View All Jobs

Information Systems Security Engineer

EAU CLAIRE, WI - Corporate Office | Full Time | Information Systems
  • Apply
Job Description

Why Work for Menards?

  • Profit Sharing & 401K, Paid Vacation & Holidays
  • Team Member Discount
  • Highly collaborative work environment
  • Pay based on experience

 

POSITION SUMMARY:

The Security Engineer is responsible for developing and implementing key security controls. This position is crucial in maintaining effective protection of the corporation’s Team Member and Guest information. This position requires a highly motivated, team-oriented person with strong communication skills. Relocation to Eau Claire, WI required.

 

PRIMARY RESPONSIBILITIES:

  • Use Python to create custom reports and automate tasks to increase efficiency
  •  Manage vulnerability scans on systems and applications, ensuring flaws are detected in a timely manner
  •  Formalize internal audit processes to measure security control effectiveness
  •  Collaborate with system-owners to determine appropriate changes to mitigate vulnerabilities
  •  Develop workflows to systematically validate security controls
  •  Drive continuous improvement across vulnerability management processes
  •  Assist in selection and implementation of new security controls
  •  Maintain a working knowledge of IS Security applications and systems and provide support to other IS teams as needed
  •  Collaborate on risk assessments and recommend controls to reduce risk

 

 

Skills & Requirements

POSITION REQUIREMENTS:

  •  Bachelor’s degree in Computer Science, MIS, related field or equivalent work experience
  •  Minimum of 2 years of experience in Information Technology, with at least 1 year of Information Security experience
  • Good understanding of application security concepts
  •  Experience evaluating and prioritizing vulnerabilities
  •  Experience in scripting for automation
  •  Proficient in Python
  •  Strong verbal and written communication skills
  •  Excellent analytical skills for root-cause determination and resolution
  •  Ability to work independently and effectively manage multiple tasks
  •  Must work within designated normal office hours assigned
  •  May be required to work overtime and provide on call support, including weekends and holidays
  •  Candidates must be eligible to work in the United States without sponsorship

 

PREFERRED QUALIFICATIONS:

  • Experience with web application and system vulnerability assessment tools such as Qualys, Nessus, or Nexpose
  •  Experience with security control testing through purple or red-team exercises
  •  One or more of the following certifications:
    •  GIAC GPEN
    • OffSec OSCP
    • ISC2 CISSP
  • Experience with security control validation
  • Experience with NIST CSF
  • Advanced Python skills
  • Experience with endpoint detection and response (EDR) or extended detection and response (XDR) solutions
  • Experience writing custom queries in security information and event management (SIEM) tools
  
Qualifications Don't see a job that meets with your interests? Sign up for a Job Alert to get notified when a job opens near you.