Junior Cybersecurity Engineer at American National Standards Institute | NY, US | Rezi

Junior Cybersecurity Engineer at American National Standards Institute

Junior Cybersecurity Engineer

American National Standards Institute · NY, US

Today

Junior Cybersecurity Engineer

American National Standards Institute · NY, US

8 hours ago
Resume preview

Impress employers and recruiters.
Choose from hundreds of resume examples.

Target Resume Now
Resume preview

Tailor your resume to this Junior Cybersecurity Engineer role.

Rezi rewrites your resume against American National Standards Institute's job description. Free.

Resume score gauge reading 58 out of 100

Don't guess if your resume is good enough.

See how it scores against the Junior Cybersecurity Engineer posting at American National Standards Institute — free, in seconds.

About the Role

The Junior Cybersecurity Engineer supports the day-to-day protection of ANSI and ANAB information systems, applications, and data. This entry-level role offers exposure to both hands-on security operations and security assurance, reporting to the Chief Information Security Officer (CISO) for technical supervision and mentoring.

Responsibilities

  • Maintain an accurate inventory of systems, infrastructure, and applications, verifying logging to the SIEM and coverage by security controls.
  • Validate security configurations and access rights on security tooling, firewalls, IPS, WAF, and endpoint protection, reporting deviations.
  • Support the change management process for firewall rulesets, including review, documentation, and periodic rule recertification.
  • Represent IT Security interests during weekly CAB meetings.
  • Assist in enforcing network segmentation and secure architecture.
  • Assist in the Vulnerability and Threat Management Program and endpoint configuration hardening.
  • Assist with cloud security activities.
  • Verify timely deployment of security and critical patches, following up on overdue items.
  • Assist in operating and maintaining security infrastructure and automated security controls.
  • Support privileged activity monitoring and related investigations.
  • Assist with cryptographic key management tasks.
  • Review security and infrastructure logs for indicators of compromise and anomalous behavior, escalating confirmed issues.
  • Create, run, and improve Incident Response Playbooks.
  • Act as first-line support during security incidents, including triage, evidence collection, documentation, and assisting with recovery.
  • Assist in performing IT security assessments, identifying risks and non-compliance.
  • Schedule and coordinate vulnerability assessments and penetration testing, consolidating results and tracking remediation.
  • Perform IT security assessments of vendors and third parties against security requirements.
  • Identify, document, and report IT security risks, assisting in developing treatments.
  • Help develop, maintain, and monitor security standards, controls, and processes, tracking exceptions.
  • Provide security input into change projects and initiatives, assessing security risk and reviewing pre-go-live tests.
  • Assist in preparing evidence, responses, and remediation tracking for audits.
  • Contribute to security education and awareness activities.
  • Maintain documentation, procedures, runbooks, and reporting for management and auditors.
  • Track emerging threats, vulnerabilities, and security technologies relevant to the environment.

Requirements

  • Bachelor's degree in computer science, computer engineering, information security, information systems, mathematics, or a related field, or an associate's degree with relevant experience or a recognized technical certification.
  • 5 years of professional experience in an information security role with genuine security exposure.
  • Prior contact with both operational security work and audit or compliance activity is an advantage.
  • Familiarity with business continuity and IT disaster recovery concepts is a plus.
  • Working knowledge of networking fundamentals (TCP/IP, DNS, routing, network segmentation), Windows and Linux operating systems, and cloud/SaaS concepts (Microsoft 365 and Azure preferred).
  • Familiarity with core security tooling, SIEM and log management, endpoint protection EDR, firewalls, IPS/WAF, vulnerability scanners, MFA, and identity management.
  • Comfortable using basic scripting (PowerShell, Python) for reporting and repetitive tasks.
  • Exposure to recognized security and risk frameworks (NIST CSF, NIST SP 800-53, ISO/IEC 27001 and 27002, CIS Controls) is preferred but not essential; willingness to learn and apply them is.
  • Rigor and attention to detail, particularly in evidence and documentation.
  • Ability to take direction and act on feedback, manage a queue of tasks without prompting, and communicate when something is not understood.
  • Curiosity and a habit of self-directed learning.
  • Understanding that security exists to protect the organization's mission, members, and activities, not to obstruct them.
  • Ability to explain risk in plain language to non-technical colleagues, ask before assuming, and recognize when an issue must be escalated.
  • Ability to handle confidential and sensitive information with discretion.
  • Occasional availability outside standard business hours during security incidents, remediation windows, or audit deadlines.
  • Interest in progressing toward a security engineering or GRC specialization, with a development path defined and supported by the Senior Cybersecurity Engineer.

