Information Security Specialist

ddc

Bohemia (NY)

On-site

USD 70,000 - 90,000

Full time

2 days ago
Be an early applicant
Application generator

Turn this role into an interview — a resume and cover letter built around what this employer wants.

Get past ATS filters

Job summary

Data Device Corporation (DDC) is seeking an Information Security Specialist to build and operate our internal security program onsite at the Bohemia, NY office. The role covers security operations, IAM, endpoint and network defense, vendor risk, compliance, and end-user enablement.

You will work with IT, engineering, and business teams to keep the company secure without slowing it down; requires 3+ years in information security and relevant certifications.

Qualifications

  • Associate’s or Bachelor's degree in Information Technology, Computer Science, Information Systems, Cybersecurity, or related field preferred.
  • 3+ years of experience in information security, IT operations, or a closely related field, with hands-on exposure to multiple security domains.
  • Working knowledge of SIEM, EDR, vulnerability scanners, identity providers (Okta, Entra ID, or similar), and cloud platforms (AWS, Azure, or GCP).
  • Solid fundamentals in networking, operating systems and authentication protocols.
  • Familiarity with compliance frameworks, especially CMMC / Cyber Essentials + practicing Europe contexts.
  • Industry certifications such as CISSP, CISM, CCIE, CCNP Security, CompTIA Security+, Network+, CISA, CRISC or similar.

Responsibilities

  • Support day-to-day security operations, including alert triage in SIEM/EDR, log review, and incident response assistance.
  • Administer identity and access management systems including SSO, MFA, directories, onboarding, transfer, and offboarding processes.
  • Maintain and improve endpoint security across fleet, including EDR health, patch management, baselines, and disk encryption.
  • Assist with network security tasks such as firewall reviews, VPN administration, segmentation, and monitoring misconfigurations.
  • Support vulnerability management: scanning, prioritizing findings, remediation coordination, and metric tracking.
  • Contribute to the compliance program by collecting evidence, maintaining policies, and preparing for audits (CMMC/NIS2/Cyber Essentials+).
  • Support vendor risk management by reviewing third-party security docs and tracking risk acceptances.
  • Build and deliver security awareness content, including phishing simulations and onboarding training.
  • Be the go-to security contact for employees for questions, suspicious emails, or access requests.
  • Document processes, runbooks, and standards to scale the program.

Skills

Security operations
Identity & access management
Endpoint security
Scripting (Python/PowerShell/Bash)

Education

Associate's or Bachelor's degree in IT/CS/IS/Cybersecurity

Tools

SIEM
EDR
Vulnerability scanners
Okta/Entra ID
AWS
Azure
GCP

Job description

For more than 60 years, Data Device Corporation (DDC) has been recognized as a world leader in the design and manufacture of high-reliability Connectivity, Power, and Control solutions for the Aerospace, Defense, and Space industries. Our dedication to supplying quality products, on-time delivery, and superior support, has contributed to the success of our customers and the critical missions they serve.

This position is 100% onsite at our Bohemia, NY office.

The salary range for this position is $70,000 to $90,000 annually and will depend upon experience.

This position requires a U.S Person or a person who can qualify for a Department of State or Department of Commerce License.

Position Summary:

The Information Security Specialist role will be helping to build and operate our internal security program. This is a hands-on role for someone who enjoys working across multiple domains rather than specializing in just one. You\'ll touch security operations, identity and access management, endpoint and network defense, vendor risk, compliance, and end-user enablement. You\'ll work closely with IT, engineering, and business teams to keep the company secure without slowing it down.

