What You'll Do:
The Information Security Junior Professional supports the organization's security program's risk and compliance activities. This role assists in policy documentation and day-to-day security operations.
Responsibilities
- Assists in the drafting, review and revision of information security policies, standards, procedures and guidelines; maintains documentation library.
- Supports audits, control testing, risk assessments and remediation activities.
- Assist with security awareness activities.
- Assess network and system configurations against applicable control requirements.
- Review Azure and AWS environment configurations for compliance with organizational standards.
- Interpret cloud shared responsibility models to determine which controls are inherited from the provider and which are the organization's obligation.
- Evaluate infrastructure evidence artifacts.
- Support hardening baseline reviews.
- Participate in security architecture reviews.
- Translate technical infrastructure findings into risk statements and remediation recommendations.
- Maintain asset and system inventories.
- Monitor security tooling and alert queues
- Assist with log review, alert tuning recommendations, and documentation of recurring false positives.
- Support user access reviews.
- Assist with vulnerability scans and track vulnerability remediation.
- Support configuration baseline reviews.
- Participate in incident response activities, maintain incident records, and assist in the preparation of incident response reports and post-incident review documentation.
- Respond to security questions in a professional and timely manner.
- Maintain confidentiality of sensitive security information.
- Other duties as assigned.
What We're Looking For:
Required Qualifications
- 2 years relevant professional experience in information security, information technology, audit, or a closely related discipline may be considered
- Internships, apprenticeships and academic project work will be considered
- Bachelor's degree in computer science, information systems, information security, cybersecurity, or related area, or equivalent level of education and experience
- Applicable military service or technical certification may be substituted
- Preferred certifications: CompTIA Security+, ISC2 Certified Information System Security professional (CISSP) or GFIAC GSEC
- Working knowledge of information security management, networking protocols, and information security principles.
- Understanding of network segmentation, routing and switching fundamentals.
- Familiarity of VPN and remote access technologies.
- Ability to read and interpret a network architecture diagram.
- Awareness of common network security controls.
- Working knowledge of Windows Server and Linux operating system fundamentals.
- Understanding of Active Directory.
- Familiarity with patch management, endpoint protection and system hardening concepts.
- Understanding of virtualization and hypervisor concepts, logging, audit trail generation, and centralized log collection.
- Understanding of cloud service models.
- Familiarity with core Azure and AWS services and constructs relevant to security and compliance.
- Understanding of cloud identity and access management concepts.
- Understanding of encryption at rest and in transit.
- Ability to recognize common cloud misconfigurations.
- Familiarity with cloud-native logging and monitoring services and at least one recognized security framework or control set.
- Ability to map technical infrastructure configurations to written control requirements.
- Strong written communication skills.
- Attention to detail.
- Proficiency in standard office productivity software.
- Ability to work independently on assigned tasks.
- Ability to interact professionally with stakeholders across the organization.
- If driving for, or on behalf of, any ECS subsidiary, a valid driver's license is required
The expected pay range for this role and location is $82k - $95k/year. The final agreed-upon compensation will be determined based on specific location and other individual qualifications.
Who We Are:
ECS Group of Companies (ECS) was founded in 1988 with the goal to raise the standards of professional engineering consulting. Today, we are a leader in geotechnical, construction materials, environmental and facilities consulting services. We are employee-owned with more than 3,000 employees in 100+ offices and testing facilities coast to coast. ECS is currently ranked #60 in Engineering News-Record’s Top 500 Design Firms (April 2026), #148 in Engineering News-Record’s Top 200 Environmental Firms (October 2025) and #50 in Zweig Group’s Hot Firm List (May 2025). For additional information about ECS, visit: www.ecslimited.com.
ECS is an Equal Opportunity Employer. To learn more, click here.