Sr IT Security Engineer
Application Security
Cisa
Cism
Cybersecurity Tools
Engineer
Firewall
Identity and Access Management
Incident Response
Information Security
InfoSec
OAuth
Remote Access Vpn
SAML
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Testing
Software Security
Solution Architecture
Vulnerability Assessment
Web Application Firewall
Job Description
Remote Sr IT Security Engineer role with AMA’s Infrastructure Ops team focused on cyber threat intelligence, security platforms, and day-to-day security operations.
Responsibilities
- Research, design, and advocate new security technologies, architectures, and products to support enterprise and customer/vendor security requirements
- Plan, document, and execute enterprise-wide security programs, including vulnerability identification and testing and a network scanning framework for public and private networks
- Configure and troubleshoot vulnerability assessment tools and endpoint solutions; run scans and research threats; summarize findings and corrective actions as appropriate
- Partner with IT, compliance, audit, and others to ensure application and infrastructure development, implementation, and administration meet IT security and regulatory audit compliance standards
- Communicate IT Security policies and procedures to management and end users across businesses
- Collect and analyze defined security metrics, including security dashboards and training results, for leadership reporting
- Develop and deliver information security awareness training, including phishing simulations and risk-based training content for high-risk users
- Identify, collect, and organize credible intelligence and subject matter relevant to current and emerging threats using available tools, applications, and open-source information
- Define and document application security standards for developers and ensure compliance with applicable security controls when those standards are used
- Design, lead, and project manage development and configuration of security tools and automation based on specific use cases
- Proactively monitor, analyze, block, and respond to malware and emerging threats; act as technical point of contact during and after security incidents, including digital forensics procedures
- Conduct operational threat hunting exercises to proactively find incidents within the AMA environment
- Perform threat modeling and risk assessments using standard security frameworks for cloud services
- Monitor and audit on-premise and cloud networks and systems, including service changes
- Document incident response procedures and support management communications during incidents
- Assist in managing security services providers
- Research new threats, attacks, and risks to infrastructure and software
- Define and document operating procedures for incident identification, investigation, and response
- Work with business teams to identify and address data security risks in business processes
- Analyze and recommend actions to improve security posture across cloud and hybrid environments and related services/configurations
- Improve security reporting by coordinating vulnerability management, penetration testing, and infrastructure compliance
- Create or update detailed operational processes and procedures covering security operations, incident management, and code development
Requirements
- Bachelor’s degree in Information Security, Engineering, Computer Science, or related field
- Demonstrated progression toward one or more security certifications: GIAC Certified Incident Handler (GCIH), GIAC Certified Intrusion Analyst (GCIA), CISSP/CISA, or CISM
- 5+ years of Security Operations experience, including cyber incident investigations
- Strong understanding of network and host-based security applications and tools
- Exposure to enterprise web application programming and Application Security (AppSec)
- Knowledge of browser security controls, web application security frameworks, and authentication infrastructures (SAML, OAUTH)
- Knowledge of technical infrastructure, endpoints, networks, databases, and systems as related to IT security and IT risk
- Understanding of cloud networking concepts and architecture to promote and develop cloud security designs and strategies (IaaS, PaaS, SaaS)
- Excellent written and verbal communication skills, including communicating technical concepts to business leaders and users clearly and with appropriate urgency/priority
- Ability to respond to security incidents promptly and independently under time pressure
- Excellent analytical, organizational, and communication skills; demonstrated ability to facilitate cross-functional teams
- Experience with continuous improvements and agile methodology
Technologies
- firewalls
- SIEM
- data loss prevention
- web application firewalls
- application security testing
- VPN
- SAML
- OAUTH
- GIAC Certified Incident Handler (GCIH)
- GIAC Certified Intrusion Analyst (GCIA)
- CISSP
- CISA
- CISM
- CISSP/CISA
Location: Chicago, IL (remote)
Salary: USD 115,523 - 150,972 per year