- Company Name
- Medpace
- Job Title
- Information Security Engineer
- Job Description
-
Job title: Information Security Engineer
Role Summary
Design, implement, and continuously improve the organization’s cybersecurity architecture to protect digital infrastructure, cloud, edge devices, and data from unauthorized use, modification, exfiltration, or damage. Leads security projects, identifies threats, and provides incident response, remediation, and access review services while fostering security awareness across the enterprise.
Expectations
• Autonomous engineering of security solutions with minimal supervision
• Maintain up‑to‑date knowledge of industry best practices, emerging threats, and regulatory requirements
• Deliver security posture enhancements that align with business objectives
• Communicate complex security concepts clearly to technical and non‑technical stakeholders
Key Responsibilities
1. Engineer and deploy enterprise‑grade security solutions (SIEM, PAM/IAM/MFA, EDR, NAC, cloud security tools for Azure/AWS, Active Directory).
2. Conduct vulnerability research, scanning (e.g., Nessus/Tenable), and threat mitigation activities.
3. Develop, document, and enforce security policies, best practices, and controls across the organization.
4. Provide security awareness training, execute testing, and verify adherence to protocols.
5. Perform incident response, diagnosis, and remediation, including forensic analysis and root cause investigation.
6. Facilitate least‑privilege access reviews, revoke over‑provisioned privileges, and manage access control mechanisms.
7. Cross‑train colleagues, document procedures, and assist staff on security‑related queries.
8. Participate in continuous professional development and contribute to security knowledge base.
Required Skills
• Strong technical foundation in information security architecture and enterprise security products.
• Experience with SIEM, PAM/IAM/MFA, EDR, NAC, cloud security (Azure/AWS), and Active Directory.
• Proficiency in basic scripting (PowerShell, Python).
• Ability to analyze security systems, implement improvements, and manage projects independently.
• Excellent written and verbal communication, critical thinking, problem‑solving, and prioritization.
• Familiarity with vulnerability assessment tools (Nessus, Tenable).
Required Education & Certifications
• Bachelor’s degree in Information Technology, Computer Science, or related field (or equivalent experience).
• Minimum 2 years of hands‑on experience implementing Information Security solutions.
• Certification(s) preferred: CISSP, CISM, CEH, or vendor‑specific (e.g., Azure Security Engineer Associate, AWS Security Specialty).
• Knowledge of regulatory frameworks (ISO, NIST, HIPAA, GDPR, SOC 2) is advantageous.
---