Information Systems Security Engineer

Nystec Rome , NY 13441

Posted 3 weeks ago

About Us:

NYSTEC is a nonprofit technology consulting company, advising agencies, organizations, institutions, and businesses since 1996. Were independent and vendor-neutral, so we have our clients best interests at heart. At NYSTEC, we know that we succeed when individuals and teams flourish personally and professionally, so our benefits and perks support that mindset.

About the Role:

The information systems security engineer assists the deputy chief information security officer (CISO) with the development and support of NYSTEC's information security initiatives. This position will interface with staff and management across all levels of NYSTEC, as well as with external business partners, to ensure that NYSTEC's critical business functions and systems are secure and in accordance with best practices. The information systems security engineer will execute all information security functions for the company to mitigate risk and to balance enhanced capacity and productivity.

Key Responsibilities

  • Ensure security configuration compliance on requirements, including but not limited to Health Insurance Portability and Accountability Act/Health Information Trust Alliance (HIPAA/HiTrust), National Institute of Standards and Technology (NIST) Cybersecurity Framework, and state and federal regulations.

  • Administer security toolsets and assist external security vendors and the NYSTEC technical systems team (Service Delivery and Internal Services) in defining the scope of internal and external vulnerability scans and penetration tests.

  • Develop and deliver security awareness training for the organization.

  • Lead the creation and review of enterprise security documents, policies, standards, guidelines, and procedures.

  • Ensure the confidentiality, integrity, and availability of the data residing on or transmitted through the organizations systems, applications, databases, and any other data repositories.

  • Collaborate with the technical services team and cross-functional departments to remediate security risks.

  • Provide recommendations for additional security solutions or enhancements to improve the overall security and defense-in-depth strategy.

  • Assist in the deployment, integration, and initial configuration of all new security solutions and any enhancements to security solutions in accordance with established best practices and standards.

  • Research, develop, implement, test, and review the organizations information security to protect information and to prevent unauthorized access.

About you:

Required Qualifications

  • Proficient in Windows operating environment using Microsoft Office applications, email, and internet programs.

  • Experienced information security professional skilled in developing, documenting, and driving the adoption of information security standards and procedures.

  • Strong background with firewall products, intrusion detection systems, demilitarized zone (DMZ), Internet Protocol Security (IPSec), Domain Name System (DNS), Simple Mail Transfer Protocol (SMTP), Hypertext Transfer Protocol (HTTP) proxies, etc.

  • Willing to maintain up-to-date knowledge of the information technology (IT) security industry, including awareness of new or revised security solutions, improved security processes, and the development of new attacks or threat outbreaks. This should include the continuation of education and certifications to maintain compliance with regulatory requirements and guidelines.

  • Good organizational skills to maintain documentation and to gather evidence for reporting and incident analysis.

  • Knowledge of security best practices across multiple platforms, such as Microsoft Windows, Microsoft Office365, and Azure.

  • Strong project management skills.

  • Strong written and verbal communication skills, time-management skills, and task prioritization skills.

  • Experienced in zero trust technologies, least privileges, network architectures, and segmentation.

  • Understands NYSTECs mission, brand mindsets, and core values and can put the behaviors into practice.

Preferred/Desired Qualifications

  • Certified information systems security professional (CISSP) or similar certification in information security preferred.

Education and Experience

  • A bachelor's degree, preferably in cybersecurity or a similar discipline, and five years of experience with security management frameworks (e.g., National Institute of Standards and Technology [NIST], SysAdmin, Audit, and Network and Security [SANS]). An equivalent combination of advanced education, training, and experience will be considered.

The pay range for this position is $79,793.00 to $109,716.20.

It is NYSTEC's policy to provide equal employment opportunity (EEO) to all individuals, regardless of actual or perceived race, color, creed, religion, sex, or gender (including pregnancy, childbirth, and related medical conditions), gender identity or gender expression (including transgender status), age, national origin, ancestry, citizenship status, physical or mental disability, protected medical condition as defined by applicable state or local law, genetic information, military service and veteran status, sexual orientation, marital status, or any other characteristic protected by local, state, or federal laws and ordinances. NYSTEC is strongly committed to this policy and believes in the concept and spirit of the law.

Federal law requires employers to provide reasonable accommodation to qualified individuals with disabilities. Please contact


icon no score

See how you match
to the job

Find your dream job anywhere
with the LiveCareer app.
Mobile App Icon
Download the
LiveCareer app and find
your dream job anywhere
App Store Icon Google Play Icon
lc_ad

Boost your job search productivity with our
free Chrome Extension!

lc_apply_tool GET EXTENSION

Similar Jobs

Want to see jobs matched to your resume? Upload One Now! Remove
Information Systems Security Engineer (Isse)
New!

Cyber Defense Technologies

Posted Today

VIEW JOBS 6/26/2024 12:00:00 AM 2024-09-24T00:00 Overview:  Cyber Defense Technologies (CDT) is seeking a highly skilled and motivated Information Systems Security Engineer (ISSE) onsite in Chantilly, Cyber Defense Technologies Chantilly Virginia

Information Systems Security Engineer

Nystec