Information Security Engineer II
Plano, TX, US
Data Analysis Incorporated
About Us
Data Analysis Incorporated (DAI) is the controlling entity of the O’Neil family of businesses. DAI and its subsidiaries operate in diverse industries worldwide, including global equity markets, health care, financial services, digital news, and insurance. Our global footprint allows our teams to be responsive to customer needs in a timely and efficient manner. We are dedicated to using technology and innovation to bring change and growth to our businesses. We believe in a dynamic workplace, creating engaging, informative products and services that help our customers succeed. Integrity is an essential characteristic for our firms and our associates; if this describes you, please apply!
Summary
As an Information Security and Data Privacy Engineer II at O’Neil, you will collaborate with internal teams that deal with PHI belonging to a large number of patients and it is imperative that this data is secured. We are building our security team to help safeguard this information, and your work will improve our overall security posture. From helping us implement detection capabilities for anomalous behavior, threat-hunting, spearheading security incident response, help conducting training for our engineering team to keeping up with industry best practices, you will be empowered to do the work that is most important for the organization. This is a technical role that will be involved in different aspects of the security incident response life-cycle.
Duties and Responsibilities
- Configuring, debugging and implementing Firewalls
- Managing and maintaining cloud infrastructure including Virtual Machines (VMs) and Networking components
- Implementing and managing cloud security policies and best practices
- Documenting cloud and infrastructure processes for training purposes
- Assist in implementing Security Information and Event Management (SIEM), which includes but is not limited to; maintaining logs, assisting in developing company best practices for security alert correlations, may perform root case analysis after incidents Assist with Endpoint Detection and Response (EDR) vendor analysis and deployment, which includes, but is not limited to; partnering with IT to develop a decision matrix for EDR vendor selection, assist with deployment, assist with developing patterns for automatic response to identified threats
- Perform regular privacy assessments and impact analysis on databases and operational processes by developing effective tools, training, and guidance to help identify and mitigate risk. This includes data anonymization, pseudonymization and encryption
- Assist with detection, analysis, and containment of an incident
- Help identify key performance metrics for security IR and implement instrumentation for those metrics
- Maintain, manage and prioritize hardware, software, systems and/or product backlog, while actively identifying risks, constraints, and dependencies that would impact roadmap
- Demonstrate, integrate, and collaborate on enhancing existing security solutions and services to address any gaps or deficiencies
- Assist with security incident response drill scenarios and lead tabletop exercises
- Ensure proper training for stakeholders regarding their incident response roles and responsibilities in the event of a breach
- Collaborate with internal teams to ensure the data retention or system requirements, user-facing privacy controls, new or existing software, and big data solutions enable the business to be data driven while protecting the data assets
- Assist to conducts structured and unstructured data scans, testing, and debugging of applications by using a variety of technical privacy tools to increase compliance and documentation of procedures and information assets
- Studies and interprets past privacy events and current privacy threats to improve privacy compliance using advanced technologies and design principles to develop and implement new tools and processes
- Assist both internal and external teams on data governance strategy, updates to legal regulations, and direction on future roadmaps Collaborate with vendors on data and privacy standards
Qualifications & Requirements
- Bachelor’s Degree in computer science, IT, systems engineering, or equivalent experience.
- 3+ years of experience in the security industry working in any combination of the following areas: Risk management, cloud operations and engineering, network security monitoring, log analysis, static and dynamic malware analysis, NIST Kill Chain, MITRE ATT&CK framework, threat hunting, SIEM, EDR
- AWS Cloud Experience: Managing and Maintaining
- AWS Cloud infrastructure and threat landscape
- AWS Certification Highly Preferred: AWS Certified Solution Architect - Associate (at least)
- Experience responding to security events
- Excellent written and verbal communication, facilitation, and presentation skills to collaborate effectively with software engineering teams
- Implementing security detection capabilities
- Proven ability to make decisions and perform complex problem-solving activities under pressure
Working Conditions
Must be able to perform the essential job duties. Work is performed primarily in an office environment. Typically requires the ability to sit for extended periods of time (66%+ each work day), ability to hear the telephone, ability to enter data on a computer and may also require the ability to lift up to 10 pounds.
Equal Opportunity Employer
O'Neil Digital Solutions is an equal opportunity employer. All aspects of employment including the decision to hire, promote, discipline, or discharge, will be based on merit, competence, performance, and business needs. We do not discriminate on the basis of race, color, religion, marital status, age, national origin, ancestry, physical or mental disability, medical condition, pregnancy, genetic information, gender, sexual orientation, gender identity or expression, veteran status, or any other status protected under federal, state, or local law.
* Salary range is an estimate based on our InfoSec / Cybersecurity Salary Index 💰
Tags: AWS Big Data Cloud Compliance Computer Science EDR Encryption Firewalls Governance Incident response Log analysis Malware MITRE ATT&CK Monitoring Network security NIST Privacy Risk management SIEM Strategy
Perks/benefits: Insurance Team events
More jobs like this
Explore more career opportunities
Find even more open roles below ordered by popularity of job title or skills/products/technologies used.