Businessolver is a company that has been delivering market-changing benefits technology and services since 1998. The Information Security Engineer is responsible for designing, implementing, and maintaining security solutions to safeguard the organization’s information assets, while collaborating with various teams to integrate security best practices into processes.
Responsibilities:
- Design, implement, and manage security technologies (e.g., firewalls, intrusion detection/prevention systems, endpoint protection)
- Monitor security systems and respond to security incidents, including investigation and remediation
- Conduct vulnerability assessments and penetration testing; recommend and implement mitigation strategies
- Develop and maintain security policies, standards, and procedures in alignment with regulatory requirements
- Collaborate with IT and business teams to ensure secure architecture and application development
- Provide security awareness training and guidance to employees
- Research and evaluate emerging security threats and technologies
- Performs other duties as assigned
- Comply with all policies and standards
Requirements:
- Bachelor's degree in Computer Science, Information Security, Cybersecurity, or a related field (or equivalent professional experience)
- 3-5+ years of hands-on experience in information security engineering, cybersecurity operations, or related discipline
- In-depth knowledge of security frameworks and standards (NIST, ISO 27001, PCI DSS, HIPAA, SOC 2, etc.)
- Experience with security technologies: SIEM, firewalls, IDS/IPS, endpoint protection, DLP, vulnerability management, and cloud security platforms (AWS, Azure, GCP)
- Proficiency in scripting or programming languages (Python, PowerShell, Bash, etc.) for automation and security tool integration
- Strong understanding of network protocols, operating systems (Windows, Linux, macOS), and secure architecture principles
- Demonstrated experience in incident response, forensics, and threat intelligence
- Familiarity with regulatory compliance requirements and audit processes
- Excellent analytical, problem-solving, and communication skills; ability to convey complex security concepts to technical and non-technical audiences
- Commitment to continuous learning and staying current with emerging threats, technologies, and industry trends
- Professional certifications strongly preferred: CISSP, CISM, CEH, GIAC, CompTIA Security+, or equivalent