Security Engineer
Role Summary:
Reporting to the Chief Information Security Officer, the Cybersecurity Engineer is responsible for implementing and maintaining security technologies, processes, and controls that protect the organization's information assets. This role supports cybersecurity operations, identity and access management, governance, risk, and compliance (GRC) activities, and emerging AI security initiatives. The engineer will assess security risks, implement technical safeguards, support regulatory and compliance requirements, monitor security events, and help establish governance frameworks for the secure adoption and use of artificial intelligence technologies.
Responsibilities:
Security Engineering & Operations
Evaluate, deploy, and administer security tools, technologies, and controls to strengthen the organization's security posture.Apply security policies, standards, and industry best practices to support enterprise security objectives.Respond to alerts and events from security monitoring systems by performing triage, investigation, analysis, and escalation.Tune detection systems to reduce false positives and develop new threat detection and response capabilities.Contribute to the organization's threat hunting program through hypothesis development, investigation, and reporting.Collaborate with internal teams and external partners during security incidents and response activities.Support vulnerability management activities, including identification, assessment, prioritization, remediation tracking, and reporting.Submit and track changes through the organization's change management process to maintain system integrity and security.Application & Cloud Security
Support secure software development practices by identifying, communicating, and addressing application security risks.Collaborate with development teams to validate remediation efforts through testing and review.Participate in security architecture reviews for cloud, SaaS, and enterprise applications.Support onboarding of new applications into the organization's identity and access management ecosystem.Identity & Access Management
Assist with implementation and administration of identity governance, privileged access management, and authentication technologies.Support periodic access certification and segregation-of-duty reviews.Governance, Risk, and Compliance (GRC)
Conduct cybersecurity risk assessments and document identified risks, mitigation strategies, and residual risk.Support the development, maintenance, and review of security policies, standards, procedures, and control frameworks.Assist with regulatory, audit, and compliance activities, including evidence collection, control validation, and remediation tracking.Maintain risk registers, exception processes, and security metrics for reporting to leadership.Participate in third-party and vendor risk assessments.Support compliance initiatives aligned with frameworks such as NIST Cybersecurity Framework (CSF), CIS Controls, ISO 27001, HIPAA, and SOC 2.AI Security & Governance
Support the secure adoption and governance of artificial intelligence and machine learning technologies across the organization.Assist in developing AI security policies, standards, and risk management practices aligned with the NIST AI Risk Management Framework.Evaluate AI-enabled applications and services for security, privacy, compliance, and operational risks.Assess and monitor risks associated with generative AI, large language models (LLMs), third-party AI platforms, and AI-integrated business processes.Collaborate with stakeholders to implement controls that mitigate AI-specific threats, including prompt injection, data leakage, model misuse, and unauthorized access.Participate in AI security reviews, risk assessments, and governance activities to ensure responsible and secure use of AI technologies.Security Awareness & Training
Assist with the delivery of cybersecurity and AI security awareness training for employees and targeted user groups.Evaluate user-reported communications to identify phishing, social engineering, and other malicious threats and respond appropriately.Maintain security documentation, including playbooks, standards, procedures, and knowledge base articles.Assist in gathering, analyzing, and reporting cybersecurity and AI governance metrics for leadership.Qualifications:
Education & Experience:
- Bachelor's degree in Information Security, Cybersecurity, Computer Science, Information Systems, or a related field preferred; equivalent experience will be considered.
- 2-3+ years of experience in cybersecurity, information security, security engineering, security operations, risk or related disciplines.
- In-depth knowledge of enterprise infrastructure, including operating systems, directory services, system configuration, application hosting, and virtualization technologies.
- Familiarity with AI, machine learning, generative AI, or emerging AI governance and security practices preferred.
- Experience implementing and managing endpoint protection strategies such as data protection and malware defense.
- Experience supporting security governance, risk management, compliance, audit, or control assessment activities.
- Experience securing cloud platforms and service-based architectures (SaaS, PaaS, IaaS).
- Proficient in analyzing network traffic and identifying abnormal or malicious activity through packet analysis and monitoring tools.
- Experience with centralized event monitoring and log analysis platforms for security incident detection and response.
- Ability to assess, prioritize, and mitigate security vulnerabilities and clearly communicate risk mitigation strategies to technical and non-technical audiences.
Skills:
- Strong understanding of IT operations and security best practices, with the ability to identify improvement opportunities and implement process enhancements.
- Familiarity with vulnerability assessment, penetration testing methodologies, and secure system configuration practices.
- Skilled in leveraging data analysis tools and techniques to obtain, clean, and organize data to generate recommendations and insights
Specialized Certifications for Consideration:
- CompTIA Security+
- CompTIA CySA+
- Certified in Risk and Information Systems Control (CRISC)
- Certified Information Security Manager (CISM)
- Certified Cloud Security Professional (CCSP)
- ISC2 Certified in Cybersecurity (CC)