Security Operations Engineer

Customers BankMalvern, PA
97d

About The Position

The Security Operations Engineer plays a critical role in protecting the financial institution's information assets and ensuring the confidentiality, integrity, and availability of systems and data. This position is responsible for monitoring, detecting, investigating, and responding to security incidents, as well as supporting the day-to-day operations of the Security Operations Center (SOC). The engineer will work closely with IT, risk, compliance, and business teams to strengthen the organization's overall security posture.

Requirements

  • 5+ years' experience in security engineering or security operations.
  • Hands-on experience reviewing and managing firewalls (rule sets, changes, compliance).
  • Experience with configuring and maintaining security tools (SIEM, endpoint detection, vulnerability management, IAM).
  • Strong understanding of networking fundamentals (TCP/IP, routing, switching, VPNs).
  • Familiarity with incident response processes and escalation.
  • Bachelor's degree in Information Security, Computer Science, or related field, or equivalent work experience.

Nice To Haves

  • Certifications such as Network+, Security+, CCNA Security, CISSP, or Palo Alto/Checkpoint firewall certifications.
  • Experience with Splunk, CrowdStrike, Tenable, Active Directory, or similar tools.
  • Exposure to Azure or other cloud security environments.
  • Prior experience in banking or financial services.

Responsibilities

  • Conduct regular reviews of firewall rules and configurations, ensuring compliance with security policies and industry best practices.
  • Configure, maintain, and optimize security tools such as SIEM, endpoint detection, vulnerability management, and EDR systems.
  • Identify, track, and coordinate takedowns of malicious or fraudulent domains, phishing sites, and spoofed websites targeting the institution or its customers.
  • Monitor security alerts and events from SIEM, IDS/IPS, firewalls, EDR, and other security tools.
  • Analyze logs, network traffic, and endpoint data to identify suspicious activities.
  • Tune and optimize detection rules to reduce false positives.
  • Document configurations, changes, and procedures; provide reporting to meet audit and compliance requirements.
  • Support compliance with industry regulations (FFIEC, GLBA, PCI-DSS, SOX, etc.).
  • Work with IT, Cloud, and Security Operations teams to resolve issues and implement secure configurations across systems.
  • Identify opportunities to streamline firewall and tool processes, enhance detection capabilities, and improve operational efficiency.
  • Assist in investigations and remediation activities during security incidents.
© 2024 Teal Labs, Inc
Privacy PolicyTerms of Service