Up-to-date knowledge of the IT security industry, including new or revised security solutions, improved security processes, and new vulnerabilities, attacks, and threat vectors
Experience with tools and technologies: Rapid7, Microsoft O365 Security solutions, Microsoft Azure Cloud Security, Palo Alto Networks Firewalls, Security Orchestration and Automation Tools, Fireeye Helix, Zscaler, Infoblox, MS Project, Penetration Testing using Kali Linux, F5, and Endpoint Security Technologies
Ability to work with IT leaders to instill Information Security industry best practices across IT, including development, third-party software support, database administration, and enterprise architecture
Responsibilities
Develop and implement a strong Information Security practice at SpartanNash
Provide oversight of the confidentiality, integrity, and availability of data residing on or transmitted to/from/through enterprise workstations, servers, systems, databases, and other data repositories
Manage day-to-day Information Security Operations
Manage Security Operations activities and personnel
Oversee security monitoring practices and analysis of security alerts
Supervise all investigations and provide ongoing communication with stakeholders and senior management
Lead and support the design and execution of vulnerability assessments, penetration tests, and security audits
Act as a point of escalation for the team and collaborate with enterprise teams during incidents
Handle and escalate security incidents as defined in incident response procedures
Facilitate and participate in eDiscovery and forensic investigations with outsourced vendors
Prepare reports and documentation for leadership detailing security evaluations and incidents
Establish Information Security processes for the team
Oversee deployment, integration, and initial configuration of new security solutions and enhancements to existing ones, in accordance with best operating procedures and enterprise security documents
Ensure projects are completed on time and within budget
Supervise, mentor, and train team members to meet job requirements on time
Delegate work assignments and coach team members to ensure systems are implemented according to specifications and standards
Design and deploy information security awareness training for all coworkers to ensure high compliance with SpartanNash’s Information Security Program
Establish, document, and enforce SpartanNash’s Information Security Policy
Partner with IT leaders to instill Information Security best practices across IT
Support strategic direction, policy, standard development, and process mapping for Information Security, leveraging quality and risk