- Company Name
- Calance
- Job Title
- Information Security Engineer
- Job Description
-
Job Title: Information Security Engineer
Role Summary: Design, deploy, and sustain robust information security controls to protect organization assets. Lead threat detection, incident response, and risk management activities across network and system environments. Act as the primary liaison between security, IT, legal, and compliance functions to enforce policies and improve security posture.
Expectations: 6‑month onsite contract with high potential for permanent placement. Deliver actionable security assessments, incident handling, and compliance documentation within defined timelines. Own initiatives end‑to‑end with minimal supervision.
Key Responsibilities:
• Create, update, and enforce security policies, standards, and procedures in line with best practices and regulations.
• Monitor network and system activity using SIEM and related tools; analyze alerts for threats.
• Conduct risk assessments, vulnerability scans, and remediation coordination with technical teams.
• Serve as first responder to security incidents: investigate, contain, remediate, document, and review incidents.
• Implement and maintain endpoint protection, DLP, firewall, IDS/IPS, and vulnerability management solutions.
• Prepare compliance evidence and support internal/external audits (ISO 27001, GDPR, CCPA, NIST).
• Deliver security awareness training and promote a security‑centric culture.
• Collaborate with IT, legal, HR, and cross‑functional stakeholders to embed controls in system development.
• Generate regular reports for senior management on posture, metrics, and incident trends.
• Stay updated on emerging threats, attack tactics, and regulatory changes to proactively reduce risk.
Required Skills:
• 3+ years in Security Engineering, Production Security, or DevOps roles.
• Deep knowledge of cybersecurity principles, threat detection, and incident response.
• Hands‑on risk assessment, vulnerability management, and remediation experience.
• Proficiency in Python and/or Bash automation for security tooling.
• Experience securing Linux and/or Windows platforms.
• Familiarity with CI/CD pipelines and IaC (e.g., Terraform).
• Strong command of SIEM, firewalls, IDS/IPS, endpoint protection, and DLP solutions.
• Understanding of compliance frameworks: ISO 27001, NIST, GDPR, CCPA.
• Effective communication and collaboration across engineering, IT, legal, and compliance teams.
Required Education & Certifications:
• Bachelor’s degree in Computer Science, Information Security, or related field (preferred).
• Relevant certifications (e.g., CISSP, CISM, CEH, CompTIA Security+) demonstrate advanced knowledge (not mandatory but highly valued).