You ensure the secure operation of TuGo’s in-house computer systems, servers, and network connections. This includes analyzing logs and events from desktops, servers, firewall, VPN, DLP and other security appliances such as access programs, data loss prevention systems, anti-virus and anti-spam systems. You analyze, identify and respond to security incidents including security breaches and vulnerability issues in a timely and accurate fashion, and conduct user activity audits where required. Additionally, you oversee security awareness training, phish testing and phish remediation. Specifically, you will: Planning Support Support enforcement of current policies, procedures and associated plans for system security administration and user access, based on industry-standard best practices. Assist in implementation of disaster recovery plans for operating systems, databases, networks, servers, and software applications. Assess the need for any security reconfigurations (minor or significant) and execute them if required. Assist in threat risk assessments to identify technology and business risks for current and future projects. Plan and perform simulated threat hunting and incident handling exercises to assess incident readiness and identify gaps in Incident Response policies of the organization. Assist IT in securing internal and external network configuration, remote access configuration, domain administration and secure data transfer. Support in administering and delivering security training to educate users on new security threats based on their job responsibilities via various phishing and training campaigns. Keep current and inform leadership on current and emerging security threats. Conduct research and advise senior leadership on security products, services, protocols and standards in support of security enhancement and development efforts. Operations Manage Crowdstrike EDR to identify endpoint, cloud and identity security alerts for possible breaches, working closely with IT Helpdesk when necessary. Oversee daily requests to release held emails by Darktrace Email Security and Microsoft 365 Defender investigating root cause before releasing messages to users. Monitor Darktrace Email Security for any harmful messages that were not held, updating its dynamic detection models, improving security. Manage Imperva Web Application Firewall (WAF) and identify security alerts for possible breaches Provide coordination and oversight of client security requests, audits and problem tickets from internal teams. Audit and recommend security enhancements to firewalls, intrusion detection systems, cryptography systems, and other security appliances. Maintain and present monthly security metrics to management Ensure information and technology infrastructure meets established compliance regulations such as PCI, HIPAA, SOC, ISO, NIST,CIS, OWASP Top 10. Audit web and mobile applications, organization databases for security risks and vulnerabilities and recommend countermeasures to ensure the security of critical data. Design, perform, and execute vulnerability assessments, penetration testing and security audits. Create and deploy end user security awareness training using KnowBe4. Deploy IT and Security policies using KnowBe4. Create and deploy end user Phish test campaigns. Actively monitor, configure and respond to Phish alert emails. Design, implement, and report on security system and end user activity audits. Monitor and review logs, dashboards and reports for: servers, firewall, intrusion detection, network traffic & devices, workstations and user access. Recommend, schedule (where appropriate), and apply fixes, security patches, disaster recovery procedures, and any other measures required in a security breach. Download and test new security software and/or technologies. Participate in investigations into problematic activity. Provide on-call security support to end-users. Additional Achieve performance targets. Collaborate and communicate effectively with team members and all other teams. Responsively and effectively handle issues. Look for ways to improve customer experience. Promote and model TuGo culture, values, and brand promise. Continuously build professional and technical expertise. Other duties as required.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
11-50 employees