Hiring.Camp

Junior Cybersecurity Engineer

ANSI Careers

·

Today

Salary
$83k – $91k
Location
New York, NY, USA, United States of America
Type
Full-time
Department
Engineering
Seniority
Entry
Experience
5+ years
Education
Master
Source
Workday

Description

Position Summary

 

The Junior Cybersecurity Engineer, also referred to as Junior Security Analyst, supports the day-to-day protection of ANSI and ANAB information systems, applications and data. The role deliberately spans two complementary sides of the security function: hands-on security operations (log and alert review, security tooling, endpoint hardening, vulnerability and patch follow-up) and security assurance (IT security assessments, vendor reviews, compliance checks and risk reporting). The incumbent is expected to become competent in both.

 

The position reports to the Chief Information Security Officer (CISO), who provides technical supervision, day-to-day direction and mentoring.

 

This is an entry-level position, suited to a candidate at the start of a cybersecurity career who wants exposure to both engineering and governance, risk and compliance (GRC) rather than one or the other.

 

Essential Functions

 

Security Operations and Monitoring

·       Maintain a complete, accurate and current inventory of systems, infrastructure and applications, and verify that every in-scope source is logging to the SIEM / log management platform. And is covered by all security controls and consoles.

·       Validate security configurations and access rights on security tooling, firewalls, intrusion prevention systems (IPS), web application firewalls (WAF), endpoint protection and anti-malware and report deviations from the approved baseline.

·       Support the change management process for firewall rulesets, including review of requests, documentation of approvals and periodic rule recertification. Represent IT Security’s interest during weekly CAB meeting.

·       Assist information security team in enforcing network segmentation/ secure architecture.

·       Assist information security team in Vulnerability and Threat Management Program, overall endpoint configuration hardening.

·       Assist information security team in Cloud security activities.

·       Verify that security and other critical patches to operating systems and firmware are deployed within defined timeframes and follow up on overdue items until closure.

·       Assist in operating and maintaining the security infrastructure and its configuration, including automated security controls across servers, endpoints, cloud workloads and network environments.

·       Support privileged activity monitoring and assist with the related investigations.

·       Assist with cryptographic key management tasks under established procedures.

·       Review security and infrastructure logs for indicators of compromise (IOCs) and anomalous behavior across networks, applications and user accounts; qualify findings by risk level and escalate confirmed issues to the Senior Cybersecurity Engineer. Create, run and improve Incident Response Playbooks.

·       Act as first-line support during security incidents: triage alerts, collect and preserve evidence, document the timeline, and assist with data and service recovery during disruption or disaster recovery events.

 

Assessment, Risk and Compliance

·       Assist in performing independent IT security assessments (audit, pentests), proactive and reactive reviews following upgrades, enhancements or incidents to identify security risks and non-compliance with ANSI / ANAB IT security policy, standards and guidelines.

·       Schedule and coordinate internal and external vulnerability assessments, support the procurement and scheduling of web application penetration testing, consolidate results and track remediation through to closure.

·       Perform IT security assessments of vendors and third parties against ANSI / ANAB security requirements, standards, and maintain the supporting records.

·       Identify, document and report IT security risks, and assist in developing treatments for risks raised internally and with third parties.

·       Help develop, maintain and monitor security standards, controls and processes, and track exceptions where a system, project or third party is not compliant with policy.

·       Provide security input into change projects and initiatives under the direction of the Chief Information Security Officer, including assessment of changes at Pre-CAB and CAB for security risk, and pre go-live test reviews.

·       Assist in preparing evidence, responses and remediation tracking for internal and external audits of the IT security function.

·       Contribute to security education and awareness activities for ANSI and ANAB staff.

·       Maintain documentation, procedures, runbooks, assessment records and recurring reporting that can be presented to management, auditors and peers without rework.

·       Track emerging threats, vulnerabilities and security technologies relevant to the ANSI / ANAB environment and summarize for the team what is material and what action it warrants.

 

Key Performance Indicators

·       Alert and Log Triage Timeliness: assigned alerts and log review queues are triaged, documented and escalated within the agreed service levels.

·       Remediation Follow-Through: vulnerabilities, patches and audit findings are tracked to closure within their defined timeframes, with slippage surfaced early rather than discovered late.

·       Assessment and Review Completion: scheduled vendor assessments, security reviews and access or configuration recertifications are completed on time and to the agreed scope.

·       Quality of Documentation and Reporting: assessment records, runbooks and evidence packages are accurate and audit-ready, requiring minimal rework by the Senior Cybersecurity Engineer or the CISO.

 

Internal ANSI / ANAB Information Security Responsibilities

 

·       Attend/complete assigned information security training by the designated completion date.

·       Read and adhere to published ISMS policies and procedures.

·       Report timely any observed violations of ISMS policy - or known encroachments on information security - to your department leader and/or the Information Technology Department.

