Erie Insurance
IT Info Security Specialist (Finance)
At Erie Insurance, you're not just part of a Fortune 500 company; you're also a valued member of a diverse and inclusive team that includes more than 6,000 employees and over 13,000 independent agencies. Our Employees work in the Home Office complex located in Erie, PA, and in our Field Offices that span 12 states and the District of Columbia.
Benefits That Go Beyond The Basics
We strive to be Above all in Service® to our customers-and to our employees. That's why Erie Insurance offers you an exceptional benefits package, including:
Position Summary
Working independently or as part of a team, contributes to the planning, implementation, and management of the Information Security program to safeguard ERIE's digital assets. Implements and maintains security systems and procedures to govern, identify, protect, detect, respond to, and recover from cybersecurity risks, threats, vulnerabilities, and incidents. Completes and may lead assignments of moderate complexity within the Information Security portfolio with minimal guidance. Performs duties in one or more of the following Information Security disciplines, including but not limited to: Application Security (AppSec); Cloud Security (CloudSec); Governance, Risk Management & Compliance (GRC); Identity & Access Management (IAM); Security Operations (SecOps), or Vulnerability Management.
What Will You Do:
This opportunity is for a Senior or Professional IT Analyst on the Information Security Vulnerability Management Team. The Vulnerability Management analyst will be responsible for identifying, continuously monitor and verifying remediation of vulnerabilities in internal and external applications, endpoints, databases, networking, and mobile and cloud services. They will lead efforts to govern Vulnerability Management by informing, advising, and collaborating with technology leadership, application and asset owners, and business units in areas such as patch management, security protocol currency, and vuln management regulatory compliance.
Preferred Experience & Skills based on level:
• Knowledge of security vulnerability and patch management processes.
• Experience conducting vulnerability scans, coordinating vulnerability remediation or similar activities.
• Knowledge of network security architecture and infrastructure concepts.
• Knowledge of network traffic flows and protocols.
• Understanding of Windows and other operating systems, endpoint applications, networking protocols, and devices.
• Experience in analytic problem-solving and performing impact/risk assessments.
• Effective communication and presentation skills. Strong influencing and negotiation skills.
What Makes You Stand Out:
• Knowledge of one or more compliance standards, such as, NIST Cybersecurity Framework (NIST CSF), or New York Department of Financial Services Part 500 Cybersecurity Regulation, etc
• Proficiency with ServiceNow and Information Technology Infrastructure Library [ITIL].
Duties and Responsibilities
This position description in no way states or implies that these are the only duties to be performed by the incumbent. Employees are required to follow any other job-related instruction and to perform any other duties as requested by their supervisor, or as become clear.
Capabilities
Qualifications
Minimum Education and Experience Requirements
Additional Experience
Physical Requirements