Jobs and Careers
PI

IS Security Engineer

Pinnacol Assurance
United Statesfull_timeVerifiedPosted 11 Feb 2025
💰 $142,400/yr($131,700/yr$142,400/yr)

About the role

 

GENERAL PURPOSE:

To serve as a Cybersecurity subject matter expert for Pinnacol Assurance. Ensure the secure operation of the company’s computer systems, servers, and network connections.

ESSENTIAL DUTIES / RESPONSIBILITIES:

  • Work as a team to implement security frameworks (NIST, CIS, NYDFS, PCI-DSS) to establish a robust, layered defense-in-depth cybersecurity posture.
  • Manage and continuously improve vulnerability assessment and remediation systems. This includes identifying, assessing, prioritizing, and remediating vulnerabilities across all systems and applications.
  • Secure cloud environments by configuring cloud security controls, managing cloud resources, and utilizing security tools to mitigate vulnerabilities.
  • Respond to and resolve cybersecurity incidents and breaches, including proactively identifying and investigating potential security events, effectively tracking and analyzing security incidents, implementing countermeasures, and coordinating response activities with internal and external teams while communicating clearly with technical and non-technical audiences.
  • Develop, implement, and manage Data Loss Prevention (DLP) policies and rules across various platforms (e.g., SASE, cloud storage, and email). Investigate data exposure incidents and implement measures to restrict access to sensitive information. Investigate data exposure incidents and restrict access to sensitive information.
  • Implement and manage logging systems, utilizing log aggregation systems for security event monitoring, log analysis, and incident investigations to detect anomalous or suspect activities and potential breaches.
  • Implement systems and policies that limit access and protect data according to the principle of least privilege. Utilize authentication and authorization technologies, including SSO and federated identity, to ensure streamlined user provisioning and de-provisioning.
  • Proactively maintain and administer critical systems and infrastructure components, including operating system and application patching, performance monitoring, troubleshooting, and vendor coordination. Maintain comprehensive system documentation.
  • Manage Secure Access Service Edge (SASE) solutions, including configuration and management of cloud security policies, DLP rules, and access controls. Implement zero-trust principles and leverage Cloud Access Security Broker (CASB) functionality.
  • Develop scripting (Python/Shell) for automating tasks, integrating with security tools, and developing custom solutions.

MINIMUM QUALIFICATIONS:

  • A bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field is preferred. Equivalent work experience in a related field will be considered instead of a degree. Continuous learning and professional development are encouraged and supported.
  • Seven years of combined experience in IT, with at least two years focused specifically on cybersecurity and five years in system administration, network engineering, or software development.
  • One or more of the following certifications is preferred:
    • Certified Information Systems Security Professional (CISSP)
    • SANS/GIAC certifications (e.g., GSEC, GCIA, GCIH)
    • Certified Information Security Manager (CISM)

INTERPERSONAL SKILLS:

  • Collaboration and Teamwork: Effectively collaborate with teams across departments to implement security controls.
  • Communication: Convey technical information to both technical and non-technical audiences. Explain security risks to stakeholders, provide clear documentation, and justify security recommendations.
  • Problem-Solving and Decision-Making: Identify the root causes of complex security challenges. Evaluate options and make sound decisions, particularly in time-sensitive situations like security incidents.
  • Adaptability and Continuous Learning: Stay current with the evolving cybersecurity landscape. Adapt to new threats, technologies, and regulations.
  • Teamwork: Work effectively in a group. Contribute to the team's success by communicating well, collaborating, and being accountable.

COMPETENCIES: 

  • Initiative - Dealing with situations and issues proactively and persistently, seizing opportunities that arise
  • Legislation, policies, procedures, and standards - Understanding and using relevant legislation, policies, procedures, and/or standards in performing one's work.
  • Leading and managing change - Supporting, implementing, and initiating change while helping others deal with the transition.
  • Interactive communication  - Listening to others and communicating articulately, fostering open

Apply for this role

Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.

Apply Now →Generate Application Kit

Free account required — sign up in 30s

Company

Pinnacol Assurance

View company profile →