Education and Experience

 

·       Bachelor's degree in computer science, computer engineering, information security, information systems, mathematics or a related field of study. An associate's degree combined with relevant hands-on experience or a recognized technical certification will also be considered.

·       5 years of professional experience in information security role with genuine security exposure. Prior contact with both operational security work and audit or compliance activity is an advantage.

·       An entry-level security certification such as CompTIA Security+, CySA+ or Network+, ISC2 Certified in Cybersecurity (CC) is preferred. Candidates without one are expected to obtain at least one within the first twelve months, with ANSI's support.

 

Other Qualifications

 

·       Familiarity with business continuity and IT disaster recovery concepts is a plus.

·       Working knowledge of networking fundamentals (TCP/IP, DNS, routing, network segmentation), Windows and Linux operating systems, cloud / SaaS concepts (Microsoft 365 and Azure preferred).

·       Familiarity with core security tooling, SIEM and log management, endpoint protection EDR, firewalls, IPS / WAF, vulnerability scanners, MFA and identity management.

·       Comfortable using basic scripting (PowerShell, Python) for reporting and repetitive tasks.

·       Exposure to recognized security and risk frameworks - NIST CSF, NIST SP 800-53, ISO / IEC 27001 and 27002, CIS Controls is preferred but not essential; the willingness to learn and apply them is.

·       Rigor and attention to detail, particularly in evidence and documentation.

·       Able to take direction and act on feedback, to manage a queue of tasks without prompting, and to say when something is not understood.

·       Curiosity and a habit of self-directed learning.

·       Understands that security exists to protect ANSI's and ANAB's mission, members and accreditation activities, not to obstruct them.

·       Able to explain a risk in plain language to non-technical colleagues, to ask before assuming, and to recognize when an issue must be escalated rather than handled alone.

·       Able to handle confidential and sensitive information with discretion.

·       Occasional availability outside standard business hours during a security incident, a scheduled remediation window, or an audit deadline.

·       Interest in progressing toward a security engineering or GRC specialization, with a development path defined and supported by the Senior Cybersecurity Engineer.

 

 


Starting compensation will be in the $82,800 to $91,100 range, depending on education, experience, and other qualifications.

 

 


This job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee. Duties, responsibilities and activities may change or new ones may be assigned at any time with or without notice.

 

ANSI provides equal employment opportunities to all employees and applicants for employment, and prohibits discrimination of any type because of race, gender identity or expression, color, national origin or ancestry, religion, creed, age, marital status, sex, sexual orientation, citizenship or authorized alien status, genetics, disability status, protected veteran status, or any other consideration protected by federal, state, or local laws. ANSI policy also prohibits unlawful discrimination based on the perception that anyone has any of those characteristics. This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

 



Important Notice for Job Seekers: Protect Yourself from Fraudulent Job Postings

We are aware of fraudulent job postings falsely claiming to represent our company. These scams may mirror our legitimate job listings and direct candidates to fake interview links or request personal information. Here's how to spot legitimate opportunities:

·       Verify jobs at www.ansi.org

·       Apply through our official Workday system at https://ansi.wd1.myworkdayjobs.com/ANSI_Careers

·       We won’t ask for an interview via Zoom links or texts.

·       We would never ask for payment

·       We won’t ask for sensitive, personal information early in an application process.

·       All communication comes from official company emails (@ansi.org).

 

We prioritize your security and use only official channels.  If you see a suspicious posting, please report it to the job board.

Skills

PythonAzureLinuxWorkdayCybersecurityPenetration TestingSIEMTCP/IPComplianceProcurementChange ManagementCompTIA

Similar Jobs

10

Cybersecurity Engineer (Junior)

Interclypse Inc.·Annapolis Junction, MD·Onsite

3d ago

Junior Cybersecurity engineer

Unisys·Home Based Colombia·Remote

1w ago

Cybersecurity Engineer, Junior

Render Security Engineering LLC·California, MD

2mo ago

Cybersecurity Engineer (Junior)

Daulfin Grey

3mo ago

JUNIOR DEVELOPER - INDUSTRIAL CYBERSECURITY

W-Industries·Houston, TX

1d ago

Entry-Level Electrical Hardware Engineer – FPGA, Networking & Cybersecurity

Gdms·Pittsfield, MA·Onsite

1w ago

Cybersecurity Test Engineer, Junior

Booz Allen Hamilton·Rome, NY

3w ago

Junior Cybersecurity und Netzwerk Engineer 80-100%

Onax·Schweiz·Onsite

3mo ago

Cybersecurity Engineer (Junior/ Senior/ Team Leader)

Sirisoft·Bangkok, Thailand

5mo ago

Junior Business Development Manager - Cybersecurity (m/w/d)

Sheriff Globalde·Deutschland·Hybrid

1y+ ago