Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
Cyber Security Engineer image - Rise Careers
Job details

Cyber Security Engineer

Overview:

AmSty is currently seeking a talented and motivated individual to join our organization and growing team as a Cyber Security Engineer within our Corporate IT Department.

The Cyber Security Engineer will leverage their broad IT skills and cyber knowledge to ensure that alerts thresholds are properly defined and acted upon; to lead cyber incident response processes to identify root cause, generate indicators of compromise and define actions necessary to contain threats.  They will use forensic tools and investigative methods to conduct computer and mobile cyber incident investigations to ensure compliance with corporate Information Security policies and all applicable laws and regulations. They will lead the resolution of cyber audit findings. They will author cyber related process and tools documentation. They will investigate where additional tools are necessary to create layers of protection. They will oversee patch management and vulnerability management processes. 


Responsibilities Include:
  • Lead the security incident management response process for AmSty – to include security monitoring, incident response, EDR/NDR/SIEM management and threat intelligence.
  • Serve as corporate focal point for SIEM/SOC functions – to include vendor management; getting logs to SIEM; determining appropriate SIEM use cases; defining, implementing and running use case alerts; reporting findings (weekly, monthly, quarterly) and setting a path for improvement as part of a continuous improvement journey.
  • Using tools in AmSty’s cyber security portfolio (EDR, NDR, SIEM, et al) - Identify, Detect, Protect and Respond to and against AmSty’s cyber weaknesses and vulnerabilities.
  • Monitor the company’s computing environment (servers, firewalls, intrusion detection/prevention systems, phish, anti-virus and malware) logs, and network traffic for activities including but not limited to policy violations, abnormal behaviors, intrusions, best practice recommendations, etc.
  • Develop and maintain website white lists, and application white lists.
  • Block or apply counter measures to remediate or lessen risk of detected issues.
  • Implement and audit domain administration restrictions and apply Group Policies on user and computer objects.
  • Analyze log files (sys logs, firewall logs, etc.) to determine security incident impact.
  • Develop and implement remediation plan for identified cyber risks.
  • Communicate with leadership and stakeholders as per Incident Response Communication Plan.
  • Serve as an active member on AmSty cyber incident response teams, which entails performing forensic and investigation services.
  • Respond to information security requests, incidents, and trouble tickets according to a defined SLA.

  • Lead Vulnerability Management Remediation Efforts:
  • Review EDR console (daily) for critical/high vulnerabilities on endpoints and initiate remediation plans.
  • Configure scanning tools to assist in identifying vulnerabilities and inventory IT systems (may include port scans, vulnerability scans, etc.).
  • Conduct weekly vulnerability management scans and initiate remediation plans.
  • Create and maintain the IT asset inventory.

  • Serve as a Risk Management Steward.
  • Author regular cybersecurity reports (i.e., monthly dashboards, audit remediation status updates, patch compliance, project status reports; Monthly, quarterly, and ad-hoc strategic and operational risk reporting and analytics for trending, risk assessment, compliance, and active exception reporting for EDR, NDR, SIEM/SOC and Vulnerability Management Functions Develop and enhance security policies, processes and procedures; supports service-level agreements (SLAs) to ensure that security controls are managed and maintained.
  • Maintains/Recommend new entries for AmSty’s cyber security Risk Register, based on vulnerabilities identified and remediations completed.
  • Maintains cyber policies.
  • Authors cyber playbooks.
  • Ensures compliance with applicable statutes and regulations.
  • Create/heighten security awareness within the organization by marketing, sending e-mails, create presentations, and present material to employees and contractors.
  • Participate in information security audits.
  • Actively support Red Team/Purple Team and table-top cyber initiatives and lead resolution of security weaknesses discovered therein.
  • Oversee penetration testing of all networks and systems to identify system and application vulnerabilities, lead resolution and remediation of findings.
  • Participate in disaster recovery and business continuity efforts.

  • Serve as an Internal Security Consultant.
  • Execute authorized information security project and initiatives.
  • Research and maintain technical proficiency in security tools, techniques, countermeasures, and basic trends in computer and network threats and exploits.
  • Serve as focal point for evaluation and implementation of new cyber tools/techniques to optimize AmSty’s cyber security portfolio and cyber defenses.
  • Maintain user security by developing access controls, monitoring and evaluation of security standards.
  • Participate in an on-call rotation for information security and resolve service outages within SLA.
  • Participate in Information Security initiatives and projects.
  • Review and monitor administrator account management (normal and privileged).
  • Serve as an advisory role in application development or acquisition projects to assess security requirements and controls, and to ensure that security controls are implemented as planned.
  • All other duties as assigned.


