Job Specifications
Winston-salem, NC
Remote
4 days ago
Last Jobs You Viewed
IT Security Engineer I
Job Summary:
The IT Security Engineer I supports the implementation, monitoring, and maintenance of security controls that protect NMG’s networks, systems, applications, endpoints, identities, and data. Working independently on established security processes and with guidance from senior IT leaders and security resources, this role monitors security alerts, investigates potential threats, supports incident response, and assists with vulnerability remediation and security compliance activities.
The IT Security Engineer I contributes to the ongoing improvement of NMG’s security posture by maintaining security controls, supporting audits and access reviews, documenting security activities, and helping strengthen security awareness across the organization. The role partners with IT and business stakeholders to resolve security issues, maintain reliable security operations, and apply established practices consistently across the environment.
Job Responsibilities:
Security Operations & Monitoring
- Monitors security alerts, logs, and protection systems to identify potential threats, vulnerabilities, and abnormal activity.
- Investigates security alerts and potential vulnerabilities using established procedures and escalates higher-risk issues appropriately.
- Supports the implementation and maintenance of security controls across networks, systems, applications, endpoints, email, and identity platforms.
- Performs routine security checks and reviews to confirm security controls are operating as expected.
- Documents security findings, actions taken, and remediation activities to support effective security operations and knowledge sharing.
Incident Response & Vulnerability Management
- Supports security incident response activities, including investigation, containment, remediation, documentation, and follow-up.
- Remediates security findings identified through vulnerability scans, third-party security tools, penetration testing, and other monitoring activities.
- Assists with root cause analysis and identifies recurring issues that may require additional controls or process improvements.
- Escalates security incidents, vulnerabilities, and control gaps based on established risk and response procedures.
- Participates in on-call and after-hours support as part of NMG’s 24/7 IT security coverage model.
Identity, Access & Security Controls
- Supports identity and access management activities, including user access reviews, role-based access, and least-privilege controls.
- Assists with maintaining appropriate security configurations across supported systems and platforms.
- Supports the review and documentation of security policies, standards, procedures, and operational controls.
- Performs assigned reviews of physical and technical security controls and escalates identified gaps.
Compliance & Risk Support
- Supports reviews of systems and processes against applicable security frameworks, regulatory requirements, and organizational standards.
- Assists with security audits by gathering documentation, validating evidence, and tracking assigned remediation activities.
- Supports disaster recovery and incident response procedures through testing, documentation, and assigned follow-up activities.
- Maintains accurate security documentation and evidence to support compliance, audits, and operational readiness.
Security Awareness & Stakeholder Support
- Supports end-user security awareness activities and reinforces established security practices across the organization.
- Responds to security-related questions and requests from internal stakeholders using established procedures and appropriate escalation.
- Communicates security risks, incidents, findings, and recommended actions clearly to technical and non-technical stakeholders.
- Collaborates with IT and business teams to resolve security issues while maintaining a strong focus on service, accountability, and business needs.
Continuous Improvement
- Identifies recurring security issues, workflow gaps, and opportunities to improve security operations.
- Recommends practical improvements to established security processes, controls, and documentation.
- Applies new security knowledge, tools, and practices to assigned responsibilities under appropriate guidance.
- Contributes to team initiatives that improve security reliability, consistency, efficiency, and scalability.
Job Competencies:
- Security Operations & Monitoring: Applies established security monitoring practices to identify, investigate, document, and escalate potential threats and vulnerabilities.
- Threat Detection & Incident Response: Uses defined response procedures to investigate security events, support containment and remediation, and document incident activity.
- Vulnerability Management: Evaluates assigned security findings, prioritizes remediation activities based on established criteria, and follows issues through resolution.
- Security Controls & Risk Awareness: Applies foundational security principles to maintain controls and recognize risks across systems, applications, networks, identities, and endpoints.
- Identity & Access Management: Applies established access management practices, including role-based access, access reviews, and least-privilege principles.
- Compliance & Security Governance: Supports security audits, control reviews, documentation, and compliance activities in accordance with established frameworks and organizational requirements.
