Colony Brands, Inc. is hiring an IT Security Engineer to advance and execute its information security program, policies, and regulatory compliance efforts. This onsite role in Monroe, WI focuses on defining and maintaining security controls, monitoring compliance, and supporting incident response in coordination with internal teams and a managed service SOC.
The ideal candidate brings a broad foundation in information security and IT auditing, along with practical experience using security tooling such as EDR, SIEM, vulnerability scanners, logging software, and identity controls. In this position, you will also help evaluate risk, recommend mitigation solutions, and partner on new systems and processes to keep security configurations operating as intended.
Responsibilities
- Develop and implement a comprehensive information security program.
- Select and deploy technical controls to meet security requirements, and define processes and standards to ensure security configurations are maintained.
- Define and promote information security policies, processes, and standards, including designing technologies in a secure manner and monitoring compliance against company policies and applicable law(s).
- Investigate and report security violations and incidents, and advise on information security issues to confirm internal controls are appropriate and operating as intended.
- Analyze information and processes to balance normal vulnerability levels with investment, personnel, and end-user capabilities.
- Serve as a subject matter expert to the business and provide security guidance.
- Partner with project teams to facilitate and implement new systems, policies, and processes.
- Coordinate with the managed service SOC to support centralized logging and help identify security incidents and misconfigured security controls.
- Coordinate and conduct responses to information security incidents, including the ability to begin forensic investigation as part of the incident response process.
- Prepare documentation, business notifications, and security alerts.
- Interact daily with employees regarding security alerts from EDR, SIEM, phishing identification tools, and general service tickets.
- Research, recommend, and develop security and risk mitigation solutions.
Requirements
- Bachelor’s degree in MIS, Computer Sciences, Information Technology or related discipline.
- 3+ years’ related business experience.
- A broad and in-depth understanding of information security and information technology auditing.
- Commitment to continuous improvement and knowledge growth, including staying current with security technologies.
- Documented ability to utilize security systems including vulnerability scanners, logging software, Multi Factor Authentication, SAML Federation, and experience with patch management processes.
- Experience with diverse desktop and server environments, networking, and operational security technologies both on premise and in the Cloud, with AWS preferred.
- Solid written and verbal communication skills across comprehension levels; experience driving Security Awareness programs is desired.
- CISSP Certification is preferred.
- Experience working with small to mid-size companies is helpful.
- PCI, SOC1, Audit &/or HIPPA experience is a plus.
Technologies
- EDR (Endpoint Detection & Response)
- SIEM (Security Incident & Event Management)
- Phishing identification tools
- Vulnerability scanners
- Logging software
- Multi Factor Authentication
- SAML Federation
- Patch management processes
- AWS
- Forensic investigation
Benefits
- Medical/Dental/Vision insurance
- A robust Wellness Program including Onsite Healthcare
- Superb Retirement Plans (401K & a company-funded Pension Plan)
- Extensive Paid Time Off (PTO) benefits
- Seven 4-day work weeks in the summer months to provide additional time off
- Educational Assistance
- Company Profit-Sharing
- Company Product Discounts
Location: Monroe, WI (onsite)
Experience: 3+ years
Employment Type: Regular/Full-Time
Visa Sponsorship: Not eligible for Visa Sponsorship
Job Category: IT