Job Closed

This listing is no longer active.

ProArch logo
ProArch

Consulting and technology- enabled by cloud, guided by data, fueled by apps, and secured by design.

Security Specialist

Security EngineerSecurity EngineerOtherRemoteMid LevelTeam 201-500H1B SponsorCompany SiteLinkedIn

Location

New York

Posted

132 days ago

Salary

0

Seniority

Mid Level

Bachelor Degree2 yrs expEnglishAWSAzureGCPIoTPythonSplunk

Job Description

Security Specialist

ProArch

• Initial setup and deployment of security solutions and operational technology security measures. • Creating and delivering detailed reports and maintaining technical documentation. • Conducting security training sessions and assessments to enhance security awareness and identify vulnerabilities. • Provide expert advice, guidance, and ad-hoc consulting services to address specific security needs. • Ongoing configuration, maintenance, and management of security solutions and systems. • Delivering presentations, conducting proof-of-concepts, and engaging with the public through various platforms. • Focuses on enhancing and optimizing security programs and processes. • Implementation & Management of Microsoft Security Solutions, Security Information & Event Management (SIEM), and Extended Detection & Response (XDR) security architecture. • Solution research & design, emerging technology evaluation. • Solution configuration management. • Ticket Queue management and supporting customers through ticket ownership. • Account & permission management, provisioning, governance for security solutions. • Microsoft or other 3rd party vendor Security workshops. • Incident Response investigation, writing, delivery, as appropriate.

Job Requirements

  • Outstanding Written, Verbal, Technical, Non-Technical, communication & presentation skills.
  • Self-directed with the ability to prioritize and handle multiple tasks concurrently, and of high quality.
  • Proven collaborator. Experience in mentoring and guiding a highly technical team.
  • Eager learner continually improving skill sets, earning certifications, and gaining industry knowledge.
  • Skilled in leading a conversation with client to drive security strategy and program improvement.
  • Exceptional analytical skills.
  • A well-understood English dialect is a must.
  • Ability to prioritize effectively and handle shifting priorities professionally.
  • Produce and review reports to support project deliverables.
  • Ongoing training and professional certifications are part of the job requirements.
  • Create clearly stated remediation recommendations based on industry best practice.
  • Successfully interface with clients, both internally and externally.
  • Document and explain technical details in concise and clear manner.
  • Manage personal schedule and project tasks.
  • Provide weekly time accounting and monthly expense reports.
  • Travel within upstate NY and occasionally out of state, as required.
  • Candidate should have a minimum of 2 years of experience in cybersecurity with additional background in Security Consulting. To be successful, this position will require the candidate to have expertise in the following areas:
  • Familiarity with Security Information and Event Management (SIEM) systems, particularly Microsoft Sentinel and Extended Detection & Response (XDR) solutions, such as Microsoft Defender XDR.
  • Familiarity with how SOAR (Security Orchestration and Automated Response) works and ability to provide workflows which can be used for automating SOC responses.
  • Incident Handling, take technical investigation ownership of incidents and coordinate response efforts.
  • Industry knowledge and experience in Managed Detection and Response (MDR) technologies.
  • Deep experience in advanced Microsoft Cloud Security implementation, advisory, and assessment.
  • Microsoft Security and Compliance including:
  • Defender for Endpoint
  • Defender for Office 365
  • Defender for Identity
  • Defender for Cloud Apps
  • Defender for Cloud
  • Defender XDR
  • Defender for IoT
  • Entra ID Identity Protection
  • Entra ID & Intune
  • Microsoft Sentinel
  • Microsoft Purview, IRM, DLP, Insider Risk
  • Experience with CrowdStrike Endpoint, Identity, XDR is highly desirable.
  • Vulnerability Management tools, such as Qualys.
  • Security Awareness Training using tools such as KnowBe4.
  • Experience in analyzing and creating remediation strategies for vulnerability management programs, security architecture reviews, cloud security reviews in a Managed Security Services Model.
  • Implement and maintain security solutions, tools, and IT Policies and standards.
  • Experience with major Identity Provider and related security solutions, such as Microsoft Entra ID, Identity Protection, Active Directory, Defender for Identity.
  • Demonstratable knowledge in Microsoft and other vendor-based licensing.
  • Experience in Policy and Device Management solution like MEM, Intune, Azure Arc, GPO.
  • Experience with Azure DevOps is desirable.
  • Advanced knowledge of Kusto Query Language (KQL). Splunk Processing Language (SPL) knowledge is a good to have.
  • Experience in Scripting languages like AZCLI, PowerShell and Python.
  • Experience in Power Automate and Logic Apps.
  • Good to have non-Microsoft Cloud Security knowledge like GCP, AWS, etc.
  • Experience in public speaking, building client relationships, security report analysis and delivery.
  • Experience in handling highly technical, project-based, and process-driven questions from customers.
  • Experience in data analysis, logging, fine-tuning and cost reduction solutions.
  • Experience developing and improving security tools onboarding and validation process.
  • Experience analyzing network topologies, security architectures, security solutions, tools, and IT Policies and standards to find gaps between in-place programs and industry best practices.
  • Knowledge of Authentication and Authorization mechanisms, Identity Access Management, user provisioning best practices.

