Procom is a cybersecurity firm seeking an Information Security Engineer to support their vulnerability and threat management programs. The role focuses on SaaS vulnerability management and involves collaboration with IT and Cybersecurity teams to enhance the security of applications and data.
Responsibilities:
- Conduct continuous identification and assessment of SaaS exposures, to include misconfigurations, permission sprawl, insecure integrations, and identity-centric risks across enterprise SaaS platforms
- Analyze security findings and provider advisories to identify and prioritize corrective action(s) based on exposure, exploitability, and business criticality
- Document and track SaaS security risks, remediation actions, and posture trends using automated risk registers, POA&Ms, and exception requests. Generate and brief technical and executive-level reports aligned to applicable regulatory and audit requirements
- Develop, implement, and sustain security configuration baselines and hardening standards, mapped to organizationally mandated frameworks (CIS, NIST CSF, etc.)
- Partner with SaaS application owners and identity, GRC, and enterprise teams to coordinate remediation of customer-controlled SaaS risks
- Plan and execute SaaS security posture assessments to measure connected application compliance and alignment across the SaaS portfolio
- Participate in cross-functional risk and threat modeling activities and provide actionable recommendations for reduction or transference of risk
- Develop, implement, and update vulnerability management policies, standards, and TTPs supporting SaaS vulnerability and exposure management processes
- Utilize autonomous skills to leverage organizational Artificial Intelligence (AI) tools to effectively and efficiently assess exposure and risk at scale
- Liaison with applications teams, business stakeholders, and vendor representatives to review security posture, remediation ownership, compensating controls, and contractual and regulatory compliance
- Support and mature proactive cybersecurity strategies to include CTEM, SaaS Attack Surface Management, Identity Threat Detection and Response (ITDR), and zero-trust access models
- Maintain up-to-date knowledge of emerging threats, vulnerabilities, and cybersecurity best practices
- Assist with cybersecurity tool evaluation and implementation, and operation
- Participate in organizational and third-party training and workshops to enhance professional knowledge and team performance
Requirements:
- Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent experience)
- Professional certification as Certified Information Systems Security Professional (CISSP), CompTIA Advanced Security Practitioner (CASP+), GIAC Security Leadership Certification (GSLC), or equivalent
- Minimum 5 years of experience in cybersecurity, with at least 3 years focused on vulnerability management, compliance validation, or threat analysis
- Experience with multiple operating systems to include Windows, MacOS, Linux, Cisco iOS, etc
- Hands-on experience with SSPM, CASB, IAM, or equivalent SaaS vulnerability management tools (e.g., Wiz, Microsoft Defender, Netskope, Entra ID, Okta)
- Familiarity with prompt engineering and leveraging of AI tools to automate manual processes and supplement data analysis
- A strong understanding of networking, infrastructure, application, and information concepts and associated security principles
- Experience in risk assessment and mitigation processes, practices, and strategies
- Strong analytical, documentation, and communication skills
- Ability to lead cybersecurity engineering projects and effectively communicate with business partners
- Excellent interpersonal and communications skills, with the ability to work collaboratively in a team environment
- Ability to work under pressure and effectively handle multiple responsibilities in a fast-paced and critical heath care environment
- Experience with business efficiency/intelligence tools (e.g., Power BI, Power Automate, Generative AI)
- Experience with industry cybersecurity frameworks (e.g., CIS, NIST, PCI DSS)
- Experience with Business Efficiency, Business Intelligence, or Generative AI products
- Exposure to incident response and disaster recovery procedures
- Exposure to virtualization and cloud platform security (e.g., Azure, AWS)
- Familiarity with DevSecOps practices and secure