Systems Security Engineer
Primarily responsible to assess, evaluate and make recommendations to management regarding security controls for vendors, applications, and supporting infrastructure. Provide guidance on internal and external audit response pertaining to SOC1|2, ISO 9001, ISO 27001 and GDPR. Primarily responsible to improvement and maintaining of information security policies, standards, and control procedures to ensure compliance with applicable regulations and industry standards. Upload security policies, standards, and control procedures to Agile document repository. Defined and manage policy and vulnerability risk exception process. Identify opportunities to drive information security risk posture and enhance process improvements. Collaborated with other organizational business units to identify and manage security risks and attack vectors. Utilized Thycotic (Secret Server) and an Administrative capacity to safeguard business critical secrets. Utilized TenableIO (Security Center) Administrative capacity to scan infrastructure to identify exploitable risks and threats. Perform preproduction risk assessments of all cloud-based applications and systems to determine and assess compliance with applicable regulations and industry standards. Monitored and maintained Test Track Pro (TTP) to mitigated outstanding risks. Maintain and track vulnerability issues with in ServiceNow ticketing system. Provide reports to management regarding critical vulnerabilities, their severity and the potential to impact the organization.