Security Engineer - Threat Management and Response
Macy'sAbout the role
Be part of an amazing story.
Macy’s is more than just a store. We’re a story. One that’s captured the hearts and minds of America for more than 160 years. A story about innovations and traditions…about inspiring stores and irresistible products…about the excitement of the Macy’s 4th of July Fireworks, and the wonder of the Thanksgiving Day Parade. We’ve been part of memorable moments and milestones for countless customers and colleagues. Those stories are part of what makes this such a special place to work.
Job Overview
The Security Engineer monitors and investigates normal and escalated security events to assess risk and exposure, performing additional forensic investigations to understand impact and determine mitigation strategies.
What You Will Do
- Respond to security events or incidents, implementing countermeasures to reduce or mitigate further exposure.
- Perform triage on events reported by various detection devices, filtering out false positives and known accepted activities.
- Track and provide daily activity details, assisting in the creation of reports that display trends and overall statistics based on correlated security incidents and event data.
- Create and implement standard operating procedures and processes to streamline investigations, daily monitoring, and analysis research, ensuring all analysts follow consistent guidelines.
- Research and explain technical concepts to both technical and non-technical personnel.
- Identify common network and website attacks, such as SQL injection, cross-site scripting, remote file inclusion, and cookie manipulation.
- Analyze and correlate security events, implementing countermeasures to mitigate intrusion attacks.
- Foster an environment of acceptance and respect that strengthens relationships, and ensures authentic connections with colleagues, customers, and communities.
- In addition to the essential duties mentioned above, other duties may be assigned.
Skills You Will Need
Security Platforms & Tools: Basic understanding of multiple security platforms, including anti-virus, firewalls, proxy servers, intrusion prevention systems (IPS), logging correlation/management, operating systems, protocols, and incident response.
Incident Response & Forensics: Ability to assess, investigate, and respond to security events and incidents, performing forensic investigations to determine impact and recommend mitigation strategies.
Network & Web Security: Knowledge of network and website attacks (e.g., SQL injection, cross-site scripting, remote file inclusion, cookie manipulation) and the ability to identify, analyze, and respond to these threats.
IDS/IPS & Network Forensics: Understanding of IDS/IPS real-time monitoring, analysis, and network forensics for detecting and investigating potential security breaches.
SIEM Technologies: Experience with or basic knowledge of Security Information and Event Management (SIEM) tools for monitoring and analyzing security incidents.
EndPoint Detection: Working knowledge of EndPoint Detection Tools (Malware Protection/EDR) to detect and respond to endpoint security threats.
Intrusion Prevention Systems: Familiarity with intrusion prevention systems (IPS) and other security technologies for mitigating potential attacks.
Event Triage & Analysis: Proficiency in performing triage on security events, filtering out false positives and known accepted activities, and prioritizing security incidents for investigation.
Data Correlation & Reporting: Ability to analyze and correlate security events, track incidents, and provide statistical reports that display trends and key insights on security incidents.
Countermeasure Implementation: Strong skills in implementing effective countermeasures to reduce or mitigate security risks and exposures.
Technical Communication: Strong written and verbal communication skills for explaining technical findings and recommendations to both technical and non-technical personnel.
Documentation & Reporting: Ability to document incidents, security events, and investigative findings in clear, concise reports and create standard operating procedures to ensure consistency across teams.
Security Protocols & Technologies: General knowledge of TCP/IP, HTTP, FTP, cookies, authentication, virus scanning, we
Apply for this role
Generate a tailored application kit with a matched cover letter, interview prep, and CV highlights — in under 60 seconds.
Apply Now →Generate Application KitFree account required — sign up in 30s