Related Categories

Related Job Pages

More Security Engineer Jobs

Infotree Global Solutions logo

Security Engineer

Infotree Global Solutions

The branch to Innovation, Talent and Results

Security Engineer132 days ago
Full TimeRemoteTeam 1,001-5,000Since 2002H1B Sponsor

• Enhance Information Security Metrics and Threat based reporting • Enhance Identity and Access Risk & Compliance Reporting based on Information Security requirements • Conceptual analysis of a Unified Risk Framework with regards to reporting and metrics development • Analysis and Integration Concept of various Information Security Areas (Data Leakage, WOA, etc. ) into the current Analytics & Reporting landscape • Understand MITRE Attack framework essential

Romania
Job Closed
OtherRemoteTeam 5,001-10,000Since 1985H1B Sponsor

• Serve as a subject matter expert (SME) on Information Security • Identify and implement new security technologies and best practices • Review security test results from vulnerability scans, penetration testing • Guide and influence multi-disciplinary teams in implementing and operating Cyber Security controls • Consults with internal teams on engineering designs and development of cloud-based systems • Learn with agility; empowered to update and enhance current security practices

United States
$105K - $155K / year
Job Closed
Charlie Health logo

Lead Security Engineer

Charlie Health

Personalized mental health treatment for teens, young adults & families in crisis.

Security Engineer132 days ago
OtherRemoteTeam 501-1,000H1B No Sponsor

This description is a summary of our understanding of the job description. Click on 'Apply' button to find out more. Role Description Charlie Health is seeking an experienced Lead Security Engineer to join our Information Security team. In this role, you will partner closely with engineering and product teams to embed secure development practices across the entire software development lifecycle (SDLC). You will be the subject matter expert on application and cloud infrastructure security, guiding the business in building secure, scalable and HIPAA-compliant software solutions. Responsibilities - Lead application security program including SAST/DAST integration, security code reviews and developer training. - Perform threat modeling and architecture reviews to identify potential security risks early in design phases. - Integrate security tooling and automate security processes into CI/CD and DevOps pipelines. - Manage application and cloud security vulnerability management program including configuration of scanning tools, validation and prioritization of findings, and remediation of risks. - Review and document new third-party integrations with Charlie Health applications and cloud infrastructure. - Perform internal penetration testing and manage third-party penetration tests. - Work with teams to build and enforce secure SDLC controls in a fast-paced agile environment. - Develop cloud security configuration baselines and monitor for gaps. - Document business continuity and disaster recovery procedures for cloud infrastructure environment. - Participate in security incident response activities related to Charlie Health applications and infrastructure systems. - Help define metrics and KPIs that demonstrate the effectiveness of the application and cloud security programs. Qualifications - 10+ years of experience in application security, secure software development, cloud security or related roles. - Bachelor’s degree in Computer Science or related field, or equivalent experience. - Proficiency in secure coding practices and languages such as Typescript, Node, Python, Java, C++ or similar. - Hands-on experience with application security tools (e.g., Burp Suite, OWASP ZAP, Fiddler). - Knowledge of container security concepts, including container image scanning, secure image pipelines, and common misconfigurations in containerized environments. - Deep understanding of web application vulnerabilities: XSS, CSRF, SQLi, session management, etc. - Experience implementing security in CI/CD pipelines such as GitHub Action and agile development workflows. - Familiarity with AWS cloud platform and AWS security best practices. - Familiarity with management and deployment of SAST, DAST, and SCA tooling. - Knowledge of authentication technologies (i.e. Auth0, Okta, etc) and how to securely integrate them with applications. - Strong communication skills with ability to clearly articulate risk to technical and non-technical audiences. Preferred Qualifications - Experience with HIPAA and securing applications in healthcare, or other regulated, environments. - OSCP, OSWE, AWS Security or other relevant security certifications. - Experience securing custom software collaboratively on a team. - Experience with Wiz or similar CNAPP tools. - Knowledge of AI/ML security best practices. - Familiarity with Infrastructure as Code (IaC). - Knowledge of security standards such as SOC2, ISO 27001/2, NIST 800-53, HITRUST, or HIPAA Security Rule. Benefits - Comprehensive benefits for all full-time, exempt employees. - Total target base compensation between $180,000 and $240,000 per year. - Cash compensation may include stock options and other Charlie Health-sponsored benefits.

United States
$180K - $240K / year
Job Closed
Procter & Gamble logo

Senior Offensive Security Engineer, Red Team

Procter & Gamble

Procter & Gamble, or P&G, is the parent company behind some of the world's most recognizable household and personal care brands. The company was established in

Security Engineer132 days ago

• Lead end-to-end red team operations aligned to priority threat actors: scenario design, ROE, pre-briefs, execution, and hot-wash/AAR • Support purple-team engagements with DFIR/SOC and Detection Engineering to convert TTPs into durable detections, runbooks, and response improvements with measurable outcomes • Orchestrate assumed-breach campaigns emphasizing evasion and control bypass (EDR/AV, email/web security, identity/conditional access, network segmentation, cloud guardrails) • Perform campaign/TTP research, develop internal PoCs/tooling (e.g., tradecraft to exercise specific controls, lightweight payloads), and steward OPSEC • Produce executive-ready risk narratives and technical reporting (ATT&CK mapping, artifacts, evidence handling) and brief senior leadership • Mentor junior engineers; set standards for craft quality, methodology, and safety • Coordinate multi-party/third-party exercises; manage risk, deconflict with production, and ensure stakeholder alignment • Contribute to operational expansion by researching, prototyping, and developing novel capabilities for offensive use • Contribute to program maturity: metrics/KPIs, roadmap, methodology standardization, control validation cadence, and integration with vulnerability management

Ohio
$110K - $165K / year
Job Closed