Habemco · 1 week ago
Cybersecurity Engineer III
Habemco is a shared services company owned by the Habematolel Pomo of Upper Lake, a federally recognized Native American tribe. The Cybersecurity Engineer III will implement security systems to enhance the organization's ability to identify, detect, respond to, and recover from cyber threats and vulnerabilities, while ensuring compliance with security standards and guidelines.
CommunitiesSocialSocial Impact
Responsibilities
Responsible for ensuring the security of the organization's systems and information assets
Develops and implements security systems, guidelines, and strategies
Protects against unauthorized access, use, disclosure, disruption, modification, and/or destruction
Conducts audits and risk assessments
Evaluates internal operations and controls and makes recommendations based on the findings
Migrates non-compliant environments to compliant environments
Ensures compliance with data protection guidelines and applicable laws
Develops security measures to safeguard existing infrastructure based on risk assessment threat modeling and supports the integration of new security solutions
Creates action plans for system hardening, monitoring, incident response, and disaster recovery
Manages vulnerability discovery platforms in cloud architecture environments, CI/CD pipelines, Static Application Security Testing (SAST), Windows & Linux operating systems, software applications
Monitors, analyzes, and configures security systems to detect, respond to, and recover from cyber threats and vulnerabilities
Implements and tunes security tools such as SIEM, DLP, and IPS to monitor logs, alerts, and detect suspicious activity
Stays informed about emerging cyber threats and update monitoring processes accordingly
Collaborates with teams to incorporate security controls into operational systems to maintain a secure environment
Supports efforts to detect, mitigate, and respond to malicious activities within the organization's network and systems
Educates and trains staff on information system security best practices
Regular, reliable attendance during normal business hours
In-person attendance and travel as requested
Other duties as assigned
Qualification
Required
Bachelor of Science degree from an accredited university with a major in Cybersecurity, Computer Science, or another technical field or in lieu of education, four (4) or more years of experience working as a Cybersecurity Analyst or related position
Four (4) or more years of direct work experience demonstrating one or more of the following competencies: Access control, cloud security, computer information security
Four (4) or more years of experience working as a Cybersecurity Engineer or related position
Three (3) or more cybersecurity certifications
Proven experience managing, operating, monitoring, and maintaining security systems
Detecting, investigating, and responding to security threats
Managing platforms that discover vulnerabilities and recommend mitigating strategies
Applicants for this position must have work authorization that does not now or in the future require sponsorship of a visa for employment authorization in the United States and with Habemco (e.g., H1-B visa, F-1 visa (STEM/OPT), TN visa.)
All offers are contingent upon signing a confidentiality agreement and satisfactory completion of drug screening and background checks
Employer observes federal standards for controlled substances
Preferred
Certified Cloud Security Professional (CCSP)
Certified Information Systems Auditor (CISA)
Certified in Risk and Information Systems Control (CRISC)
Certified Information Privacy Professional (CIPP)
AWS Certified Security - Specialty
CompTIA PenTest+
CompTIA CASP+
GIAC Certified Incident Handler (GCIH)
GIAC Certified Intrusion Analyst Certification (GCIA)
GIAC Security Expert (GSE)
GIAC Certified Detection Analyst (GCDA)
Cisco Certified CyberOps Professional
Microsoft Certified: Information Protection and Compliance Administrator Associate
Microsoft Certified: Identity and Access Administrator Associate
Master of Science degree from an accredited university with a major in Cybersecurity, Computer Science, or another technical field
Benefits
Competitive pay and benefits
Quarterly performance bonuses
401(k) with a 4% match