Security Engineer
Cloud Platforms
Cybersecurity Tools
Endpoint Security
Engineer
Identity and Access Management
Incident Management
Incident Response
Information Security
Information Technology (IT)
InfoSec
Security Automation
Security Compliance
Security Engineer
Security Operations
Security Standards
Security Testing
Job Description
Grand BK Corp offers comprehensive benefits and a supportive work setup for security professionals in Carlstadt, NJ (onsite). This role provides a competitive salary range of $87,450 to $134,200 per year, with schedule coverage Mon-Fri, 8:30am to 5:30pm. If you thrive in a hands-on security environment, you will contribute to incident response, detection engineering, threat hunting, vulnerability management, and compliance support.
Benefits
- Health, Dental & Vision insurance / EAP (Employee Assistance Program) per company policy
- 401(k) Retirement Plan with up to 5% match per company policy
- Life Insurance and AD&D (Accidental death & Dismemberment) per company policy
- BTA Insurance (Business Travel Accident Coverage)
- Company provided lunch
- Paid-time off (PTO) and Paid Holidays per company policy
- Celebration & Condolence Benefits per company policy
- Smart Card: Earn additional 4 points to the standard $1 = 1 point
- Holiday Gift certificates per company policy
- FSA (Flexible Spending Account) per company policy
- DCFSA (Dependent Child Care Spending Account) per company policy
Responsibilities
- Monitor and manage security tools, including XDR/EDR, SIEM, vulnerability scanners, and email security; review security dashboards and alerts daily.
- Coordinate with the external SOC for alert triage and escalation, document alert dispositions (true positive, false positive, benign), and escalate confirmed incidents.
- Serve as first responder for security incidents, performing triage, containment, evidence collection with chain-of-custody documentation, and forensic analysis.
- Develop, tune, and test SIEM detection rules, correlation logic, and SOAR playbooks to improve automated detection and response.
- Conduct proactive threat hunting across endpoint, network, and cloud telemetry, and support purple team exercises with the SOC.
- Monitor threat intelligence sources such as NVD and CISA alerts and vendor bulletins; translate relevant advisories into detection signatures and use them to prioritize vulnerabilities.
- Run vulnerability scans and assessments using tools such as Nessus and Kenna, track remediation and patch compliance, and follow up with IT teams on overdue items.
- Perform web application security assessments aligned to OWASP Top 10 and internal penetration tests; coordinate external penetration testing engagements and validate findings.
- Collect and maintain PCI-DSS compliance evidence, conduct access reviews (AD and AWS IAM), and support configuration audits and external audit walkthroughs.
- Implement and maintain security controls on AWS infrastructure, including WAF rules, security groups, and network ACLs, and support firewall rule management.
- Support PAM operations, USB and external storage controls (SecurA), endpoint compliance monitoring, and Zero Trust initiatives such as micro-segmentation and identity verification.
- Lead or execute technical security projects including PAM deployment, tool rollouts, and compliance initiatives.
- Run security awareness training and phishing simulation campaigns, manage the training platform, and track completion rates.
- Handle security account provisioning and access requests, manage onboarding/offboarding security checklists, keep policies and runbooks current, and produce weekly and monthly security metrics reports.
Requirements
- Bachelor’s degree in Information Technology, Computer Science, Cybersecurity, or a related field.
- 4+ years of experience in information security, security engineering, security operations, or IT infrastructure (level I or II based on experience).
- Strong knowledge of network security (TCP/IP, DNS, firewall, VPN, IDS/IPS, network segmentation) and operating system security and hardening (Windows Server, Linux).
- Hands-on experience operating security tools including SIEM/XDR, endpoint protection, and vulnerability scanners (Nessus, Kenna, Nmap), plus alert analysis, triage, and patch coordination.
- Experience with security incident response and forensic analysis, including understanding common attack vectors (phishing, malware, ransomware) and the MITRE ATT&CK framework.
- Familiarity with detection engineering, threat hunting, and security automation, including SOAR platform and playbook development.
- Scripting skills for security automation (Python, PowerShell, or Bash) and knowledge of penetration testing tools and methods (Burp Suite, Metasploit, OWASP).
- Cloud security experience, preferably AWS (IAM, Security Groups, CloudTrail).
- PCI-DSS or other compliance framework experience, ideally in retail; experience working with an external SOC or MSSP is preferred.
- Certifications such as CompTIA Security+, CySA+, CEH, or GSEC are preferred; advanced certifications (CISSP, GCIA, GCIH, SSCP) are a plus.
- Bilingual in Korean and English preferred.
Compensation
$87,450 - 134,200 per year. Actual compensation will be determined based on relevant experience, qualifications, skills, and other job-related factors.