Senior Information Security Engineer
Job description
About the role
Hexens is seeking a highly skilled Senior Information Security Engineer to join our dynamic team. In this pivotal role, you will be responsible for safeguarding our information systems and ensuring the integrity of our data. You will work closely with various departments to implement security measures and respond to security incidents. If you are passionate about cybersecurity and have a proven track record in the field, we would love to hear from you.
Key facts
What you'll do
- Design, implement, and maintain security protocols to protect sensitive information and systems from unauthorized access and breaches.
- Conduct thorough risk assessments and vulnerability analyses to identify potential security threats and weaknesses in our infrastructure.
- Develop and enforce security policies, standards, and procedures in alignment with industry best practices and regulatory requirements.
- Collaborate with IT teams to ensure that security measures are integrated into system architecture and application development processes.
- Monitor security alerts and incidents, responding promptly to mitigate risks and minimize potential damage.
- Lead incident response efforts, conducting forensic investigations and root cause analyses to prevent future occurrences.
- Provide training and guidance to staff on security awareness and best practices to foster a culture of security within the organization.
- Stay updated on the latest cybersecurity trends, threats, and technologies to continuously improve our security posture.
- Prepare detailed reports and presentations for management on security incidents, risk assessments, and compliance status.
- Participate in security audits and assessments, working with external auditors to ensure compliance with relevant standards and regulations.
- Collaborate with legal and compliance teams to ensure that all security practices adhere to applicable laws and regulations.
- Mentor junior security team members, sharing knowledge and expertise to enhance the overall capabilities of the security team.
Requirements
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field.
- A minimum of 5 years of experience in information security or a related discipline.
- Strong understanding of security frameworks such as NIST, ISO 27001, and CIS Controls.
- Proficiency in security tools and technologies, including firewalls, intrusion detection/prevention systems, and endpoint protection solutions.
- Experience with security incident response and forensic investigation techniques.
- Familiarity with cloud security principles and practices, particularly in environments such as AWS, Azure, or Google Cloud.
- Excellent analytical and problem-solving skills, with the ability to think critically under pressure.
- Strong communication skills, both verbal and written, to effectively convey complex security concepts to non-technical stakeholders.
- Relevant security certifications such as CISSP, CISM, or CEH are highly desirable.
Nice to have
- Experience with penetration testing and vulnerability assessment tools.
- Knowledge of programming or scripting languages such as Python, Java, or PowerShell.
- Familiarity with DevSecOps practices and tools.
- Previous experience in a regulated industry, such as finance or healthcare.
- Understanding of data privacy regulations, including GDPR and CCPA.
Skills & tools
- Security Information and Event Management (SIEM) systems
- Intrusion Detection Systems (IDS)
- Firewalls and VPN technologies
- Endpoint protection solutions
- Vulnerability management tools
- Cloud security tools and practices
- Incident response and forensic investigation tools
Practical notes
- This position is full-time, and the specific location is currently unspecified.
- Salary details are not provided; however, competitive compensation will be offered based on experience and qualifications.
- Visa sponsorship may be available for qualified candidates.
- Interested applicants can apply through the following link: https://hexens.bamboohr.com/careers/36.
At Hexens, we value innovation, collaboration, and a commitment to excellence. If you are ready to take on the challenge of protecting our digital assets and making a significant impact in the field of information security, we encourage you to apply for the Senior Information Security Engineer position. Join us in our mission to create a secure environment for our clients and stakeholders.