Information Security Engineer
HybridCharlotte, North Carolina, United States
Job Summary
Review and correlate security logs, lead or participate in computer security incident response activities for moderately complex events, and conduct technical investigations to identify causes and recommend mitigation strategies. Play a major role in phishing disruption efforts by creating new logic and procedures to identify attacks, while identifying vulnerabilities, performing risk assessments, and evaluating remediation alternatives. Design, document, test, and maintain moderately complex security solutions related to networking, cryptography, cloud, and endpoint security. Utilize industry-leading best practices to implement components ensuring availability, integrity, and confidentiality. Collaborate with peers to resolve issues and achieve goals within a fast-paced, high-demand environment.
Required Qualifications
- 4+ years of Information Security Engineering experience, or equivalent demonstrated through one or a combination of: work experience, training, military experience, education
Desired Qualifications
- Advanced Information Security technical skills
- Experience detecting and mitigating phishing attacks directed towards employees and the company brand
- Experience creating regular expressions and YARA rules
- Ability to manage complex issues and develop solutions
- Experience in one or more of the following security disciplines: information security monitoring; incident response; vulnerability management; host/network forensics; cyber-crime investigations; Domain-based Message Authentication, Reporting and Conformance (DMARC); or cyber threat intelligence
- Ability to execute in a fast paced, high demand, environment while balancing multiple priorities
- Certifications in one or more of the following: Global Information Assurance Certification (GIAC)
- Hands-on experience with information security tools such as an enterprise SIEM solution, IDS/IPS, endpoint security solutions, email/web security gateways, and other security detection/mitigation devices
- Experience with host and/or network log analysis as applied to incident response / threat hunting
- Knowledge of offensive security, with the ability to think like an adversary when hunting and responding to incidents
- Strong experience in operating system and application security hardening and best practices
- Strong investigative mindset with an attention to detail
- Advanced problem solving skills, ability to develop effective long-term solutions to complex problems
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.