Location
Reston, VA, United States
Posted on
Dec 08, 2021
Profile
Salary: $150,000 / year
The Senior Security Engineer will design, install, configure, and maintain a set of security tools and serve as Subject Matter Expertise (SME) on the security tools he or she is responsible for. The Senior Security Engineer will design the Enterprise SIEM and build security monitoring use cases to monitor the firm’s security posture. This candidate will perform a key role in triaging security incidents, building run books, building incident response plans and automating security processes. This role will also involve the operations of the firm’s security tools.
PRINCIPAL RESPONSIBILITIES
• Design, install, configure and maintain the operation of a wide range of security tools: endpoint detection and response, RSA authentication service, SIEM, SOAR, email security, web proxy, etc. Must be an expert of a few security tools and be familiar with others.
• Design and fine tune security tools to protect the firm’s security posture. Evaluate new function releases of responsible platforms and able to operate the platform in optimal state.
• Gather security requirements and conduct proof-of-concepts to evaluate security vendors
• Provide incident response at network, endpoint and applications.
• Develop security monitoring for applications, endpoints and network.
• Lead advanced security analytics efforts for continuous monitoring of the technology environments
• Drive security automation of repeatable processes, containment & remediation activities and to improve efficiency
• Interface with senior stakeholders across the IT leadership team to proactively interpret risks and priorities.
• Responsible for day-to-day operations to monitor, troubleshoot, and ensure optimum performance of information security infrastructure
• Manage relationship with external security vendors, lead vendor assessments, and support incident response and remediation efforts
• Support the OF’s diversity and inclusion strategy by following policies and procedures that ensure opportunities for employees and diverse business partners.
• Assist with other job duties as assigned.
PRINCIPAL JOB REQUIREMENTS
• Experience
(10 years)
in design, implement and operate security tools in highly technical security infrastructure environments, preferably in Financial Services or related verticals with significant Compliance and Regulatory requirements
• Experience (10 years) in developing security monitoring use cases, performing incident responses, and fine-tuning security use cases to protect the firm’s assets and operations
• Hands-on experience with security technologies related to email security, web proxies, SIEM, SOAR, etc.
• Hands-on experience in defining
SIEM
security use cases, fine tuning log data, developing dashboards
• Experience with incident response and threat hunting
• Experience with SOAR and UBA methodologies
• Evaluate and recommend new and emerging security products and technologies
• Tenacious perseverance in investigating problems and processes, firm believer in established methodologies and best practices
• Experience in operating on-prem or
cloud-based
security platforms
• Understand how to evaluate various security configurations to maximize protection for the firm
• Experience with vendor security risk assessment and due diligence
• Perform daily operational processes for all information security systems and adhere to change control processes
•
Participating in tier 2 and tier 3 security operations support
and in information security incident handling as well as identifying security issues risks and developing mitigation plans
• Specialty certifications like CEH, GMON, GSOC, GCIH, GISP are preferred
• Ability to listen and integrate ideas from diverse groups of individuals, build and maintain respectful relationships, collaborate with others, and resolve conflicts constructively.
#zr7
IND 005-010
Company info
Sign Up Now - EmploymentCrossing.com
Recruiter job
90 Day Old Job