Businessolver is a company that provides market-changing benefits technology and services. The Information Security Engineer is responsible for designing, implementing, and maintaining security solutions to protect the organization's information assets, while collaborating with various teams to integrate security best practices into their processes.
Responsibilities:
- Design, implement, and manage security technologies (e.g., firewalls, intrusion detection/prevention systems, endpoint protection)
- Monitor security systems and respond to security incidents, including investigation and remediation
- Conduct vulnerability assessments and penetration testing; recommend and implement mitigation strategies
- Develop and maintain security policies, standards, and procedures in alignment with regulatory requirements
- Collaborate with IT and business teams to ensure secure architecture and application development
- Provide security awareness training and guidance to employees
- Research and evaluate emerging security threats and technologies
- Performs other duties as assigned
- Comply with all policies and standards
Requirements:
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field (or equivalent professional experience)
- 3-5+ years of hands-on experience in information security engineering, cybersecurity operations, or related discipline
- Professional certifications strongly preferred: CISSP, CISM, CEH, GIAC, CompTIA Security+, or equivalent
- In-depth knowledge of security frameworks and standards (NIST, ISO 27001, PCI DSS, HIPAA, SOC 2, etc.)
- Experience with security technologies: SIEM, firewalls, IDS/IPS, endpoint protection, DLP, vulnerability management, and cloud security platforms (AWS, Azure, GCP)
- Proficiency in scripting or programming languages (Python, PowerShell, Bash, etc.) for automation and security tool integration
- Strong understanding of network protocols, operating systems (Windows, Linux, macOS), and secure architecture principles
- Demonstrated experience in incident response, forensics, and threat intelligence
- Familiarity with regulatory compliance requirements and audit processes
- Excellent analytical, problem-solving, and communication skills; ability to convey complex security concepts to technical and non-technical audiences
- Commitment to continuous learning and staying current with emerging threats, technologies, and industry trends