IT Security Engineer
- Salary
- $115K–$130K
- Hiring from
- United States
- Work type
- Hybrid
- Posted
Show job descriptionHide job description
FORTH (Set Forth, LLC) has been serving consumers who are exiting debt since 2009. As a trusted leader in debt resolution technology, FORTH provides powerful tools and secure payment solutions that empower consumers while giving clients an all-in-one platform to manage operations efficiently.
We have over 140 employees across various states supporting 450+ B2B relationships. Every department, every role, every person drives our success. We’re more than a company. We’re a community of thinkers & builders shaping the future of debt relief technology.
About the Role
The IT Security Engineer is responsible for ensuring the confidentiality, integrity, and availability of an organization’s information systems and data. This role involves designing, implementing, and
maintaining security measures to protect against cyber threats, vulnerabilities, and data breaches. The IT Security Engineer will work closely with other IT teams to deploy/maintain security technologies, monitor network activity, and respond to security incidents.
Responsibilities
Duties and Responsibilities include but are not limited to the following:
Network Security and Infrastructure Protection:
- Design and implement security architectures, policies, and procedures to protect company
- networks, systems, and data.
- Manage and configure firewalls, intrusion detection/prevention systems (IDS/IPS), and other
- network security technologies.
- Implement and manage Virtual Private Networks (VPNs), Secure Sockets Layer (SSL), and other
- secure communications protocols.
Endpoint Security:
- Deploy and maintain endpoint protection software (antivirus, endpoint detection and response - EDR, etc.).
- Monitor and enforce security controls across servers, workstations, mobile devices, and other endpoints.
- Perform regular vulnerability assessments and patch management to ensure endpoint security is up to date.
Incident Detection and Response:
- Monitor and analyze security alerts using Security Information and Event Management (SIEM) tools, leveraging AI-driven threat detection and automated log correlation.
- Investigate and respond to security incidents, utilizing automated incident response playbooks and AI tools to accelerate containment, mitigation, and recovery.
- Conduct post-incident analysis, prepare incident reports, and implement corrective actions to prevent recurrence.
AI Security and Governance:
- Enforce and monitor adherence to company AI Acceptable Use Policies and security guidelines across all enterprise tools and workflows.
- Assess and review third-party AI tools, plugins, and agents for security, data privacy, and compliance before organizational adoption.
- Implement and maintain safeguards to prevent unauthorized exposure of sensitive data, PII, and trade
- secrets in AI prompts and contexts.
- Deploy and manage AI security automation to continuously defend IT systems and accelerate threat mitigation.
Vulnerability Management:
- Regularly conduct vulnerability assessments and penetration testing on internal/external systems, including AI models, agents, and RAG pipelines.
- Collaborate with development teams to fix vulnerabilities and weaknesses in applications, systems, and infrastructure.
- Maintain an up-to-date inventory of vulnerabilities and ensure timely remediation.
Access Control and Identity Management:
- Design and implement strong identity and access management (IAM) solutions for human users and non-human/AI agent identities.
- authentication, authorization, and role-based access controls (RBAC).
- Enforce multi-factor authentication (MFA) and least privilege access across all platforms.
- Manage privileged access and ensure secure management of credentials.
Data Protection and Encryption:
- Ensure the encryption of sensitive data both at rest and in transit.
- Develop and implement data loss prevention (DLP) policies and monitor for potential data exfiltration risks.
- Assist with compliance initiatives and relevant data protection regulations.
Security Audits and Compliance:
- Conduct regular security audits to ensure compliance with industry standards, AI governance frameworks (e.g., NIST AI RMF), and internal policies.
- Prepare for and support external audits and certifications.
- Develop and maintain documentation for security policies, procedures, and best practices.
Training and Awareness:
- Conduct security awareness training for employees to promote a security-conscious culture.
- Provide guidance to other IT staff on security best practices and potential risks.
Additional Responsibilities
- Perform daily duties in line with Forth, LLC Information Security Policies and Procedures.
- Ensure that information Confidentiality, Integrity and Privacy is always maintained with processing information assets.
Qualifications and Required Skills
- Bachelor’s degree in information technology, Computer Science, or related field (or equivalent experience).
- 5 years of experience in IT security or related IT fields, with hands-on experience in network security, endpoint protection, and vulnerability management.
- Strong knowledge of network protocols, firewalls, VPNs, and encryption techniques.
- Experience with SIEM tools (e.g., Splunk, SolarWinds, ArcSight).
- Hands-on experience with security incident management, including identifying, containing, and responding to cyberattacks.
- Familiarity with endpoint protection technologies and solutions (e.g., Sentinel One, CrowdStrike, Symantec, Carbon Black).
- Solid understanding of security best practices, including least privilege, secure software development, and data protection.
Preferred Certifications
- Certified Information Systems Security Professional (CISSP)
- Certified Ethical Hacker (CEH)
- Certified Information Security Manager (CISM)
- Certified Cloud Security Professional (CCSP)
- CompTIA Security+
- GIAC Security Essentials (GSEC)
- Cisco Certified Network Associate (CCNA) Security
Preferred Technical Skills
- Proficiency with firewalls, VPN, IDS/IPS, and other network security devices.
- Strong knowledge of operating systems (Windows, Linux, Unix, etc.) and security configurations.
- Familiarity with cloud security principles and platforms (e.g., AWS, Google Cloud).
- Experience with scripting or automation (e.g., Python, PowerShell, Bash) is a plus.
- Working knowledge of security standards and frameworks (e.g., NIST, ISO 27001, CIS Controls).
- Familiarity with AI security risks (e.g., prompt injection, data leakage), AI security standards (e.g., NIST AI RMF, OWASP Top 10 for LLMs), and AI-assisted security tools.
Soft Skills:
- Strong analytical and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to work independently and as part of a collaborative team.
- Strong attention to detail and a proactive approach to security.
- Ability to prioritize and manage multiple tasks effectively in a fast-paced environment.
Pay Range and Compensation Package
- $115,000 - $130,000
- Full-time, benefits-eligible
- 401K, medical, dental, vision, PTO, holidays, flexible work arrangements, professional development opportunities, etc.
In-Office Requirements
- This role requires a minimum of two days per week in office.
Reports to
- Chief Security and Compliance Officer
Location
- Schaumburg, IL