Founded in 1971, Gypsum Management & Supply, Inc. (GMS) is the leading North American specialty distributor of interior building products. Our product offerings of wallboard, ceilings and complementary construction products are designed to provide a comprehensive solution for our core customer- building contractors who install our products in commercial and residential buildings. GMS's operating model enables GMS to continue to grow and expand in scope, while maintaining a high level of customer service, promoting an entrepreneurial culture, and preserving the customer intimacy of a local business.
GMS and its family of companies operate a network of nearly 300 building product distribution yards, and more than 100 tool sales and service centers, for customers across the U.S. and Canada. The Field Support Center in Tucker, Georgia serves each GMS location, providing the support needed to enable local teams to deliver outstanding service to contractors and builders in their local communities.
Qualified applicants with arrest or conviction records will be considered for employment in accordance with state and local law.
Position Summary:
The primary functions of the BMC Senior Security Engineer include acting as technical and hands-on for Cyber Security Projects; Support Enterprise Security Technologies; Full Endpoint lifecycle management using the Client Management platform; Assess and modify procedures to ensure the safety of information systems assets and protect systems from intentional or inadvertent access, modification, or destruction; Prioritize remediation of gaps based on internal and external audits.
Duties & Responsibilities:
- Act as technical hands-on for Cyber Security Projects.
- Support Enterprise Security Technologies.
- Client Management platforms.
- Assess and modify procedures to ensure the safety of information systems assets and to protect systems from intentional or inadvertent access, modification, or destruction.
- Write security reports and make recommendations.
- Prioritize remediation of gaps based on internal and external audits.
- Work with stakeholders to provide security solutions that support their business requirements
- Identify, develop, and implement mechanisms to detect security incidents in order to enhance compliance with and support of security standards and procedures in place.
- Conduct security risk assessments on new products and systems, periodic security risk assessments on existing systems and identify and/or recommend appropriate security countermeasures and best practices.
- Respond to discovered security incidents by informing appropriate custodians, determining root cause, and identifying and executing remedial actions (if necessary) required to re-establish respective information system security.
- Assist management in setting up strategic planning of information security, compliance and internal audit policies and procedures to ensure compliance with the security and privacy regulations and state and federal laws protecting customer and employee confidentiality and privacy.
- Maintain awareness of changes in security risks, security measures, and computer systems assessing new requirements for current and emerging compliance regulations.
Basic Qualifications:
- In lieu of a degree, 10 or more years of relevant experience may suffice. Bachelor's degree in Computer Science preferred.
- Minimum of 10 years of information systems security or related auditing experience.
- Preferred certifications: CCNA, CCNP, CISSP, CEH, CISA or equivalent.
- Hands-on experience with client management tools like SCCM, Intune, Altiris or BMC Client Management, with full lifecycle experience in endpoints and servers.
- Ability to clearly communicate Information Security matters to executives, auditors, end users, and engineers, using appropriate language, examples, and tone.
- Strong analytical, technical, and problem-solving skills.
- Ability to work effectively, independent of assistance or supervision.
- Self-starter, Innovative, creative, and extremely responsive, with a strong sense of urgency.
- Willing to share knowledge and assist others in understanding technical and business topics.
- Willingness to work outside of regular business hours as required, which can include evenings, weekends, and holidays.
- Experience with a variety of security products including, but not limited to, endpoint security, network security, MFA, and DMZ silos.
- Working knowledge of information systems security standards and practices (e.g., access control and system hardening, system audit and log file monitoring, security policies, and incident handling).
- Experience with TACACS+, IDS, IPS and various SIEMS.
- Working knowledge of protocols and technologies such as Secure DNS, TCP, NTP, UDP, SSL, TLS, SFTP, SMTP, and DHCP.
- At least one technical certification related to a major platform.
- Ability to quickly understand security systems in order to identify and validate security requirements.
Recommended Skills and Capabilities:
- Experience with performing vulnerability scans and assessments as well as computer forensics.
- Information Security best practices and common processes.
- A solid understanding of various firewalls, with actual experience in design, installation, configuration, and operation.
- Knowledge of network protocols, data flows, and vulnerabilities within a TCP/IP environment
- Ability to perform network protocol analysis and raw data capture.
- A solid understanding and knowledge of LDAP.
- Knowledge of NIST, OWASP , ISO 27001/2, PCI-DSS.
- Self-motivated, self-directed and shows attention to detail while working.
- Works ethically and with integrity supporting organizational goals and values.
- Displays commitment to excellence.
- Completes work in a timely manner and meets deadlines.
- Contributes to building a positive team spirit and treats others with respect.
- Maintains confidentiality of information and uses information appropriately.
- Exhibits sound judgment when making decisions and recommendations.
- Fosters collaboration toward a common vision and shared goals.
Core Competencies:
- Strive to do the right thing by displaying trust and integrity.
- Embody the principles of servant leadership, even in a non-people management role, by putting the needs of others first, valuing diverse perspectives by sincerely appreciating and considering others' opinions and ideas and demonstrating a positive and humble attitude.
- Demonstrated ability to work independently and on a team; ability to lead, execute and/or delegate as needed, while also collaborating with others to get the job done.
- Establish and maintain effective working relationships at every level of the organization; invest in building relationships with the Field Operations and Field Support Center team members.
- Ability to self-manage, show initiative, be proactive, and drive results.
- Communicate professionally, both verbally and in writing to coworkers and customers.
Physical Requirements:
- Must be able to remain in a stationary position in an office environment 80% of the time.
- Will frequently move about inside the office to access files, office machinery, etc.
- Must be able to operate basic office machinery.
- Must be able to communicate with team and management and be able to exchange accurate information in these situations.
- Must be able to travel occasionally.
Required Cognitive Skills:
- Must be able to problem solve and prioritize tasks.
- Must be able to complete work in a timely manner and meet deadlines.
- Must be able to manage stress depending on deadlines and ongoing projects.
- Must be able to multitask.
- Must be able to receive and analyze technical information.
- Must be able to quickly communicate solutions if problems occur.
- Must be able to demonstrate a high degree of sound judgement and initiative.
Benefits & Perks:
- Medical, Dental, Vision, Disability & Life Insurance
- Wellness Benefits
- 401(k) Retirement Plan
- Employee Stock Purchase Program
- Paid Holidays & Vacation Days
- Professional Growth Opportunities
- Development & Training Programs
This job description is subject to change at any time.
EQUAL OPPORTUNITY EMPLOYER
Launch your career with a national building materials distributor and discover opportunities for growth and advancement. We value our team members and believe them to be our greatest assets. As such, we invest in training and strive to provide a work-life balance.
We are a smoke-free workplace committed to providing a safe and healthy environment for all. Smoking, including the use of e-cigarettes, is only permitted in designated areas and is prohibited in and around all company buildings, vehicles, and workspaces. Violations of this policy may result in disciplinary action.
|