Information Systems Security Engineer

NYSTEC
Rome, NY, US
$79.8K-$109.7K a year
Full-time

About Us :

NYSTEC is a nonprofit technology consulting company, advising agencies, organizations, institutions, and businesses since 1996.

We’re independent and vendor-neutral, so we have our clients’ best interests at heart. At NYSTEC, we know that we succeed when individuals and teams flourish personally and professionally, so our benefits and perks support that mindset.

About the Role :

The information systems security engineer assists the deputy chief information security officer (CISO) with the development and support of NYSTEC's information security initiatives.

This position will interface with staff and management across all levels of NYSTEC, as well as with external business partners, to ensure that NYSTEC's critical business functions and systems are secure and in accordance with best practices.

The information systems security engineer will execute all information security functions for the company to mitigate risk and to balance enhanced capacity and productivity.

Key Responsibilities

  • Ensure security configuration compliance on requirements, including but not limited to Health Insurance Portability and Accountability Act / Health Information Trust Alliance (HIPAA / HiTrust), National Institute of Standards and Technology (NIST) Cybersecurity Framework, and state and federal regulations.
  • Administer security toolsets and assist external security vendors and the NYSTEC technical systems team (Service Delivery and Internal Services) in defining the scope of internal and external vulnerability scans and penetration tests.
  • Develop and deliver security awareness training for the organization.
  • Lead the creation and review of enterprise security documents, policies, standards, guidelines, and procedures.
  • Ensure the confidentiality, integrity, and availability of the data residing on or transmitted through the organization’s systems, applications, databases, and any other data repositories.
  • Collaborate with the technical services team and cross-functional departments to remediate security risks.
  • Provide recommendations for additional security solutions or enhancements to improve the overall security and defense-in-depth strategy.
  • Assist in the deployment, integration, and initial configuration of all new security solutions and any enhancements to security solutions in accordance with established best practices and standards.
  • Research, develop, implement, test, and review the organization’s information security to protect information and to prevent unauthorized access.

About you :

Required Qualifications

  • Proficient in Windows operating environment using Microsoft Office applications, email, and internet programs.
  • Experienced information security professional skilled in developing, documenting, and driving the adoption of information security standards and procedures.
  • Strong background with firewall products, intrusion detection systems, demilitarized zone (DMZ), Internet Protocol Security (IPSec), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), Hypertext Transfer Protocol (HTTP) proxies, etc.
  • Willing to maintain up-to-date knowledge of the information technology (IT) security industry, including awareness of new or revised security solutions, improved security processes, and the development of new attacks or threat outbreaks.

This should include the continuation of education and certifications to maintain compliance with regulatory requirements and guidelines.

  • Good organizational skills to maintain documentation and to gather evidence for reporting and incident analysis.
  • Knowledge of security best practices across multiple platforms, such as Microsoft Windows, Microsoft Office365, and Azure.
  • Strong project management skills.
  • Strong written and verbal communication skills, time-management skills, and task prioritization skills.
  • Experienced in zero trust technologies, least privileges, network architectures, and segmentation.
  • Understands NYSTEC’s mission, brand mindsets, and core values and can put the behaviors into practice.

Preferred / Desired Qualifications

Certified information systems security professional (CISSP) or similar certification in information security preferred.

Education and Experience

A bachelor's degree, preferably in cybersecurity or a similar discipline, and five years of experience with security management frameworks (e.

g., National Institute of Standards and Technology NIST , SysAdmin, Audit, and Network and Security SANS ). An equivalent combination of advanced education, training, and experience will be considered.

The pay range for this position is $79,793.00 to $109,716.20.

30+ days ago
Related jobs
Promoted
NYSTEC
Rome, New York

The information systems security engineer assists the deputy chief information security officer (CISO) with the development and support of NYSTEC's information security initiatives. The information systems security engineer will execute all information security functions for the company to mitigate ...

NYSTEC
Rome, New York

The information systems security engineer assists the deputy chief information security officer (CISO) with the development and support of NYSTEC's information security initiatives. The information systems security engineer will execute all information security functions for the company to mitigate ...

Appian
New York, US

Here at Appian, our core values of Respect, Work to Impact, Ambition, & Constructive Dissent & Resolution define who we are.In short, this means we constantly seek to understand the best for our customers, we go beyond completion in our work, we strive for excellence with intensity, & we embrace can...

Appian
New York, US

Here at Appian, our core values of Respect, Work to Impact, Ambition, & Constructive Dissent & Resolution define who we are.In short, this means we constantly seek to understand the best for our customers, we go beyond completion in our work, we strive for excellence with intensity, & we embrace can...

HelloFresh
New York, US

As the Systems Development Engineer for Strategic Initiatives, you will be responsible for developing & maintaining the Ignition based Supervisory Control & Data Acquisition (SCADA) systems for HelloFresh. Systems Development Engineer, Strategic Initiatives. Work closely with cross-functional teams,...

Fastly
New York, US

Fastly helps people stay better connected with the things they love.Fastlys edge cloud platform enables customers to create great digital experiences quickly, securely, & reliably by processing, serving, & securing our customers applications as close to their end-users as possible at the edge of the...

BAE Systems
Rome, New York

BAE Systems is looking to hire a Contractor Special Security Officer (CSSO) who will also server as the Facility Security Officer for programs executed out of the Electronic Systems, Rome, NY site. Provide classification guidance to employees, develop and provide security education and awareness tra...

Morgan Stanley
New York, US

The team's responsibility includes Engineering, Integration, Development and Operations of Network Configuration Management, Network Monitoring, Network Security and Network Packet Inspection Tools across both Vendor Made Solutions (Cisco / IBM / Redhat / OpenText / Broadcom / cPacket / Corvil) and ...

SoundCloud
New York, US

As a Senior Cloud Network Engineer, you will support architecting, operating, & maintaining our hybrid cloud network infrastructure. SoundCloud is looking for a Senior Cloud Network Engineer to join our Systraf team. Youll leverage your deep expertise in multi-region network topology, cloud networki...

JPMorgan Chase Bank, N.A.
New York, US

Act as a point of escalation for analysts on the team Required qualifications, capabilities, and skills * 3+ years of experience in cybersecurity operations, including threat detection, incident response, and vulnerability management * Demonstrated experience in network traf...