- Problem Solving & Decision Making: Investigates routine and moderately complex security issues, applies sound judgment within established guidelines, and escalates issues requiring broader expertise or authority.
- Operational Excellence: Maintains accurate documentation, follows established procedures, and supports reliable security operations, including audit readiness and on-call responsibilities.
- Collaboration & Business Partnership: Works effectively with IT and business stakeholders to resolve security issues, coordinate remediation, and incorporate security practices into day-to-day operations.
- Continuous Improvement: Identifies opportunities to improve security processes, controls, documentation, and workflows and applies lessons learned to assigned work.
- Security Communication: Communicates security findings, incidents, risks, and required actions clearly to both technical and non-technical audiences.
Basic Qualifications:
- Minimum three (3) years of professional experience in IT security, cybersecurity, systems administration, network security, or a related field.
- Working knowledge of cybersecurity principles, common threats, defensive practices, and security controls.
- Experience monitoring security alerts, investigating security events, or supporting vulnerability remediation.
- Working knowledge of networking concepts, including TCP/IP, DNS, VPNs, and firewall technologies.
- Experience supporting Windows, Linux, and/or macOS environments.
- Working knowledge of identity and access management concepts, including authentication, authorization, role-based access, and least privilege.
- Familiarity with risk assessment, threat identification, security documentation, and incident response practices.
- Demonstrated experience documenting technical issues, findings, and remediation activities.
- Proficiency with common productivity and collaboration tools used to document, track, and communicate technical work.
Preferred Qualifications:
- Security certification such as Security+, SSCP, CEH, CCSP, CISSP, or equivalent.
- Experience supporting security frameworks, compliance standards, or audit processes such as PCI DSS, Zero Trust, or SOC 2.
- Hands-on experience with security tools for endpoint protection, vulnerability management, security monitoring, identity management, or incident response.
- Experience supporting security controls in cloud environments such as AWS, Azure, or GCP.
- Experience with IT Service Management (ITSM) and asset management platforms.
- Scripting or automation experience using tools such as PowerShell or Python.
- Familiarity with CI/CD pipelines and secure software development lifecycle practices.
- Experience supporting enterprise security operations across networking, identity and access management, vulnerability management, and incident response.
About NMG:
Nationwide Marketing Group works on behalf of thousands of independent appliance, furniture, bedding, electronics, specialty electronics, custom installation, and rent-to-own dealers, helping them grow their businesses and thrive on their own terms. With more than 5,000 members operating some 14,000 storefronts, Nationwide Marketing Group is the largest buying, marketing, and business support organization of its kind, representing billions in combined annual sales across the membership. For more than 50 years, we have remained committed to the independent channel, empowering members with the scale, sophistication, and efficiencies they need to compete while delivering the business intelligence, tools, and resources required to win in a changing marketplace. To learn more, visit nationwidegroup.org or our Nationwide Marketing Group LinkedIn page.
Why You Want to Work Here:
At Nationwide Marketing Group, we believe our strength comes from the diversity of our people and the communities we serve. We’re committed to building teams where every individual feels valued, included, and supported to do their best work. Different voices and perspectives do more than broaden our thinking. They help us serve our members better.
But culture at NMG goes beyond our commitment to diversity and inclusion. We’re a community built on collaboration, respect, and a shared drive to help independent businesses thrive. You’ll join a team that celebrates wins together, tackles challenges head-on, and invests in both professional and personal growth.
NMG is proud to be an equal opportunity employer. We do not discriminate based on race, color, sex, age, national origin, religion, sexual orientation, gender identity or expression, veteran status, disability, or any other protected characteristic. If you need reasonable accommodations during the hiring process, let us know and we’ll make sure you have the support you need.
What We’ll Do For You:
- Competitive base pay and performance bonus, dependent on role
- Medical, dental, and vision benefits with low-cost coverage options
- Employer paid basic life and AD&D
- Employer paid short-term and long-term disability
- MetLife supplemental insurance options
- Matching 401(k) with 100 percent vesting
- Open PTO policy, paid holidays, and ten weeks of paid parental leave
- Business casual work environment