Associate Director, Information Security Engineer
Manager
Analytics
Cyber Security
Cybersecurity Tools
Data Platform
Data Processing
Data Security
Engineer
Facilities Management
Ids/ips
Incident Response
Information Security
Information Technology (IT)
InfoSec
Log Management
Management
Network Security
Offensive Security
Project Management
Risk Management
Security
Security Compliance
Security Engineering
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
Splunk
Splunk Siem
Wireless Security
Job Description
Manage and operate security monitoring and SIEM capabilities to protect PPFA from incidents and system compromises in a 24x7 environment.
Responsibilities
- Manage Information Technology security protections to reduce impact of security incidents and system compromises across PPFA
- Deliver 24x7 security monitoring, event investigation and analysis, and provide countermeasure proposals
- Provide support and guidance to Tier I Analysts
- Provide technical assistance for Tier II and Tier III incidents as assigned
- Interface with the InfoSec Operations Team, MSSP, and IT MSP for security event architecture, collection, management, reporting, and alerting within PPFA SIEM platforms
- Engage with InfoSecOps, InfoSec, ITOps/MSP, the MSSP, ATS, and staff across PPFA and Affiliates
- Identify, implement, and maintain Information Security toolsets, with a primary focus on SIEM
- Interface with IT Ops to ensure proper security event logging setup
- Support Information Security SIEM management needs for PPFA and Affiliates where applicable
- Serve as a Subject Matter Expert for PPFA SIEM (currently Splunk): configure, manage, operate, and administer as part of managed SIEM operations
- Provide security monitoring and threat/risk analysis on a 24/7 basis
- Ensure established processes for event identification are followed; recommend new or refined event filtering and ensure updates are completed
- Ensure established processes for collecting relevant data and performing analysis are followed; confirm appropriate event assignment
- Follow an established process for Tier II escalations, identifying escalation source (MSSP, MSP, Affiliate, or other) and applying the correct triage and documentation processes
- Create and maintain Standard Operating Procedures (SOPs) for the Information Security Ops group and recommend security process improvements
- Support complex security tool-specific tasks using assistance and guidance from management, vendors, and MSSP resources
- Support vulnerability assessment setup, scanning, analysis, and remediations in coordination with IT Ops staff and corporate vendors
- Assist in Incident Response activities as assigned by management
- Other duties as assigned
Requirements
- Bachelor’s degree and 5+ years of industry experience
- Independent decision-making, including identifying analysis tracks for escalated events, analysis assignments, and escalation decisions from Tier I events through Incident Response-level remediations
- Experience with compliance requirements and standards including PCI, HIPAA, ISO 27001, NIST, CSF, MITRE ATT&CK, ITIL, COBIT, Sarbanes-Oxley, and SANS 20
- Experience with UNIX, AIX, Solaris, Linux, and Windows Server
- Knowledge of Network/System Intrusion Detection or Prevention Systems (IDS/IPS)
- Experience with Security Information and Event Management (SIEM)
- Experience with vulnerability scanner and penetration testing systems
- Wireless networking experience
- Switches/routers experience; basic firewall configuration
- Knowledge of TCP/IP networking, VPN, VLAN, NAT, and security concepts
- Security software and hardware asset management experience
- Ability to conduct forensic analytical studies and investigations
- Flexibility to adapt quickly to changing priorities and ambiguous situations
- Strong commitment to Planned Parenthood’s mission of promoting Sexual and Reproductive Health
- Passion for working on newer technologies and exploring the security domain
Technologies
- Splunk, SIEM
- UNIX, AIX, Solaris, Linux
- Windows Server
- IDS/IPS
- Vulnerability scanner, Penetration testing systems
- Wireless Networking
- Switches/Routers, Firewalls
- TCP/IP, VPN, VLAN, NAT
- PCI, HIPAA, ISO 27001, NIST, CSF
- MITRE ATT&CK, ITIL, COBIT, Sarbanes-Oxley, SANS 20
Location and Travel
- New York, NY (onsite)
- Travel: 0-10% as needed
Compensation
- $125,000 - $130,000 per year