Lead Info Security Engineer

IGH ICW GROUP HOLDINGS, INC.

United States

On-site

USD 150,000 - 250,000

Full time

4 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

ICW Group is seeking an Information Security Engineer IV to design secure architectures and drive cybersecurity initiatives across all ICW systems. You will lead incident response, monitor for breaches, and partner with business units to strengthen security controls.

The role requires a Bachelor's degree with a minimum of 10 years in security engineering and extensive AWS security experience. Certifications like CISSP or security-related credentials are preferred.

Qualifications

  • Bachelor's degree in Engineering, Cybersecurity, Networking, or Computer Science.
  • Minimum 10 years in security engineering designing secure networks, systems, and applications.
  • 3–5 years AWS cloud security experience preferred.
  • Experience with IDS/IPS, firewalls, SIEM, antivirus, network analyzers, malware analysis, and forensics tools.
  • GSEC, CISSP, and/or Security+ preferred; AWS Security Specialty preferred.

Responsibilities

  • Design secure architectures and cybersecurity approaches for ICW Group systems.
  • Lead security incident response including preparation, detection, containment, and recovery.
  • Monitor networks and systems for security breaches and respond to incidents.
  • Develop and enforce information security policies, standards, and methodologies.
  • Collaborate with stakeholders to reduce attack surfaces and improve security posture.

Skills

Risk assessment
Security architecture
Incident response
Communication
Cloud security (AWS)
Security policy & procedures
Leadership

Education

Bachelor's Degree in Engineering/Cybersecurity/Networking/CS

Tools

IDS/IPS
Firewalls
SIEM
Antivirus
Network Packet Analyzers
Malware analysis
Forensics tools

Job description

Are you looking to make an impactful difference in your work, yourself, and your community? Why settle for just a job when you can land a career? At ICW Group, we are hiring team members who are ready to use their skills, curiosity, and drive to be part of our journey as we strive to transform the insurance carrier space. We’re proud to be in business for over 50 years, and its change agents like yourself that will help us continue to deliver our mission to create the best insurance experience possible. Headquartered in San Diego with regional offices located throughout the United States, ICW Group has been named for the twelfth consecutive year in a row and for the 20th time overall as a Top 50 performing P&C organization offering the stability of a large, profitable and growing company combined with a focus on all things people. It’s our team members who make us an employer of choice and the vibrant company we are today. We strive to make both our internal and external communities better everyday! Learn more about why you want to be here!

PURPOSE OF THE JOB

The purpose of the Information Security Engineer IV is to design secure architectures and develop cybersecurity approaches and techniques for the security of all ICW related systems and infrastructure. This position will assist with strategic initiatives for short and long-term plans to identify and reduce the attack surface across applications and systems. The Information Security Engineer IV will drive the architecture to monitor and defend ICW Group’s technology against potential threats that jeopardize the financial growth and security goals of the Company.

