Search jobs > New York, NY > Senior security engineer

Full-time, Senior Security Engineer

Prosum
NY, United States
Full-time
  • Full-time Employment job opportunity.
  • Visa transfers or sponsorships are not available.
  • Hybrid position, work schedule 1 day onsite in New York (10154)
  • Salary & bonus

The Senior Security Engineer is a critical technical role responsible for managing cybersecurity measures, responding to incidents, and playing a vital role in the organization's administration, development, auditing, and documentation of IT Security systems.

The Senior Security Engineer will work closely with the InfoSec team and the Enterprise Architecture and Service Delivery (EA&SD) team and contribute to enhancing the organization's internal and Cloud security framework.

This role involves participation in Incident Response, Business Continuity and Disaster Recovery planning, vulnerability assessments, and ensuring compliance with the organization's data security policy, ISO 27001 : 2022, ISO 27017 : 2015, ISO 22301 standards, and client audit requirements.

Qualifications for the Role :

  • Bachelor's degree in Computer Science or related field, or at least 5 years of relevant experience.
  • Minimum of five years in a System Security Engineer role or similar.
  • Demonstrated ability to develop and manage security systems.
  • Expertise in Azure, AWS, Microsoft E5, Sentinel, Defender for Endpoint, and other security technologies.
  • Proficiency in network security and monitoring.
  • Recognized security certifications (CISSP, CISM, CISA, GIAC, CCSP, OSCP, CEH, etc.).
  • Skilled in automation scripting with Python, Bash, & PowerShell.
  • Experience in designing security architecture for various deployment models.
  • Knowledgeable in enterprise security solutions and security protocols.
  • Experience with regulatory compliance and information security management frameworks (NIST, IS027001, PCI DSS, GDPR, HIPAA, etc.).
  • Familiarity with security frameworks like MITRE ATT&CK and CIS 20.
  • Experience with DevOps and CI / CD pipeline security aspects, including container orchestration security.
  • Knowledge of data privacy practices and laws.

Responsibilities :

  • Implement and configure security systems under the CISO's guidance while supporting the security infrastructure for various platforms and applications.
  • Provide 24 / 7 support for security incidents, ensuring immediate escalation and remediation.
  • Mentor junior staff in the utilization of security tools, report generation, and issue resolution and facilitate cross-training within the team.
  • Document and escalate unresolved network security issues.
  • Create and maintain comprehensive documentation for security processes and systems.
  • Demonstrate in-depth knowledge of on-premises and Cloud environments, particularly Azure / AWS / MS E5 platforms.
  • Enhance visibility and detective capability in a fully managed Azure / AWS environment.
  • Conduct penetration testing and provide security report gaps with remediations.
  • Support the design, development, implementation, and troubleshooting of various information systems and cybersecurity software.
  • Automate security testing and auditing to prevent regressions and catch issues before they reach production.
  • Provide security expertise on system, network, encryption, authentication, and governance.
  • Gather reports, metrics, and key performance indicators to measure and validate the effectiveness of existing security controls for team review.
  • Participate in and develop material to raise security awareness across the organization.

Identity Management & Policy Control :

  • Manage Active Directory, Privileged Identity Management, Local Administrator Password Solution, and related privilege management technologies.
  • Collaborate with leadership to drive the Zero Trust security model and hardening CIS standards.

Business Continuity & Disaster Recovery :

Lead the Business Continuity and Disaster Recovery efforts, working closely with the CIO, CISO, and Director of EA&SD to test and refine BC / DR strategies.

Event & SIEM Management :

  • Respond to security incidents, monitor system logs and network traffic, and investigate security breaches to enhance security protocols.
  • Service Delivery Platform Protection :
  • Participate in Service Delivery projects to develop and implement security measures and partner with third-party services for firewall reviews and security software testing.
  • Risk, Control, Threat & Vulnerability Management :
  • Support the Governance, Risk, and Compliance Manager in audit preparations and vulnerability management, including leading penetration tests and managing endpoint security.
  • Incident Response :
  • Remain on-call for security incidents, collaborating with vendors and the Service Delivery team to mitigate threats.
  • Security Assessment & Engineering :
  • Proactively test security controls to identify vulnerabilities that could be exploited by malicious actors and provide remediation efforts to close security gaps.
  • Maintain operational efficiency and a healthy state of all endpoint security agents.
  • Maintain security architecture diagrams and participate in cybersecurity initiatives and working groups.
  • 3 hours ago
Related jobs
Promoted
VirtualVocations
Queens, New York

A company is looking for a Senior Application Security Engineer to execute its product security strategy. ...

Promoted
The Rockridge Group
New York, New York

Senior Security Engineer to join its IT Security Team in our New York office. Operational management of security platforms including, but not limited to, firewalls, load balancers, web proxies, endpoint security technologies. Assist and train team members in the use of cloud security tools and the r...

Promoted
VirtualVocations
Queens, New York

A company is looking for a Senior Principal Security Engineer (Applied Cryptography and Authentication). ...

Promoted
Unreal Gigs
New York, New York

We are looking for a seasoned Full-Stack Engineer who is passionate about building sophisticated systems that leverage big data and AI. Innovate and implement advanced data processing frameworks, utilizing real-time streaming and machine learning models. Bachelor’s or Master’s degree in ...

Promoted
Abridge
New York, New York

We are seeking Staff and Senior Full Stack Engineers to join our growing team! You’ll help us build internal. Abridgers are engineers, scientists, designers, and health policy experts from a diverse set of backgrounds—an experiment in alchemy that helps us transform an industry dominated...

Promoted
Rockstar Games
New York, New York

Rockstar Games is seeking a talented and experienced Senior Full Stack Engineer to join our online development team. This is a full-time, in-office position based out of Rockstar's NYC headquarters in Downtown Manhattan. Knowledge and application of web security best practices. Subject to those same...

Promoted
National Black Mba Association
New York, New York

Senior Full Stack Engineer - Managed Investments Engineering. In this position, work with a group of engineers to build high-quality applications, sourcing and integrating investment data, and providing analytic capabilities to our business stakeholders. Collaborate across engineering teams as well ...

Promoted
Kroll
New York, New York

We are looking for an experienced Senior Full-Stack Engineer for our Private Capital Markets team. We are building an extensive private asset valuation platform with a modern technology stack and need a savvy engineer for hands-on design and implementation. This is a fully remote role in continental...

James Perse Los Angeles
New York, New York

JAMES PERSE IS CURRENTLY HIRING A FULL TIME SENIOR CLIENT ADVISOR FOR OUR MADISON AVENUE (UPPER EAST SIDE) LOCATION OBJECTIVE OF THE POSITION The Senior Client Advisor is responsible for achieving all objectives set forth by the company with a focus on client development and client sales. In the abs...

Macy’s
The Bronx, New York

The Visual Security Officer is an entry-level opportunity within Asset Protection with the primary responsibilities of communicating suspicious activity to Asset Protection detectives and management, maintaining a safe business environment, and providing strong customer service. The Visual Security ...