Job Description
The Information Security Engineer II develops, executes, and monitors enterprise-wide information security from policy through implementation across all Security departments including SECOPS, DEVSECOPS, and Threat Analytics. This "hands‑on" position serves as the process owner for all ongoing security activities and is responsible for protecting the confidentiality and integrity of client, employee, and proprietary business information in accordance with federal/state laws and regulations.
Essential Duties and Responsibilities
- Enforces policy and supports security procedures, applications, and systems through the documentation of the resolution of assigned cases that range from simple to complex.
- Recommends changes to existing security process and procedures.
- Utilizes Endpoint Threat Detection, Response, and Hunting toolsets.
- Creates requirements for product evaluations and/or procedures to enhance productivity and effectiveness.
- Provides direct support to the business and IT staff for security‑related issues.
- Drives the delivery of new and upgraded security applications, systems, and workflows.
- Tests new systems for effective operations.
- Leads efforts to proactively maintain and improve the automation, reliability, consistency, and quality of existing IT security tools and environments.
- Assists in the design, deployment, integration, and configuration of security solutions or enhancements to ensure functionality.
- Ensures the confidentiality, integrity, and availability of data residing on or transmitted to, from, or through the enterprise workstations, servers, application systems, and data repositories.
- Initiates, facilitates, and promotes activities to create information security awareness.
- Disseminates and educates users on security policies and practices.
- Participates in regular security awareness training and updates to ensure consistent compliance with IT Security Policies.
- Works cross‑functionally and interacts with internal business units and stakeholders to support the business’s needs.
- Tracks and documents security service requests and completed cases using an automated customer case request system.
- Participates in daily activities and reporting required for regulatory and contractual information security obligations.
- Coordinates tasks performed within the infrastructure (system administration, network administration, application support, etc.) for security updates and initiatives.
- Performs analysis, design, and development of security features for system architecture.
- Participates in security incident investigations and provides ongoing communication to security management.
- Identifies root causes of security events and proposes solutions; closes out and documents investigations.
- Maintains up‑to‑date industry knowledge through formal/informal training, industry associations, and research of latest technologies critical to the success of the company’s information security program.
- Continuously works to identify and improve security solutions to defend the company against data security threats.
- Applies appropriate mitigation strategies and communicates security issues to management.
- Provides guidance/training to less experienced staff.
- Provides IT Security consultative support to internal and external clients.
- Manages IT Security related projects and assignments as assigned.
- Applies appropriate security architecture frameworks and standards.
Client Responsibilities
- Internal and external client facing position that requires excellent customer service skills and interpersonal communication skills.
- Manages difficult or emotional client situations, responds promptly to client needs, solicits client feedback, and meets commitments to clients.
Qualifications
- BS/BA and 8+ years of experience (or equivalent combination of education and experience), including 4 years of subject‑matter expertise in respective areas.
Computer Skills
- Microsoft Office Suite.
- Endpoint Management (BigFix, WSUS/SCCM, Symantec, Trend Micro, etc.).
- Identity and Access Management.
- Certificate Management.
- Patch Management (Windows and Unix).
- Intrusion Detection and Prevention.
- Security Awareness Training.
- Mobile Device Management.
- Endpoint Detection and Response (EDR).
- Web Content Filtering.
- Device Encryption.
- Vulnerability Assessment Tools.
- Firewall and VPN.
- Secure E‑mail, Anti‑SPAM.
- Web Server applications.
- Web API Service Security.
- Business Continuity (Disaster Recovery).
- Compliance and Audit (HIPAA, HITRUST, SOC, GovRAMP, PCI – a plus).
- OS Administration (Windows, Linux, Unix).
- Authentication and SSO.
- Container Security.
- Certificates, Licenses, Registrations.
- Security Certification preferred (OWASP, ISSA, ISACA membership – a plus).
Other Skills and Abilities
- Excellent analytical, problem‑solving, and communication skills.
- Familiarity with SSAE SOC 1 and SOC 2, HITRUST, federal/state security and privacy frameworks, HIPAA, PCI and regulatory requirements for information security.
- Ability to work on a team and build good working relationships with team members and internal clients.
- Good understanding of standard policies and procedures for information security.
- Reasoning Ability – ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists.
- Ability to define problems, collect data, establish facts, and draw valid conclusions.
- Mathematical Skills – ability to apply concepts such as fractions, percentages, ratios, and proportions to practical situations; add, subtract, multiply, and divide in all units of measure; compute rate, ratio, and percent; draw and interpret bar graphs.
- Language Skills – ability to respond to common inquiries or complaints from customers, regulatory agencies, or members of the business community; respond effectively to the most sensitive inquiries or complaints.
Competencies
- Composure
- Decision Quality
- Organizational Agility
- Problem Solving
- Customer Focus
- Drive for Results
- Peer Relations
- Time Management
- Dealing with Ambiguity
- Learning on the Fly
- Political Savvy
Physical Demands
Regularly required to sit, talk or hear, stand, walk, use hands to handle and reach, and occasionally lift up to 25 pounds.
Work Environment
Common office setting with computers and printers; moderate noise level; exposure to moving mechanical parts, chemicals, outdoor weather conditions, and risk of electrical shock or vibration.
Work Location
On‑site at the San Diego Headquarters for direct support to internal clients; no remote work.
Working Hours
Exempt; flexible hours to meet deadlines, including nights, weekends, or holidays when required. Core business hours Monday‑Friday 8:00am‑5:00pm.
Travel
Domestic travel up to 10% of time.
Perks
- Medical, Dental, Vision, and Wellness Programs.
- Paid Time Off and Company Paid Holidays.
- Incentive Compensation.
- 401K with Company match.
- Life and Disability Insurance.
- Tuition Reimbursement.
- Employee Referral Bonus.
Equal Opportunity Employer
Equal Opportunity Employer, Male/Female/Disabilities/Veterans. OSHA/ADA: Reasonable accommodations may be provided to enable individuals with disabilities to perform essential functions.
Salary
US$110,982 – $155,376 – $199,769 (based on experience).