Sobre este puesto de Senior Security Engineer en Vermont Information Processing
Annual Compensation: $160,000 - $190,000
Position Type: Remote
About us
Vermont Information Processing is the leading technology provider to the beverage industry, route accounting, warehouse, delivery, and sales platforms trusted by distributors, bottlers, and over 1,600 suppliers for 50+ years. Backed by Warburg Pincus, VIP is investing in security as a first-class discipline across a growing family of companies. You will join at the moment the program is being built, with executive sponsorship, a funded roadmap, and visible board-level impact.
About the role
You will be VIP's senior hands-on security engineer and the technical lead of a small, high-leverage team, one junior analyst at headquarters and a 24/7 managed SOC behind you. Your mandate: take a well-tooled environment (CrowdStrike, QRadar + SecurityHQ, Okta, Palo Alto, Nessus/Vulcan) and make its protections enforced, extended, and verified, across headquarters, our private cloud, and five newly acquired business units. You will also serve as technical lead for incident response alongside our retained DFIR partners.
What you will own
- Network segmentation remediation: redesign internal zones, eliminate permissive “any-to-any” paths, and stand up east–west traffic visibility as part of our Palo Alto migration.
- Detection & response engineering: own the SIEM/SOC relationship, tune and extend coverage from VIP-core to cloud workloads and acquired business units; build the alert-to-action pipeline.
- Vulnerability & patch program: unify a multi-tool estate (Windows, Mac, Linux, cloud) into one find–fix–verify loop with risk-based prioritization.
- Identity & access hardening: partner with IT on Okta expansion, privileged-access rollout (Devolutions/BeyondTrust), and closing gaps in remote and vendor access, including customer VPN tunnel hygiene (inventory, certificates, least-privilege policy).
- Incident response: act as internal technical lead during security events, coordinating evidence handling and containment with our DFIR and vCISO partners; run tabletop exercises.
- Mentorship: grow the junior security analyst into an operations-capable engineer; set the technical bar for the team.
What success looks like in year one
- Customer and vendor VPN tunnels inventoried, certificate-based, and least-privilege; “any-to-any” internal paths eliminated from priority zones.
- East–west network monitoring live; subsidiary and cloud telemetry flowing to the SOC.
- One unified vulnerability remediation loop with measurable MTTR improvement.
- A tested incident-response muscle: at least one full tabletop and one live-fire detection exercise completed.
What you bring
- 7+ years of hands-on security engineering across network, endpoint, and identity domains.
- Deep practical experience with enterprise firewalls and segmentation design (Palo Alto strongly preferred), SIEM operations, and EDR platforms.
- Demonstrated incident-response experience, you have contained real events and worked with forensic partners.
- The judgment to operate in a lean team: you prioritize by risk, automate what repeats, and communicate clearly to executives.
- Security certifications such as CISSP, GIAC (GCIA/GCIH/GDSA), or PCNSE are valued; experience is weighted over letters.
Nice to have
- Experience integrating acquired companies or multi-entity environments.
- Exposure to iSeries/AS400 or long-lived enterprise platforms.
- Scripting/automation (Python, PowerShell) for security operations.