The Security Engineer II at OneStep is responsible for designing and implementing security solutions to protect organizational and client assets while mentoring junior staff. This role involves managing incident responses, ensuring compliance with regulations, and leading security projects.
Purpose of the Position The Security Engineer Level 2 at One Step Data, Inc., designs, implements, and maintains security solutions to protect organizational and client assets. This role involves leading projects, managing incident responses, ensuring compliance with relevant regulations (including Arizona's data breach notification laws), and mentoring junior staff to ensure a strong security posture aligned with industry best practices. Responsibilities • Design and implement security controls and architectures tailored to each client's unique needs to safeguard data and systems. • Lead the integration of cybersecurity best practices into development and deployment processes, collaborating with internal teams and clients. • Help design, implement, and maintain security tools, processes, and policies to ensure client product and system security, ensuring compliance with relevant standards (e.g., NIST, CIS, ISO 27001, HIPAA, PCI DSS). • Lead vulnerability assessments and penetration testing to identify and mitigate risks, ensuring timely remediation of critical vulnerabilities across multiple client environments. • Manage incident response processes, coordinate with stakeholders (including clients) during incidents, ensure compliance with Arizona's data breach notification laws, and conduct post-incident reviews. • Develop and update security policies and procedures; conduct training programs to educate both internal staff and client employees on best practices. • Manage security-related projects from start to finish; mentor junior security engineers to enhance their skills. • Monitor network traffic and security alerts for potential threats across multiple client environments. • Monitor security alerts and events using Security Information and Event Management (SIEM) and other monitoring tools. • Assist in patch management to ensure systems are updated with the latest security patches for all clients. • Review and investigate security events to identify vulnerabilities or breaches; communicate findings to clients as necessary. • Create and maintain regular security status reports for senior management and clients to provide visibility into security posture. • Support internal and external audits by providing relevant security data and documentation; ensure compliance with regulatory requirements. • Collaborate with sales and account management teams to assess potential clients' security needs and propose appropriate solutions. • Implement automation and advanced security tools (e.g., multi-factor authentication, encryption) to efficiently manage security across multiple clients. Skills, Knowledge & Abilities • Strong analytical and problem-solving abilities. • Excellent communication skills, both written and verbal; ability to explain complex security concepts to non-technical clients. • Ability to work collaboratively in a team environment and with clients. • Strong interest in learning and growing in the field of cybersecurity. • Experience with security frameworks (NIST, CIS, ISO 27001). • Familiarity with cloud security (AWS, Azure, etc.). • Understanding of common attack vectors and mitigation techniques (e.g., phishing, malware). • Knowledge of compliance standards relevant to MSP clients (e.g., HIPAA, PCI DSS). • Experience with automating security tasks and managing security in a multi-client environment. Preferred Education & Experience • A Bachelor's degree in Computer Science, Information Security, or a related field, or equivalent practical experience. • Must have relevant certifications such as CompTIA Security+, Certified Ethical Hacker (CEH), Certified Cloud Advance Security Professional (CASP), SSCP, CISSP or CISM. • 4 to 6 years of experience in cybersecurity, including at least 2 years as a security engineer; experience in security frameworks (NIST, CIS, ISO 27001) and cloud security (AWS, Azure, etc.). • Knowledge of network protocols (TCP/IP, HTTP, DNS, etc.). • Familiarity with firewalls, intrusion detection systems, and vulnerability management tools. • Knowledge of operating systems (Windows, Linux, MacOS) and basic system administration. • Experience with common security tools and techniques for identifying and mitigating threats. • Experience working in an MSP environment or with multiple clients is highly desirable. • Familiarity with Arizona's data breach notification laws (A.R.S. 18-551 and 18-552) and other relevant state regulations. #J-18808-Ljbffr
Databricks is seeking a Security Engineer II to join their Incident Response team, focusing on security threats and incident management. This role requires expertise in cloud environments and incident response processes.
Axon Enterprise is seeking a Senior Application Security Engineer II to enhance application security within the software development lifecycle. This role involves partnering with development teams to implement security practices and tools while promoting a culture of secure coding.
The Information Security Engineering and Architecture Engineer III at L.A. Care Health Plan is responsible for implementing and maintaining security measures in technology solutions. This role requires collaboration with various departments to ensure security is integrated from the beginning of projects.
Microsoft is seeking a Security Analyst II to enhance its security team, focusing on protecting customers from various threats through effective investigations. The role involves analyzing data, conducting threat research, and improving incident response capabilities.
TekValue IT Solutions is seeking a Cyber Security Analyst level II for an on-site position in Virginia Beach. The role involves ensuring cybersecurity best practices and compliance with privacy regulations.
The Security Engineer II at OneStep is responsible for designing and implementing security solutions to protect organizational and client assets while mentoring junior staff. This role involves managing incident responses, ensuring compliance with regulations, and leading security projects.
Databricks is seeking a Security Engineer II to join their Incident Response team, focusing on security threats and incident management. This role requires expertise in cloud environments and incident response processes.
Axon Enterprise is seeking a Senior Application Security Engineer II to enhance application security within the software development lifecycle. This role involves partnering with development teams to implement security practices and tools while promoting a culture of secure coding.
The Information Security Engineering and Architecture Engineer III at L.A. Care Health Plan is responsible for implementing and maintaining security measures in technology solutions. This role requires collaboration with various departments to ensure security is integrated from the beginning of projects.
Microsoft is seeking a Security Analyst II to enhance its security team, focusing on protecting customers from various threats through effective investigations. The role involves analyzing data, conducting threat research, and improving incident response capabilities.
TekValue IT Solutions is seeking a Cyber Security Analyst level II for an on-site position in Virginia Beach. The role involves ensuring cybersecurity best practices and compliance with privacy regulations.
The Security Engineer II at OneStep is responsible for designing and implementing security solutions to protect organizational and client assets while mentoring junior staff. This role involves managing incident responses, ensuring compliance with regulations, and leading security projects.
Databricks is seeking a Security Engineer II to join their Incident Response team, focusing on security threats and incident management. This role requires expertise in cloud environments and incident response processes.
Axon Enterprise is seeking a Senior Application Security Engineer II to enhance application security within the software development lifecycle. This role involves partnering with development teams to implement security practices and tools while promoting a culture of secure coding.
The Security Engineer II at OneStep is responsible for designing and implementing security solutions to protect organizational and client assets while mentoring junior staff. This role involves managing incident responses, ensuring compliance with regulations, and leading security projects.