Security Engineer

3 weeks ago


New York, United States Yoh, A Day & Zimmermann Company Full time

*NO C2C * NO CONTRACT * NO C2C * NO CONTRACT*


HYBRID REMOTE - 2 days per week onsite.


Cloud/DevOps Security Engineer



You Will:

  • Design, implement, operationalize, and maintain cutting-edge Cloud, Pipeline and Application security technologies on-premises and in the Cloud.
  • Perform risk and compliance self-assessments; identify, document, and remediate risks associated with defects in the current implementation or limitations of the above security controls.
  • Conduct vendor and product feature assessments and proof of concepts to help us maintain the best-in-class cyber security technology portfolio. Partner with other technology teams to define and implement our cyber security strategy.
  • Design and operationalize, through code development, the automated workflows for response to operational issues and for deployment of configuration changes.
  • Partner with other technology teams to enhance the CI/CD Pipeline with additional security controls and to broaden the self-service capabilities of our Cloud environment.
  • Resolve escalated service issues and coach other engineers on troubleshooting efforts.
  • Partner with other technology teams in handling and responding to internal customer issues, conducting problem analysis, providing solutions for service level improvements, and ensuring timely remediation of security issues in accordance with corporate policies and standards.
  • Provide advisory consulting services on the topics of cloud, pipeline and application security to the leadership, partner teams, internal customers; work with Company suppliers on product enhancements.
  • Enhance existing and develop new processes, procedures, and baselines with respect to cyber security and the use and operation of information systems.
  • Support internal and external audit and compliance reviews, lead the team on gathering requirements and evidence, and provide timely responses.
  • Drive initiatives to grow the cyber security mindset and best practices across the Company, with an emphasis on gaining measurable results


Required Skills:

  • Intellectual curiosity and proven record of spotting anomalies and inconsistencies and identifying creative solutions to resolve security control deficiencies and to optimize performance.
  • Strong analytical, critical thinking, and problem-solving skills, to assess the level of risk and potential impact of sub-optimal implementation of security controls to mitigate new cyber threats and reduce attack surfaces to the enterprise.
  • Understanding of configuration best practices and performance baselines.
  • 5+ years of experience with implementing and operating Cloud Security controls in the domains of Network, Endpoint, Data, and Identity Security.
  • Knowledge of CI/CD pipeline components and the integrations with the various security controls; knowledge of GIT.
  • Working knowledge of Python, Terraform, programming and operating of Jenkins.
  • Proven ability to interpret and correlate the data produced by various event sources -- network security devices, operating systems, web servers, Public Cloud IaaS, endpoint security agents, etc.
  • Familiarity with TCP/IP protocol stack, including routing, network address translation, TCP/UDP connectivity, application-level protocols (HTTP, SMTP, DNS, etc.)
  • Ability to further develop DevSecOps skillset to implement various security controls, define infrastructure as code, deploy cloud-based security services.
  • Working knowledge of using an enterprise-grade SIEM to build dashboards, alerts, and reports.
  • Strong communication and documentation skills; ability to develop reference documentation, network diagrams, standard operating procedures, process workflow and decision tree diagrams.
  • Excellent organizational skills. You are detail-oriented and have an ability to manage and follow up on multiple competing priorities effectively.
  • Customer-focused demeanor; excellent interpersonal skills and a sense of humor.
  • Bachelor’s degree in information technology or any STEM discipline; master’s degree is preferred.


Nice to have

  • Developer-level knowledge of some of the following technologies: Puppet, Ansible, Splunk Phantom, Active Directory Group Policy.
  • Experience with consuming vendor APIs.
  • Knowledge of Microsoft Windows PowerShell.
  • Recognized Security Industry and Public Cloud IaaS certifications (AWS, Azure, GCP).
  • Familiarity with security industry standards and best practices (NIST 800-53, ISO27001, NIST CSF, HITRUST, NYDFS-Cybersecurity, HIPAA, FedRAMP, OWASP, etc.)
  • Familiarity with ITIL; experience with incident, problem, change, and risk management.


Location:

  • 2 days a week at our offices in Holmdel, NJ, Bethlehem, PA, Stamford CT and New York, NY


  • Security Engineer

    2 days ago


    New York, United States CACI International Full time

    CACI is seeking a Cyber Security Engineer to support our Makalu contract. If you are interested and passionate about working as part of a modern, fast-paced agile software development team, then this opportunity is for you! On team Makalu, cyber security engineers are an integral part of the development team. Cyber security engineers are expected to be...

  • Security Engineer

    1 week ago


    New York, United States Nationstaff Full time

    About This Role We are seeking a highly capable Security Engineer / Senior Security Engineer, who will be responsible for various technical and cryptographic security aspects. This role requires a certain range of experience and an in-depth understanding of security engineering facets. Primary ResponsibilitiesPerform security analysis/audits/reviews/testing,...

  • Security Engineer

    3 weeks ago


    New York, United States Nationstaff Full time

    About This Role We are seeking a highly capable Security Engineer / Senior Security Engineer, who will be responsible for various technical and cryptographic security aspects. This role requires a certain range of experience and an in-depth understanding of security engineering facets. Primary ResponsibilitiesPerform security analysis/audits/reviews/testing,...


  • New York, United States NYC Health Hospitals Full time

    MetroPlusHealth provides the highest quality healthcare services to residents of Bronx, Brooklyn, Manhattan, Queens and Staten Island through a comprehensive list of products, including, but not limited to, New York State Medicaid Managed Care, Medicare, Child Health Plus, Exchange, Partnership in Care, MetroPlus Gold, Essential Plan, etc. As a wholly-owned...

