A technology solutions company in Dearborn, Michigan is seeking an experienced security professional to evaluate, implement, and manage security solutions while leading security projects. Candidates should have over 10 years of IT experience with 5-7 years focused on system/network security, including threat modeling and compliance with regulations like HIPAA and PCI-DSS. The ideal candidate has relevant security certifications and is ready to provide recommendations to enhance the security posture.
Qualifications
10+ years of IT experience, including 5-7 years in system/network security.
Security certifications like CISSP or CEH preferred.
Proven knowledge of IT security regulations (HIPAA/HITECH, PCI-DSS) is important.
Responsibilities
Evaluate, implement, and manage security solutions.
Lead security projects and cross-functional teams.
Implement and manage security policies and procedures.
Monitor and investigate alerts, determining root causes.
Provide recommendations for improved security posture.
Skills
Hands on experience in Azure
Hands on experience in AWS Security
Ability to set up monitoring of security events in cloud
Familiar with Information Security concepts
Experience with security tools administration
Conduct risk/vulnerability analysis
Proven experience in threat modeling
Knowledge in compliance with IT Security regulations
Education
BS in IT, Computer Science, Management Information Systems or equivalent
Security certification (CISSP, ISSMP, etc.)
Tools
Security event correlation tools
Intrusion detection/prevention tools
Web security gateways
Endpoint security software
Job description
Responsibilities
Able to evaluate, implement and manage security solutions.
Able to lead security projects and cross functional project teams.
Able to implement and manage security policies, procedures and incident response strategies.
Protects against unauthorized access, modification, or destruction of information assets.
Works with end users to determine needs of individual departments.
Hands on experience in Azure or AWS Security
Ability to set up monitoring of security events in cloud
Conduct Access Control review of applications database and OS on cloud
Hands on experience in Cloudera security or Hadoop Security
Implements policies or procedures, and tracks compliance.
Familiar with a variety of Information Security concepts, practices, and procedures.
Security tool system administration
Functions as a system (or backup) administrator for 4 or more security tools.
Makes recommendations to improve the functionality of the security tools to improve security posture and/or customer experience.
Identify unsuccessful and successful intrusion attempts by reviewing and analyzing security events logs and event summary information.
Conduct third party security or audit
Ensure the integrity and protection of networks.
Monitor logs for potential, successful and unsuccessful intrusion attempts.
Communicate intrusions and compromises to team leaders.
Monitor and investigate alerts, determining root cause and appropriate mitigations.
Works with end users to determine needs of individual departments, implementing policies or procedures.
Able to serve as a subject matter expert on security projects/initiatives.
Work as part of a team to lead elements of larger security projects.
Through various consultative methods (PER process, meetings, service requests, etc.) work with our customers to review their requirements and access the overall security.
Provide recommendations to improve security while achieving the business goal.
Understand that we must enable the business while securing it.
Conduct risk/vulnerability analysis on projects/new technology, providing remediation steps as appropriate.
Stay current on threats affecting the industry as a whole; provide recommendations to address as appropriate.
Stay current on emerging technology and provide recommendations on how MH could use this technology to improve security.
Keeps management advised during the incident.
Creates appropriate documentation of the incident including lessons learned and ways to minimize a repeat incident.
Qualifications
BS in IT, Computer Science, Management Information Systems or equivalent degree preferred. Work experience may be substituted.
At least 10 years of IT experience with at least 5-7 years of system/network security experience, including threat modeling, threat assessments, risk identification techniques, penetration testing.