Let’s get started
By clicking ‘Next’, I agree to the Terms of Service
and Privacy Policy
Jobs / Job page
IT Security Engineer image - Rise Careers
Job details

IT Security Engineer

This position is eligible for our Hybrid Work Policy. Eligible employees can work from home up to one day each week. JOB SCOPE Responsible for conducting penetration testing of information systems, networks, applications, and databases for vulnerabilities and risks within technology environments. Provides simulated cyberattacks and security assessments, under general direction, to probe existing security measures for potential weaknesses and check for exploitable vulnerabilities. Maintains deep knowledge of vulnerabilities and exploits to discern how they affect different systems and network protocols and their communication with each other. Works closely with engineering and technical operations staff to plan, discover, test, and report on penetration testing engagements and identified findings. DUTIES AND RESPONSIBILITIES Perform web application penetration testing, network penetration testing, mobile application penetration testing, and source code reviews. Basic understanding of a software development lifecycle, scripting languages, and public and private cloud environments. Lead penetration testing engagements to including scoping, testing, reporting, and debriefing findings to business stakeholders. Demonstrate expertise with applications, operating systems, firmware, etc with regards to vulnerabilities and appropriate remediation activities to eliminate risk to the business. Able to work with applications, platforms, and business owners to identify scope and outline requirements for testing engagements. Document and create reports outlining the findings identified as part of an engagement and communicate to business stakeholders. Proficiency in at least one programming language (e.g., Bash, Python, PHP, Ruby) to support development of testing scripts and tools. Review information security trends and leverage new source for emerging threats and vulnerabilities. Ensures compliance with security standards, policies, and procedures. Adheres to industry specific local, state, and federal regulations, as applicable. BASIC / MINIMUM QUALIFICATIONS Bachelor's degree in computer science or information Systems or related field or equivalent experience Minimum of Four (4) years of IT/network Operations/Support At least Four (4) year of Information Security Operations ADDITIONAL JOB QUALIFICATIONS Strong knowledge of Microsoft Office tools, especially Excel, Word, Visio, and Power Point with the ability to document, prepare and present data driven summaries. Contribute to the development of the penetration testing methodologies, testing capabilities and practices, and engagement deliverables within the security operations team. Experience with open-source security testing standards and projects, such as OWASP, OSSTMM, NIST 800-115, and/or PTES. Strong knowledge of network and application testing technologies and tools, such as Burp Suite, OWASP ZAP, Metasploit, Kali Linux Suite, Postman, and others. Working knowledge of TCP/IP and advanced host and network security administrative and technical controls. Demonstrated capabilities with the ability to work across functional boundaries, build consensus and drive results. Strong written and verbal communication skills and should have good presentation skills. Must be a problem solver, able to balance competing priorities, have a strong process orientation and be able to manage through complexity and rapid change. PREFERRED QUALIFICATIONS Experience in a security operations support role performing penetration testing or similar. Experience with penetration testing tools such as: Burp Suite, Kali Linux Suite, OWASP Zap. Current security certifications, such as CompTIA Security, CISSP, CEH, and SANS GIAC. ESE340 2024-42240 2024 Here, employees don’t just have jobs, they build careers. That’s why we believe in offering a comprehensive pay and benefits package that rewards employees for their contributions to our success, supports all aspects of their well-being, and delivers real value at every stage of life. A qualified applicant’s criminal history, if any, will be considered in a manner consistent with applicable laws, including local ordinances. This job posting will remain open until 2024-12-09 02:47 PM (UTC) and will be extended if necessary. The base pay for this position generally is between $78,900.00 and $139,500.00. The actual compensation offered will carefully consider a wide range of factors, including your skills, qualifications, experience, and location. We comply with local wage minimums and also, certain positions are eligible for additional forms of other incentive-based compensation such as bonuses.
Spectrum Glassdoor Company Review
3.3 Glassdoor star iconGlassdoor star iconGlassdoor star icon Glassdoor star icon Glassdoor star icon
Spectrum DE&I Review
No rating Glassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star iconGlassdoor star icon
CEO of Spectrum
Spectrum CEO photo
Chris Winfrey
Approve of CEO

Average salary estimate

$109200 / YEARLY (est.)
min
max
$78900K
$139500K

If an employer mentions a salary or salary range on their job, we display it as an "Employer Estimate". If a job has no salary data, Rise displays an estimate if available.

What You Should Know About IT Security Engineer, Spectrum

Are you ready to take your career to the next level as an IT Security Engineer with an innovative company based in Highlands Ranch, CO? In this engaging role, you will become a vital asset to our team by conducting penetration testing across various information systems, networks, applications, and databases to identify and mitigate potential vulnerabilities. Leveraging your knowledge of emerging threats and security protocols, you will simulate cyberattacks and perform thorough assessments to understand and enhance our existing security measures. Collaborating closely with our engineering and technical operations teams, you will lead penetration testing engagements—from scoping and testing to reporting and discussing findings with stakeholders. Your ability to proficiently communicate complex technical details and trends is essential to ensure comprehensive risk management for the business. If you enjoy translating technical complexities into actionable plans and driving preventative measures to bolster our security posture, you’ll fit right in! Plus, we offer a flexible hybrid work policy that allows you to work from home up to one day a week. Join us as we navigate the complex landscape of cybersecurity, develop effective methodologies, and contribute to our ongoing mission to safeguard our technology environments.

Frequently Asked Questions (FAQs) for IT Security Engineer Role at Spectrum
What are the main responsibilities of an IT Security Engineer at this company?

