- Company Name
- Tradition
- Job Title
- IT Security Engineer
- Job Description
-
Job Title: IT Security Engineer
Role Summary
The IT Security Engineer leads threat detection, risk management, and the deployment of security solutions. The role focuses on safeguarding enterprise systems, responding to incidents, and ensuring compliance with internal policies and regulatory frameworks.
Expectations
- Demonstrate advanced knowledge of security best practices and controls.
- Maintain continuous improvement of security posture through proactive threat hunting and vulnerability management.
- Communicate security concepts to technical and non‑technical stakeholders.
- Stay current with emerging threats, threat intelligence feeds, and relevant certifications.
Key Responsibilities
- Support information‑security risk management, compliance activities, and governance initiatives.
- Collaborate with stakeholders to identify, document, and mitigate security risks.
- Manage and coordinate security products and solutions with key software and service vendors.
- Lead incident response: investigation, containment, remediation, and post‑incident analysis.
- Deploy, manage, and continuously improve security tools (vulnerability management, identity management, attack‑surface monitoring).
- Conduct proactive threat hunting, research, and analysis; deliver actionable intelligence.
- Perform security assessments, audits, and penetration testing using industry‑standard methodologies.
- Deliver security awareness training and phishing simulations.
- Ensure compliance with company policies and applicable regulatory frameworks.
- Undertake ongoing training and maintain relevant security certifications.
Required Skills
- Strong experience as a security engineer or similar technical role.
- Deep understanding of security principles, practices, and standards applied to real‑world solutions.
- Proven hands‑on expertise in Linux/Unix administration, enterprise networking or Microsoft technologies.
- Familiarity with encryption concepts, email security, vulnerability management, identity & access management, SIEM, IDS/IPS/WAF, firewalls, and endpoint protection.
- Experience integrating security controls into DevOps/CI‑CD pipelines and scripting/automation.
- Ability to communicate complex security or intelligence information effectively to diverse audiences.
Required Education & Certifications
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity or related field.
- Preferred certifications: CISSP, CISM, CEH, OSCP, GIAC, GCIH, GCFA or equivalent.