Pay range: $52.32 - 62.32
Plus Health, Dental, Vision, Short Term/Long Term Disability, and Group Life pending eligibility.
Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organization’s information assets. Also responsible for analyzing the information security environment and assisting with the development of security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure. '-Works with the technical team to recover data after a security breach. -Configures and installs firewalls and intrusion detection systems. -Develops automation scripts to handle and track incidents. -Investigates intrusion incidents, conducts forensic investigations and mounts incident responses. -Delivers technical reports and formal papers on test findings. -Installs firewalls, data encryption, and other security measures. -Maintains access by providing information, resources, and technical support. -Ensures authorized access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements. -Updates job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations. -Accomplishes information systems and organization mission by completing related results as needed. '-Builds, deploys, and tracks security measurements for computer systems and networks. -Mitigates security vulnerabilities by implementing applicable solutions and tools. -Performs vulnerability testing, risk analyses, and security assessments. -Collaborates with colleagues on authentication, authorization, and encryption solutions. -Tests security solutions using industry standard analysis criteria. -Responds to information security issues during each stage of a project’s lifecycle. -Performs risk assessments and testing of data processing systems. -Establishes system controls by developing framework for controls and levels of access; recommending improvements
-Establishes computer and terminal physical security by developing standards, policies, and procedures; coordinates with facilities security; recommends improvements. -Safeguards computer files by performing regular backups; developing procedures for source code management and disaster preparedness; recommends improvements. '-Determines the sensitivity of the data in order to recommend the appropriate security needs. -Develops proposals for, and consider cost effective equipment options to satisfy security needs. -Communicates with the technical team, management team and users companywide if data security is breached. -Designs infrastructure to alert the technical team of detected vulnerabilities. -Evaluates new technologies and processes that enhance security capabilities. -Supervises changes in software, hardware, facilities, telecommunications and user needs. -Defines, implements, and maintains corporate security policies. -Analyzes and advises on new security technologies and program conformance. -Creates, tests, and implements network disaster recovery plans. -Recommends security enhancements and purchases. -Trains staff on network and information security procedures. -Develops security awareness by providing orientation, educational programs, and on-going communication. -Recommends modifications in legal, technical and regulatory areas that affect IT security.
Quals--
Senior Information Security Compliance Engineer
Location: *** – Atlanta Office Department: Information Security – Governance, Risk & Compliance
Work Environment: A hybrid work schedule, as defined by the department, is possible following the initial onboarding phase, depending on business needs and individual performance. The hybrid schedule may be modified at the manager’s discretion, business needs, and various audit / assessment activities requiring more focused onsite work.
Overview: This role is primarily responsible for supporting the organization’s government compliance program, ensuring adherence to applicable foreign and domestic regulatory requirements and maintaining alignment with mandated cybersecurity and IT compliance frameworks. In support of this mission, the position also contributes to broader Information Security Compliance efforts by executing special projects driven by evolving regulatory and cybersecurity requirements, processing and responding to third-party risk management questionnaires, developing and maintaining documentation of processes and procedures to support audit readiness and operational consistency, and assisting with additional Information Security Compliance activities as needed to strengthen the organization’s overall compliance posture.
Required Qualifications:
· Demonstrated experience in Information Technology audit, with the ability to identify, evaluate, and validate control evidence sufficient to support and demonstrate compliance with regulatory and industry requirements.
· Deep understanding of NIST SP 800-171 or comparable control frameworks (e.g., NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001/27002, FedRAMP, PCI DSS, or CIS Critical Security Controls), with the ability to rapidly apply control-based concepts across regulatory environments.
· Ability to research and interpret new regulatory requirements, providing concise summaries to senior leadership
· Strong written and verbal communication skills across multiple channels and organizational levels
· Self-starter with the ability to work independently and deliver clear, actionable results
· Demonstrated passion for learning and applying government compliance standards
· Skilled in drafting and interpreting policies and procedures
· Proficient in identifying, implementing, and managing security controls
· Knowledgeable in collecting and interpreting evidence and artifacts for audits and assessments
· Solid grasp of IT domains including information security, network architecture, and cloud computing
· Prior experience in Governance, Risk & Compliance (GRC) organization or comparable role
Preferred Qualifications:
· Prior experience with U.S. Government IT compliance requirements
· Experience developing and maintaining System Security Plans (SSPs)
· Project management experience and ability to drive action across functional areas
· Foundational understanding of emerging AI tools and technologies, with the ability to evaluate their application for enhancing productivity and automation while identifying associated risks, potential misuse, and impacts to the organization’s security and compliance posture
· Experience in the aviation industry
Desired Certifications:
· Certified Information Systems Security Professional (CISSP)
· Certified Information Systems Auditor (CISA)
· Certified in Risk and Information Systems Control (CRISC)
Equal opportunity employer including disability/veterans.