The Security Engineer will apply expert knowledge to mitigate security risks, conduct security reviews, and manage vulnerabilities across systems. This role involves configuring and maintaining security solutions, including Barracuda WAF, AWS WAF, and other security tools like Splunk, Nessus, and Trend Micro. The Security Engineer will ensure the security posture of both on-prem and cloud environments, focusing on proactive identification and remediation of security threats, and providing oversight for software and hardware upgrades.
Responsibilities:
- Identify and mitigate security risks across systems and networks.
- Perform security reviews and vulnerability management.
- Conduct security control assessments and interpret scan reports.
- Troubleshoot and resolve application security issues.
- Manage security ticketing, patch management, and system monitoring.
- Provide technical support for AWS cloud service administration, Active Directory, and Windows system administration.
- Deploy code and manage systems and infrastructure upgrades.
- Utilize tools such as Tenable, DbProtect, Trend Micro, Splunk, and AWS WAF for security analysis.
- Develop and document security waivers and exceptions.
- Perform security risk assessments for third-party vendors and assist in ATO (Authority to Operate) package development.
Qualifications:
- Strong expertise in AWS Cloud, with experience in Barracuda Cloud WAF (required).
- Experience with security tools like Nessus, DBProtect, Trend Micro, and Splunk.
- Proficient in Windows systems administration and cloud security.
- Strong knowledge of Active Directory (AD) administration and Microsoft IIS.
- Expertise in PowerShell scripting and vulnerability remediation.
- Experience with security controls, incident response, and patch management.
Preferred Skills:
- Familiarity with cloud migration, ATO processes, and GRC Archer onboarding.
- Experience with Microsoft Sentinel and Defender ATP.
- Experience with Unix-based systems (e.g., Ubuntu/Redhat).
- Knowledge of compliance and audit frameworks (e.g., OIG audit response).
Additional Information:
- AWS Cloud Migration experience preferred.
- Ability to respond to system outages and manage queues effectively.
#CJ