Overview
Security Operations Engineer Jobs in Tucson, AZ at Winsor Consulting Group, LLC
Title: Security Operations Engineer
Company: Winsor Consulting Group, LLC
Location: Tucson, AZ
Department: Security & Compliance
Reports to: Security Director
About Us
Winsor Consulting Group is a leading Managed Service Provider (MSP) committed to delivering exceptional IT solutions to our clients. We are seeking a talented and driven Cybersecurity Engineer to join our team.
Job Description
As a Cybersecurity Engineer at Winsor Consulting, you will play a critical role in protecting Winsor and our clients' sensitive data and systems. You will be responsible for designing, implementing, and maintaining robust security solutions to mitigate cyber threats. Additionally, there will be responsibilities to assist Winsor clients to ensure their environments are aligned with CMMC requirements.
The goal of this member is to strengthen the Cyber Security posture and overall security programs of Winsor and its client(s).
Job Duties:
- Assess security capabilities, while leveraging available security functionality and tools
- Lead efforts to manage monitoring and incident response
- Participating with clients in the strategic design process to translate business requirements into secure technical designs
- Working knowledge and/or experience managing SIEMs, the configuration of their log sources, investigating logs generated by these sources, and assisting in remediation of alarms generated by SIEM platform
- Root cause analysis for all false positives and legitimate threats
- Act as liaison between client and Winsor during security incidents
- Management of Information Security Risk Platform, including remediation tracking and regular progress reporting
- Maintenance of information security policy documents including annual review and regular upkeep
- Management of security tool sets within the environment, including:
- Endpoint/Server Antivirus, Antiransomware, and EDR
- Comanaged threat detection and response platform
- Continuous vulnerability management platform
- Application Whitelisting platform
- Lead the strategy and execution of events, incident response and postmortem analysis in partnership with legal, internal audit and other partners
Preferred Skills:
- Strong understanding of cybersecurity principles and best practices
- Experience with network security, endpoint protection, and data loss prevention
- Knowledge of networking monitoring tools and protocols
- Strong understanding of IP networking including DNS, messaging, and routing
- Proficiency in security tools and technologies
- Configuration and management of various Security Technologies (UTM Firewalls/AntiMalware/MFA/VPN/DLP)
- Configuration/administration of routers and switches
- Knowledge and configuration of datasearching platforms such as OpenSearch or Elastic
- Excellent problemsolving and analytical skills
- Strong communication and interpersonal skills
Experience:
- Two or more years of cyber security experience, preferably including experience working with or as part of a Managed Security Services Provider (MSSP)
- Taskoriented, selfstarter attitude
- Previous experience with the following tool types: o Endpoint Antivirus
- Vulnerability scanners oTicketing Platforms
- Security Information & Event Manager (SIEM) oIncident Response
- 2+ years of experience as a practitioner and management with information security governance, including organizational structure/concepts/controls, audits, information technology security/risk/risk frameworks, information technology governance, internal and external audit, and compliance functions
- Experience with the controls and concepts within the NIST Cyber Security Framework
- Experience in developing and maintaining policies, procedures, standards, and guidelines
- Experience in driving riskbased decisions supporting business owner expectations and needs
Education: EXAMPLE
- High school diploma or equivalent required.
- Associate degree in Cybersecurity, Information Technology, Computer Science, or related field preferred.
- Relevant professional certifications such as CISSP, CISM, Security+, and CMMC Registered Practitioner (RP) are highly preferred.