IT Security Engineering Lead / Manager:
Security Incident Handling & Response:
Well versed in handling Security incidents and violations of standard security practices including malware, ransomware, phishing, Advanced
Persistent Threats, (DDoS) attacks, etc. Experience analyzing data from security tools such as EDR, SIEM, Firewall/UTM logs, Vulnerability Assessment reports, Pen test reports, etc.
Firewall/IDS/IPS Skills:
Significant experience with the design installation and management of firewalls, including IDS/IPS integration and configuring UTM (unified threat management) features such as AV, Content filtering, IPS/IDS, etc.
SOC/SIEM Management:
Significant experience in managing security information and event management (SIEM) tools and services. Ability to configure alerting within the SIEM and analyzing alerts to translate into real-time actions to mitigate or remediate threats. Incident Response Plan development experience preferred.
Audit & Compliance:
Significant experience in supporting security audits to confirm adherence to good security practices and ensuring regulatory compliance. Building Corrective Action Plans (CAPs) for each gap or variance and following through with mitigation or remediation.
Advanced Malware Prevention:
Significant experience with the installation, and use of modern EDR platforms like SentinelOne and CrowdStrike to prevent, detect, and identify Advanced Persistent Threats (APTs) that might circumvent traditional security solutions like anti-virus, firewalls, and IPS/IDS.
Digital Forensics:
Familiar with forensic tools and investigative methods used to find data, anomalies, and malicious activity on the network, in files, or other areas of the business.
Cultural and Work Environment:
Must be highly motivated and self-driven individual who can take initiative and work independently. Ability to handle tasks across multiple clients in a thoughtful and efficient manner.
What will you be doing?
As a IT Security Engineering Lead / Manager at Enterprise Integration, you will lead and manage a team that works cohesively to address enterprise clients’ needs. You will work with various clients implementing security controls, supporting UTM / Firewalls, IDS/IPS solutions, Endpoint Protection solutions, Data Loss Prevention, and Advanced Persistent Threat technology. You will help maintain operational effectiveness and efficiency of the clients security infrastructure.
We are a learning organization so you will be involved in conducting research on emerging products, services, protocols, and standards in support of security systems. You will participate in the review of security implications of new applications, optimizing network integrity by reconfiguring network core equipment, installing local and/or wide area networks, communications software, equipment, and network facilities and suggesting changes and upgrades to the security infrastructure.
The details:
Our environment consists of the below technologies, so the more alignment with this list, the better.
What you need for this position
8 - 10 Years of experience in large IT security environments, with progressively increased leadership roles.
2 - 4 Years of experience Managing a team of Engineers.
Must have a comprehensive understanding of all 8 domains of cybersecurity
Highly desired skill in automation of incident and vulnerability management of day to day operations
Should have a minimum of the Security+ certification and working towards certs such as:
CISSP, CEH, CASP+, Cisco CyberOps, CCNP Security
Additional Desired Skills: