Cybersecurity Engineer
King's Hawaiian · Colorado, United States
Food and Beverage Manufacturing · 1,001-5,000 employees
About the role
The Cybersecurity Engineer supports the cybersecurity program by managing security controls, monitoring infrastructure, and handling incident response. They are also responsible for conducting security research, performing audits, and ensuring compliance with regulatory standards like PCI DSS and HIPAA.
What they look for
Requirements
Candidates must have a bachelor's degree in IT or equivalent experience, along with strong technical knowledge of Azure AD, Active Directory, and SIEM systems. Professional certifications such as CISA, CISM, GSEC, or CISSP are preferred.
Benefits
Full description
Joining King’s Hawaiian makes you part of our `ohana (family). We are a family-owned business for over seventy years, respecting our roots while thinking about our future as we continue to grow and care for our customers and the communities we serve. Our `ohana members build an environment of inclusivity as they freely collaborate, pursue learning through curiosity, and explore innovation as critical thinkers. Beyond that, we are also passionate about supporting the long-term health and well-being of our employees and their families. If you’re excited to rise with our team, come and join our `ohana!
The Cybersecurity Engineer is responsible for supporting the cybersecurity program and strategy at a tactical and operational level (network, infrastructure, applications, and databases) to ensure that security controls are functioning efficiently and effectively. The Cybersecurity Engineer will assist with security logging, monitoring, alert management, GRC system administration, incident handling, vulnerability remediations, and configuration management. Furthermore, this position also supports the Information Technology team in doing security research and development, product evaluations, consulting, project support, and any other operational tasks needed to support the overall requirements of the program and strategy.
ESSENTIAL JOB DUTIES AND RESPONSIBILITIES
- Research and evaluate emerging cyber security threats and ways to manage them.
- Translate raw SIEM data into actionable items for the environment.
- Onboard and manage vendor relationships in our GRC tool.
- Review SOC2 reports and interface with vendors to ensure they are maintaining adequate security posture based on risk to the organization.
- Assist with maintaining PCI DSS 4.0 compliance as needed.
- Proactively identify security flaws and vulnerabilities; both internal and external.
- Audit systems for secure configuration.
- Plan, implement, and upgrade security measures and controls.
- Define, implement, and maintain corporate security policies.
- Track common vulnerabilities and exposures (CVE) based security threats and map to internal controls and remediation plans.
- Map security practices to regulatory controls (HIPAA, CIS, PCI DSS).
- Monitor networks for security breaches and conduct root cause analysis (RCA) post breach.
- Conduct penetration testing individually, with the security team, or consultants.
- Perform security audits, risk assessments, and analysis.
- Make recommendations for enhancing systems security.
- Analyze corporate environment to identify potential intrusion points, leaks, and breaches. Research attempted breaches in security and rectify security weaknesses.
- Provide additional information security assistance as required.
BASIC AND PREFERRED QUALIFICATIONS (EDUCATION and/or EXPERIENCE)
- Bachelor’s degree in related field (IT) or equivalent experience required.
- CISA, CISM, GSEC, CISSP, or other relevant certifications preferred.
ADDITIONAL QUALIFICATIONS (JOB SKILLS, ABILITIES, KNOWLEDGE)
- Strong knowledge of Azure AD and related security.
- Strong understanding of Identity Access and Management Systems (IAM).
- Expert level knowledge of Active Directory Services.
- Strong knowledge of Security Incident and Event Monitoring and management (SIEM).
- Strong knowledge of perimeter security methodologies.
- Knowledge of physical and logical security standards.
- Strong risk-assessment and measurement skills.
- Strategic thinking, planning, solution assessment, and validation skills.
- Strong collaboration, partnering, and teamwork skills.
- Expert level knowledge of PowerShell.
- Knowledge of SDLC methodologies.
- Knowledge of ITIL and ITSM methodologies.
- Windows Expert and working knowledge of Linux Operating Systems.
ESSENTIAL JOB DUTIES AND RESPONSIBILITIES
- Research and evaluate emerging cyber security threats and ways to manage them.
- Translate raw SIEM data into actionable items for the environment.
- Onboard and manage vendor relationships in our GRC tool.
- Review SOC2 reports and interface with vendors to ensure they are maintaining adequate security posture based on risk to the organization.
- Assist with maintaining PCI DSS 4.0 compliance as needed.
- Proactively identify security flaws and vulnerabilities; both internal and external.
- Audit systems for secure configuration.
- Plan, implement, and upgrade security measures and controls.
- Define, implement, and maintain corporate security policies.
- Track common vulnerabilities and exposures (CVE) based security threats and map to internal controls and remediation plans.
- Map security practices to regulatory controls (HIPAA, CIS, PCI DSS).
- Monitor networks for security breaches and conduct root cause analysis (RCA) post breach.
- Conduct penetration testing individually, with the security team, or consultants.
- Perform security audits, risk assessments, and analysis.
- Make recommendations for enhancing systems security.
- Analyze corporate environment to identify potential intrusion points, leaks, and breaches. Research attempted breaches in security and rectify security weaknesses.
- Provide additional information security assistance as required.
BASIC AND PREFERRED QUALIFICATIONS (EDUCATION and/or EXPERIENCE)
- Bachelor’s degree in related field (IT) or equivalent experience required.
- CISA, CISM, GSEC, CISSP, or other relevant certifications preferred.
ADDITIONAL QUALIFICATIONS (JOB SKILLS, ABILITIES, KNOWLEDGE)
- Strong knowledge of Azure AD and related security.
- Strong understanding of Identity Access and Management Systems (IAM).
- Expert level knowledge of Active Directory Services.
- Strong knowledge of Security Incident and Event Monitoring and management (SIEM).
- Strong knowledge of perimeter security methodologies.
- Knowledge of physical and logical security standards.
- Strong risk-assessment and measurement skills.
- Strategic thinking, planning, solution assessment, and validation skills.
- Strong collaboration, partnering, and teamwork skills.
- Expert level knowledge of PowerShell.
- Knowledge of SDLC methodologies.
- Knowledge of ITIL and ITSM methodologies.
- Windows Expert and working knowledge of Linux Operating Systems.
King's Hawaiian is an equal opportunity employer. We celebrate diversity and are committed to creating an inclusive environment for our ohana.