Summary
VEIC is seeking an Information Security Engineer II to support blue team security operations and security engineering. The role independently monitors and responds to security incidents, engineers and maintains security technologies, leads security projects, supports digital forensics and governance activities, and advises teams on cyber risk and security best practices.
Responsibilities
- Lead Independently monitors, triages, and responds to security alerts and incidents across the security stack, escalating and documenting activities as appropriate
- Coordinates response efforts for security incidents, including containment, eradication, and recovery activities
- Engineers, implements, and maintains information security technologies, including SIEM content, detection rules, data onboarding, and automation
- Owns security engineering projects end-to-end, from scoping and design through implementation and operational handoff, with minimal oversight
- Serves as a point of contact within Information Technology for information security technologies, processes, and procedures
- Works closely with Information Technology colleagues on technology and process improvement initiatives
- Partners with teams across the organization to support the security of the technologies and systems they use, extending beyond the core IT environment
- Maintains a strong working knowledge of VEIC’s IT systems and their business value
- Collaborates with internal stakeholders, providing support and guidance on issues of moderate to high complexity
- Proactively identifies and escalates security issues, risks, and operational performance concerns
- Performs investigative tasks of moderate complexity and partners with the Manager, Information Security on digital forensics and other investigative efforts
- Works closely with the Manager, Information Security on governance and policy activities, including policy maintenance, control reviews, and audit evidence collection
- Advises business units across the organization on cyber risk, helping ensure processes remain both practical and secure
- Collaborates with technologists across the organization, providing guidance on security best practices
- Explores and develops security automation capabilities, including AI-assisted tools, to enhance security operations
- Provides training and guidance to VEIC staff and teams on information security risks in support of organizational and departmental initiatives
- Promotes a culture of information security across the organization
- Supports the work of other VEIC staff as necessary to achieve organizational goals and objectives
- Performs administrative tasks, reporting, and stakeholder communications as needed
- Participates in on-call and after-hours response activities as needed for security incidents, including on-site response for events requiring a physical presence
- Other duties as assigned
Skills
- Strong personal commitment to the mission, vision, goals, and values of VEIC
- Strong professional interest in and commitment to the information security field
- Strong understanding of information security concepts and principles
- 3 or more years of experience in information security operations and/or security engineering within a professional environment, or an equivalent combination of education and experience from which comparable knowledge and skills have been acquired
- Demonstrated proficiency in securing and administering Microsoft 365 security products, including Defender for Endpoint, Purview, Entra ID, and Intune
- Proficiency with core infrastructure technologies, including enterprise operating systems such as Windows and Linux, TCP/IP networking, storage systems, virtualization, and containerization
- Proficiency in scripting or programming languages such as PowerShell and Python
- Working knowledge of security technologies including vulnerability scanning, event log management, endpoint security, firewalls, and web application firewalls
- Working knowledge of cloud technologies and concepts
- Familiarity with digital forensics tools, techniques, and procedures
- Familiarity with physical security concepts and practices
- Demonstrated ability to work independently and manage projects from initiation through completion
- Strong interpersonal, written, and verbal communication skills, with a customer service-oriented approach
- Strong analytical, critical thinking, and problem-solving skills
- Ability to remain organized, detail-oriented, and accurate while managing multiple tasks and competing priorities in a dynamic, fast-paced environment
- Ability to communicate complex technical concepts to non-technical audiences in a clear and user-friendly manner
- Commitment to continuous learning and professional development
- Possess, or be willing to obtain, an entry- to mid-level information security certification such as CompTIA Security+, CySA+, or GSEC within the first six months of employment
- Ability to remain stationary at a workstation for extended periods (typically 6-8 hours per day with regular breaks)
