- Страна
- США
- Зарплата
- 125 000 $ – 130 000 $
Откликайтесь
на вакансии с ИИ

Associate Director, Information Security Engineer
Сильная социальная миссия организации, конкурентная заработная плата для некоммерческого сектора и полностью удаленный формат работы. Позиция предлагает хороший баланс между техническим лидерством и управленческими функциями.
Сложность вакансии
Роль требует глубоких знаний Splunk и опыта управления SIEM на уровне эксперта, а также понимания специфических стандартов (HIPAA, PCI). Высокая ответственность за координацию между MSSP и внутренними командами в режиме 24/7 добавляет сложности.
Анализ зарплаты
Предложенная зарплата ($125k - $130k) находится в пределах рыночного диапазона для некоммерческих организаций США, однако она несколько ниже медианы для коммерческого сектора (FinTech или BigTech), где аналогичные роли уровня Associate Director могут оплачиваться выше $150k. Тем не менее, для сектора NGO это очень достойное предложение.
Сопроводительное письмо
I am writing to express my strong interest in the Associate Director, Information Security Engineer position at Planned Parenthood Federation of America. With over five years of experience in cybersecurity and a deep technical background in SIEM management, particularly with Splunk, I am confident in my ability to strengthen PPFA’s security posture. My expertise in managing complex security event architectures and coordinating with MSSPs aligns perfectly with the requirements of this role.
Throughout my career, I have developed a robust understanding of compliance frameworks such as HIPAA and NIST, which are vital for protecting sensitive healthcare data. I am particularly drawn to this opportunity because of Planned Parenthood's mission to provide equitable access to reproductive health care. I am eager to apply my skills in vulnerability assessment, incident response, and security operations to ensure that the data of your patients, donors, and staff remains secure and resilient against evolving threats.
Составьте идеальное письмо к вакансии с ИИ-агентом

Откликнитесь в ppfa уже сейчас
Присоединяйтесь к миссии Planned Parenthood и защитите критически важные данные в роли ведущего инженера по информационной безопасности!
Описание вакансии
Planned Parenthood is the nation’s leading provider and advocate of high-quality, affordable sexual and reproductive health care for all people, as well as the nation’s largest provider of sex education. Planned Parenthood organizations serve all people with care and compassion, with respect, and without judgment, striving to create equitable access to health care. Through health centers, programs in schools and communities, and online resources, Planned Parenthood is a trusted source of reliable education and information that allows people to make informed health decisions. We do all this because we care passionately about helping people lead healthier lives.
Planned Parenthood Federation of America (PPFA) is a 501(c)(3) charitable organization that supports the independently incorporated Planned Parenthood affiliates, which operate non-profit health centers across the U.S. PPFA also works to educate the public on and advocate for issues of sexual and reproductive health. Formed as the advocacy and political arm of Planned Parenthood Federation of America, Planned Parenthood Action Fund is a separate non-profit membership organization tax-exempt under section 501(c)(4). The Action Fund engages in educational, advocacy, and limited electoral activity, including grassroots organizing, legislative advocacy, and voter education in furtherance of the Planned Parenthood mission.
Planned Parenthood Federation of America (PPFA) and Planned Parenthood Action Fund seek a dynamic and effective Associate Director, Information Security Engineer. This job reports directly to the Dir, Security Operations in the Information Security division of PPFA. The Office of Information Security provides the strategy and implementation of the information security program that safeguards the data entrusted to Planned Parenthood by its patients, supporters, donors, and staff.
Purpose:
- The Security Engineer manages Information Technology security protections with the goal of protecting PPFA from and reducing the impact of security incidents and system compromises for the organization. This position provides security monitoring, event investigation and analysis, and countermeasure proposals on a 24x7 basis along with providing support and guidance to Tier I Analysts, will provide technical assistance for Tier II & III incidents as assigned, and is responsible to directly interface with the InfoSec Operations Team, Managed Security Service Provider (MSSP) and IT Managed Service Provider (MSP) as it relates to security event architecture, collection, management, reporting, and alerting within PPFA’s SIEM Platforms.
Engagement:
- The Security Engineer will engage with InfoSecOps, InfoSec, ITOps/MSP, the MSSP, ATS and staff within both PPFA and Affiliates.
Delivery:
The Security Engineer will deliver by identifying, implementing, and maintaining Information Security toolsets, primarily focused on SIEM, to protect the organization; interfacing with IT Ops to ensure proper security event logging setup; and, where applicable, supporting the Information Security SIEM management needs of PPFA and Affiliates.
- Act as a Subject Matter Expert for PPFA’s SIEM (currently Splunk) and be able to configure, manage, operate, and administer the platform from a managed SIEM perspective.
- SIEM Security Monitoring – Provide security monitoring and threat/risk analysis in a 24/7 environment.
- SIEM Event Filtering – Monitor & ensure established processes for event identification are followed, and, where required, make recommendations for new or refined event filtering, ensuring all updates are completed.
- SIEM Event Investigation & Assignment – Monitor & ensure established processes are followed for collecting relevant data and performing the necessary levels of analysis on that data. Ensure events are assigned appropriately.
- Tier II Event Escalations - Follow an established process for handling Tier II escalations, identifying the source of the escalation (MSSP, MSP, Affiliate, or other) and the appropriate triage and documentation processes.
- Creating and maintaining Standard Operating Procedures (SOPs) for the Information Security Ops group, and providing recommendations on security process improvements
- Support and engage on complex security tool-specific tasks with the assistance and guidance of management, vendor & MSSP resources
- Assist in Vulnerability Assessments setup, scanning, analysis, and remediations, working with IT Ops staff and corporate vendors as needed in correcting errors and alerts as found with the IT infrastructure systems.
- Assist in IR incidents as assigned by management
- All other duties as assigned
Knowledge, Skills and Abilities (KSAs):
- Bachelor’s degree and 5+ years of industry experience
- Passion to work on newer technologies and explore the security domain.
- Independent decision-making capabilities, especially in identifying analysis tracks for escalated events, analysis assignments, and escalation decisions ranging from a base Tier I event to Incident Response level remediations.
- Experience in compliance requirements and industry standards like PCI, HIPAA, ISO 27001, NIST, CSF, MITRE ATT&CK, ITIL, COBIT, Sarbanes-Oxley, and SANS 20.
- UNIX, AIX & Solaris, Linux, Windows Server Operating Systems
- Network/System Intrusion Detection or Prevention Systems (IDS/IPS)
- Security Information and Event Management (SIEM)
- Vulnerability scanner/Penetration testing systems
- Wireless Networking
- Switches/Routers, Firewalls (basic configuration)
- TCP/IP networking, VPN, VLAN, NAT, and security concepts
- Software & Hardware Asset Management
- Security threat and attack countermeasures
- Experience conducting forensic analytical studies and investigations
- Flexibility and ability to adapt to quickly changing priorities and ambiguous situations
- A deep commitment to Planned Parenthood’s mission of promoting Sexual and Reproductive Health
Travel: (0-10% travel as needed)
Planned Parenthood's cultural ethos, "In This Together", reflects our commitment to building a workplace culture that fosters belonging, promotes learning throughout the employee lifecycle, and recognizes individual contributions to our mission.
Planned Parenthood Federation of America participates in the E-Verify program. Planned Parenthood Federation of America is an equal employment opportunity employer and is committed to maintaining a non-discriminatory work environment, and does not discriminate against any employee or applicant for employment on the basis of race, color, religion, sex, national origin, age, disability, veteran status, marital status, sexual orientation, gender identity, or any other characteristic protected by applicable law. Planned Parenthood is committed to creating a dynamic work environment that values diversity and inclusion, respect and integrity, customer focus, and innovation.
Создайте идеальное резюме с помощью ИИ-агента

