|
|
Careers At UN1F1ED2 Global Packaging Group
We offer excellent benefits including health, dental, vision, life, STD, LTD, EAP, FSA, 401K, vacation, and paid holidays.
UN1F1ED2 Global Packaging Group is an Equal Opportunity Employer.
Current job opportunities are posted here as they become available.
IT Security Engineer
Job Title : IT Security Engineer
Reports To: IT Manager
FLSA Status: Exempt
Department: IT/IS
Division: 100
Pay Range to Start : $125K - $ 150 K ( Based on Experience )
Summary
The IT Security Engineer is responsible for administering and strengthening the organization’s cybersecurity program across infrastructure security, compliance, and user awareness. This role leads security patching and vulnerability remediation for servers and network-connected hardware; manages internal audits, compliance documentation, and the System Security Plan (SSP); supports risk assessments and disaster recovery testing; and drives security training and awareness initiatives. The position partners closely with the Senior Network Engineer, who retains ownership of server architecture, configuration, and infrastructure standards as well as technology procurement.
Essential Duties and Responsibilities
Security Patching and Vulnerability Management
- Own security patching and vulnerability remediation for all servers, network-connected hardware, and infrastructure systems
- Plan, schedule, test, and deploy security updates in coordination with infrastructure owners and maintenance windows
- Validate patch compliance, document exceptions, and track remediation status to closure
- Perform vulnerability scanning, risk prioritization, and remediation follow-up across server and hardware platforms
- Coordinate with the Senior Network Engineer, who retains ownership of server architecture, configuration, and overall infrastructure standards
Security Operations and Monitoring
- Monitor security alerts, logs, and anomalies across systems, endpoints, and supported security platforms
- Investigate security events and coordinate remediation with internal teams and third-party providers
- Support threat detection, incident response, and control validation using available monitoring and security tools
- Administer endpoint protection, antivirus, and related detection technologies
Incident Response and Recovery
- Serve as a primary responder or coordinator during cybersecurity incidents
- Perform incident triage, root cause analysis, containment coordination, and recovery support
- Coordinate with internal stakeholders and external vendors during active incident response
- Document incidents, lessons learned, and corrective actions to improve future response readiness
Identity and Access Security
- Review and validate identity-related security settings, access risks, and MFA compliance
- Support periodic access reviews and identify remediation needs for excessive or outdated access
- Partner with system and infrastructure administrators to enforce least-privilege and role-based access practices
- Support audit readiness for access control compliance
Network and Security Infrastructure Support
- Support firewall, VPN, remote access, and related security operations without owning core network configuration
- Review security posture and recommend hardening improvements for network and infrastructure platforms
- Monitor for suspicious traffic or activity and escalate concerns as appropriate
- Coordinate implementation and verification of approved hardening standards across servers and hardware platforms
Compliance, Audits, and Security Program Support
- Plan and conduct internal security audits, control reviews, and remediation tracking across applicable frameworks and internal requirements
- Coordinate risk assessments, evaluate control effectiveness, and track corrective actions to closure
- Manage the System Security Plan (SSP), including updates to scope, system boundaries, control implementation statements, and supporting evidence
- Coordinate audit readiness activities and support external assessments, customer questionnaires, and compliance reviews
- Support business continuity and disaster recovery planning activities, including test coordination, documentation of results, and follow-up on corrective actions
- Lead security training and awareness initiatives for employees and internal stakeholders
Documentation, Policy, and Process Ownership
- Develop, maintain, and govern security documentation, including policies, standards, procedures, control evidence, and audit artifacts
- Maintain related compliance documentation as systems, controls, or scope change
- Develop and improve repeatable IT and security processes, standards, and compliance workflows
- Prepare awareness materials, training content, and recurring security communications
Vendor Coordination and Tool Management
- Act as an internal technical owner for assigned security tooling and backup/disaster recovery platforms
- Coordinate with third-party providers, including MDR, MSP, auditors, and other security or compliance partners
- Evaluate and recommend security tools, platform improvements, and process enhancements
- Serve as the security and compliance reviewer for hardware procurement, partnering with the Senior Network Engineer to evaluate proposed equipment and verify its inclusion on all applicable approved product, compatibility, security, and CMMC compliance lists before purchase approval.
Qualifications
-
Bachelor’s degree in Information Technology, Cybersecurity, Computer Science, or a related field preferred; equivalent experience will be considered
- 3–5+ years of experience in cybersecurity, systems security, compliance, or infrastructure security roles
- Experience conducting risk assessments, control reviews, vulnerability remediation, and internal audit preparation
- Experience supporting business continuity and disaster recovery planning, test execution, documentation, and corrective action tracking
- Working knowledge of NIST 800-171, CMMC, DFARS, CUI handling, and general IT compliance practices
- Knowledge of endpoint protection, patch management, system hardening, access control, and security monitoring concepts
- Ability to develop and maintain policies, standards, procedures, audit evidence, and technical security documentation
- Strong communication, organization, and cross-functional collaboration skills
Preferred Certifications
- CompTIA Security+
- CompTIA Network+
- CompTIA CySA+ or a comparable security operations certification
- ISC2 Certified in Cybersecurity (CC) or CISSP, depending on experience level
- CMMC Registered Practitioner (RP) or a comparable compliance-focused credential preferred
- ITIL, Microsoft security, or vendor-specific endpoint and security platform certifications are a plus
Work Environment
- The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.
- This role is primarily office-based with routine interaction with end users, IT staff, server rooms, network closets, and production or warehouse areas as needed.
- The position may require occasional after-hours work for patching, maintenance windows, incident response, disaster recovery testing, or audit preparation activities.
- The employee may occasionally be exposed to moderate noise, moving mechanical parts, elevated work areas, or risk of electrical shock when working around technical equipment.
- Occasional travel to other divisions, branch locations, or customer sites may be required.
Physical Demands
- The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.
- The employee must occasionally lift and/or move equipment or materials up to 30 pounds.
- The employee is regularly required to sit, use hands, speak, hear, and work at a computer for extended periods.
- The employee is occasionally required to stand, walk, bend, reach, climb, balance, stoop, kneel, crouch, or crawl when accessing equipment, cabling, or technical spaces.
- Specific vision abilities required by this job include close vision and the ability to adjust focus for reading screens, labels, technical documentation, and diagrams.
Applicant Tracking System Powered by
|