Qualifications - Required:
  • Bachelor of Science Degree from an accredited college or university in Computer Science, Information Security, Engineering, or related field, or equivalent certifications.
  • At least one professional security certification such as CISSP, CISA, CEH, applicable SANs programs, or other industry certifications (e.g., Cisco, Microsoft, VMware, et al).
  • Minimum of three years of active work experience with networking and/or cyber security tools.
  • Knowledge of network, infrastructure architecture and security (including network segmentation concepts, firewalls, routers, VPN solutions etc.).
  • Strong knowledge/familiarity with the administration of firewalls, including defining, configuring, and managing firewall policies; accessing firewall policies; troubleshooting firewall policies; and monitoring network traffic.
  • Significant experience with using leading EDR tools to detect and respond to incidents.
  • Previous Security Operations Center Analyst or Network Engineer experience.
  • Working knowledge of securing Linux, Windows, TCP/IP, and networking technologies.
  • Understanding of the fundamentals of security principles and best practices.
  • Strong critical thinking ability and investigative/problem solving skills.
  • Eager/willing to learn/gain new technical knowledge.
  • Ability to work well in a small group/team setting.
  • Excel in written and verbal business communications; Demonstrate strong written and oral presentation skills for technical and non-technical audiences, as well as the ability to work closely with all business areas; ability to develop new and existing documentation.
  • Ability and willingness to travel to other offices as required.


Desired Qualifications and Certifications:
  • Five years of active cyber security work experience with experience with Security Operations Center, Cyber Incident Response experience and forensic incident investigations and use of the following tools:
  • Vulnerability detection management software.
  • Leading SIEM Software (search, query, optimize use cases).
  • Leading Firewalls including NextGen.
  • Experience with malware analysis; packet capture/analysis and sandboxing.
  • Experience with creating Java, Python or Ruby scripts to remediate cyber incidents or automate security operations.
  • Knowledge of and experience managing information security assessments including: Penetration tests, Red team tests and physical/social engineering testing, internal network testing policy/procedure reviews, application testing.
  • Understanding of encryption and access management.
  • Understanding of evidence handling and chain-of-custody procedures.
  • Knowledge of Industrial Control Systems and related cyber protections.
  • Member of FBI InfraGard.
  • Related experience in chemical, petrochemical or oil and gas industry.
  • Network technologies and troubleshooting (Cisco certification).
  • Experience implementing the National Institute of Standards and Technology (NIST) Special Publication (SP) 800 series and the Risk Management Framework (RMF).
  • Desired Certifications (at least one of the following certifications);
  • Professional certifications (e.g., Certified Information System Security Professional (CISSP) or equivalent certification - CISM, CEH (lab), CIA, CISA, CFE, etc.).
  • EnCase Certified Examiner (EnCE).
  • Certified Forensic Security Responder (CFSR).
  • SANS Certifications (GCFE, GCFA, GNFA, GREM).
  • Cisco network technology and troubleshooting certifications.


Other Information:
  • Due to the nature of this work, evening and weekend work may be required. 24/7 on-call for cyber related incidents.


Relocation is not available with this position.


No sponsorship is available with this position.


Americas Styrenics LLC is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, gender identity, sexual orientation, national origin, ancestry, age, disability, veteran status or marital status.

 


To all recruitment agencies: We are not responsible for any fee related to unsolicited resumes from 3rd party staffing and recruiting agencies (whether submitted through this website or sent directly to employees) unless a written agreement is in place between the agency and Amsty  (“Company”) and an authorized Company representative makes a written request to the agency to assist with this requisition. Similarly, no fee will be paid for candidates who apply and claim to be represented by an agency. Any unsolicited resumes, CVs, or other candidate information submitted by an agency will become the property of Company, and no fee will be paid in the event such candidate is hired.

Average salary estimate

$95000 / YEARLY (est.)
min
max
$80000K
$110000K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About Cyber Security Engineer, AmSty

If you’re excited about protecting digital landscapes, AmSty in The Woodlands, TX, has the perfect opportunity for you as a Cyber Security Engineer! We are on the lookout for a driven individual with a knack for tackling cyber threats head-on. In this dynamic role, you will be at the forefront of safeguarding our organization by monitoring security incidents and leading our incident response processes. Your expertise will help in identifying root causes of security breaches while generating effective indicators of compromise. You will routinely engage with forensic tools to execute thorough investigations, ensuring compliance with our corporate security policies and legal standards. One of the key aspects of your role will involve overseeing our patch and vulnerability management processes, ensuring that we remain one step ahead of potential threats. As a Cyber Security Engineer at AmSty, your responsibilities will also include continuous monitoring of our digital environment and developing action plans to mitigate risks. You’ll communicate findings with leadership and collaborate closely with our incident response teams. Every day will be an opportunity to enhance our security policies and introduce innovative solutions, ensuring that our security protocols are robust and reliable. If you’ve got a strong background in security operations, a passion for technology, and a desire to learn and grow, we invite you to consider joining our dedicated team. Your contribution will be vital in fostering a safer business environment as we navigate the evolving cyber landscape!

Frequently Asked Questions (FAQs) for Cyber Security Engineer Role at AmSty
What are the primary responsibilities of a Cyber Security Engineer at AmSty?