As an IT Security Engineer, your primary responsibilities will include conducting various types of penetration testing, such as web applications, networks, and mobile apps. You'll lead projects from scoping to reporting, ensuring comprehensive vulnerability assessments while maintaining strong communication with business stakeholders. You'll also be instrumental in developing penetration testing methodologies and staying abreast of security trends.

Join Rise to see the full answer
What qualifications do I need to apply for the IT Security Engineer position?

To qualify for the IT Security Engineer role, you need at least a Bachelor's degree in Computer Science or a related field, combined with a minimum of four years in IT support and information security operations. Proficiency in at least one programming language and familiarity with security protocols is essential. Experience with tools like Burp Suite and OWASP ZAP is preferred, along with relevant security certifications, such as CompTIA Security or CISSP.

Join Rise to see the full answer
What is the work culture like for the IT Security Engineer position?

The work culture for IT Security Engineers in our company is collaborative, innovative, and supportive. You will be part of a dynamic team that values continuous learning and proactive problem-solving. With a hybrid work policy, you also have the flexibility to balance your work and personal life effectively, contributing to a positive overall experience.

Join Rise to see the full answer
Can I work remotely for the IT Security Engineer role?

Yes, this position is eligible for our Hybrid Work Policy, allowing you to work from home up to one day each week. This flexibility is designed to help you maintain a healthy work-life balance while fulfilling your responsibilities effectively.

Join Rise to see the full answer
What skills will help me succeed as an IT Security Engineer here?

To succeed as an IT Security Engineer at our company, strong analytical skills combined with excellent written and verbal communication are crucial. You should also be adept in technical problem-solving, risk assessment, and have hands-on experience with penetration testing tools and methodologies. Being a team player who can collaborate effectively across departments will enhance your contributions.

Join Rise to see the full answer
Common Interview Questions for IT Security Engineer
Can you explain the penetration testing process?

The penetration testing process typically involves several key steps: scoping to define the engagement's focus, reconnaissance to gather information about the target, scanning to identify vulnerabilities, exploiting those vulnerabilities to assess their severity, reporting the findings to stakeholders, and finally debriefing to discuss remediation strategies.

Join Rise to see the full answer
What programming languages are you familiar with related to penetration testing?

I am proficient in several scripting languages, including Python and Bash, which I use to develop custom testing scripts and automation tools to enhance my penetration testing efforts and streamline processes.

Join Rise to see the full answer
Describe a challenging security assessment you conducted?

In one instance, I led a penetration test on a complex network with multiple interconnected systems. The biggest challenge was navigating the various protocols and ensuring all potential vulnerabilities were identified. By using a structured, methodical approach and employing multiple tools, I was able to uncover critical security issues that were subsequently addressed.

Join Rise to see the full answer
How do you stay updated on the latest security threats?

I stay updated by regularly reading industry publications, following cybersecurity experts on social media, participating in security forums, and attending webinars. This continuous education helps me recognize emerging threats and adapt our security strategies accordingly.

Join Rise to see the full answer
What tools do you use for penetration testing?

I primarily use tools like Burp Suite, Metasploit, and OWASP ZAP for penetration testing. Each tool serves a specific purpose, whether it's web application testing, network exploitation, or vulnerability scanning, allowing a comprehensive assessment of security postures.

Join Rise to see the full answer
How do you prioritize vulnerabilities found during testing?

I prioritize vulnerabilities based on several key factors, such as their potential impact on the business, exploitability, and compliance requirements. This risk-based approach helps focus efforts on the most critical issues that could pose significant threats.

Join Rise to see the full answer
Can you give an example of how you've communicated technical findings to non-technical stakeholders?

I once prepared a presentation for non-technical stakeholders where I translated complex technical findings into straightforward, actionable items. I used visual aids and analogies to simplify concepts, ensuring they understood the implications and necessary remediation steps.

Join Rise to see the full answer
What do you do if you find a critical vulnerability during a test?

If I discover a critical vulnerability, my first step is to document it in detail, including the associated risks and potential impacts. I communicate the findings to the relevant stakeholders immediately and recommend actionable steps for remediation to mitigate the risks associated with it.

Join Rise to see the full answer
Describe your familiarity with compliance regulations relevant to security?

I'm well-versed in compliance regulations such as NIST, HIPAA, and PCI-DSS. I have worked on several projects that required alignment with these frameworks, ensuring that our security practices not only meet industry standards but also protect sensitive data effectively.

Join Rise to see the full answer
How would you enhance the current security measures in place?

To enhance current security measures, I would conduct a thorough risk assessment, evaluate recent incidents and breaches, and leverage new security technologies and strategies. Continuous training and awareness programs for staff would also be vital to cultivate a security-first culture within the organization.

Join Rise to see the full answer
Similar Jobs
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 12 days ago
Photo of the Rise User
Posted 13 days ago
Photo of the Rise User
Posted 3 days ago
Photo of the Rise User
Posted 8 days ago
Photo of the Rise User
Jimdo Remote No location specified
Posted 4 days ago
MAT Holdings, Inc Hybrid 6700 Wildlife Wy, Long Grove, IL 60047, USA
Posted 4 days ago

Charter Communications, Inc. (NASDAQ:CHTR) is a leading broadband connectivity company and cable operator serving more than 31 million customers in 41 states through its Spectrum brand. Over an advanced communications network, the company offers a...

197 jobs
MATCH
Calculating your matching score...
FUNDING
SENIORITY LEVEL REQUIREMENT
TEAM SIZE
EMPLOYMENT TYPE
Full-time, hybrid
DATE POSTED
December 7, 2024

Subscribe to Rise newsletter

Risa star 🔮 Hi, I'm Risa! Your AI
Career Copilot
Want to see a list of jobs tailored to
you, just ask me below!