
Security Engineer
- Pittsburgh, PA
- $115,000-135,000 per year
- Permanent
- Full-time
- Security Engineer will administer the Firm's security solutions including, CrowdStrike EDR/NGAV, Identity Protection, and NG-SIEM, SEG, PAM/VPAM, EPM, vulnerability scanning, and other security related technology
- Subject-matter-expertise and administer CrowdStrike EDR/NGAV, Identity Protection, and NG-SIEM
- Conduct threat and vulnerability analysis and coordinate attack surface reduction configuration implementation and patching remediation with technical stakeholders
- Demonstrate expertise in information security solutions, operational practices, threats, and emerging technologies
- Deliver reliable and scalable solutions and services, aligned to the Firm's client and shareholder requirements, that reduce risk and balance operational impact and usability
- Lead and improve security event management processes, develop and execute SOP, and conduct incident response preparation, orchestration, investigation, and reporting
- Liaise with our managed security service providers and ensure continuous processes and relationship improvements and maturation
- As a Security Engineer, you will develop methods and controls for migration-to-cloud strategies including CNAPP, CI/CD Pipeline, DevOps guardrails, and Azure CSP controls and monitoring
- Maintain awareness of current and emerging threats, vulnerabilities, and vectors of attack and participate in threat modeling, analysis, and reporting
- Develop end user awareness training and reinforce security concepts through engagement, communication, and simulation
- Participate in security governance, develop policies, processes and procedures, measures, and metrics and ensure compliance with the Firm's security requirements
- Strong Information Systems and Technology background with at least five (5) years of experience in Information Security
- Experience managing information security platforms such as EDR, PAM, MFA, SIEM, and NGFW
- Experience in security event management and security incident response processes, tools, and procedures
- Experience with scripting and query languages such as python, PowerShell, CQL, and XQL
- Expertise in malware detection technologies and remediation
- Expertise in the following technologies providers (or comparable): CrowdStrike, Palo Alto, Tenable, and Azure
- Expertise with network design, operation, security, and monitoring, Windows and Linux desktop/server and database security
- Knowledge and experience with varying information security processes and tools
- Proficient knowledge of IP networking and public cloud security principles
- Understanding of ISO/IEC 27001:2022 ISMS principles
- Ability to identify security technology risks
- Ability to communicate clearly and effectively with people from both technical and non-technical backgrounds
- Ability to visualize, plan and execute any areas of process improvement that increase the efficiency and delivery of our security capabilities