Security Engineer
Job Description
Hybrid Security role in Wayzata, MN with a strong focus on day-to-day cybersecurity operations and continuous improvement. Trean Corporation offers a full-time position with benefits and a hybrid work model that requires a minimum onsite presence of three days per week at a designated company office location. Salary range: $100,000 - $115,000 per year.
The Security Engineer supports Trean’s cybersecurity operations program by monitoring alerts, investigating incidents, reviewing security requests and tickets, performing risk assessments, and strengthening controls and operational standards over time.
Responsibilities
- Monitor and investigate security alerts and suspicious activity across the enterprise environment.
- Analyze suspected cybersecurity events and perform triage, containment, eradication, and recovery activities.
- Manage cybersecurity incidents through the full incident response lifecycle, including investigation, documentation, escalation, and post-incident review.
- Act as the primary reviewer and analyst for security alerts, security-related requests, security incidents, and risk assessments, ensuring timely investigation, documentation, remediation recommendations, and follow-through.
- Review, analyze, and resolve security-related tickets, requests, and reported security concerns.
- Perform application, vendor, infrastructure, and technology risk assessments and provide recommendations to mitigate identified risks.
- Review security questionnaires, technology implementations, and proposed business or technology changes to identify security risks and control gaps.
- Assess security vulnerabilities, system misconfigurations, and control weaknesses, partnering with stakeholders to drive remediation efforts.
- Research emerging cyber threats and attacker TTPs, then recommend improvements to security controls and defenses.
- Develop and maintain security procedures, response playbooks, technical documentation, and operational standards.
- Identify opportunities to improve cybersecurity processes, incident response workflows, ticket handling procedures, and operational efficiency.
- Recommend and implement enhancements to security controls, monitoring capabilities, and security processes based on lessons learned, risk assessments, and emerging threats.
- Participate in projects and technology initiatives to ensure security requirements and risks are appropriately considered.
- Support evaluation and secure adoption of emerging technologies, including artificial intelligence solutions, within the organization.
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, or a related field, or an equivalent combination of education and experience.
- 2-4 years of experience in cybersecurity, security operations, incident response, or a related information security role.
- Demonstrated experience performing day-to-day security operations, including alert triage, incident investigation, security ticket review, remediation tracking, and resolution of security-related requests.
- Experience supporting or participating in cybersecurity incident response activities, including investigation, containment, eradication, recovery, and documentation.
- Experience conducting or participating in technology, application, vendor, or cybersecurity risk assessments.
- Experience identifying security vulnerabilities and control weaknesses, with recommendations for remediation.
- Knowledge of current cybersecurity threats, attack techniques, defensive security principles, and industry best practices.
- Understanding of information security concepts including identity and access management, endpoint security, vulnerability management, security monitoring, and incident response.
- Strong analytical and problem-solving skills to assess risk, prioritize work, and recommend practical solutions.
- Ability to assess and manage multiple security events, incidents, assessments, and requests in a fast-paced environment.
- Ability to learn new technologies, evaluate security risks, and recommend process and security control improvements.
- Strong written and verbal communication skills, including documenting findings and communicating to technical and non-technical audiences.
- Ability to work independently, exercise sound judgment, and collaborate effectively with cross-functional teams.
- Ability to work in a hybrid environment with a minimum onsite presence of three days per week at a designated company office location.
- Demonstrated integrity, trustworthiness, and the ability to maintain strict confidentiality when handling sensitive company, customer, employee, and cybersecurity-related information.
Preferred Qualifications
- Experience conducting application, vendor, or technology risk assessments.
- Experience supporting security engineering initiatives and implementation of security controls.
- Security certifications such as Security+, CySA+, SSCP, GSEC, GCIH, or equivalent.
- Experience working in a regulated industry such as insurance, financial services, healthcare, or a similar environment.
- Experience identifying opportunities to improve security processes, workflows, and operational effectiveness.
- Exposure to cloud security, identity and access management, artificial intelligence technologies, or security automation.
- Experience reviewing vendor security questionnaires, technology implementations, or application security assessments.
Working Conditions
- Professional office environment.
- Uses standard office equipment; physical demands align with a normal office position with some light lifting.
- Full-time role with benefits.
- Hybrid work model with at least three days per week onsite at a designated company office location.
Additional Information
- This job description is not a contract of employment and represents minimum requirements and major responsibilities, not all responsibilities.
- Trean Corporation may change and update this job description as necessary.
- Employment is “at will,” meaning employment may be terminated by either the employee or the company at any time and for any reason, with or without cause or advance notice.
- Trean will not sponsor applicants for work visas.