Sr. Information Security Engineer
Cyber Security Engineer
When you work at Battelle, you are plugged into a powerful network of people who are solving the world's energy concerns, our national security, and the health of our nation. Since 1929, Battelle has been delivering innovative products and solutions and is an important social partner in building tomorrow's technology workforce by investing millions annually in science education and community service. Are you ready to Fast Forward Your Future?
Our Corporate Information Technology (CIT) Team is currently seeking a Senior Cyber Security Professional. This position is located in Columbus, OH.
Responsibilities:
This senior security professional is a general operational security practitioner, who will also hold primary responsibility for running and maintaining the vulnerability and patch management program, including: communication, status tracking, metrics generation and reporting. Metrics and status reporting are critical in reducing risk and exhibiting maturity in the VA program.
This position will contribute to the translation of Battelle's CyberSecurity strategic direction into practice, providing security solutions that meet the needs of the business while conforming to regulatory obligations, Battelle's security policy, and the Chief Information Officer's vision, goals and direction.
The successful candidate will act as an advisor to security resources assigned to all large CIT projects and will participate in enterprise cross functional teams (both business and technical) and internal department initiatives.
Vulnerability Management:
· Maintains an inventory of systems and applications in the environment.
· Monitors for vulnerability announcements and emerging threats related to the in-scope assets.
· Collaborates with cross-functional partners to create and documents remediation plans, escalates challenges, and tracks exceptions.
· Risk ranks security vulnerabilities based on risk, threats, and existing countermeasures.
· Coordinates testing of patches and countermeasures.
· Coordinates and track implementation, prioritized by risk.
· Validates successful remediation of vulnerabilities.
· Tracks and reports on remediation, based on risk and SLA's
Consults on security requirements for CIT projects, including writing requirements and overseeing the security project lifecycle.
Researches, evaluates, and stays current on emerging security tools, trends, policies, best practices, techniques, and technologies.
Oversee the creation and maintenance of information security policies, lead security risk assessment efforts, and own the awareness and training programs for the company.
Actively participates with 3rd party vendor and customers to review/assess recommended solutions, identifying any incompatibilities, challenges, or issues with proposed solutions; work with appropriate individuals and team(s) to resolve issue within time, cost, and quality constraints.
A successful candidate will be able to manage multiple simultaneous projects and tasks that involve different team members.
Requirements:
Fluent in network technologies (TCP/IP, routers, switches, load balancers) and the design and function of security devices such as SEIM, firewalls, endpoint protection (AV, encryption, HIPS), spam filters, vulnerability scanning tools, and network packet analyzers.
Broad knowledge of operating systems (Windows, UNIX, Linux), including hardening and testing of systems for deployment.
Understanding of security vulnerability management methodologies, remediation planning and prioritization. Experience with multiple vulnerability assessment tools is a plus.
Experience performing security assessments of third party products and solutions, and the ability to conduct ROI and gap analysis for potential and existing products.
The position requires exceptional written and verbal communication skills for interactions at all levels across the organization.
Minimum of a Bachelors of Science degree is required with a minimum of 10 Years of IT experience and five years of security experience across multiple domains (incident management, operations, software development processes, etc).
Certifications such as CISSP or SANS GSEC are desirable.