Golden 1 Logo - Large Picture Banner (Mobile)

Senior Information Security Engineer

Sacramento, CA, USA Req #5208
Friday, April 26, 2024

TITLE: Senior Information Security Engineer
STATUS: EXEMPT
REPORT TO: manager – Information security
DEPARTMENT: IT – Information Security
JOB CODE: 4345

PAY RANGE: $118,200.00 - $135,000.00 ANNUALLY

 

GENERAL DESCRIPTION:

The Senior Information Security Engineer is responsible for building and maintaining the computer and network security infrastructure for the Golden 1.  This positon requires a full and comprehensive picture of Golden 1’s technology and information needs, which will be used to develop and test security structures designed to protect the computer and network infrastructure.  This position is also responsible for performing technical assessments of risks, threats and vulnerabilities related to new and existing information systems and supporting process within the Golden 1 and external vendor connections.  

TASKS, DUTIES, FUNCTIONS:

  1. Review and investigate suspicious activity identified in intrusion detection system (IDS)/intrusion prevention systems (IPS), web application firewall, vulnerability scan results and other data sources.  Provide recommendations to IT management and monitor to ensure that recommendations are effectively implemented. 
  2. Perform vulnerability assessments and penetration testing to identify exposures and risks, and report findings to management.  Coordinate and lead technology staff in the identification and remediation of system vulnerabilities across the computing environment. 
  3. Provide consultative support as a security subject matter expert on Golden 1 projects and initiatives.
  4. Advise, participate in the development of business systems designs, ensuring hardening standards, and configurations meet information security policy and procedures.
  5. Work in conjunction with IT to ensure appropriate procedures and processes are in place and effective in the detection and prevention of system intrusions as well as in establishing and managing a functional anti-virus/malware/DLP policy.
  6. Monitor, measure, test and report on the effectiveness and efficiency of information security controls as well as compliance with information security policies and procedure.
  7. Implementation, administration and maintenance of IDS/IPS, URL filter, email gateway, certificate issuance and control, network management, identity access control, and other information security infrastructure and controls as necessary.
  8. Regularly review IDS/IPS/HIDS/SIEM rules, wireless rogue access point detection configuration and procedures and practices to ensure optimal effectiveness of security in the business environment. 
  9. Regularly review firewall, VPN, and web content filtering configuration and rules to ensure optimal efficiency and adherence information security standards. 
  10. Actively participate with internal and external auditors during examinations, providing support and assistance in addressing audit recommendations.
  11. Drive the security development of network systems architecture, design, and ongoing review of system configuration in collaboration with relevant team members.
  12. Keep management updated on outstanding issues that are not resolved in a timely manner in accordance with established escalation procedures.
  13. Develop and maintain a clear understanding of the business area needs and incorporating these needs into technical solutions by updating, developing and maintaining a thorough knowledge of credit union procedures, products, service, and data processing systems.
  14. Maintains a thorough understanding of state and federal laws and regulations related to credit union compliance including bank secrecy and anti-money laundering laws appropriate to the position.
  15. Performs other job-related duties as necessary.

PHYSICAL SKILLS, ABILITIES, AND EXERTION UTILIZED IN THE PERFORMANCE OF THESE TASKS:

  1. Effective oral and written communication skills required with a focus on troubleshooting and error identification.
  2. Must possess sufficient manual dexterity to skillfully operate applicable computer hardware, a variety of hand tools and standard office equipment. 

ORGANIZATIONAL CONTACTS & RELATIONSHIPS:

  1. INTERNAL:  All levels of staff and management. 
  2. EXTERNAL:  Vendors, service providers, organizational groups, and other financial institutions as needed.

QUALIFICATIONS:

  1. EDUCATION: Bachelors of Science in Computer Science, Management Information Systems, Information Security Information Assurance or equivalent work experience.   
  2. EXPERIENCE:
  • Minimum of 6 years or more hands on experience in the management, configuration, administration, installation, and evaluation of network (Cisco desired) or operating systems software (Microsoft, Linux desired), hardware and applications.
  • At least 4 years’ experience in organizational information security, information assurance or providing security consulting services.
  • Subject matter expert with of  Firewalls and Intrusion Detection/Prevention systems
  • Subject matter expert with operating systems security principles.
  • Subject matter expert with networking security principles.
  • Demonstrates strong knowledge of information security principles, objectives, and security system standards including but not limited to: network topology threats, vulnerabilities, segmentation, filtering, tunneling, authenticating, access control, cryptography, system and network hardening.
  • Demonstrates strong knowledge of risk assessment methodologies, VoIP and mobile device.
  • Demonstrates strong knowledge of business, network systems, hardware concepts, and applications including: DNS, LDAP, virtualization, Database design/hardening, E-mail/secure messaging, Data Loss Prevention, and end point protection.
  • Strong sense of ethics, integrity, and professionalism.
  • Demonstrates the ability to articulate methodologies and concepts; communicate effectively in providing technical guidance and expertise to management and other staff.

PHYSICAL REQUIREMENTS:

  1. Prolonged sitting throughout the workday to accomplish tasks.
  2. Availability for emergency and on call duty 24 hours a day, 7 days a week, as needed.
  3. Occasional travel may be required.
  4. Lift and carry communications equipment and computer hardware weighing up to fifty pounds.
  5. Corrected vision in the normal range required to configure, test, and troubleshoot network server hardware and data.
  6. Hearing within normal range.
  7. Must possess sufficient manual dexterity to skillfully operate applicable computer hardware, a variety of hand tools and standard office equipment.
  8. May work additional work hours to accomplish tasks.

LICENSES/CERTIFICATIONS:

  • Possession of a valid California Driver’s License is required
  • One of the following security certifications: CEH, Security +, SSCP, SANS GIAC, or equivalent

One of the following technical certifications: MCP, CCNA, or equivalent

REV. 4/26/2024

Other details

  • Job Family Senior Professional
  • Job Function Senior Professional
  • Pay Type Salary
  • Employment Indicator Remote
  • Min Hiring Rate $118,200.00
  • Max Hiring Rate $135,000.00
Location on Google Maps
  • Sacramento, CA, USA