  • IT Security Engineer

    13 hours ago


    New York, United States NYC Health Hospitals Full time

    MetroPlusHealth provides the highest quality healthcare services to residents of Bronx, Brooklyn, Manhattan, Queens and Staten Island through a comprehensive list of products, including, but not limited to, New York State Medicaid Managed Care, Medicare, Child Health Plus, Exchange, Partnership in Care, MetroPlus Gold, Essential Plan, etc. As a wholly-owned...


  • New York, United States OPT Nation Full time

    In this role you will work closely with development teams across platform engineering to ensure our applications are secure. We are looking for a skilled application security engineer to analyze software designs and implementations from a security perspective and identify and resolve security issues. You will perform security analysis and implement controls...


  • New York, New York, United States OPT Nation Full time

    In this role you will work closely with development teams across platform engineering to ensure our applications are secure. We are looking for a skilled application security engineer to analyze software designs and implementations from a security perspective and identify and resolve security issues. You will perform security analysis and implement controls...

  • Security Engineer

    5 days ago


    New York, United States Infojini Full time

    •Develop security configurations. •Establish security best practices as well as review all vendor designs ensuring compliance with security standards and governance models. •Provide expertise in integration and engineering of Security platforms. •Manage test cases and identify risks associated with system integrations •Work with vendors to...

  • Software Engineer

    1 week ago


    New York, United States Opal Security Full time

    Opal is building the next generation of access management. We've all felt the pain of not getting the access we need to do our job. At Opal, we’re building a central hub for authorization to make access management automated, intelligent, and easy to use. We are taking an age old problem in enterprise software and making it simple. Our product prioritizes...

  • Security Engineer

    3 weeks ago


    New York, United States The Rockridge Group Full time

    Job DescriptionJob DescriptionJob Title: Security EngineerLocation: 100% RemoteDuration: 6 months Contract To Hire About the Position Company X is seeking an exceptional Security Engineer to join its IT Security Team in our New York office. This person will join a distributed, highly collaborative team that is responsible for the setup and maintenance of...


  • New York, United States Abnormal Security Full time

    Job DescriptionJob DescriptionAbout the RoleAbnormal Security is looking for an ambitious and growth-minded Senior Product Manager to drive innovation for our flagship Messaging Security Products (MSP) product lines.At Abnormal, we keep our customers—ranging from Global 2000 organizations to small businesses—safe from complex and cutting edge attacks...

  • Security Engineer

    1 week ago


    New York, United States TSR Consulting Full time

    About TSR: TSR is a relationship-based, customer-focused IT and technical services staffing company. For over 40 years TSR, Inc. and its wholly owned subsidiary, TSR Consulting Services, have prospered in the Information Technology staffing business, earning the respect of companies both large and small with well refined candidate screening, timely...


  • New York, United States Glocomms Full time

    Glocomms is partnered with an industry-leading media platform seeking to bring on a talented and experienced Senior Security Engineer to join its growing Payments technology team. The ideal candidate will have a Bachelor's or Master's degree in Computer Science, Information Security, or a related field, along with 5-7 years of proven experience in a security...

  • Security Engineer, XRM

    13 hours ago


    New York, United States META Full time

    The Meta Security team is responsible for improving the security posture of the software and services used throughout our company. Our work spans Facebook, Instagram, WhatsApp, Oculus, and all of the underlying systems and infrastructure that power these products behind the scenes. We are seeking a passionate and experienced security engineer to help design...


  • New York, United States Assured Guaranty Full time

    Position Summary The goal of information security is to protect the confidentiality, integrity, and availability of information assets. The information security team is responsible for defining and implementing security policy and standards and continuously monitoring for new threats. The Cloud Security Engineer is a hands-on technical role, responsible for...


  • New York, United States SoHo Dragon Full time

    Job DescriptionJob DescriptionSalary: SoHo Dragon represents a large non-profit client that needs to hire a Security Operations Engineer. This role is 100% remote.Description:As a Security Operations Engineer you will be responsible for maintaining and enhancing the security posture of our digital environment with a focus on Microsoft technologies. You will...


  • New York, United States Zolon Tech Full time

    Job Title: Security Engineer (Palo Alto) Location: Primarily remote (Must be available to visit Data Centers in Richmond VA and Ashburn VA as needed) Duration: 12 Months contract to Hire Our client, a major Healthcare Insurance Organization is looking for a Security Engineer with specific expertise in Palo Alto Firewalls. Roles and Responsibilities: Design,...


  • New York, United States Cogent Infotech Corp Full time

    Cogent Infotech is seeking a senior security engineer on behalf of our client, an innovative technology company in NYC. This is a 1-year contract that can be extended for multiple years or be converted into a permanent position. This position requires the successful candidate to work on-site in Brooklyn 5-days per week. Qualified candidates are encouraged to...


  • New York, United States Hex Technologies Inc Full time

    === Excerpt: Design and implement scalable security infrastructure and help build a culture of security for a rapidly growing team. Status: Open === About the role Don’t you wish the security practice at your company was more modern, effective and not chasing its tail? Are you excited by the idea of tackling novel security problems while empowering a...


  • New York, United States RIT Solutions, Inc. Full time

    Cloud Security Engineer/ (AWS/ Terraform/Palo Alto a +) NYC/ Hybrid 1 Year+ Must Have LinkedIn MANAGER WANTS SEE SENIOR (12+ YEARS preferred) CANDIDATES THAT ARE AWS CLOUD SECURITY ENGINEERS WITH AWS AND TERRAFOM. This will move fast and be a hire this week. The manager said he needs great experience with AWS, Ansible and Terraform. They want a minimum of 10...