WinCo Foods
WinCo Foods · Phoenix, AZ · 2 wk ago
ManagementFull-time
About the role
Design, implement and support information security solutions for WinCo Foods’ technology environment. Actively monitor current threats and counter-measures, recommend and implement improvements to security architecture and security technology. Ensure ongoing regulatory compliance and the protection of WinCo Foods’ payment systems, computer systems, network devices and sensitive data.
Responsibilities
- Maintain an atmosphere of friendly, enthusiastic customer service with an emphasis on taking care of the customer.
- Provide exceptional customer service by telephone, email, and in person.
- Work with other Information Technology (IT) teams to ensure logical and physical security of all systems and data.
- Identify security gaps or weaknesses, and recommend solutions to reduce risk to the company.
- Lead initiatives to implement new security solutions.
- Identify vendors, evaluate tools and implement the solution(s).
- Establish vulnerability-scanning procedures and work with the necessary teams to prioritize and install patches and security fixes based upon risk and impact.
- As the subject matter expert for IT Security on company technology projects lead by other teams.
- Develop security protection goals, objectives and metrics consistent with enterprise best practices.
- Produce periodic reports on security metrics and incidents.
- Perform log and event analysis of systems and security technologies to identify anomalies and suspicious activity.
- Develop monitoring and alerting for security technologies including IDS/IPS, firewall, vulnerability scanning, security logging and event management.
- Respond to security incidents and coordinate response, containment, forensics and mitigation.
- Conduct information security investigations and threat assessments.
- Perform maintenance, configuration and support of IDS/IPS, firewall, web proxy, vulnerability scanning, SIEM, and other security technologies.
- Promote security awareness across the organization through end-user training, knowledge transfer, and documentation of threats and vulnerabilities.
- Actively research and communicate current threats and attack vectors to IT management.
- Develop, document and update IT security procedures and policies.
- Perform on-call support for security events.
- Perform other projects and duties as needed and assigned.
Requirements
- Educational requirements: Associates degree in IT, Computer Science, or related field AND five (5) years of IT Security or Engineering experience OR equivalent combination (seven (7) years) of education, training, and/or experience demonstrating considerable knowledge of IT security.
- Experience: At least five (5) years direct experience working in an enterprise technology environment in a security or engineering role.
- Technical skills: Demonstrating technical working knowledge of design considerations for Firewall, LAN, WAN, WLAN, VPN, Windows Server, Active Directory, DMZs, Certificate (PKI) Infrastructure, Unix/Linux, Virtual Infrastructure, and network protocols.
- Implementing and managing enterprise security solutions: Implementing and managing enterprise security solutions such as antivirus, encryption methodologies, IPS/IDS, Web Content Filtering, Identity and Access Management, email security, and monitoring and alerting.
- Security tools: Demonstrating familiarity with security tools used for penetration testing, vulnerability scanning and forensics.
- Security best practices: Implementing security best practices related to networks, servers, end-user devices and sensitive information.
- Log and event analysis: Hands-on with log aggregation or SIEM technologies including implementation and support.
- Cyber security concepts: Understanding of cyber security concepts, principles and industry-recognized security frameworks such as ISO 27002, NIST, CIS CSC, etc.
- Troubleshooting: Hands-on hardware and software troubleshooting.
- Data privacy practices: Understanding of applicable data privacy practices and laws.
- Customer service: Exhibiting excellent customer service skills, working well with others and demonstrating professionalism and courtesy in all customer interactions.
- Organizational skills: Demonstrating strong organizational skills, initiative and self-direction to effectively manage time and perform tasks to meet timelines and work quality expectations.
- High-pressure environments: Effectively prioritize and execute tasks in a high-pressure environment.
- Attention to detail: Continually assess WinCo’s security posture, and design and implement solutions for gaps.
- Communication: Demonstrate strong written and oral communication skills.
- Passion for IT Security: Be highly motivated with a passion for IT Security.
- Research: Communicate complex, technical, information and ideas to all levels of audiences.
- Interpersonal skills: Exhibit strong interpersonal skills.
- On-call availability: Be on call to respond to security incidents, including evenings, weekends and holidays as required.
- Travel: Travel up to 10% of the time.