
Cybersecurity Engineer
Posted Sep 11

Posted Sep 11
This is a fully remote position, open to applicants in Minnesota.
• Analyze, triage, and investigate security alerts and incidents.
• Examine and assess security events, including suspicious activities, phishing attempts, malware, unauthorized access, and possible account or system compromises.
• Collaborate on incident response efforts with the Security Operations Center, technology service providers, and internal stakeholders, encompassing containment, remediation, and recovery processes.
• Document investigations, findings, and response actions, and propose enhancements based on lessons learned and emerging threats.
• Oversee vulnerability and patch management initiatives, including monitoring patching activities conducted by technology service providers.
• Evaluate results from vulnerability assessments, prioritize remediation based on risk, track remediation progress, and report any outstanding vulnerabilities and risks.
• Manage security awareness and phishing simulation initiatives, including training, communication, and employee follow-up.
• Administer and support security tools and platforms for monitoring, vulnerability management, threat detection, and incident response.
• Review firewall events and take part in periodic reviews of firewall rules and configurations.
• Suggest enhancements to endpoint, identity, email, firewall, and network security measures.
• Maintain information security policies, standards, procedures, operational documentation, and playbooks.
• Assist with security assessments, audits, compliance efforts, operational metrics, and reporting.
• Review vendor security advisories, evaluate organizational impact, and coordinate remediation or mitigation efforts.
• Provide cybersecurity insights for new technologies and solutions.
• Aid in vendor security questionnaires and associated documentation.
• Perform other related tasks as assigned.
• Associate's or Bachelor's degree with 5 years of experience in cybersecurity, information security, security operations, or a related area, or an equivalent combination of education and experience.
• At least 1 year of experience supporting systems and services in a regulated setting; experience in an FDA-regulated environment is preferred.
• Security+, CySA+, SSCP, GSEC, or other relevant cybersecurity certifications are highly desirable.
• Experience in investigating security alerts and supporting incident response efforts.
• Experience in assessing and prioritizing vulnerabilities and coordinating remediation and patch management activities.
• Familiarity with administering or supporting security technologies, including security monitoring, endpoint protection, email security, and vulnerability management solutions.
• Strong understanding of common cybersecurity threats and attack strategies, including phishing, ransomware, malware, identity-based attacks, and endpoint compromises.
• Working knowledge of network security principles, including firewalls, VPNs, network segmentation, and access controls.
• Familiarity with cybersecurity frameworks and industry best practices, such as the NIST Cybersecurity Framework or CIS Controls.
• Excellent analytical and problem-solving capabilities with the ability to investigate technical issues and evaluate risk.
• Strong written and verbal communication skills, capable of effectively conveying information to both technical and non-technical stakeholders.
• High attention to detail with the ability to organize and prioritize work, adhere to documented procedures, and meet set timelines.
• Proven independent and sound decision-making abilities; capable of thinking critically and making decisions in a fast-paced environment.
• A mindset geared towards continuous improvement; actively seeking opportunities to drive innovation and efficiency within the organization.
• Adaptable and willing to learn; responsive to business and site requirements in a dynamic environment.
• Maintain a positive, approachable, and professional demeanor.
• Annual performance incentive bonus.
• New hire equity package.
• Medical insurance.
• Dental insurance.
• Vision insurance.
• 401(k) matching.
• Paid time off (PTO).
• Paid holidays.
Sony Interactive Entertainment
Squads
Neo4j
PingWind Inc. (SDVOSB)
Get handpicked remote jobs straight to your inbox weekly.