Навыки
- Linux
- PCI DSS
- Information Security
- HIPAA
- Incident Response
- TCP/IP
- Windows Server
- Firewalls
- Forensics
- SIEM
- IDS/IPS
- MITRE ATT&CK
- Splunk
- Vulnerability Assessment
- NIST CSF
Возможные вопросы на собеседовании
Роль требует статуса эксперта (SME) по Splunk. Работодателю важно понимать практический опыт настройки.
Опишите ваш опыт администрирования Splunk: как вы настраивали сбор данных и оптимизировали правила корреляции для снижения количества ложных срабатываний?
Позиция подразумевает работу с медицинскими данными. Знание HIPAA критично для этой организации.
Какие специфические требования безопасности HIPAA вы учитываете при проектировании архитектуры логирования и мониторинга?
Вакансия включает взаимодействие с внешними провайдерами (MSSP/MSP). Важно уметь эффективно выстраивать процессы.
Расскажите о вашем опыте взаимодействия с MSSP. Как вы контролируете качество их работы и обеспечиваете эффективную передачу инцидентов на уровень Tier II/III?
Инженер должен уметь не только находить уязвимости, но и помогать в их устранении.
Как вы выстраиваете процесс приоритизации уязвимостей после сканирования, если ИТ-команда ограничена в ресурсах для патчинга?
Работа в ИБ часто связана с неопределенностью и быстрой сменой приоритетов.
Приведите пример, когда вам приходилось принимать критическое решение по инциденту в условиях неполной информации. Каков был результат?
Похожие вакансии
ДИРЕКТОР ДЕПАРТАМЕНТА ИНФОРМАЦИОННОЙ БЕЗОПАСНОСТИ
Director of IT & Security
Director of IT & Security
Director of Cybersecurity / Information Security
Специалист по защите информации (Mobile Security Engineer)
Senior Information Security (ИБ)
1000+ офферов получено
Устали искать работу? Мы найдём её за вас
Quick Offer улучшит ваше резюме, подберёт лучшие вакансии и откликнется за вас. Результат — в 3 раза больше приглашений на собеседования и никакой рутины!
- Страна
- США
- Зарплата
- 125 000 $ – 130 000 $