← Back to jobs
Whippany, Hanover, NJ, USA
No related jobs found
Responsibilities
· Support day-to-day security operations, including alert triage in SIEM and EDR platforms, log review, threat monitoring, investigation, containment, escalation, and incident-response activities.
· Administer identity and access management controls, including SSO, MFA, Active Directory and Microsoft Entra ID, privileged access, and joiner, mover, and leaver processes; conduct periodic access reviews and remove stale accounts and unnecessary entitlements.
· Maintain and improve endpoint security across the company’s technology environment, including EDR health, patch management, configuration baselines, software control, disk encryption, and remediation of exceptions.
· Perform and coordinate network security activities, including firewall and access-control-list reviews, VPN administration, segmentation, secure configuration, wireless security, and monitoring for misconfigurations and unauthorized activity.
· Operate the vulnerability management program by performing or coordinating scans, prioritizing vulnerabilities based on business risk and exposure, assigning remediation to system owners, validating closure, and reporting trends and metrics.
· Support cybersecurity incident response, disaster recovery, and business continuity planning, including exercises and testing designed to restore critical business systems within established recovery objectives.
· Support compliance with applicable customer, contractual, and regulatory requirements, including CMMC, DFARS, ITAR and other U.S. export controls, and, where applicable, NIS2, Cyber Essentials, Cyber Essentials Plus, CMS, DCPP, ISO/IEC 27001, GDPR, and customer-specific information-security requirements.
· Collect and maintain audit evidence; develop and maintain policies, procedures, system security plans, plans of action and milestones, risk registers, data-flow diagrams, network diagrams, control documentation, and recurring compliance records; support customer questionnaires and internal and external audits.
· Support third-party and supplier risk management by reviewing security documentation, assessing risks, tracking remediation and risk acceptances, and monitoring relevant service-provider controls.
· Develop and deliver security awareness and role-based training, phishing simulations, onboarding content, and practical guidance on reporting suspicious activity, protecting CUI and FCI, and responding to security events.
· Serve as a knowledgeable point of contact for employee security questions, suspicious emails, lost devices, access requests, and other security concerns.
· Research, recommend, implement, and document security technologies, standards, configuration baselines, processes, and runbooks so the security program scales with the company.
· Coordinate effectively with internal teams, external service providers, assessors, and other stakeholders, and participate in an on-call rotation when needed.
· Perform other tasks as assigned.
Required Education and Experience
Preferred Qualifications
Bachelor's degree
No related jobs found
← Back to jobs