Select, configure, and implement security controls to reduce information security risk in the organization
Ensure compliance with KnitWell Group’s corporate information security policies and enforce implementation of security architecture
Safeguard the security of all computing platforms, data, and networking within the corporation; oversee security configuration and monitoring
Design, implement and configure security applications and infrastructure to support corporate policies and regulations
Lead application and system development teams to configure and deploy systems and applications securely, including cloud implementations
Design, plan, and conduct infrastructure security assessments of networking, servers, operating systems, databases and applications
Design secure network infrastructure including network segmentation, firewall policies, and security device configuration
Perform security baseline discovery and identify gaps between procedures, policy, and industry standards/best practices
Research and identify industry information security best practices and develop action plans to execute changes
Serve as a technical Team Lead on security projects and prepare deployment and post-deployment plans
Manage the full lifecycle of digital certificates including issuance, renewal, revocation, replacement, inventory tracking, and automated certificate management
Administer and optimize SIEM tools for real-time threat detection, analysis, and response; develop correlation rules, dashboards, and alerts
Analyze logs and security data from firewalls, endpoints, servers, and cloud services to identify potential threats and vulnerabilities
Collaborate with incident response teams to investigate and remediate security incidents
Perform all other security engineering duties as assigned
Requirements
Bachelor’s degree in Computer Science, Electrical & Computer Engineering or other related engineering discipline preferred, or equivalent work experience
5+ years in information security, with emphasis on security engineering
CISSP and GIAC certification desirable; other industry security certifications a plus
Risk Assessment experience; knowledge of IT risk management concepts such as risk assessment, risk identification, risk response and mitigation, risk monitoring and reporting
Experience in Cloud computing
Understanding of industry accepted framework, such as the NIST SP800 framework
Hands-on experience assessing complex networks and systems and leading design and configuration of complex security controls
Familiarity with Cloud implementations of applications and infrastructure
Knowledge of secure network infrastructure design including network segmentation, firewall policies, and security device configuration
Experience managing the full lifecycle of digital certificates and implementing automated certificate management solutions integrated with enterprise PKI
Experience administering and optimizing SIEM tools, developing correlation rules, dashboards and alerts
Ability to analyze logs and security data from firewalls, endpoints, servers, and cloud services
Experience collaborating with incident response teams to investigate and remediate security incidents
Must be authorized to work for any employer in the US without sponsorship