# Information Security Engineer

*/JobTypes/Information_Security_Engineer*

## Neighborhood

### Related (delivered by)

- [Evaluate vulnerability assessments of local computing environments, networks, infrastructures, or en...](/Tasks/Evaluate_vulnerability_assessments_of_local_computing_environments,_networks,_infrastructures,_or_en...) — delivered by · Tasks
- [Test efficacy of security protocols](/Processes/Test_efficacy_of_security_protocols) — delivered by · Processes

### Who staffs this

- [Enterprise Fintech Provider](/CompanyTypes/Enterprise_Fintech_Provider) — staffs · CompanyTypes
- [Consumer Fintech Company](/CompanyTypes/Consumer_Fintech_Company) — staffs · CompanyTypes

### Perform

- [Remediate Vulnerabilities](/Tasks/Remediate_Vulnerabilities) — perform · Tasks
- [Harden Systems Against Security Vulnerabilities](/Tasks/Harden_Systems_Against_Security_Vulnerabilities) — perform · Tasks
- [Test controls for effectiveness](/Tasks/Test_controls_for_effectiveness) — perform · Tasks
- [Automate security detections](/Tasks/Automate_security_detections) — perform · Tasks
- [Integrate security into infrastructure](/Tasks/Integrate_security_into_infrastructure) — perform · Tasks
- [Implement Identity and Access Controls](/Tasks/Implement_Identity_and_Access_Controls) — perform · Tasks
- [Automate detection, response, and patching pipelines](/Tasks/Automate_detection,_response,_and_patching_pipelines) — perform · Tasks
- [Conduct architecture and threat-model reviews](/Tasks/Conduct_architecture_and_threat-model_reviews) — perform · Tasks
- [Design and deploy security controls and tooling](/Tasks/Design_and_deploy_security_controls_and_tooling) — perform · Tasks
- [Develop security automation scripts and integrations](/Tasks/Develop_security_automation_scripts_and_integrations) — perform · Tasks
- [Harden infrastructure and cloud configurations](/Tasks/Harden_infrastructure_and_cloud_configurations) — perform · Tasks
- [Integrate security into build and deployment pipelines](/Tasks/Integrate_security_into_build_and_deployment_pipelines) — perform · Tasks
- [Manage identity, access, and secrets infrastructure](/Tasks/Manage_identity,_access,_and_secrets_infrastructure) — perform · Tasks
- [Remediate vulnerabilities at the system level](/Tasks/Remediate_vulnerabilities_at_the_system_level) — perform · Tasks
- [Automate security monitoring and response](/Tasks/Automate_security_monitoring_and_response) — perform · Tasks
- [Evaluate and deploy security products](/Tasks/Evaluate_and_deploy_security_products) — perform · Tasks
- [Engineer security controls and tooling](/Tasks/Engineer_security_controls_and_tooling) — perform · Tasks
- [Remediate infrastructure vulnerabilities](/Tasks/Remediate_infrastructure_vulnerabilities) — perform · Tasks
- [Integrate security into deployment pipelines](/Tasks/Integrate_security_into_deployment_pipelines) — perform · Tasks
- [Harden system and network configurations](/Tasks/Harden_system_and_network_configurations) — perform · Tasks

### Required knowledge

- [Cryptography and Key Management](/Knowledge/Cryptography_and_Key_Management) — requires knowledge · Knowledge
- [Authentication and Authorization Protocols](/Knowledge/Authentication_and_Authorization_Protocols) — requires knowledge · Knowledge
- [Secure Architecture Design](/Knowledge/Secure_Architecture_Design) — requires knowledge · Knowledge
- [Network Security](/Knowledge/Network_Security) — requires knowledge · Knowledge
- [Cloud and network security architecture](/Knowledge/Cloud_and_network_security_architecture) — requires knowledge · Knowledge
- [Common attack techniques and mitigations](/Knowledge/Common_attack_techniques_and_mitigations) — requires knowledge · Knowledge
- [Secure software development practices](/Knowledge/Secure_software_development_practices) — requires knowledge · Knowledge
- [Secure Configuration Standards](/Knowledge/Secure_Configuration_Standards) — requires knowledge · Knowledge
- [Network Security Architecture](/Knowledge/Network_Security_Architecture) — requires knowledge · Knowledge
- [Identity and Access Management](/Knowledge/Identity_and_Access_Management) — requires knowledge · Knowledge

