This technical role is responsible for managing, supporting, implementing, and troubleshooting the Firm's full suite of security products, while leading day-to-day incident investigation, security assessments, and audits.
Responsibilities
- Manage core security infrastructure: IDS/IPS, firewalls, antivirus, web filtering, DLP, NAC, DDoS protection, third-party remote access, application whitelisting, and EDR solutions
- Own SIEM operations and privileged account management systems
- Investigate and resolve security events end-to-end
- Conduct security audits, risk assessments, and firewall/network/system configuration reviews
- Run vulnerability scans across networks, servers, systems, and applications
- Produce weekly security metrics reports
- Partner with consultants, MSSP/SOC vendors, and third-party providers on security services
- Contribute security architecture input to project reviews
- Evaluate and test emerging security technologies
Qualifications
- Deep knowledge of security best practices across systems, networks, and telecommunications
- Strong analytical, troubleshooting, and root-cause investigation skills
- Excellent communication, documentation (SOPs, guidelines, architecture diagrams), and project-planning abilities
- Comfortable balancing security with business needs; works well independently and in teams
- Able to manage multiple projects in a fast-paced environment
- Available for on-call rotation, off-hour emergency calls, and occasional travel
- Reports to and collaborates closely with the Director of Information Security
Technical Experience
- SIEM/IDS/IPS: Microsoft Sentinel; Vectra AI, Snort, Suricata, AlienVault, or similar
- Endpoint Security: CB Application Control, ThreatLocker, Microsoft Defender for Endpoint
- Vulnerability & Pen Testing: Nessus, Tenable, Rapid7 Nexpose, Cobalt Strike, Qualys
- Scripting: Python, PowerShell, VB
- PAM: CyberArk, BeyondTrust, or similar