Jobs and Careers
DU

Sr. Security Engineer

Duluth Trading Company
United States, United Statesfull_timeVerifiedPosted 2 Dec 2024
💰 $115,000/yr($90,000/yr$115,000/yr)

About the role

Position Overview

 

The Sr. Security Engineer is responsible for designing, implementing, and maintaining the organization's information security infrastructure to ensure data confidentiality, integrity, and availability. This role provides advanced security expertise to reduce enterprise risk and articulates technical security requirements. The engineer monitors the effectiveness of IT security controls, raises security awareness among employees, and ensures compliance with industry regulations such as PCI, NIST, and Sarbanes-Oxley, safeguarding our retail operations across all digital platforms. You will be responsible for designing, implementing, and maintaining security solutions to protect against cyber threats and vulnerabilities. This is a hands-on role that requires a strong technical background and a passion for cybersecurity.

Position Details

Work Environment:

We are headquartered in the Madison, WI area, but this job may be performed remotely within the United States. If you happen to live near and enjoy coming into the office, we will welcome you too!

 

What You’ll Do: 

 

Security Architecture & Engineering - Lead the design, implementation, and maintenance of security solutionsacross various IT domains, including:

  • Deploy and manage endpoint protection and response (EDR) utilizing Microsoft Enterprise Mobility andSecurity, Defender for Enterprise, antivirus software, and other endpoint security tools
  • Network Security: Assist with the security configuration and maintenance of firewalls, intrusiondetection/prevention systems (IDS/IPS), and other security-based infrastructure.
  • SIEM systems, DNS security, IPS, HIDS, behavioral analysis, FIM, and other security solutions
  • Cloud Security: Support the implementation and management of security controls in cloud environments(Azure and GCP), including identity and access management (IAM), data loss prevention (DLP), securityinformation and event management (SIEM), conditional access rules, DLP, and threat detection toolset - Security tools and technologies.

Security Operations & Monitoring: 

  • Manage and maintain existing security tools such as antivirus, malware protection, vulnerability scanners, and cloud-based platforms --
  • Monitor the effectiveness of IT security controls, ensuring appropriate levels of data confidentiality, integrity, and availability. --
  • Utilize SIEM and behavioral analysis tools to monitor network activities for potential threats. --
  • Respond to security incidents, conduct root cause analysis, and implement measures to prevent recurrence. --
  • Contribute to the continuous improvement of security monitoring and incident response processes. -- Implement Data Loss Prevention (DLP) strategies and oversee backup and disaster recovery plans.

Policy Development and Compliance: 

  • Lead the development and maintenance of security documentation, including policies, standards, procedures, incident response plans. 
  • Raise security awareness among employees and ensure policy compliance. 
  • Ensure policies align with business objectives and regulatory requirements like PCI-DSS, NIST, and Sarbanes-Oxley.

 

Identity and Access Management: 

  • Manage IAM systems and implement least privilege access controls. 
  • Utilize tooling such as Google GAM, powershell scripting, and Microsoft Entra for efficient user access management and auditing.

 

Threat Intelligence and Vulnerability Management: 

  • Stay abreast of the latest security threats, vulnerabilities, and attack techniques by monitoring threat intelligence feeds, security advisories, and industry publications. 
  • Proactively identify and assess vulnerabilities in our systems and applications through regular vulnerability scans, penetration testing, and code reviews. 
  • Coordinate and collaborate with third-party security vendors to conduct penetration testing and vulnerability assessments.
  • Develop and maintain comprehensive threat models to identify potential attack vectors and prioritize security controls.

 

Collaboration and Training:

  • Work with IT and development teams to integrate security into all projects. 
  • Provide guidance to IT team members and conduct security awareness training.

 

 

What We’re Looking For:

  • Bachelor's Degree in Computer Science, Information Security or related Equivalent work experience will be considered.
  • CISSP - Certified Information Systems Security Professional
  • CISM - Certified Information Security Manager
  • CEH - Certified Ethical Hacker
  • GIAC - Global Information Assurance Certi

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Duluth Trading Company

View company profile →