POSITION SUMMARY:
The Managed Service Security Engineer is responsible for monitoring, detecting, and responding to security incidents to protect client environments. This role involves the identification of vulnerabilities, analyzing security risks, responding to security operations service tickets, and implementing protective measures. The Security Engineer will also perform security audits, incident response, compliance-related activities and projects, and provide technical guidance and mentorship to analysts and support staff.
PRINCIPAL DUTIES AND RESPONSIBILITIES:
- Client and Internal Support: Act as a point of contact and escalation to provide security-related support to clients and junior staff, addressing concerns, incidents, and queries in a timely manner.
- Security Monitoring: Configure and perform continuous security monitoring of client systems, networks, and applications for malicious activities or security breaches.
- Incident Response: Respond to security incidents, conduct investigations, containment, and remediation efforts to mitigate risks and protect client environments.
- Vulnerability Management: Identify, assess, and prioritize vulnerabilities in client systems, recommending and implementing mitigation strategies.
- Threat Intelligence: Utilize threat intelligence tools to identify potential risks and implement proactive defense recommendations.
- Compliance Support: Ensure client systems adhere to regulatory and compliance standards (e.g., PII, HIPAA, PCI-DSS) as required.
- Security Audits: Perform internal and external security audits, including the preparation, maintenance, and presentation of audit documentation.
- Documentation: Assist with the development and maintenance detailed records of security incidents, operational tasks, and system configurations in accordance with best practices.
KNOWLEDGE, SKILLS AND ABILITIES:
- Education: Bachelor's degree in information technology, Computer Science, a related field, or additional years of relevant job experience.
- Experience: Minimum of 2-3 years of experience in an IT security or service role, preferably in a managed services environment.
- Certifications: Relevant certifications such as CASP+, CISSP, CEH, CompTIA Security+, or equivalent are preferred.
- Skills:
- Strong understanding of security frameworks (e.g., NIST, ISO 27001).
- Experience with security information and event management (SIEM) tools.
- Excellent analytical and problem-solving abilities.
- Strong communication and interpersonal skills for client-facing interactions.
- Ability to manage multiple security incidents and tasks simultaneously.