ESSENTIAL DUTIES AND RESPONSIBILITIES
  • Monitors, defends and drives improvements for ICW Group IT Information Security.
  • Monitors networks and systems for security breaches, using software that detects intrusions and anomalous system behavior and develops strategies to respond to and recover from a security breach.
  • Identifies gaps in the technical tool/technology suite and makes recommendations.
  • Leads security incident response, including preparation, detection, analysis, containment, eradication, and recovery.
  • Researches and implements methods to remediate network and application security vulnerabilities.
  • Leads and participates in security architecture controls reporting, compliance audits, monthly and ad-hoc statistics and trends, and risk-focused reports including internal and 3rd party Risk Assessments.
  • Utilizes automated tools to identify, assess, and report security concerns, with emphasis placed on effective communication to stakeholders.
  • Takes an active lead to inform, advise, and partner with business units to help better secure operations.
  • Leads complex security endeavors.
  • Overseas complex security projects and issues.
  • Develops a set of security standards to respond to and recover from a security breach.
  • Provides support by proposing solutions, coordinating implementation, and enforcing information systems security policies, standards, and methodologies.
  • Uses advanced technologies including Intrusion Detection & Prevention Systems (IDS/IPS), Firewalls, SIEM, Antivirus, Network Packet Analyzers, Malware analysis and forensics tools to detect intrusions, breaches in compliance, etc.
  • Prepares and analyses system security reports by collecting, analyzing, and summarizing data and trends and makes recommendations to improve security.
  • Maintains operational security posture for an information system or program to ensure information system security policies, standards, and procedures are established and followed.
  • Creates and updates technical security standards for assets and software.
  • Serves as cyber security technical subject matter expert for the organization.
  • Provides information security expertise to system development teams throughout the life cycle process.
  • Partners with systems engineering teams to ensure system design and implementation are consistent with company policies, requirements, and directives.
  • Conducts risk assessments, penetration tests and diagnoses internet/extranet security, intrusion attempts, and cyber-crime response.
  • Leads and conducts information security risk assessments including documenting processes, service level agreements and best practices.
  • Develops the overall security design, development, testing and implementation of security solutions.
  • Recommends compliance strategies that support customer requirements and alignment to company policy.
  • Ensures security quality, adherence to security guidelines, profitability, and information security related metrics for self and assigned projects.
  • Collaborates with key stakeholders on remediation strategies and follows remediation activities through closure.
  • Partners with project management and other internal teams in determining overall security solutions.
  • Prepares and presents comprehensive reports and recommendations to senior management and stakeholders on security-related matters.
  • Develops and implements comprehensive security architectures encompassing all areas of IT and business technology for ICW Group using standard and advanced security measures.
  • Works with peers, cross functional architecture leadership, and other internal groups to drive technical security risk down in targeted areas while ensuring adherence to ICW architecture standards.
  • Coaches and educates others to increase early detection rates and decrease IT risk and security.
  • Documents as is state of information security.
  • Keeps current on industry trends, principles, and thought to define long range technology transitions.
  • Performs end to end full stack reviews of current or incoming technologies for ITSEC compliance.
  • Ensures that proposed and existing technology architectures are aligned with organizational security goals and objectives.
SUPERVISORY RESPONSIBILITIES

This position has no supervisory responsibility but may mentor and train junior engineers.

EDUCATION AND EXPERIENCE

Bachelor's Degree from four-year college or university required with major or emphasis Engineering, Cybersecurity, Networking, or Computer Science related discipline. Minimum 10 years of experience working in a security engineering related role designing secure networks, systems and application architectures or equivalent combination of education and experience required. Minimum 3-5 years of experience in AWS Cloud Security services preferred. Direct experience using advanced technologies such as Intrusion Detection & Prevention Systems (IDS/IPS), Firewalls, SIEM, Antivirus software, Network Packet Analyzers, content filtering, Malware analysis and forensics tools to detect intrusions. Experience in cyber security role requiring knowledge of data analysis, risk assessment, risk mitigation, investigation methods, incident management concepts and practices, and policy and procedure development. Experience with AWS Services such as AWS Identity & Access Management, AWS Organizations, AWS Security HuB, Guard Duty, CloudTrail, AWS CloudTrail.

CERTIFICATES, LICENSES, REGISTRATIONS

Certification in GSEC, CISSP, and/or Security+ preferred. AWS Certified Security – Specialty, preferred.

KNOWLEDGE AND SKILLS

Strong knowledge of risk assessment tools, technologies, and methodologies. Knowledge of disaster recovery, computer forensic tools, technologies, and methods. Knowledge of enterprise security platforms. Ability to communicate network security issues to peers and management. Ability to read and use the results of mobile code, malicious code, and anti-virus software. Strong understanding of endpoint security solutions to include File Integrity Monitoring and Data Loss Prevention. Demonstrated experience as a lead engineer in the design, implementation and support in an enterprise IT environment. Ability to apply principles of logical or scientific thinking to a wide range of intellectual and practical problems. Ability to hypothesize on root cause of inefficiencies and then test out probable solutions against those hypotheses. Must be able to read, write and speak English effectively. Ability to effectively communicate/present technical information to a non-technical audience. Ability to cross train and share information with team members.

