EngineerJobs.io
← Back to all jobs

Job Description

In this onsite role in Asheville, NC, you will manage cybersecurity across CRI’s networks, systems, and data to reduce risk from evolving cyber threats.

Responsibilities

  • Oversee all security matters to protect organizational networks, systems, and data from cyber threats.
  • Partner with the CTO on hardware/software security review and configuration to ensure devices have appropriate security settings.
  • Manage security tools and services including password managers, VPNs, secure communications channels, and secure document sharing systems.
  • Continuously monitor network traffic, system logs, and security alerts for suspicious activity and anomalies.
  • Detect and mitigate attacks before they occur.
  • Run regular vulnerability assessments, penetration testing, and incident response activities to limit security threats and minimize downtime.
  • Establish and maintain disaster recovery plans to support rapid recovery after disruptions or disasters.
  • Review, refine, and implement current security protocols across information, operations, cyber, network, and personnel.
  • Define and implement IT security policies, including access controls, security classifications, data protection protocols, and incident response plans.
  • Set procedures for information storage, access privileges, document sharing protocols, and security for off-premises devices.
  • Conduct compliance audits and prepare documentation for review.
  • Own online and communications op sec for websites and public interfaces connected to the organization, bank, and other accounts.
  • Develop security classification designations for documents, projects, and departments.
  • Train team members on process upkeep and organized maintenance.
  • Work with the Training Unit to create training materials covering the risk landscape, mitigation strategies, and practical security measures; assist with security configurations.
  • Manage and protect CRI’s online presence and reputation, including IP address security, uploading memos and videos, and troubleshooting.
  • Proactively respond to and protect against hacking and phishing attempts.
  • Configure existing technology and/or build in-house analytics tools for tracking related activity.
  • Handle technical elements of online reputation management; others manage outreach, content, and legal responses.
  • Recommend best-fit providers for VPNs, firewalls, secure WiFi configurations, transcription services, alternative communications systems (Signal, iMessage, Slack, Zoom, Gmail, and a proprietary in-house end-to-end encryption platform), and VoIP.
  • Define security and functionality configurations for the software and hardware used across these services.
  • Select and manage relationships with online security service providers (e.g., MalwareBytes, Norton, DeleteMe).
  • Stay current with latest cyber threats, vulnerabilities, and security trends.
  • Acquire and set up physical infrastructure and hardware including home security systems, routers, modems, extenders, Starlinks, battery backup systems, hard drives, monitors, printers, USBs, and related equipment.
  • Set protocols for connecting to WiFi networks and printers, managing camera/microphone on-off behavior, sharing addresses, and related operational security.
  • Oversee quarterly housekeeping such as bug sweeps and penetration tests.
  • Perform due diligence on potential vendors/contractors, decide which contractors to engage, coordinate with them, and ensure successful delivery.

Requirements

  • Degree in computer science, IT, systems engineering, or a related qualification.
  • 4 years of work experience with incident detection, incident response, and forensics.
  • Experience with Firewalls (functionality and maintenance), Office 365 Security, VSX, and Endpoint Security.
  • Proficiency in Python, C++, Java, Ruby, Node, Go, and/or Power Shell.
  • Ability to work under pressure in a fast-paced environment.
  • Strong attention to detail with an analytical mind and outstanding problem-solving skills.
  • Great awareness of cybersecurity trends and hacking techniques.

Technologies

  • Python, C++, Java, Ruby, Node, Go, Power Shell
  • Firewalls, Office 365 Security, VSX, Endpoint Security
  • Signal, iMessage, Slack, Zoom, Gmail, proprietary in-house end-to-end encryption platform
  • VoIP
  • MalwareBytes, Norton, DeleteMe
  • VPNs, Starlinks

Benefits

  • Mission-Driven Culture
  • Health & Wellness Support
  • Professional Growth & Development
  • Competitive Compensation
  • Flexible Benefits
  • Relocation assistance
  • Community events such as team dinners and hikes
  • Coffee/tea station with a variety of tinctures and powders and a fully stocked pantry of healthy snacks
  • Organic, plant-based lunches and dinners prepared by an in-house chef multiple times per week
  • Specialized healing equipment open to all employees (e.g., sauna, red light therapy, AI deep tissue massage machine)
  • Bring your dog to work

Location and Reporting

  • Full-time, on-site role based in Asheville, NC.
  • May consider strong candidates who would work remotely with the ability to travel to HQ as needed.
  • Reports to the Chief Technology Officer.

Pay

  • From $140,000.00 per year

Work location: In person

Similar Jobs