Sr. Information Security Engineer – Security Operations

Reports To

<p>CISO</p>

As a member of CAQH's Information Security Incident Response team, the Sr. Information Security Engineer – Security Operations will coordinate the response activities for cyber security incidents across the corporate environment. 

Specific Responsibilities

 

  • Conducts investigations and responds to internal and external Information security threats.
  • Implements advanced security monitoring techniques to identify malicious behavior on SaaS, cloud systems, network, and endpoints.
  • Manages, administrates, and improves security monitoring products for DLP, SIEM, EDR, Cloud Security products, IDS and other security technologies.
  • Develops automation response scripts to remediate threats.
  • Performs threat hunting activities to identify compromised resources.
  • Performs threat research and intelligence gathering to improve detection and response capabilities.
  • Maintains operational playbooks, process diagrams and documentation for security monitoring and response.
  • Reviews proposed Security deployments to ensure security monitoring requirements are met.
  • Provides off-hour support as needed for security monitoring and response activities.
  • Experience leveraging common scripting languages, including PowerShell or Python, to parse logs and automate repeatable tasks

 

 Incident Response

  • Works closely with MDR services, external forensic providers, and in house IT teams to respond to and remediate security incidents both internal and external.
  • Reviews compromised systems to identify root cause of security incidents and takes remediation actions
  • Research new TTPs (tactics, techniques, and procedures) that threat actors are utilizing to undermine enterprise IT environments.
  • Provide timely detection, identification, and alerts of possible attacks/intrusions, anomalous activities, and misuse activities, and distinguish these incidents and events from benign activities.
  • Correlate incident data to identify specific vulnerabilities and make recommendations that enable swift remediation.
  • Plans, implements, and documents incident handling and response tasks and procedures.

 

Emerging Threats Monitoring:

  • Obtains information and stays up to date on the latest threats and security trends in a fast and efficient way to keep the enterprise environment protected.
  • Assists in the investigation and resolution of security issues.

As a member of CAQH's Information Security Incident Response team, the Sr. Information Security Engineer – Security Operations will coordinate the response activities for cyber security incidents across the corporate environment. The successful candidate will focus on reviewing, triaging, analyzing, remediating, and reporting on cyber security incidents. The individual will be the escalation point for Security Operations Center (SOC) analysts, and as such, will manage validated cyber security incidents, in accordance with the Information Security Incident Response Plan. The successful candidate will perform functions such as log analysis, conduct in-depth technical analysis of network traffic and endpoint systems, enrich data using multiple sources, and be responsible for rapid handling and mitigation of cyber security incidents.
 

The Sr. Information Security Engineer – Security Operations is a full-time, remote, exempt position and reports to the CISO.

 

Knowledge, skills and abilities
  • Fundamental understanding of security tools such as SIEM, IDS/IPS, web proxies, DLP, CASB, SIEM, DNS security, WAFs, DDoS protection, VPN, EDR, and firewalls.
  • Programming and Scripting: Ability to write scripts in languages like Python, Bash, or PowerShell to automate tasks and analyze data.
  • Incident Handling and Response: Knowledge of incident response processes, from detection and analysis to containment, eradication, and recovery.
  • Cybersecurity Laws and Regulations: Understanding of laws and regulations related to data protection and privacy (e.g., HIPAA).
  • Risk Assessment and Management: Ability to assess, prioritize, and manage risks associated with cybersecurity threats.
Experience
  • 5+ years of incident analysis, security architecture, malware research, SOC, or any other similar incident response experience.
  • 5+ years of working experience with Information Security, Network Security, and Security Monitoring and Incident Response.
  • GSEC, GCIA, GFE, GCFA, CISA, CISSP, CISM, or CIA certification(s) preferred.
  • Network / System Administration experience / background preferred.
  • Advanced Cloud knowledge - Microsoft Azure preferred.
Education

Bachelor’s degree in computer science degree or related field preferred.

Cloud Security Architect

Position

Cloud Security Architect

Reports To

<p><span>Chief Information Security Officer (CISO)</span></p>

The Cloud Security Architect will be responsible for designing, developing, and managing the security architecture of our cloud-based systems and services.

Specific Responsibilities
  • Works with business units to identify system vulnerabilities, performing hands-on cloud security risk assessments and managing remediation efforts where necessary.
  • Work closely with application development teams to ensure the secure deployment and maintenance of cloud applications and infrastructure.
  • Anticipates security threats and potential weaknesses in the existing cloud/software-as-a-service (SaaS) structure and helps create new technologies, processes, and systems to solve cloud security risk problems.
  • Researches and creates a comprehensive strategy for cloud-native security (i.e., data classification and categorization; data segmentation; server access control; resources-based access control and access control lists; user identity access management and attestation; data-at-rest encryption; data-in-transit encryption; encryption key management, logging, auditing, and anomaly detection; and role-based access control).
  • Assists in the integration of development pipelines with secure configuration parameters to remove or reduce known threat vectors and vulnerabilities in infrastructure-as-code (IaC) and continuous integration/continuous delivery (CI/CD) build configurations and release automation.
  • Supports and administers an enterprise-wide cloud access security broker, security web gateway solutions, cloud management platforms, and cloud governance solutions, serving as the subject matter expert for these technologies.
  • Deploys strong identity and access management controls, including cloud infrastructure entitlement management across application and cloud computing environments.

The Cloud Security Architect will be responsible for designing, developing, and managing the security architecture of our cloud-based systems and services. This role requires a deep understanding of security principles and controls, cloud security/operations tooling, and experience working with Microsoft Azure. The role will require cross-functional interaction and collaboration with various business and technology partners to influence and execute CAQH cloud security strategy.

 

This is a full-time, exempt, remote position.

Knowledge, skills and abilities
  • Deep understanding of cloud native technologies, microservices and serverless applications.
  • Proven knowledge of fundamental cloud and application security concepts and frameworks such as OWASP.
  • Experience with CI/CD pipelines and automation in cloud-based environments.
  • Experience with Infrastructure as Code deployments and familiar with relevant tools.
  • Strong understanding of containers and container orchestration systems.
  • Strong scripting and/or programming skills.
  • Knowledge of cyber security frameworks (ISO 27001, NIST 800-53, CIS Controls, PCI DSS, HITRUST).
Experience
  • 7+ Years of overall IT Experience with a major emphasis on Information Security.
  • 5+ Years of experience building and integrating systems within cloud providers.
Education
  • Bachelor’s degree preferred.
  • Cloud Security Certifications, CISSP or CCSP certifications preferred.