Information Security Engineer
Hamilton Porter is proud to support the hiring needs, of one of the leaders in small business refinancing. Our long time client, is looking for an Information Security Engineer.
Location: Remote (travel to Headquarters in Arlington VA twice a year)
The Information Security Engineer is responsible for working collaboratively with technology management teams. The Information Security Engineer will deploy and operate technical security controls, manage information security processes, validate compliance with information security standards, monitor security events and audit trails, respond to security incidents, and support audit and regulatory compliance activities.
What You Will Do:
- Provide tools, strategies and best in class service to establish repayment behaviors with customers
- Design, implement, and operate technical cybersecurity controls
- Define effective information security standards, processes, and procedures
- Perform security assessments and penetration tests
- Evaluate, recommend, deploy, and operate security tools and technologies
- Manage and analyze security events to ensure observability
- Ensure compliance with internal policies/standards and regulatory requirements
- Respond to security incidents; perform technical forensic investigations and root cause analyses
- Monitor industry trends and threat landscape
- Recommend necessary changes and improvements in controls or countermeasures
- Provide technical security mentoring to engineering peers and cybersecurity analysts.
What We’re Looking For:
- 5+ years of hands-on information security operations experience
- Expertise hardening, protecting, monitoring, and managing operating systems, mobile devices, and cloud services commonly employed in a mid-size corporate environment
- Proven track record of effectively supporting information security tools and processes (e.g.: patch and configuration management, log management, spam/malware control, web filtering, firewalls, proxies, APT, IDS, DLP, HIDS/NIDS, EDR, XDR, network access control, threat and vulnerability management)
- Experience protecting high-volume, high-availability web-facing environments
- Advanced network security -- thorough understanding of the OSI model and comprehensive knowledge of common protocols and services for levels 3 through 7
- Knowledge of encryption algorithms and related technologies, secure communications, TLS, PKI, encryption at rest
- Experience supporting technical infrastructure and applications testing, interpreting findings and prioritizing remediation activities
- Working knowledge of application security, common vulnerabilities, secure software delivery lifecycle, CI/CD processes and tools
- Advanced practical skills in at least one scripting language (e.g.: Python, Ruby, PowerShell)
- Comprehensive knowledge of Windows security and relevant topics (IDM, Active Directory, Azure, Office365, WMI, PowerShell)
- Familiarity with common cloud services (AWS preferred) and comprehensive knowledge of controls typically employed in a cloud-centric corporate, engineering, and production environments
- Familiarity with managing end-user controls in a hybrid (Windows/Mac/Mobile) environment
- Advanced written and verbal communication skills including ability to present technical subjects to technical and non-technical audiences
- Strong work ethics, attention to detail, and organizational skills
- Ability to work independently, lead technical security discussions, and effectively collaborate in a team setting, including with peers from different verticals
- Mid-level or higher technical industry certifications (OSCP, GPEN, GIAC)
- Experience at a 24/7 B2B SaaS company processing financial or regulated information
- Supporting information security audits and interpreting information security governance contexts for technical audiences
Compensation:
- Competitive base salary ($130K - $150K - DOE) + up to 10% performance bonus
- Outstanding Health Coverage - tons of company covered options across Health, Dental, Vision options + Flexible PTO + Pet and Car Insurance and Financial Services such as LegalShield
- 401K through Fidelity with 25% match
- Tons of other company wide perks...
Apply today we are quick to interview, and it's a 3 step interview process that moves fast!