### Requires ability

- [Information Ordering](/Ability/Information_Ordering) — requires ability · Ability
- [Deductive reasoning](/Ability/Deductive_reasoning) — requires ability · Ability
- [Problem sensitivity](/Ability/Problem_sensitivity) — requires ability · Ability
- [Systems thinking](/Ability/Systems_thinking) — requires ability · Ability
- [Written expression](/Ability/Written_expression) — requires ability · Ability
- [Written Comprehension](/Ability/Written_Comprehension) — requires ability · Ability

### Type of

- [Information Security Engineer](/Occupations/Information_Security_Engineer) — type of · Occupations
- [Information Security Analysts](/Occupations/Information_Security_Analysts) — type of · Occupations

### Required skills

- [Detection Engineering](/Skills/Detection_Engineering) — requires skill · Skills
- [System Hardening](/Skills/System_Hardening) — requires skill · Skills
- [Programming](/Skills/Programming) — requires skill · Skills
- [Identity and access engineering](/Skills/Identity_and_access_engineering) — requires skill · Skills
- [Infrastructure and cloud hardening](/Skills/Infrastructure_and_cloud_hardening) — requires skill · Skills
- [Security automation scripting](/Skills/Security_automation_scripting) — requires skill · Skills
- [Security tooling engineering](/Skills/Security_tooling_engineering) — requires skill · Skills
- [Threat modeling](/Skills/Threat_modeling) — requires skill · Skills
- [Configuration Hardening](/Skills/Configuration_Hardening) — requires skill · Skills
- [Control Engineering](/Skills/Control_Engineering) — requires skill · Skills
- [Security Automation](/Skills/Security_Automation) — requires skill · Skills

### Uses software

- [Security Information and Event Management Software](/Software/Security_Information_and_Event_Management_Software) — uses software · Software
- [Endpoint Detection and Response Platform](/Software/Endpoint_Detection_and_Response_Platform) — uses software · Software
- [Infrastructure as Code Tool](/Software/Infrastructure_as_Code_Tool) — uses software · Software
- [AWS Security Hub](/Software/AWS_Security_Hub) — uses software · Software
- [CrowdStrike Falcon](/Software/CrowdStrike_Falcon) — uses software · Software
- [HashiCorp Vault](/Software/HashiCorp_Vault) — uses software · Software
- [Python](/Software/Python) — uses software · Software
- [Terraform](/Software/Terraform) — uses software · Software
- [Configuration Management Software](/Software/Configuration_Management_Software) — uses software · Software
- [Security Orchestration Platform](/Software/Security_Orchestration_Platform) — uses software · Software
- [Identity and Access Management System](/Software/Identity_and_Access_Management_System) — uses software · Software

### Engage in

- [Harden systems and configurations](/Activities/Harden_systems_and_configurations) — engage in · Activities
- [Automate detection, response, and patching pipelines](/Activities/Automate_detection,_response,_and_patching_pipelines) — engage in · Activities
- [Design and deploy security controls and tooling](/Activities/Design_and_deploy_security_controls_and_tooling) — engage in · Activities
- [Harden infrastructure and cloud configurations](/Activities/Harden_infrastructure_and_cloud_configurations) — engage in · Activities
- [Engineer security controls and tooling](/Activities/Engineer_security_controls_and_tooling) — engage in · Activities
- [Automate security monitoring and response](/Activities/Automate_security_monitoring_and_response) — engage in · Activities

### Problems this exposes

- [triaging duplicate CVE alerts across SIEM, EDR, and cloud-posture tools into one real exploit path](/Problems/triaging_duplicate_CVE_alerts_across_SIEM,_EDR,_and_cloud-posture_tools_into_one_real_exploit_path) — exposes problem · Problems
- [proving control effectiveness for SOC2/ISO audits from scattered evidence sources](/Problems/proving_control_effectiveness_for_SOC2%2FISO_audits_from_scattered_evidence_sources) — exposes problem · Problems
- [reconciling IAM least-privilege findings with the access engineering actually needs to ship](/Problems/reconciling_IAM_least-privilege_findings_with_the_access_engineering_actually_needs_to_ship) — exposes problem · Problems
- [mapping detection coverage gaps against the MITRE ATT&CK matrix for each new asset class](/Problems/mapping_detection_coverage_gaps_against_the_MITRE_ATT&CK_matrix_for_each_new_asset_class) — exposes problem · Problems
