Job Closed
This listing is no longer active.
Headquartered in New York, New York, Planned Parenthood is a nonprofit organization dedicated to providing high-quality reproductive healthcare services and edu
Associate Director, Information Security Engineer
Location
United States
Posted
82 days ago
Salary
$125K - $130K / year
Seniority
Senior
Job Description
Associate Director, Information Security Engineer
Planned Parenthood
• The Security Engineer manages Information Technology security protections with the goal of protecting PPFA from and reducing the impact of security incidents and system compromises for the organization. • This position provides security monitoring, event investigation and analysis, and countermeasure proposals on a 24x7 basis along with providing support and guidance to Tier I Analysts, will provide technical assistance for Tier II & III incidents as assigned, and is responsible to directly interface with the InfoSec Operations Team, Managed Security Service Provider (MSSP) and IT Managed Service Provider (MSP) as it relates to security event architecture, collection, management, reporting, and alerting within PPFA’s SIEM Platforms. • The Security Engineer will engage with InfoSecOps, InfoSec, ITOps/MSP, the MSSP, ATS and staff within both PPFA and Affiliates. • The Security Engineer will deliver by identifying, implementing, and maintaining Information Security toolsets, primarily focused on SIEM, to protect the organization; interfacing with IT Ops to ensure proper security event logging setup; and, where applicable, supporting the Information Security SIEM management needs of PPFA and Affiliates. • Act as a Subject Matter Expert for PPFA’s SIEM (currently Splunk) and be able to configure, manage, operate, and administer the platform from a managed SIEM perspective. • SIEM Security Monitoring – Provide security monitoring and threat/risk analysis in a 24/7 environment. • SIEM Event Filtering – Monitor & ensure established processes for event identification are followed, and, where required, make recommendations for new or refined event filtering, ensuring all updates are completed. • SIEM Event Investigation & Assignment – Monitor & ensure established processes are followed for collecting relevant data and performing the necessary levels of analysis on that data. Ensure events are assigned appropriately. • Tier II Event Escalations - Follow an established process for handling Tier II escalations, identifying the source of the escalation (MSSP, MSP, Affiliate, or other) and the appropriate triage and documentation processes. • Creating and maintaining Standard Operating Procedures (SOPs) for the Information Security Ops group, and providing recommendations on security process improvements. • Support and engage on complex security tool-specific tasks with the assistance and guidance of management, vendor & MSSP resources. • Assist in Vulnerability Assessments setup, scanning, analysis, and remediations, working with IT Ops staff and corporate vendors as needed in correcting errors and alerts as found with the IT infrastructure systems. • Assist in IR incidents as assigned by management. • All other duties as assigned.
Job Requirements
- Bachelor’s degree and 5+ years of industry experience
- Passion to work on newer technologies and explore the security domain.
- Independent decision-making capabilities, especially in identifying analysis tracks for escalated events, analysis assignments, and escalation decisions ranging from a base Tier I event to Incident Response level remediations.
- Experience in compliance requirements and industry standards like PCI, HIPAA, ISO 27001, NIST, CSF, MITRE ATT&CK, ITIL, COBIT, Sarbanes-Oxley, and SANS 20.
- UNIX, AIX & Solaris, Linux, Windows Server Operating Systems
- Network/System Intrusion Detection or Prevention Systems (IDS/IPS)
- Security Information and Event Management (SIEM)
- Vulnerability scanner/Penetration testing systems
- Wireless Networking
- Switches/Routers, Firewalls (basic configuration)
- TCP/IP networking, VPN, VLAN, NAT, and security concepts
- Software & Hardware Asset Management
- Security threat and attack countermeasures
- Experience conducting forensic analytical studies and investigations
- Flexibility and ability to adapt to quickly changing priorities and ambiguous situations
- A deep commitment to Planned Parenthood’s mission of promoting Sexual and Reproductive Health
Benefits
- Health insurance
- Retirement plans
- Paid time off
- Professional development opportunities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Security Engineer
RelayGo anywhere onchain, instantly. Relay makes it easy to move money across any blockchain with a powerful API + App.
• Own Relay's security posture • Lead threat modeling, vulnerability management, access controls, and dependency auditing • Map Relay's attack surface and document gaps • Harden CI/CD pipelines, secrets management, and least-privilege access • Build and maintain observability • Instrument monitoring, alerting, and dashboards that give the team real-time visibility into Relay's health • Define and enforce SLOs by setting availability and performance targets, and drive the team to meet them • Lead incident response • Own the incident response process end to end: triage when things break, run postmortems, and make sure the same issue doesn't happen twice • Drive compliance readiness • Prepare Relay for customer security reviews and formal certifications (SOC 2, etc.) • Embed security and reliability practices into team culture as we grow
Senior Engineer, Security – AppSec
ArcadiaWe transform data into powerful insights that deliver results.
• Design, implement, and maintain application security controls across Arcadia’s cloud-native SaaS platform • Partner with Product and Engineering teams to embed security into system design, development workflows, and CI/CD pipelines • Conduct threat modeling, architecture reviews, and secure design assessments for new and existing services • Own and improve vulnerability management processes, including identification, prioritization, and remediation tracking • Implement and maintain security tooling such as SAST, DAST, dependency scanning, container scanning, and secrets detection • Participate in security incident response activities including detection, investigation, containment, and remediation • Monitor and analyze logs, alerts, and security events to identify suspicious activity and emerging threats • Contribute to detection engineering by tuning alerts, improving signal quality, and reducing noise • Support threat intelligence analysis and apply insights to improve preventive and detective controls • Perform post-incident analysis and recommend technical and process improvements • Build security-as-code solutions to automate control enforcement, validation, and remediation • Use scripting and automation to reduce manual effort and improve consistency • Support secure AWS architecture using services such as EKS, ECS, Lambda, IAM, and VPC • Contribute to identity and access management best practices across AWS, Okta/Auth0, and SaaS platforms • Translate compliance requirements (e.g., SOC 2, ISO 27001, HITRUST, HIPAA) into practical technical controls • Partner with Security Assurance to support audits, evidence collection, and continuous control monitoring • Help identify and remediate security risks discovered through assessments, audits, or incidents
Application Security Intern
DoyensecWe work at the intersection of software development and offensive engineering to help companies craft secure code.
• Perform professional security testing for both startups and Fortune 500 companies • Engage in cutting-edge offensive security research, including tools development
IS Technical Specialist – RACF Security Engineer
Huntington National BankSine 1866, Huntington National Bank has served midwestern communities with banking and financial services for consumers and businesses of all sizes. The regiona
• Ensure that Huntington’s identity & access management services are designed to be compliant with security and privacy standards and other industry standards and practices. • Alter security standards and settings to evolve with emerging threats in the mainframe space. • Work with other IBM Related Huntington Mainframe teams to complete application installs/decommissions • Work with Portfolio Manager deliver IAM projects and key milestones. • Consult with business units when implementing access for new systems. • Other duties as assigned




