Information Security Engineer – Threat and Vulnerability Management

Faegre Drinker Biddle & ReathPhiladelphia, PA
Hybrid

About The Position

Faegre Drinker has an opportunity for an Information Security Engineer – Threat & Vulnerability Management to work with our Technology& Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm’s threat and vulnerability management program. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

Requirements

  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment
  • Bachelor’s degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Four years or more of relevant information security experience.
  • Hands-on experience with vulnerability management or threat and vulnerability assessment, including scanning, analysis, and risk-based prioritization of findings
  • Experience with vulnerability scanning platforms such as Tenable, Rapid7, Qualys, or equivalent
  • Working knowledge of application, operating system, and network security fundamentals, including common monitoring tools
  • Experience with incident response, digital forensics, and cyber threat intelligence in an operational environment, including analysis of threat actor tactics and indicators of compromise
  • Thorough understanding of current security principles, techniques, and protocols.
  • Ability to effectively communicate information security issues, risks, and recommendations to both technical and non-technical peers and management, including through well-written reports

Nice To Haves

  • A Master’s degree in cybersecurity or a related field may be considered in lieu of one year of experience

Responsibilities

  • Conducts ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments using the firm’s vulnerability scanning platform
  • Prioritizes findings using a risk-based approach that considers exploitability, threat intelligence, asset criticality, and exposure, and presents clear remediation recommendations to system owners and the Director
  • Maintains a current threat profile for the firm, tracking threat actors, campaigns, and tactics targeting law firms, professional services, and the firm’s clients and industries
  • Monitors threat intelligence feeds, information sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or its clients
  • Translates threat intelligence into action, including prioritizing vulnerabilities under active exploitation, recommending new detections, and briefing the Director and peers on emerging threats
  • Executes prompt injection and cross-client data isolation test cases as directed, and brings threat intelligence on emerging AI attack techniques into the testing program
  • Special projects and other duties as assigned

Benefits

  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off
  • discretionary bonus
  • life, health, accident, and disability insurance
  • a 401(k) plan
© 2026 Teal Labs, Inc
Privacy PolicyTerms of Service