PHYSICAL REQUIREMENTS

Office environment – no specific or unusual physical or environmental demands and employees are regularly required to sit, walk, stand, talk, and hear. Employees are required to reach with hands and arms; stoop, kneel, crouch, or crawl. Employees must occasionally lift and/or move up to 30 pounds. Employees are required to have visual acuity and be capable of operating and viewing computers and other electronic devices for extended periods of time.

WORK ENVIRONMENT

This position operates in an office environment and requires the frequent use of a computer, telephone, copier, and other standard office equipment. We are currently not offering employment sponsorship for this opportunity.

The current range for this position is $139,874.00 - $250,377.40 This range is exclusive of fringe benefits and potential bonuses. If hired at ICW Group, your final base salary compensation will be determined by factors unique to each candidate, including experience, education and the location of the role and considers employees performing substantially similar work.

WHY JOIN ICW GROUP?
  • Challenging work and the ability to make a difference
  • You will have a voice and feel a sense of belonging
  • We offer a competitive benefits package, with generous medical, dental, and vision plans as well as 401K retirement plans and company match
  • Bonus potential for all positions
  • Paid Time Off
  • Paid holidays throughout the calendar year
  • Want to continue learning? We’ll support you 100%
  • ICW Group is committed to creating a diverse environment and is proud to be an Equal Opportunity Employer.

ICW Group will not discriminate against an applicant or employee on the basis of race, color, religion, national origin, ancestry, sex/gender, age, physical or mental disability, military or veteran status, genetic information, sexual orientation, gender identity, gender expression, marital status, or any other characteristic protected by applicable federal, state or local law.

Job Category IT

At ICW Group we offer a work environment that encourages entrepreneurialism and celebrates success. Our team members are hands-on contributors who are given the opportunity to make an impact. It's our people who make us an employer of choice and the vibrant company we are today.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Information Security Engineer III
Information Security Engineer III

IGH ICW GROUP HOLDINGS, INC. • United States

Hybrid
USD 122,000 - 218,000
Information Security Engineer III
Information Security Engineer III

ICW Group • San Diego (CA)

Hybrid
USD 122,000 - 218,000
Medical benefits
Dental benefits
Vision benefits
+2
Information Security Engineer III
Information Security Engineer III

icwgroup • San Diego (CA)

On-site
USD 120,000 - 180,000
Data Engineer II
Data Engineer II

ICW Group • San Diego (CA)

On-site
USD 95,000 - 161,000
Competitive benefits package
Paid time off
401K retirement plan with companymatch
Sr. Human Resources Business Partner
Sr. Human Resources Business Partner

IGH ICW GROUP HOLDINGS, INC. • United States

On-site
USD 91,000 - 153,000
Medical, dental, vision
401K plan
Paid time off
+2
Senior Third Party Risk Analyst
Senior Third Party Risk Analyst

IGH ICW GROUP HOLDINGS, INC. • United States

On-site
USD 79,000 - 133,000
Bonus potential
Paid time off
Paid holidays
+1
Director, Group Product Management (Technical)
Director, Group Product Management (Technical)

ICW Group • Atlanta (GA), Northern (KY)

On-site
USD 161,000 - 288,000
Medical, dental, vision plans
401K with company match
Bonus potential
+1
Privacy & Compliance Program Manager
Privacy & Compliance Program Manager

IGH ICW GROUP HOLDINGS, INC. • Carmel Point (CA)

On-site
USD 119,000 - 202,000
Bonus potential
Paid Time Off
401K retirement plan
Director, Group Product Management (Technical)
Director, Group Product Management (Technical)

IGH ICW GROUP HOLDINGS, INC. • United States

On-site
USD 161,000 - 288,000
Competitive benefits
401K
Bonus potential
+1
Technical Product Owner - Specialty lines
Technical Product Owner - Specialty lines

IGH ICW GROUP HOLDINGS, INC. • Atlanta (GA)

Hybrid
USD 106,000 - 189,000
Medical, Dental, Vision benefits
401K with company match
Paid Time Off
+1