Position Description:
The IT Security Engineer designs, implements, and manages security solutions to protect an organization’s digital assets, ensuring compliance with security policies and industry standards. Key responsibilities include: Evaluating, deploying, and maintaining security technologies and tools; performing risk assessments and vulnerability analyses; and preparing detailed reports and recommendations for improving the organization’s security posture. This role involves collaborating with stakeholders to develop security protocols, incident response plans, and operational processes that align with organizational goals while safeguarding sensitive data and systems.
Roles and Responsibilities:
- Design and Implementation of Security Solutions
- Conduct regular risk assessments and vulnerability scans to identify weaknesses in IT systems.
- Analyze findings and prioritize vulnerabilities for remediation.
- Develop and implement mitigation strategies to address risks.
- Monitor systems and networks for suspicious activities or breaches using SIEM tools and other technologies.
- Investigate, document, and respond to security incidents in alignment with incident response plans.
- Perform root cause analyses and recommend improvements to prevent future incidents.
- Create and update security policies, standards, and procedures to align with best practices and regulatory requirements.
- Ensure compliance with frameworks such as ISO 27001, NIST 800-53
- Work with IT, business units, and leadership to integrate security into all aspects of technology and operations.
- Provide technical guidance and support for secure application development and system configurations.
- Access Control and Identity Management
- Manage access control systems, including role-based access and privileged account management.
- Implement multi-factor authentication and single sign-on solutions.
- Educate others, as needed, on cybersecurity risks, phishing, and best practices.
- Ensure systems meet compliance requirements for applicable laws and regulations.
- Support internal and external security audits, providing evidence and implementing corrective actions as needed.
- Stay up-to-date on emerging threats, vulnerabilities, and cybersecurity trends.
- Proactively update security solutions and strategies to address new risks.
- Maintain detailed documentation of security configurations, incidents, and risk assessments.
- Prepare periodic reports for management on security metrics, incidents, and areas of improvement.
- Provide security expertise in IT and business projects to ensure security requirements are met.
- Evaluate new technologies for security compliance before implementation.
- Manage and maintain tools such as endpoint detection, encryption, data loss prevention (DLP), and vulnerability management systems.
- Ensure tools are updated and properly configured for optimal performance.
Qualifications:
- 5+ years demonstrated knowledge and experience in in general program/project management and\or Specialist contributor support.
- At least 4+ years in consulting or government contracting environment
- Bachelors Degree in business, Computer Science, Information Technology or a related field is required, Masters preferred
- Certifications such as CISSP, CISM, CEH, or CompTIA Security+
- Excellent communication, interpersonal, and organizational skills, able to present to upper management, as needed
- Innovative; thinks outside of box in delivering solutions to customer
- Strong decision making, and problem-solving, communication, and writing skills
A Commitment to Equal Opportunity
Zavenia is an Equal Employment Opportunity and Affirmative Action employer dedicated to fair and unbiased employment decisions. We do not discriminate based on race, color, sex (including gender and transgender status), age, religion, national origin, disability, marital status, veteran status, domestic partner or civil union status, gender identity, medical condition, genetic information, sexual orientation, or any other status protected by applicable federal, state, and local laws. Our hiring and promotion decisions are based exclusively on an individual’s qualifications and suitability for the role.