Job description
Information Security Engineers
Job purpose
To develop information security standards, policies and controls, build and maintain the technology protecting the organisation's networks and data, and monitor, investigate and respond to breaches and intrusions, so that digital files and electronic infrastructure remain protected and weaknesses are closed before exploitation.
Skills
- Knowledge of computers and electronics across hardware, software and applications development, supported by engineering and technology and by telecommunications. Specialist command of penetration testing and vulnerability assessment method, perimeter protection and encryption technology, security control design, forensic examination of breaches, and the cybersecurity standards against which computing environments are reviewed. A bachelor's degree is the norm, with a substantial minority qualified by post-secondary certificate or shorter college study, and several years of related experience and on-the-job training.
- Trains staff in information security standards and best practice and oversees their use; recommends enhancements to management and explains technical exposure in terms non-specialists can act on; supports users installing and operating security products; and deals with parties outside the organisation. Coordinates others engaged in monitoring and assessment.
- Identifies weaknesses through penetration testing, scans networks with vulnerability assessment tooling, judges existing controls against performance indicators, and investigates breaches to establish how access was obtained and what damage was done. The problems are adversarial and often novel: an intrusion method may have no settled precedent, and a wrong call either leaves the exposure open or obstructs legitimate operation.
- Develops response and recovery strategies for breaches and oversees plans to safeguard computer files against accidental or unauthorised modification, destruction or disclosure. Determines own tasks and priorities under time pressure.
- Work is carried out at a workstation using monitoring, testing and development environments. No manual handling or dexterity demands.
Responsibilities
- No formal line management, but guides and directs the work of others and carries some accountability for their output. Coordinates the monitoring of networks and systems for breaches, oversees vulnerability and risk assessments and system testing, and oversees documentation of security and emergency measure policies. The standards and training set here govern how the rest of the organisation handles its systems.
- No budget is held. Recommends security enhancements and the tooling to give effect to them, with some oversight of the resources committed to monitoring; authority to commit expenditure rests above the role.
- Builds, maintains and upgrades the organisation's security technology — firewall and encryption software, detection and prevention tooling, vulnerability scanning instruments — and develops further tools to detect and analyse threats. Accountable for the configuration and continued functioning of that estate.
- Accountable for the confidentiality and integrity of digital files and electronic infrastructure. Writes reports on breach investigations and network evaluations, coordinates documentation of security policies and procedures, and reviews computing environments for compliance with cybersecurity standards. The material held is sensitive in its content and in what it discloses about the organisation's own weaknesses.
Effort required
- Exacting attention over long stretches of detailed technical work: test output, scan results and control indicators must be read precisely, because the failure that matters is the anomaly not noticed. Judgement is exercised frequently, under time pressure and on incomplete information while an incident is live, with effects reaching co-workers and company results.
- Personal accountability is pronounced: breaches must be investigated and reported to management, including where the cause is a control the postholder designed. Requires composure while an incident is running. No exposure to distress or aggression.
- Predominantly seated work at a workstation. No lifting or exertion.
Working conditions
- Indoor, environmentally controlled office work throughout, without hazard, noise or weather exposure, and no contact with aggressive or distressed people. Psychological demand arises from a high volume of contact by electronic mail, telephone and face-to-face discussion, and from the consequence of an error in a security control.
- Most posts follow a regular established schedule, a minority varying with production or contract demands, and the working week more often than not runs beyond forty hours; no shift or on-call obligation is evidenced. Autonomy is considerable: tasks, priorities and goals are largely set by the postholder, and decisions are frequent and reach beyond the immediate team. Work is done under time pressure, in a competitive field, inside recognised security standards.