- Company Name
- The Phoenix Group
- Job Title
- Information Technology Security Engineer
- Job Description
-
**Job Title:** Information Technology Security Engineer
**Role Summary:**
Secure and protect a macOS‑centric legal services organization’s confidential data, internal systems, and communications. Conduct continuous security posture reviews, manage incident response, ensure compliance with privacy regulations, oversee endpoint protection, and collaborate with attorneys, IT staff, and vendors to embed security into projects and new technologies.
**Expectations:**
- Maintain an up‑to‑date security posture through vulnerability scans, risk assessments, and testing.
- Serve as the primary point of contact for external audits and potential security certifications.
- Design, implement, and exercise incident response plans; lead investigations and remediation.
- Align security practices with HIPAA, GDPR, CCPA, and other regulatory frameworks.
- Educate and train staff on security awareness to reduce avoidable incidents.
- Manage security tools, agents, and patching cycles.
- Evaluate, deploy, and maintain security solutions such as firewalls, IDS/IPS, encryption, and access controls.
- Conduct vendor security reviews and ensure third‑party safeguards.
- Support additional security or technology initiatives as required.
**Key Responsibilities:**
1. Perform ongoing vulnerability scanning, risk assessments, and related testing.
2. Recommend and implement security improvements.
3. Serve as lead for external audits and certification processes.
4. Build, refine, and exercise incident response procedures.
5. Draft and enforce internal security standards and guidelines.
6. Partner with SOC/EDR providers to analyze alerts and report to leadership.
7. Lead security awareness training for staff.
8. Manage endpoint protection platforms and act as the subject‑matter expert.
9. Complete client security questionnaires and review outside counsel requirements.
10. Collaborate with attorneys, IT, and vendors to embed security measures.
11. Ensure timely patching and maintenance of security tools and agents.
12. Evaluate, design, and maintain firewalls, IDS/IPS, encryption, antivirus, and access controls.
13. Review new and existing systems for risk and compliance alignment.
14. Oversee vendor security review process.
15. Perform additional tech or security tasks as assigned.
**Required Skills:**
- Hands‑on experience with VPNs, firewalls, SIEMs, endpoint protection, IDS/IPS.
- Strong knowledge of encryption, secure development, and core network security protocols.
- Familiarity with GDPR, HIPAA, CCPA, ISO, SOC frameworks.
- Analytical mindset for identifying and resolving vulnerabilities.
- Ability to explain complex security concepts to non‑technical stakeholders.
- Detail‑oriented with strong multi‑tasking capability.
- Experience with Azure cloud environments and Entra identity/MFA.
- Proficiency in macOS security administration.
**Required Education & Certifications:**
- Bachelor’s degree in IT, cybersecurity, or related field (or equivalent experience).
- Minimum five years in a hands‑on security engineering or equivalent cybersecurity role.
- Preferred certifications: CISSP, CISM, or equivalent.
- Experience in legal or financial services is an advantage.
Washington dc-baltimore, United states
Hybrid
Mid level
05-12-2025