- Regular use of computer, keyboard, mouse, and telephone/headset requiring fine motor skills and repetitive hand/wrist movements
- Visual acuity to view digital screens, documents, and presentations for prolonged periods
- Verbal communication abilities are sufficient for clear articulation during in-person and virtual meetings, presentations, and discussions
- Auditory capabilities to participate effectively in conversations, conference calls, and virtual collaboration sessions
- Cognitive focus for simultaneous management of multiple communication streams, projects, and stakeholder relationships
- Occasional movement between meeting spaces, collaboration areas, and individual workstations
- Minimal lifting requirements (typically under 15 pounds) for office supplies, equipment, or materials
- This position does not require regular travel
- Experience with Splunk, including Splunk Enterprise Security (ES), is a plus
- Experience with Proofpoint email security products is a plus
- Familiarity with offensive security concepts is a plus
- Familiarity with Mac Endpoint security is a plus
- Occasional in-person attendance at company events or meetings (typically 0–2 times per year) may be encouraged, but participation is often optional or available virtually
Qualifications
Must Haves
- Strong personal commitment to the mission, vision, goals, and values of VEIC
- Strong professional interest in and commitment to the information security field
- Strong understanding of information security concepts and principles
- 3 or more years of experience in information security operations and/or security engineering within a professional environment, or an equivalent combination of education and experience from which comparable knowledge and skills have been acquired
- Demonstrated proficiency in securing and administering Microsoft 365 security products, including Defender for Endpoint, Purview, Entra ID, and Intune
- Proficiency with core infrastructure technologies, including enterprise operating systems such as Windows and Linux, TCP/IP networking, storage systems, virtualization, and containerization
- Proficiency in scripting or programming languages such as PowerShell and Python
- Working knowledge of security technologies including vulnerability scanning, event log management, endpoint security, firewalls, and web application firewalls
- Working knowledge of cloud technologies and concepts
- Familiarity with digital forensics tools, techniques, and procedures
- Familiarity with physical security concepts and practices
- Demonstrated ability to work independently and manage projects from initiation through completion
- Strong interpersonal, written, and verbal communication skills, with a customer service-oriented approach
- Strong analytical, critical thinking, and problem-solving skills
- Ability to remain organized, detail-oriented, and accurate while managing multiple tasks and competing priorities in a dynamic, fast-paced environment
- Ability to communicate complex technical concepts to non-technical audiences in a clear and user-friendly manner
- Commitment to continuous learning and professional development
- Possess, or be willing to obtain, an entry- to mid-level information security certification such as CompTIA Security+, CySA+, or GSEC within the first six months of employment
- Ability to remain stationary at a workstation for extended periods (typically 6-8 hours per day with regular breaks)
- Regular use of computer, keyboard, mouse, and telephone/headset requiring fine motor skills and repetitive hand/wrist movements
- Visual acuity to view digital screens, documents, and presentations for prolonged periods
- Verbal communication abilities are sufficient for clear articulation during in-person and virtual meetings, presentations, and discussions
- Auditory capabilities to participate effectively in conversations, conference calls, and virtual collaboration sessions
- Cognitive focus for simultaneous management of multiple communication streams, projects, and stakeholder relationships
- Occasional movement between meeting spaces, collaboration areas, and individual workstations
- Minimal lifting requirements (typically under 15 pounds) for office supplies, equipment, or materials
- This position does not require regular travel
Nice to Haves
- Experience with Splunk, including Splunk Enterprise Security (ES), is a plus
- Experience with Proofpoint email security products is a plus
- Familiarity with offensive security concepts is a plus
- Familiarity with Mac Endpoint security is a plus
- Occasional in-person attendance at company events or meetings (typically 0–2 times per year) may be encouraged, but participation is often optional or available virtually
Benefits
- Remote work arrangement.
- VEIC provides ergonomic assessments and appropriate accommodation to support team members, if needed.
- Encouraging regular movement breaks as part of the company's commitment to wellness.
- Flexible work arrangements that promote sustainable productivity.
- Occasional in-person attendance at company events or meetings is often optional or available virtually.