Information Security Engineer - Threat and Vulnerability Management

esswd

Philadelphia (Philadelphia County)

Hybrid

USD 122,000 - 138,000

Full time

3 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Benefits offered by this job

Flexible working environment
Volunteer events
Wellness programs
Professional environment with experts
Health, dental, vision, and 401(k)
Generous paid time off

Job summary

Faegre Drinker is seeking an Information Security Engineer - Threat & Vulnerability Management to join its Technology & Innovation team in Philadelphia, New York City, or Washington, D.C. The role owns the firm’s vulnerability management program and collaborates across teams to protect clients.

The ideal candidate has a cybersecurity degree and 4+ years of information security experience, with hands-on vulnerability management.

Qualifications

  • Bachelor's degree in cybersecurity, information systems, or related field.
  • Four years or more of relevant information security experience. A Master's degree may substitute one year of experience.

Responsibilities

  • Conducts vulnerability assessments across servers, endpoints, cloud, Azure, and Microsoft 365 environments.
  • Prioritizes findings with a risk-based approach and provides remediation recommendations to owners and the Director.
  • Maintains a current threat profile for the firm, tracking actors, campaigns, and tactics affecting clients.
  • Monitors threat intel feeds and dark web sources for indicators of compromise and credential exposure.
  • Translates threat intel into actions, prioritizing vulnerabilities under active exploitation and briefing peers.
  • Executes tests on prompt injection and cross-client data isolation as directed.

Skills

Problem-solving
Communication skills
Teamwork
Adaptability
Deadline management

Education

Bachelor's degree in cybersecurity or related field
Master's degree in cybersecurity or related field

Job description

Faegre Drinker is a firm designed for clients and designed for you. We understand that our people are critical to our success and we are committed to investing in our paraprofessional, administrative and operations professionals. We are always looking for talented, service-focused individuals to join our flexible and high-performing culture. With technology tools and resources that support our hybrid work environment, our colleagues enjoy a culture of learning, support for work and personal goals, opportunities to give back to our communities, and competitive benefits and rewards programs. At Faegre Drinker, you will have the opportunity to share your expertise within and across teams and contribute to our success.

Job Description Summary

Faegre Drinker has an opportunity for an Information Security Engineer - Threat & Vulnerability Management to work with our Technology& Innovation team in our Philadelphia, New York City, or Washington, D.C. offices. You will be part of a dynamic team responsible for owning the firm's threat and vulnerability management program. This position will work with other talented individuals who share a passion for doing great work in the best interest of our clients.

Job Description
What you would do
  • Conducts ongoing vulnerability assessments across servers, workstations, network devices, cloud infrastructure, Microsoft Azure, and Microsoft 365 environments using the firm's vulnerability scanning platform
  • Prioritizes findings using a risk-based approach that considers exploitability, threat intelligence, asset criticality, and exposure, and presents clear remediation recommendations to system owners and the Director
  • Maintains a current threat profile for the firm, tracking threat actors, campaigns, and tactics targeting law firms, professional services, and the firm's clients and industries
  • Monitors threat intelligence feeds, information sharing communities, and dark web sources for indicators of compromise, credential exposure, and mentions of the firm, its people, or its clients
  • Translates threat intelligence into action, including prioritizing vulnerabilities under active exploitation, recommending new detections, and briefing the Director and peers on emerging threats
  • Executes prompt injection and cross-client data isolation test cases as directed, and brings threat intelligence on emerging AI attack techniques into the testing program
  • Special projects and other duties as assigned
What is expected
  • Ability to problem-solve
  • Excellent interpersonal, verbal and written communication skills, including the ability to communicate effectively in a virtual environment (e.g., via phone, web/videoconference)
  • Ability to concentrate on tasks, make decisions and work calmly and effectively in a high-pressure, deadline-orientated environment
  • Demonstrated ability to use good judgment in taking initiative while asking for direction or clarification and consulting others, as appropriate
  • Willingness to be flexible with time and adjust to a changing work environment
  • Ability to build and maintain positive relationships, both internally and externally, while maintaining a client service orientation
  • Ability to use sound judgment and discretion in dealing with highly confidential information
  • Ability to take direction and accept supervision
  • Demonstrated ability to work independently, organize and accurately prioritize work, be detail-oriented, understand when urgency is required and use good judgment in varied situations
  • Ability to work effectively with co-workers in a team oriented collaborative environment
What we offer
  • Flexible working environment for work-life success
  • Opportunity to participate in firm-sponsored volunteer events
  • Wellness programming with personalized content and activities
  • Professional environment and the opportunity to work with experts at the top of their fields
  • Variety of health plan options, as well as dental, vision and 401(k) plans
  • Generous paid time off

The anticipated initial salary for someone who is hired into this position is $121,800 - $137,700.

Actual initial salary may be above or below the above-identified range and will be based on the relevant skills, training, experience, and other job-related factors, including the location where the position is filled, in all cases consistent with applicable law. This is an exempt role and the initial salary range listed above is just one component of Faegre Drinker's total compensation and benefits package for professional staff, which includes, but is not limited to, a discretionary bonus; life, health, accident, and disability insurance; and a 401(k) plan.

What is required
  • Bachelor's degree in cybersecurity, information systems, or a related field, or equivalent years of experience
  • Four years or more of relevant information security experience. A Master's degree in cybersecurity or a related field may be considered in lieu of one year of experience
  • Hands-on experience with vulnerability management or threat and
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Threat & Vulnerability Security Engineer
Threat & Vulnerability Security Engineer

esswd • Philadelphia

Hybrid
USD 122,000 - 138,000
Flexible working environment
Volunteer events
Wellness programs
+3
Senior Information Security Engineer - SIEM and Detection
Senior Information Security Engineer - SIEM and Detection

esswd • Philadelphia

Hybrid
USD 160,000 - 183,000
Flexible working environment for work–
Volunteer events
Wellness programming
+4
Senior Information Security Engineer – SIEM and Detection
Senior Information Security Engineer – SIEM and Detection

Faegre-Drinker-Biddle- • Philadelphia

Hybrid
USD 160,000 - 183,000
Hybrid work environment
Wellness programming
Health plan options
+3
Information Security Engineer – Threat and Vulnerability Management
Information Security Engineer – Threat and Vulnerability Management

Jobtailor • Washington

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Manatt, Phelps & Phillips, LLP • New York (NY)

Hybrid
USD 80,000 - 100,000
Cybersecurity/Info Security Engineer (Remote- 130K)
Cybersecurity/Info Security Engineer (Remote- 130K)

Merit Personnel & Consulting • New York (NY)

Remote
USD 117,000 - 143,000
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper LLP (US) • Baltimore (MD)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

PRI Technology • New York (NY)

On-site
USD 120,000 - 180,000
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Atlanta (GA)

Hybrid
USD 94,000 - 131,000
Medical/dental/vision insurance
401(k)
Hybrid work schedule
Senior Information Security Analyst (SecOps)
Senior Information Security Analyst (SecOps)

DLA Piper • Chicago (IL)

Hybrid
USD 94,000 - 131,000
Hybrid work arrangement
Medical/dental/vision insurance
401(k)