Overview
Skills
Job Details
Job Description:
We are seeking an experienced IT Security Engineer with a strong focus on compliance and risk management to help safeguard our organization s technology infrastructure. This role is responsible for assessing, implementing, and monitoring security controls, ensuring adherence to regulatory standards, and reducing organizational risk. The IT Security Engineer will work closely with cross-functional teams to design secure solutions, respond to security incidents, and maintain a robust security posture.
Responsibilities:
Develop, implement, and maintain security policies, standards, and procedures aligned with industry best practices and compliance frameworks (ISO 27001, NIST, SOC 2, HIPAA, PCI-DSS, etc.).
Conduct risk assessments, vulnerability scans, and security audits to identify and remediate risks.
Collaborate with IT and business units to ensure systems, applications, and processes align with security and compliance requirements.
Monitor security systems and respond to incidents, providing root cause analysis and recommendations.
Support security awareness and training programs to reduce human-related risks.
Assist with vendor risk assessments and third-party compliance evaluations.
Prepare documentation and reports for compliance audits and regulatory reviews.
Stay current with evolving cybersecurity threats, trends, and compliance regulations.
Qualifications:
Proven experience as an IT Security Engineer, Security Analyst, or similar role with a focus on compliance and risk management.
Strong knowledge of security frameworks, regulations, and best practices (NIST, ISO, GDPR, HIPAA, SOC 2, etc.).
Hands-on experience with firewalls, IDS/IPS, SIEM, endpoint protection, and vulnerability management tools.
Familiarity with cloud security (AWS, Azure, Google Cloud Platform) and securing hybrid environments.
Excellent understanding of risk assessment and mitigation strategies.
Strong problem-solving, communication, and documentation skills.
Relevant certifications such as CISSP, CISM, CISA, CRISC, or CompTIA Security+ pr