Title: IT Security Engineer Reports To: Director, IT Security Location: Purchase, NY FLSA Status: Exempt Who We Are: Triton International is the world's largest and most reliable container leasing company. We provide our customers with efficiency and certainty in an unpredictable world. Our customers depend on our extensive worldwide network and large equipment inventory to meet their needs and help keep global commerce moving forward. We are guided by our values of integrity, reliability, creativity, excellence, teamwork, and long-term view, alongside core competencies that foster a culture of leadership, innovation, and sustainable growth. Together, these principles empower our team, driving our continued success and cementing our position as an industry leader. Why You'll Love This Job: As part of the Triton Team, you will play an integral part in our mission "to support the supply chains that connect the world."
- Impact: Contribute to meaningful projects that make a difference in the global supply chain.
- Growth: Take advantage of professional development opportunities and grow your career with us.
- Culture: Be part of a supportive, innovative, high-performing global team where your ideas are valued.
- Benefits: Enjoy a comprehensive benefits package.
What You'll Do: The IT Security Engineer is responsible for designing, implementing, and maintaining security measures to protect the organization's IT infrastructure, data, and systems. This role involves assessing risks, managing access controls, responding to incidents, and ensuring compliance with security policies and standards. Key responsibilities include:
- Incident Response:
- Be the Technical lead for the Incident Response process, including detecting, analyzing, mitigating, reviewing the impact, remediation planning containment and recovery management of security incidents.
- Liaise with the 3rd party Security Operations Center (SOC) and participate in investigations of suspicious activity providing on-call support for all security solutions.
- Vulnerability Management:
- Responsible for Vulnerability Remediation Management Process
- Research and analyze vulnerabilities, identifying potential threats and developing mitigation strategies.
- Application Vulnerability Planning, Testing and Management
- Risk Assessment and Management:
- Conduct 3rd party security risk assessments and evaluate vendor risks (e.g., SOC2 Type 2 reports).
- Review requests for new software/hardware and perform security risk assessments.
- Manage penetration testing
- DevSecOps:
- Review access control policies and implement measures to ensure secure access.
- Maintain Azure policies aligned with NIST standards.
- Remediate noncompliance policies with Terraform pipelines
- Drive automation
- Infrastructure/Network Security:
- Provide technical security guidance on all systems and associated software (firewalls, intrusion detection systems, anti-virus software, endpoints, wireless, email/web security.).
- Review logs and monitoring tools (server, firewall, intrusion detection, network traffic) for unusual activity, interpret findings, and recommend resolutions.
- Review and approve firewall rules
- Assess the impact of security patches.
- Security Architecture:
- Review existing security architecture and define standards.
- Evaluate new applications and systems to define security requirements.
- Recommend additional security solutions or enhancements to improve overall enterprise security.
- Security Monitoring and Operations:
- Manage SOC tools (e.g., Red Canary, Defender, Tenable).
- Review and align security requests with IT Policy and standards
- Review emerging threats (CISA/PWC/Microsoft/Red Canary) and determine impact to Triton
- Maintain up-to-date detailed knowledge of the IT security industry including awareness of new or revised security solutions, improved security processes, and the development of new attacks and threat vectors.
What We're Looking For: Required skill sets:
- College diploma or university degree in Computer Science or Cyber Security.
- 3-5 years of IT work experience in Cyber Security.
Preferred skill sets:
- Experience with security tools such as Tenable, Proofpoint, and Knowbe4 -PhishER
- CISSP, CISA, CISM, or similar security certifications preferred. Strong knowledge of IT security frameworks (e.g., NIST 2.0).
- Working technical knowledge of current systems software, protocols, and standards, including NIST 2.0 and NIST SP 800-53 Rev 5.
- Working experience with Terraform, PowerShell, Azure DevOps, Azure design, and Windows operating systems.
- Work experience in cybersecurity designs for systems, networks, and multi-level security requirements
- Knowledge of risk management processes and experience in conducting risk assessments.
- Knowledge of law enforcement practices and procedures related to security incidents and breaches.
- In-depth technical knowledge of Azure Defender and Azure Cloud security.
- Knowledge of computer networking concepts and protocols (e.g. TCP/IP, DNS) and network security methodologies.
- Knowledge of network access, identity, and access management (e.g. public key infrastructure, Oauth, OpenID, SAML, SPML).
- Knowledge of capabilities and applications of network equipment including routers, switches, servers, transmission media, and related hardware.
- Knowledge of remote access technology concepts.
- Knowledge of application firewall concepts and functions (e.g. single point of authentication enforcement, data anonymization, DLP scanning, SSL security).
You'll Succeed Here If You Are:
- Aligned to Triton's company values which include Integrity, Reliability, Creativity, Excellence, Teamwork and Long-term view.
- An intuitive individual with keen instincts to pre-empt risks and attacks, while adhering to the company's IT policies, processes, and procedures
- Experienced in assessing security risks, managing incidents, and implementing security measures to mitigate threats.
- Interested in conducting research into IT security issues and products.
- An analytical thinker who can identify gaps in existing architectures and design new security architectures to further improve Triton's IT Security infrastructure.
- Committed to providing service excellence to internal and/or external clients and customers.
- Conscientious, consistent, organized, and demonstrate strong attention to detail.
- An active listener and team-player who strives to communicate openly, honestly, and respectfully within a highly collaborative environment.
- Driven and willing to grow and develop, consistently exhibiting the ability and desire to learn new skills relating to IT Security
What We Offer:
- *Competitive salary: expected base salary range for this role is $89,000 - $120,000 per year
- Bonus potential
- Comprehensive benefit plans
- Generous time off
- Learning and development
- Employee Resource Groups (ERGs)
- Hybrid working schedule of 3 days in the office (Monday - Wednesday)
*The expected base salary range for this role is referenced above. It is not typical for offers to be made at or near the top of the range. Salary offers are based on a wide range of factors including location, relevant skills, training, experience, education, and, where applicable, licensure or certifications obtained. Market and organizational factors are also considered. In addition to salary and a generous employee benefits package, successful candidates are eligible to receive a discretionary bonus. How to Apply: Ready to join our team? Visit our career's portal at https://www.tritoninternational.com/careers We look forward to hearing from you! Triton is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment and will not be discriminated against on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, protected veteran status, or any other characteristics protected by federal, state, or local law.
|