Develop and implement security architectures and designs for both new and existing systems, ensuring alignment with industry best practices, adherence to relevant regulatory requirements, and compliance with established organizational security policies. Conduct security risk assessments and vulnerability analyses to proactively identify potential weaknesses and vulnerabilities within systems, and develop and recommend effective mitigation strategies to address these identified risks. Evaluate and carefully select appropriate security technologies and solutions to effectively address specific and evolving security needs; create and maintain comprehensive security documentation, including detailed system security plans (SSPs), thorough security control assessments (SCAs), and comprehensive security test and evaluation (ST&E) reports. Configure and maintain a wide range of critical security tools and technologies, including firewalls, intrusion detection/prevention systems (IDS/IPS), security information and event management (SIEM) systems, advanced endpoint detection and response (EDR) solutions, and vulnerability scanners, ensuring optimal performance and effectiveness. Implement and rigorously enforce security policies and procedures across all systems and networks to ensure consistent security posture; collaborate closely with IT teams to seamlessly integrate security controls into capability development systems, experiments, and prototypes, encompassing requirements gathering, design, testing, and deployment; and automate security tasks and processes to improve overall efficiency and significantly reduce the risk of human error. Continuously monitor security logs and alerts to proactively identify potential security incidents and breaches, enabling swift and effective response actions. Thoroughly investigate security incidents and breaches to determine root causes and scope of impact, and develop and implement comprehensive and effective remediation plans to address the identified issues. Actively participate in incident response activities, including containment, eradication, and recovery efforts, to minimize the impact of security incidents; and develop and maintain robust incident response plans and procedures to ensure coordinated and effective responses. Ensure that all systems and applications strictly comply with relevant security standards and regulations, such as NIST, ISO 27001, HIPAA, PCI DSS, and GDPR, maintaining a strong security posture and mitigating compliance risks. Develop and maintain engaging security awareness training programs for employees to promote a security-conscious culture; collaborate closely with IT teams, developers, and other stakeholders to seamlessly integrate security into all aspects of the organization's operations; effectively communicate security risks and issues to management and other stakeholders in a clear and concise manner; provide expert security guidance and support to other IT staff; actively participate in security meetings and relevant industry conferences; and mentor junior security staff to foster their professional development.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
501-1,000 employees