Job Description
MAIN RESPONSIBILITIES
- Conducts regular security assessments and penetration tests to proactively identify weaknesses in our systems and infrastructure.
- Develops and implements security controls and measures to mitigate risks and enhances the overall security posture.
- Promptly identifies and investigates any suspicious activities that may signal a security breach, while performing a fast analysis and correlation of events to ensure timely resolution of potential issues.
- Conducts weekly system scans to uphold compliance with PCI regulations and policies. Additionally, it ensures adherence to other regulatory standards, such as SOC2, necessitating comprehensive understanding of processes, documentation, and related requirements.
- Guarantees optimal performance and configuration of all security tools and systems by managing and maintaining their settings. This includes removing redundant servers and computers, verifying that all authorized users have appropriate access permissions to applications and systems, and ensuring effective implementation of endpoint protection policies, including handling any necessary exceptions.
- Assists in the creation of tailored training modules and simulated attacks, utilizing customizable templates to educate employees within the company, and creating awareness of cybersecurity threats.
- Emphasizes the importance of ongoing updates to ensure all users are promptly informed of cybersecurity protocols, especially with the arrival of new personnel.
- Responds to alerts through various channels including email, the Help Desk ticketing system, and any other notifications from fellow employees, prioritizing actions based on the criticality of each alert.
- Facilitates information exchange between analysts and other IT departments. In the event of a new vulnerability affecting a product managed by another team, ensure prompt sharing of relevant details, and recommend viable alternatives to address the issue.
- Checks that all scheduled tasks and updates perform successfully, as well as coordinating the updates with Infrastructure personnel so that they are performed without affecting the operation.
- Collaborates with cross-functional teams to implement security best practices and ensure compliance with relevant regulations and standards.
- Stay up to date with the latest cybersecurity trends, threats, and technologies to continuously improve our security posture.
- Complies fully and consistently with the Company's standards, policies, and procedures and the local and federal laws applicable to our industry, business, and employment practices.
- May perform other duties and responsibilities as assigned, in accordance with the education and experience requirements contained in this document.
QUALIFICATIONS
- Bachelor’s degree in Computer Science, Information Technology, or a related field.
- 2+ years of experience in information technology roles.
KNOWLEDGE, SKILLS AND ABILITIES
- Proven experience in cybersecurity analysis, incident response, and risk management.
- Strong knowledge of networking protocols and security technologies.
- Highly knowledgeable about computers, including networks, operating systems, applications, and web apps.
- Experience with security tools such as SIEM, IDS/IPS, firewalls, and vulnerability scanners.
- Excellent analytical, problem-solving, and communication skills.
- Ability to work independently and collaboratively.
- Excellent multitasking skills and ability to manage multiple projects.
- Proven ability to prioritize and handle multiple tasks at once; strong attention to detail is a must.
- Proven organizational skills, with experience working in a fast-paced and high-volume environment.
- Ability to identify solutions independently and make sound business decisions.
- Experience utilizing Microsoft Office products (MS Word, Excel, and Outlook).
- Bilingual (writing, conversational and reading comprehension in English and Spanish)
CERTIFICATIONS/ LICENSES/ PROFESSIONAL AFFILIATIONS
- Certifications such as CompTIA Security+, CEH (Certified Ethical Hacker), CISSP, CISM, or GIAC certifications, and membership in recognized cybersecurity professional organizations (e.g., ISACA, (ISC)²), are preferred.
WORKING CONDITIONS
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.
- The noise level in the work environment is usually moderate.
- Will operate a computer, copier, and other modern office equipment. The employee generally works indoors in an office.
- Ability to work in a fast-paced environment with flexible hours, including evenings or weekends, to respond to security incidents, perform system maintenance, or support cross-functional cybersecurity initiatives.
- Occasional offsite visits may be required, as requested by the organization.
PHYSICAL REQUIREMENTS
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
- Ability to sit for extended periods while working on a computer and managing various cybersecurity projects and incidents.
- Regular use of hands and fingers for typing, digital navigation, and handling office equipment.
- Occasional lifting and carrying of equipment, such as laptops, servers, or security hardware, typically up to 25 pounds.
- Strong visual and auditory skills are essential for monitoring system alerts, analyzing logs, and assessing potential security threats.
Grupo Ferré Rangel is proud to be an Equal Employment Opportunity employer. We are committed to providing reasonable accommodations for qualified individuals with disabilities and disabled veterans in our job application procedures. We also consider qualified applicants with criminal histories, consistent with applicable federal, state and local law.
Pay: $45,000.00 - $55,000.00 per year
Benefits:
- 401(k)
- 401(k) matching
- Employee assistance program
- Health insurance
- Life insurance
- Paid time off
- Retirement plan
Work Location: In person