Key Position Accountabilities:
  • Support day-to-day security operations, including alert triage in our SIEM and EDR platforms, log review, and assisting with incident response when something needs investigation.
  • Help administer identity and access management systems, including SSO, MFA, directory services, and the onboarding, transfer, and offboarding processes. Conduct periodic access reviews and clean up stale accounts and entitlements.
  • Maintain and improve endpoint security across the fleet, including EDR health, patch management, configuration baselines, and disk encryption.
  • Assist with network security tasks such as firewall rule reviews, VPN administration, segmentation work, and monitoring for misconfigurations.
  • Support the vulnerability management program: scanning, prioritizing findings, coordinating remediation with system owners, and tracking metrics over time.
  • Contribute to our compliance program by helping collect evidence, maintain policies, complete customer security questionnaires, and prepare for audits including CMMC/NIS2/Cyber Essentials+/[other compliance obligations].
  • Support vendor risk management, including reviewing third-party security documentation and tracking risk acceptances.
  • Build and deliver security awareness content, including phishing simulations, onboarding training, and internal guidance.
  • Serve as a knowledgeable point of contact for employees with security questions, suspicious emails, lost devices, or access requests.
  • Document processes, runbooks, and standards so the program scales as the company grows.
Qualifications:
  • Associate’s or Bachelor’s degree in Information Technology, Computer Science, Information Systems, Cybersecurity, or related field preferred.
  • 3+ years of experience in information security, IT operations, or a closely related field, with hands-on exposure to multiple security domains.
  • Working knowledge of common security tools: SIEM, EDR, vulnerability scanners, identity providers (Okta, Entra ID, or similar), and cloud platforms (AWS, Azure, or GCP).
  • Solid fundamentals in networking, operating systems and authentication protocols.
  • Familiarity with compliance frameworks, especially CMMC [Cyber Essentials / etc for Europe]
  • Comfortable scripting in Python, PowerShell, or Bash for automation and ad hoc tasks.
  • Strong written and verbal communication skills, with the ability to explain security concepts to non-technical audiences.
  • Self-directed and comfortable working across teams in a fast-moving environment.
  • Industry certifications such as CISSP, CISM, CCIE, CCNP Security, CompTIA Security+, Network+, CISA, CRISC or similar.
  • Willingness to be part of the on-call rotation
Desired Characteristics:
  • Strong technical curiosity and desire to learn emerging technologies.
  • Familiarity with offensive security concepts and tooling
  • Understanding or experience with CMMC Level 2 Certification
  • Interest in Artificial Intelligence and business process automation.
  • Strong analytical and problem-solving skills.
  • Excellent verbal and written communication skills.
  • Ability to work effectively with technical and non-technical users.
  • Organized and detail-oriented with strong follow-through.
  • Self-motivated with the ability to manage multiple priorities.
  • Team player with a customer-service mindset.

This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. This job description indicates, in general the nature and levels of work, knowledge, skills, abilities and other essential functions (as covered under the ADA) expected of the employee. Duties, responsibilities and activities may change at any time with or without notice as required.

Data Device Corporation is an Affirmative Action/Equal Opportunity Employer and is committed to providing equal employment opportunity (EEO) for all persons in all facets of employment. All qualified applicants will receive consideration for employment without regard to race, color, religion, age, gender, sexual orientation, gender identity, national origin, citizenship status, marital status, genetic information, disability, protected veteran status or any other legally protected status.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Specialist
Information Security Specialist

Data Device Corporation • Bohemia (NY)

On-site
USD 70,000 - 90,000
Hands-On Information Security Specialist (Onsite)
Hands-On Information Security Specialist (Onsite)

Data Device Corporation • Bohemia (NY)

On-site
USD 70,000 - 90,000
Cyber Security Engineer
Cyber Security Engineer

Pride Veteran Staffing Inc • Whippany (NJ)

On-site
USD 85,000 - 125,000
Onsite Information Security Specialist - Domain Defender
Onsite Information Security Specialist - Domain Defender

ddc • Bohemia (NY)

On-site
USD 70,000 - 90,000
Security Administrator - Intermediate
Security Administrator - Intermediate

Computer World Services • Fort Meade (MD)

On-site
USD 75,000 - 80,000
Sr. IT Security Engineer
Sr. IT Security Engineer

Republic Airways • Carmel (IN)

On-site
USD 90,000 - 130,000
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

D2 Consulting • Arnold (MO)

On-site
USD 120,000 - 130,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
Information Systems Security Engineer (ISSE)
Information Systems Security Engineer (ISSE)

D2 Technical Services • Springfield (VA)

On-site
USD 130,000 - 140,000
Health/Dental/Vision
401(k) match
Accrued PTO
+3
IT Security Engineer II
IT Security Engineer II

MedImpact Healthcare Systems Inc. • San Diego (CA)

On-site
USD 110,982 - 199,769
Medical, Dental, Vision, and Wellness
401K with Company match
PTO and Holidays
+4
Information Systems Security Engineer (ISSE) - FULLY CLEARED with POLYGRAPH REQUIRED
Information Systems Security Engineer (ISSE) - FULLY CLEARED with POLYGRAPH REQUIRED

Constellation Technologies, Inc • Fort Meade (MD)

On-site
USD 140,000 - 265,000
Health insurance
HSA with company contributions
Dental package
+5