiality, integrity, availability, authentication, non-repudiation).
- Basic/fundamental knowledge of security system design tools, methods, and techniques.
- Basic/fundamental knowledge of critical infrastructure systems with information communication technology that were designed without system security considerations.
- Basic/fundamental knowledge of network security architecture concepts including topology, protocols, components, and principles (e.g., application of defense-in-depth).
- Basic/fundamental knowledge of network systems management principles, models, methods (e.g., end-to-end systems performance monitoring), and tools.
- Basic/fundamental knowledge of cybersecurity-enabled software products.
- Basic/fundamental knowledge of multi-level security systems and cross-domain solutions.
- Basic/fundamental knowledge of program protection planning (e.g., IT supply chain security/risk management policies, anti-tampering techniques, and requirements).
- Basic/fundamental knowledge of configuration management techniques.
- Basic/fundamental knowledge of enterprise IT architectural concepts and patterns (e.g., baseline, validated design, and target architectures).
- Basic/fundamental knowledge of integrating an organization’s goals and objectives into the architecture.
- Basic/fundamental knowledge of network security (e.g., encryption, firewalls, authentication, honey pots, perimeter protection).
- Basic/fundamental knowledge of physical and logical network devices and infrastructure (e.g., hubs, switches, routers, firewalls).
- Functional understanding of Microsoft Azure AD/Entra, Intune, and 365 operation with specific regard to cybersecurity considerations.
- Basic/fundamental understanding of KQL and experience writing queries.
Qualifications
Preferred certifications include: CompTIA Security+, CompTIA Network+, VMware, CyberArk, CISSP, CEH, SANS GPEN, GCIH.