Sr IS Systems Engineer
About the role
This position will be responsible for designing, implementing, and maintaining robust security solutions to protect our organization's information assets. This role requires a strong understanding of cybersecurity principles, hands-on experience with security technologies, and the ability to collaborate with cross-functional teams to mitigate risks and ensure the integrity of our systems.
Responsibilities
Design and implement security infrastructure, including firewalls, intrusion detection systems, VPNs, and endpoint protection solutions, to safeguard company networks and data.
Develop and enforce security policies and procedures to ensure compliance with industry regulations and best practices. This includes creating incident response plans, access control policies, and security awareness training programs.
Implement, architect and provide guidance on Identity management best practices
Implement, architect and provide guidance on Data security best practices
Remediate vulnerabilities and provide guidance on the method of remediation
Conduct regular vulnerability assessments and penetration testing to identify and remediate security weaknesses in our systems.
Stay updated on emerging threats and recommend proactive measures to strengthen our defenses.
Implement security monitoring tools to detect and respond to security incidents in real-time.
Cook up incident response efforts, investigate security breaches, and implement corrective actions to prevent future occurrences.
Assess the security risks associated with new technologies, systems, and processes. Work closely with IT and business teams to identify potential threats and develop strategies to mitigate risks effectively.
Maintain documentation and evidence of compliance activities for audits and regulatory inspections.
Coordinate with the Information Security Operations Manager to create new or modify existing technical security documents, playbooks or runbooks.
Participate in Security Operations activities such as monitoring and triage of security events, intrusion detection, analysis of anomalies, threat hunting, security operation monitoring, and tuning of security systems and tools.
Monitor, track, and maintain certificates/certificate providers.
Document security breaches and assess the damage.
Assist with support of existing systems and/or business requests.
Detect and respond to cyber security threats to ensure Blaze CU operates securely.
Identify gaps and propose solutions to increase security efficiency and effectiveness.
Identify, evaluate, and apply vulnerability remediations or provide recommendations.
Act as technical security advisor to the institution, members and peers.
Subscribe to threat notification networks, new regulations and information sharing networks to stay current on requirements and new threats to the industry.
Build relationships across the organization to ensure efficient use of controls.
Create a robust network of diverse information security and technical professionals.
Attend continuing technical security and fraud education appropriate to the position.
Attend a certain number of company sponsored security training/education classes including the following areas – BSA, AML, OFAC, privacy, safeguarding member information and physical security.
Offer training on technical controls affecting the security and privacy of member information.
Requirements
Minimum High School degree or equivalent. Bachelor’s degree in business, computer science or related field preferred
4+ years’ experience in Information Security, preferably in the financial industry
Security+/CySA+/Pentest+/Microsoft or similar certifications preferred
Advanced knowledge of Identity access management
Advanced knowledge of Data security best practices
Demonstrated Knowledge Advanced PC skills and aptitude in various software applications
Advanced problem-solving skills to evaluate risk, analyze complex security incidents and develop solutions to mitigate risk
Understanding of local and wide area networks (LAN/WAN), Internet, electronic communication systems, telecommunications, virtualization
Advanced understanding of information security technologies (e.g. firewalls, VPNs, IDS/IPS, penetration testing, security devices)
Experience with programming and scripting languages
Understanding cryptographic algorithms, encryption techniques, hashing functions, digital signatures, and certificate management
Familiarity with SSL/TLS protocols and PKI infrastructure
Awareness of emerging technologies such as cloud computing, containerization, Internet of Things (IoT), and artificial intelligence (AI), and their security implications
Ability to assess risks and implement security controls for new technologies
Ability to analyze results, prioritize vulnerabilities, and recommend remediation measures
Advanced understanding of information security technologies such as endpoint protection, SEIM, firewalls, VPNs, IDS/IPS, vulnerability scanning, and data loss prevention
Communication Skills Ability to proactively respond to members/staff to document and develop new and ongoing techniques to improve processes; written communications draw from expert information from the field whether as an individual contributor or manager
Physical Requirements Ability to sit and stand; answer calls; operate computer; interact with internal staff and public on the phone; travel to designated offices; lift up to 20 lbs