Skills

  • Security Operations
  • Security Assurance
  • Log and Alert Review
  • Security Tooling
  • Endpoint Hardening
  • Vulnerability Management
  • Patch Management
  • IT Security Assessments
  • Vendor Reviews
  • Compliance Checks
  • Risk Reporting
  • SIEM
  • Log Management
  • Firewalls
  • Intrusion Prevention Systems (IPS)
  • Web Application Firewalls (WAF)
  • Endpoint Protection
  • Anti-malware
  • Change Management
  • Network Segmentation
  • Secure Architecture
  • Vulnerability and Threat Management
  • Cloud Security
  • Patch Deployment
  • Privileged Activity Monitoring
  • Cryptographic Key Management
  • Indicators of Compromise (IOCs)
  • Incident Response Playbooks
  • Triage
  • Evidence Collection
  • Disaster Recovery
  • Penetration Testing
  • Risk Assessment
  • Security Standards
  • Security Controls
  • Security Processes
  • Risk Treatment
  • Audits
  • Security Education
  • Awareness Training
  • Documentation
  • Procedures
  • Runbooks
  • Reporting
  • Threat Intelligence
  • Vulnerability Tracking
  • Security Technologies
  • Business Continuity
  • IT Disaster Recovery
  • Networking Fundamentals
  • TCP/IP
  • DNS
  • Routing
  • Windows Operating Systems
  • Linux Operating Systems
  • Cloud Concepts
  • SaaS Concepts
  • Microsoft 365
  • Azure
  • Security Tooling
  • SIEM
  • Log Management
  • Endpoint Protection (EDR)
  • Firewalls
  • IPS/WAF
  • Vulnerability Scanners
  • Multi-Factor Authentication (MFA)
  • Identity Management
  • Scripting
  • PowerShell
  • Python
  • NIST CSF
  • NIST SP 800-53
  • ISO/IEC 27001
  • ISO/IEC 27002
  • CIS Controls
  • Attention to Detail
  • Feedback Management
  • Task Management
  • Self-Directed Learning
  • Risk Communication
  • Escalation
  • Confidentiality
  • Discretion

Location

  • Onsite

Work Type

  • Full-time

Experience Level

  • Entry-level
  • 5 years of professional experience

Education Level

  • Bachelor's degree in computer science, computer engineering, information security, information systems, mathematics, or a related field
  • Associate's degree combined with relevant hands-on experience
  • Recognized technical certification
  • CompTIA Security+
  • CompTIA CySA+
  • CompTIA Network+
  • ISC2 Certified in Cybersecurity (CC)

Salary/Compensations

  • $82,800 to $91,100

Benefits

  • Support for obtaining security certifications within the first twelve months

About the Company

  • ANSI provides equal employment opportunities to all employees and applicants for employment, and prohibits discrimination of any type because of race, gender identity or expression, color, national origin or ancestry, religion, creed, age, marital status, sex, sexual orientation, citizenship or authorized alien status, genetics, disability status, protected veteran status, or any other consideration protected by federal, state, or local laws.
  • ANSI policy also prohibits unlawful discrimination based on the perception that anyone has any of those characteristics.
  • This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.

Equal Opportunity

  • ANSI provides equal employment opportunities to all employees and applicants for employment, and prohibits discrimination of any type because of race, gender identity or expression, color, national origin or ancestry, religion, creed, age, marital status, sex, sexual orientation, citizenship or authorized alien status, genetics, disability status, protected veteran status, or any other consideration protected by federal, state, or local laws.
  • ANSI policy also prohibits unlawful discrimination based on the perception that anyone has any of those characteristics.
  • This policy applies to all terms and conditions of employment, including recruiting, hiring, placement, promotion, termination, layoff, recall, transfer, leaves of absence, compensation and training.