Responsible for the design, testing, evaluation, implementation, support, management, and deployment of security systems/devices used to safeguard the organization s information assets. Also responsible for analyzing the information security environment and assisting with the development of security measures to safeguard information against accidental or unauthorized modification, destruction, or disclosure. '-Works with the technical team to recover data after a security breach. -Configures and installs firewalls and intrusion detection systems. -Develops automation scripts to handle and track incidents. -Investigates intrusion incidents, conducts forensic investigations and mounts incident responses. -Delivers technical reports and formal papers on test findings. -Installs firewalls, data encryption, and other security measures. -Maintains access by providing information, resources, and technical support. -Ensures authorized access by investigating improper access; revoking access; reporting violations; monitoring information requests by new programming; recommending improvements. -Updates job knowledge by participating in educational opportunities; reading professional publications; maintaining personal networks; participating in professional organizations. -Accomplishes information systems and organization mission by completing related results as needed. '-Builds, deploys, and tracks security measurements for computer systems and networks. -Mitigates security vulnerabilities by implementing applicable solutions and tools. -Performs vulnerability testing, risk analyses, and security assessments. -Collaborates with colleagues on authentication, authorization, and encryption solutions. -Tests security solutions using industry standard analysis criteria. -Responds to information security issues during each stage of a project s lifecycle. -Performs risk assessments and testing of data processing systems. -Establishes system controls by developing framework for controls and levels of access; recommending improvements
-Establishes computer and terminal physical security by developing standards, policies, and procedures; coordinates with facilities security; recommends improvements. -Safeguards computer files by performing regular backups; developing procedures for source code management and disaster preparedness; recommends improvements. '-Determines the sensitivity of the data in order to recommend the appropriate security needs. -Develops proposals for, and consider cost effective equipment options to satisfy security needs. -Communicates with the technical team, management team and users companywide if data security is breached. -Designs infrastructure to alert the technical team of detected vulnerabilities. -Evaluates new technologies and processes that enhance security capabilities. -Supervises changes in software, hardware, facilities, telecommunications and user needs. -Defines, implements, and maintains corporate security policies. -Analyzes and advises on new security technologies and program conformance. -Creates, tests, and implements network disaster recovery plans. -Recommends security enhancements and purchases. -Trains staff on network and information security procedures. -Develops security awareness by providing orientation, educational programs, and on-going communication. -Recommends modifications in legal, technical and regulatory areas that affect IT security.
Quals--
Senior Information Security Compliance Engineer
Work Environment: A hybrid work schedule, as defined by the department, is possible following the initial onboarding phase, depending on business needs and individual performance. The hybrid schedule may be modified at the manager s discretion, business needs, and various audit / assessment activities requiring more focused onsite work.
Overview: This role is primarily responsible for supporting the organization s government compliance program, ensuring adherence to applicable foreign and domestic regulatory requirements and maintaining alignment with mandated cybersecurity and IT compliance frameworks. In support of this mission, the position also contributes to broader Information Security Compliance efforts by executing special projects driven by evolving regulatory and cybersecurity requirements, processing and responding to third-party risk management questionnaires, developing and maintaining documentation of processes and procedures to support audit readiness and operational consistency, and assisting with additional Information Security Compliance activities as needed to strengthen the organization s overall compliance posture.
Required Qualifications:
Demonstrated experience in Information Technology audit, with the ability to identify, evaluate, and validate control evidence sufficient to support and demonstrate compliance with regulatory and industry requirements.
Deep understanding of NIST SP 800-171 or comparable control frameworks (e.g., NIST SP 800-53, NIST Cybersecurity Framework, ISO/IEC 27001/27002, FedRAMP, PCI DSS, or CIS Critical Security Controls), with the ability to rapidly apply control-based concepts across regulatory environments.
Ability to research and interpret new regulatory requirements, providing concise summaries to senior leadership
Strong written and verbal communication skills across multiple channels and organizational levels
Self-starter with the ability to work independently and deliver clear, actionable results
Demonstrated passion for learning and applying government compliance standards
Skilled in drafting and interpreting policies and procedures
Proficient in identifying, implementing, and managing security controls
Knowledgeable in collecting and interpreting evidence and artifacts for audits and assessments
Solid grasp of IT domains including information security, network architecture, and cloud computing
Prior experience in Governance, Risk & Compliance (GRC) organization or comparable role
Preferred Qualifications:
Prior experience with U.S. Government IT compliance requirements
Experience developing and maintaining System Security Plans (SSPs)
Project management experience and ability to drive action across functional areas
Foundational understanding of emerging AI tools and technologies, with the ability to evaluate their application for enhancing productivity and automation while identifying associated risks, potential misuse, and impacts to the organization s security and compliance posture
Experience in the aviation industry
Desired Certifications:
Certified Information Systems Security Professional (CISSP)
Certified Information Systems Auditor (CISA)
Certified in Risk and Information Systems Control (CRISC)
Note: a strong candidate will hold at least 1 of the certifications listed above in good standing.
------------
Equal Employment Opportunity
NLB Services is an Equal Opportunity Employer. All qualified applicants will receive consideration without regard to race, color, religion, sex (including pregnancy, sexual orientation and gender identity), national origin, age, disability, genetic information, protected veteran status, or any other characteristic protected by applicable law.
Reasonable Accommodation
NLB Services provides reasonable accommodations during the recruitment process as required by law. Applicants requiring an accommodation due to a disability, pregnancy-related limitation, or sincerely held religious belief, practice or observance may contact their recruiter or email
notifications@nlbservices.com
.
Benefits
Based on employment status and assignment, eligible employees may receive benefits, such as Medical, Dental and Vision Insurance, Health Insurance, Disability Insurance, etc. Eligibility and benefit terms vary by assignment.
Other Important Terms- Applicants must be legally authorized to work in the United States.
- Any employment offer may be contingent upon job-related screening, employment eligibility verification and other requirements permitted by applicable law.
- Following a conditional offer of employment, candidates may be required to complete job-related background screening, which may include criminal history checks and/or drug testing, as applicable and permitted by federal, state, and local law.
----------------------------------