As a Cyber Security Engineer at AmSty, you will be tasked with leading the security incident management response process. This includes monitoring security alerts, managing EDR/NDR/SIEM functions, conducting vulnerability management, and leading efforts in incident investigations. A significant part of your role will involve authoring incident response documentation, communicating findings to stakeholders, and continually improving our security processes.

Join Rise to see the full answer
What qualifications are required for becoming a Cyber Security Engineer at AmSty?

To qualify for the Cyber Security Engineer position at AmSty, you must hold a Bachelor’s degree in Computer Science, Information Security, or a related field. Additionally, a minimum of one professional security certification such as CISSP, CISA, or CEH is required, along with three years of experience in networking or cyber security tools. Familiarity with network security principles and practical experience with EDR tools is highly beneficial.

Join Rise to see the full answer
What skills are essential for a Cyber Security Engineer at AmSty?

Essential skills for a Cyber Security Engineer at AmSty include strong problem-solving abilities, investigative skills, and critical thinking. Proficiency in security monitoring tools, firewall management, and incident response is crucial. Candidates should also possess excellent communication skills to relay technical findings to both technical and non-technical audiences effectively.

Join Rise to see the full answer
What can I expect in terms of career development as a Cyber Security Engineer at AmSty?

At AmSty, we prioritize professional growth and development. As a Cyber Security Engineer, you will have opportunities to expand your knowledge through training programs and industry certifications. You will also be involved in cutting-edge security initiatives, allowing you to hone your skills and advance your career in the field of information security.

Join Rise to see the full answer
What does AmSty’s team environment look like for a Cyber Security Engineer?

At AmSty, our Cyber Security Engineer plays a crucial role within a collaborative and supportive team. You will work closely with other IT professionals in a friendly and dynamic atmosphere. Regular team discussions and partnerships in incident response initiatives ensure a collective approach to cybersecurity challenges while fostering personal and team growth.

Join Rise to see the full answer
Common Interview Questions for Cyber Security Engineer
Can you describe your experience with incident response planning as a Cyber Security Engineer?

When answering this question, emphasize specific instances where you led or participated in incident response efforts. Discuss any frameworks you utilized and the outcomes of your actions, showcasing your ability to adapt plans based on evolving threats.

Join Rise to see the full answer
What tools do you typically use for vulnerability management?

Be ready to discuss tools you have experience with, such as EDR systems, vulnerability scanners, and SIEM solutions. Highlight how you've used these tools to translate data into actionable security strategies and improve an organization's overall security posture.

Join Rise to see the full answer
How do you stay updated with the latest cybersecurity trends and threats?

Discuss your proactive methods for staying informed, such as attending industry conferences, participating in webinars, or subscribing to cybersecurity journals. Express your commitment to continual learning as cybersecurity is a constantly changing field.

Join Rise to see the full answer
Explain a time when you successfully resolved a security incident.

Use the STAR method (Situation, Task, Action, Result) to articulate a relevant experience where you effectively identified and contained a security threat. Make sure to highlight the skills you employed and the lessons you learned from the experience.

Join Rise to see the full answer
What’s your approach to conducting a cybersecurity audit?

In your response, describe the steps you take when conducting audits, including what criteria you evaluate and how you engage with teams to ensure compliance. Emphasize your analytical skills and detail-oriented approach.

Join Rise to see the full answer
What is your experience with implementing security policies?

Share specific instances where you developed or contributed to security policies within an organization. Discuss your approach to engaging stakeholders in the implementation process and how you measured the effectiveness of these policies.

Join Rise to see the full answer
How do you prioritize conflicting tasks in a fast-paced environment?

Illustrate your time management skills by discussing techniques you use for prioritization, such as assessing the potential impact of tasks on the organization's cybersecurity. This showcases your decision-making abilities in high-pressure situations.

Join Rise to see the full answer
Describe your experience with network segmentation and secure architecture.

Talk about your practical experience in establishing network segmentation and ensuring secure architecture. Highlight any relevant projects where you successfully identified segments and secured them against potential vulnerabilities.

Join Rise to see the full answer
How do you measure the effectiveness of your security measures?

Discuss key performance indicators (KPIs) you track that help assess the success of implemented security measures. Highlight how metrics shape your security strategy and prompt necessary adjustments.

Join Rise to see the full answer
What’s your familiarity with forensic analysis in your role?

Provide insights into your experience with forensic analysis tools and techniques. Discuss specific cases where you employed forensic methods to investigate incidents, emphasizing your analytical skills and attention to detail.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
AmSty Hybrid The Woodlands, TX
Posted 12 days ago
Photo of the Rise User
Posted 9 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 14 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 10 days ago
Photo of the Rise User
Privia Health Remote Remote, USA, United States
Posted 7 days ago

Founded in 2008, AmSty is a leading integrated producer of polystyrene and styrene monomer. Amsty is located in Texas.

12 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, on-site
DATE POSTED
December 25, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!