Vice President, Detection Intelligence & Content Engineering

CLS Group

Woodbridge Township (NJ)

On-site

USD 168,000 - 189,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CLS Group is seeking an IT Security SME to strengthen the company’s security posture across on-premises and cloud environments. The role emphasizes building and refining detection capabilities, governance, and security operations collaboration with the global team.

You will lead technical investigations, develop detections, and help automate security workflows while ensuring compliance with GDPR, NIST, ISO, and related standards.

Qualifications

  • Hands-on IT Security analysis and engineering experience including securing systems, networks and infrastructure.
  • Experience with intrusion detection, malware analysis, forensics and incident response in cloud/hybrid environments.
  • Extensive knowledge of cloud environments such as AWS and Azure.
  • Ability to design, implement and maintain security controls across environments.
  • Strong documentation and report writing skills for technical and business audiences.

Responsibilities

  • Develop and enrich CLS IT Strategy in consultation with CLS IT teams, mirroring initiatives in the overall CLS Strategy.
  • Provide security advice and support for IT projects as Detection Intelligence & Content Engineering SME.
  • Research new security products and services to ensure CLS uses best tools and solutions.
  • Write and tune detection rules in Splunk and GreyMatter.
  • Design analyst dashboards to expedite investigations.
  • Automate tasks and optimize BAU workflows through automation.
  • Coordinate SecOps and SecEng via bi-weekly security engineering calls.

Job description

  • Department: IT Security
  • Reports To: Global Head, Cyber Operations
  • Expected full-time salary range between $ 168,000 - $189,000 + variable compensation + 401(k) match + benefits.
  • Note: Disclosure as required by NY Pay Transparency Law of the expected salary compensation range for this role.
What you will be doing:
SME Consultancy:
  • As part of the IT Security team, develop and enrich CLS IT Strategy in consultation with the CLS IT teams, ensuring that all initiatives are mirrored in respective strategies including the overall CLS Strategy
  • Provide security advice and support for information technology projects as Detection Intelligence & Content Engineering subject matter expert (SME)
  • Research new security related products and services to ensure that CLS is equipped with appropriate industry best tools and solutions
  • Detections development: write and tune detection rules in Splunk & GreyMatter.
  • Quality Assurance: assess rule base fidelity and ensure that any vendor tuning is of adequate quality.
  • Threat Modelling: translate threat intelligence and TTP’s into technical detections.
  • Tool integration: ensure security tooling are interconnected and data flows are optimized. This includes addressing logging gaps, parsing errors, and log outages in collaboration with Security Engineering.
  • Dashboarding: design analyst dashboards to expedite investigations.
  • Satisfy project requirements: Evidencing functional and non-functional requirements and design custom detections for project deliverables.
  • Automate tasks: Analyze BAU tasks and optimize workflows through automation activities.
  • Act as the bridge between SecOps and SecEng including running bi-weekly security engineering calls.
Regulatory Compliance & Reporting:
  • Ensure incident response efforts and documentation comply with industry standards and best practices (GDPR, SOC, NIST, ISO etc.)
  • Maintain detailed documentation and reporting for audits and compliance reviews.
Process Improvement & Risk Mitigation:
  • Develop and refine DICE standard operating procedures and playbooks.
  • Conduct root cause analysis and post incident reports to identify areas for improvement.
  • Recommend and implement process improvements to enhance detection, response and recovery capabilities.
Operational:
  • Operate and maintain controls related to SIEM, DLP, Vulnerability Management, Cyber Threat Intelligence, Endpoint Protection, etc with an emphasis on cloud deployments and implementations.
  • Conduct IT Security risk assessments for all high impact projects, defining security mitigating controls that impact the technology architectures of CLS, service providers, and business partners.
  • Review and update IT Security procedures to reflect best practice and mitigate current and emerging threats.
  • Assigned ownership of IT Security Monitoring and Response related FRB and Internal Audit finding(s) and effective /timely resolution with IT Security.
  • Maintain relationships with third-party IT security vendors and strategic partners.
What we’re looking for:
  • ‘Hands-on’ IT Security analysis and engineering experience including securing systems, networks and infrastructure; operational support, including on-call experience
  • Proven experience including combination of intrusion detection, malware analysis, forensics and incident response, particularly in cloud/hybrid environments.
  • Extensive knowledge of cloud environments such as AWS & Azure.
  • Monitor, tune and develop technical IT Security controls and frameworks to ensure appropriate preparation, monitoring and response to threats.
  • Ensure a risk-based approach to IT Security is adopted in every part of the business and solutions
  • Work with members of the IT Security team to help design, implement and maintain security
  • Prepare for, identify (hunt) and remediate cyber threats
  • Operate and maintain IT Security controls related to SIEM, DLP, Vulnerability Management, Cyber Threat Intelligence, Endpoint Protection, etc.
  • Deliver IT Security projects from concept, approval, design, and implementation to operation
  • Ability to collaborate effectively with others to drive forward key security objectives
  • Strong documentation and report writing skills (to both technical and business audiences)
  • Excellent time management and organizational skills combined with technical IT Security acumen
  • Expert knowledge of Firewalls, TCP/IP, IPS, DLP, proxies, SIEM, & Endpoint Protection software
  • Financial and/or Banking industry experience preferred
Qualifications / certifications:
  • 7+ years’ experience in security operations and/or incident response type roles including 2+ years in leadership or team lead role.
  • S. in a technology discipline (Computer Science, Computer Engineering, Cybersecurity or equivalent);
  • Security certifications such as CISSP and at least one GIAC GCIH, GSEC, GCFA, GCIA, GREM, GCFR or equivalent is preferred.
  • Proven track record with SIEM technologies including Splunk with accompanying certifications preferred i.e. Splunk Certified Cybersecurity Defense Analyst.
  • Knowledge of incident handling life cycle based on an established framework: ISO 27035, SANS, NIST SP 800-61, CERT, ENISA
  • Experience with security and automation in hybrid native environments.
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

Hybrid
USD 80,000 - 110,000
Sr Information Security Analyst
Sr Information Security Analyst

Scorpion Therapeutics • Michigan

Hybrid
USD 120,000 - 180,000
Hybrid work two days from home
Career development opportunities
Cyber Security Engineer
Cyber Security Engineer

Career Listings • Columbus (OH)

On-site
USD 130,000 - 170,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Cyber Security Specialist
Cyber Security Specialist

Jim Adler & Associates • Houston (TX)

On-site
USD 90,000 - 125,000
IT Security - Sr. Analyst
IT Security - Sr. Analyst

CKE Restaurants, Inc. • Franklin (TN)

On-site
USD 85,000 - 110,000
Cybersecurity Engineer
Cybersecurity Engineer

Accylerate • Richmond (VA)

On-site
USD 120,000 - 180,000
Sr. Security Engineer - SIEM, Automation & Elastic Security
Sr. Security Engineer - SIEM, Automation & Elastic Security

Red Lobster, Inc. • Orlando (FL)

On-site
USD 90,000 - 130,000
Information Security Engineer
Information Security Engineer

Gotham Technology Group • New York (NY)

On-site
USD 120,000 - 160,000