Join to apply for the Information Security Engineer II role at Yuhaaviatam of San Manuel Nation.
Under the direction of the Manager, Information Security Architecture & Engineering, the Information Security Engineer II is a key contributor to enterprise cybersecurity, specializing in operational tools that enable the Security Operations Center (SOC) to detect and prevent threats. This role involves managing security projects from planning to decommissioning, conducting risk analysis, addressing threats, remediating vulnerabilities, and performing vendor risk assessments to protect the enterprise assets and data. Additionally, the position strengthens the vulnerability management program by analyzing data, identifying trends, facilitating discussions, and driving cross-functional efforts to patch systems.
This position requires a skilled and motivated cybersecurity professional with a solid foundation in security operations and risk management. They possess technical expertise in managing security tools and technologies, with hands-on experience in threat detection, prevention, and response within a SOC environment. They demonstrate project management skills, leading security projects from start to finish. Their analytical abilities help them understand new technologies and forecast potential issues. Excellent communication skills enable them to collaborate with various teams and enhance the organization’s security posture.
Essential Duties And Responsibilities
- Drives infrastructure changes by recommending and implementing secure configurations for networks, servers, and cloud environments based on security analysis.
- Leads vulnerability management efforts, including planning and conducting regular scans, analyzing results, and prioritizing remediation based on risk assessments.
- Conducts vendor risk assessments on new technologies implemented to the enterprise and ensures secure implementation of the new technology from inception to completion.
- Evaluates emerging security technologies and recommends enhancements to existing toolsets or processes.
- Executes penetration testing exercises, documents findings, and works with stakeholders to address identified security gaps.
- Collaborates with IT teams to ensure systems and applications meet regulatory and departmental security requirements (e.g., NIST, PCI).
- Mentors Security Engineer I staff in tool deployment, feature optimization, and basic risk analysis tasks.
- Participates in Sec Engineering/SOC team exercises providing technical expertise and leading remediation of identified security gaps in detection and prevention.
- Performs other duties as assigned to support the efficient operation of the department.
Educational, Experience And Qualifications
- Bachelor’s degree in information security, technology, statistics, mathematics, or related field required.
- Minimum four (4) years of experience in Information Security, inclusive of two (2) years of Information Security engineering required.
- Experience with Casino and Tribal government technology and security goals strongly preferred.
- Related, relevant, and/or direct experience may be considered in lieu of minimum educational requirements indicated above.
Knowledge, Skills And Abilities (KSA)
- Demonstrated experience in performing detailed assessments and/or implementations of modern information security technologies.
- Proven experience designing, managing, and monitoring in areas such as Identity and Access Management, Endpoint Security, Threat Intelligence, Vulnerability Management, Data Loss Prevention, and PCI Compliance.
- Experience leading enterprise-level projects from inception to completion.
- Strong success record in security or systems engineering.
- Ability to influence change within the enterprise to support new programs and initiatives.
- Skilled in threat modeling, risk assessments, testing controls, and designing risk mitigation strategies.
- Knowledge of network protocols, secure application design, configurations, security tools deployment, and firewalls.
- Ability to perform penetration testing and vulnerability assessments.
- Professional image with a service-oriented approach.
- Strong interpersonal, negotiating, troubleshooting, and analytical skills.
- Excellent written and verbal communication skills for engaging with all enterprise levels.
- Self-motivated, proactive, capable of handling multiple tasks with attention to detail.
Licenses, Certifications and Registrations
- Possibility of needing a gaming license per San Manuel Tribal Gaming Commission requirements.
- Certifications in at least two of the following: ITIL, ISACA, CompTIA, ISC2, SANS, GIAC required.
- Certifications in Ethical Hacking, Incident Response, Security Architecture, Forensics, and Coding Languages are strongly preferred.
- Valid driver’s license required for role involving operation of Tribe-owned or patron vehicles.
Physical Requirements/Working Conditions
The physical demands and environment are typical for an office setting, with requirements for travel, working evenings, weekends, and holidays, and physical activities including sitting, walking, lifting, and operating vehicles. Reasonable accommodations will be made as per law.
Join our team today and be part of one of the largest private employers in the Inland Empire! We value growth and well-being of our employees.