NASCO
Cybersecurity Engineer II
NASCO, Delmar, New York, United States, 12054
Overview As Cybersecurity Engineer II you will provide engineering support and will consult/troubleshoot security related matters for enterprise products, information systems and network architectures. This role promotes compliance with security policies and procedures, recommends secure best practices during architecture, designs and implements phases of the product lifecycle. TheCybersecurityEngineer II protects against the unauthorized access, modification, or destruction of systems or data. In this role, you will demonstrate the importance of building security requirements and practices into the systems engineering process and the software development lifecycle. A wide degree of security-relevant creativity and latitude is expected, including regular communication with manager regarding status of projects and initiatives. Responsibilities Provides daily, ongoing security oversight of assigned moderately complex systems, including the security impact of proposed modifications, additions, and technology refresh evolutions Works within a team to develop customized technical solutions to unique problems while adhering to security policies, procedures, standards and best practices Develops creative technical and procedural solutions to effectively secure information systems without introducing significant operational overhead Aids in the development of architectural designs, and reviews new product implementations Assists withtroubleshooting and performs research to identify the cause of issues and identify potential solutions Provides mitigation recommendations to reduce identified security risks Establishes and enforces security best practices, protection objectives, process improvements and effective security controls with associates and customers Assists in security incident response and documentation Assesses the overall security risks to the system by understanding system security vulnerabilities and associated threats Analyzes impact of software installations, configurations and infrastructure modifications to minimize system downtime when recommending security remediations Assists in mentoring junior team members on security operations processes and procedures Advises associates of the security features and procedures used in their products and systems Performs regularly scheduled security reviews (e.g., technology, operations and personnel) Participates in annual reviews of policies, procedures and security controls in support of security framework assessments Qualifications Required Knowledge, Skills, and Abilities: Technically proficient knowledge of network and security architecture principles, enterprise-grade firewall and intrusion detection and prevention systems fundamentals, endpoint security systems and other security protective/detective systems Knowledge of cybersecurity operation processes and essential security program functions that include event monitoring and security information and event management technologies, risk management, vulnerability scanning and management, access controls and authentication measures Ability to connect threat analysis to risk management principles to formulate security priorities and provide business level risk decision support Ability to gather, analyze and interpret business drivers and developing practical security solutions that provide value to security and support the business Ability to work with customers to understand and respond to their information security needs and/or concerns, represent our security program and how the program protects the customers data, and discuss the roadmap designed to continuously improve our security posture Ability to present technical information to technical and nontechnical audiences using collaborative systems and presentation software Ability to quickly learn and understand complex environments, independently reaching stretch goals, and continually improving knowledge and capabilities Diversified security operations with experience of Privileged Access Management tools. Experience: 8 years of experience in Information Security 5 years of experience implementing and enforcing security directives, policies, publications and regulations 5 years of experience with software and security architectures and has a clear understanding of security protocols and standards 3 years of experience in networking concepts and services 5 years of experience with IT system, local and wide-area network administration, telecommunications, and/or security protection technologies including multi-factor authentication and single sign-on technologies 5 years of experience conducting risk assessment work, IT auditing of compliance requirements, or framework gap analysis 5 years of experience with multiple cloud provider security standards and cloud administration capabilities Required Training, Certification and Education: Bachelors degree in computer science, information systems, engineering, business administration or a related field; experience can be substituted Benefits Overview At NASCO, we trust our workforce to be fully remote, working from their home . This benefit offers significant, personalized outcomes for each associate including work/life balance, savings on commuting, work clothing, and increased time to spend on personal activities. Our full benefit package is designed to support the physical, mental, and financial health of our associates. We offer: Physical and Mental Health Benefits Choice of Blue Cross Blue Shield Medical, Dental, and Vision Plans Telehealthcare for Medical and Behavioral visits Generous PTO with buy/sell options 9 Company holidays, a floating day off, and a day off for volunteering Employee Assistance Program Wellness program - earn insurance discounts or credit towards health-related items Financial Health Benefits 401K Plan with employer matching contributions Company-funded spending/reimbursement accounts to help with out-of-pocket medical expenses Bonus and Recognition programs Tuition Assistance Consultation with financial planner Basic Life & AD&D Insurance, Short and Long-Term Disability Insurance provided, and Supplemental Term Life Insurance is available Group Discount programs - mobile, technology services, etc., to help you save money Other Benefits E-Learning Comprehensive and current library of e-learning and performance support assets, available on demand and at no cost NASCO is an Equal Opportunity Employer/veterans/disability/race/color/religion/sex/sexual orientation/gender identity/national origin. Must have legal authority to work in the US. We will not accept applicants that use AI when answering the screening questions. Applicants who use AI to answer any questions or to complete their application will not be considered for employment. Location US-Home Office/ Remote Positions 1 Category Other - Other Travel Requirements 0-20%