- Company Name
- Access | Information Management
- Job Title
- Security Engineer
- Job Description
-
**Job title:** Security Engineer
**Role Summary:**
Design, implement, and manage security controls across cloud and on‑premises environments. Monitor security events, conduct vulnerability assessments, automate security operations, and embed security into the software development lifecycle. Support compliance with SOC 2, ISO 27001, HIPAA, and related frameworks.
**Expectations:**
Deliver secure system architecture and timely incident response. Maintain continuous improvement of security posture through automation, threat research, and cross‑functional collaboration. Achieve and sustain compliance certifications and internal security metrics.
**Key Responsibilities:**
- Design and deploy security solutions for AWS, Azure, or GCP and on‑prem infrastructure.
- Monitor SIEM, EDR, IAM, and vulnerability tools; investigate alerts and coordinate incident resolution.
- Perform vulnerability assessments; drive remediation with IT and development teams.
- Develop and maintain automation scripts (Python, PowerShell, Bash) to streamline security tasks.
- Integrate security controls into the SDLC and collaborate with engineering, QA, and DevOps teams.
- Implement and validate controls for SOC 2, ISO 27001, HIPAA, and other regulatory requirements.
- Research emerging threats, technologies, and industry best practices; recommend enhancements.
- Contribute to organization‑wide security awareness and training initiatives.
**Required Skills:**
- Cloud security expertise (AWS, Azure, or GCP).
- Network and endpoint security fundamentals.
- Scripting proficiency in Python, PowerShell, or Bash.
- Familiarity with SIEM, EDR, IAM, vulnerability management, and automation platforms.
- Knowledge of NIST, CIS, MITRE ATT&CK, and other security frameworks.
- Strong analytical, problem‑solving, and communication abilities.
**Required Education & Certifications:**
- Bachelor’s degree in Computer Science, Cybersecurity, or related field.
- 3–5 years in security engineering or operations.
- Certifications such as CISSP, CEH, AWS Security Specialty, or equivalent are preferred.