Information Security Specialist II

US, Washington, Seattle
IT – Information Security /
Full Time /
On-site
Who We Are:

At Brooks, we believe a run can change a day, a life, the world. Everyone who works here is a key part of our obsession to make the best running gear on the planet. We want our business — which also happens to be our passion — to be a place where everyone feels welcome and comfortable being themselves. Our company culture defines us, bonds us together, and drives our success. We live this culture daily through our brand values: Runner First, Word is Bond, Champion Heart, There is no “I” in Run, and Keep Moving. This means we always solve for the runner, do what we say we will, give it our all, are generous with our humanity, and find a way to keep moving every day, because joy is kinetic. 

Are you ready to help create something extraordinary?

Your Job:

The Information Security team is seeking an early career security professional to detect and respond to security threats. As a Brooks Information Security Specialist II, you will primarily be responsible for day-to-day defense of enterprise technologies, computing assets and network infrastructure. You will conduct ongoing threat detection using logs and signals from multiple sources including network, host-based, endpoint security, and phish reports, ensuring the confidentiality, integrity and availability of critical information systems and resources.
 
You will correlate activity across assets and environments to identify patterns of anomalous activity and prevent abuse. Requires understanding of core infrastructure concepts such as common operating systems, networking, storage and how systems interact. You will perform incident response to identify, contain, and mitigate attacks.
 
Keys to success in this role include a sense of curiosity and a strong desire for continuous improvement of our security program and your own professional skills. If you are passionate about keeping current on security-related technical trends and excited to work with some of the most talented, creative, and innovative people, using the latest software, technologies, and sourcing solutions to ensure the protection of all systems and services deployed over a globally expanding network, then we are looking forward to hearing from you.

Responsibilities:

    • Incident Handling and Response
    • Investigate suspicious emails
    • Thoroughly investigate and respond to cyber events and incidents
    • Learn, follow, and maintain incident response playbooks
    • Document, refine, and automate processes using our Security, Orchestration, Automation, and Response (SOAR) tool
    • Gap Analysis and Remediation
    • Work with purple team to test detection of attacker TTPs and tune out false positive results.
    • Assist in the recommendation of the implementation of security solutions and practices that protect company services and assets
    • Maintain Situational Awareness
    • Ensure logs from all appropriate systems are being ingested for Continuous Monitoring and Anomaly Detection and/or Forensic Investigations
    • Validate hardware and software inventory, comparing scans to asset databases to find outliers and suggesting process improvements to improve data accuracy
    • Work with stakeholders to make sure accounts and privileges are properly maintained
    • Maintain a current awareness of information security issues and trends
    • Maintain professional security certifications and accreditations
    • Other responsibilities as required

Qualifications:

    • Bachelor’s degree or equivalent education and experience
    • 3 years information technology/information security experience
    • Ability to communicate technical subject matter to non-technical individuals
    • Possess excellent analytical skills
    • Ability to prioritize and organize tasks in a dynamic business environment
    • Able to accomplish goals while working as a member of a team or independently
    • Use business knowledge, innovative thinking, and sound judgment to resolve problems and challenges
    • Practical knowledge of Windows, Linux, and network system administration
    • Knowledge of security best practices

    • Preferred Qualifications:
    • Professional certification such as CISA, Security+, Net+ or GSEC
    • Experience as security incident response team member
    • Knowledge of Information Technology Infrastructure Library (ITIL) standards and processes
    • Experience configuring infrastructure systems and knowledge of network protocols
Compensation:
The pay range for this position, based out of the Brooks Seattle HQ, is $84,210 - $126,367 per year. Base pay offered will vary depending on job-related knowledge, skills, and experience.

Other:
Brooks is proud to offer a robust benefits package to our employees and their families!  
Benefits- including medical, dental, vision, life and AD&D insurance, disability insurance, HSA and employer contribution, FSA, family & fertility assistance, 401K Savings Plan and match, employee assistance program, and transportation assistance.  
Paid Time Off- Brooks offers generous time off including three to five weeks of paid time off, eleven paid holidays, paid sick and parental leave. 
Bonus- in addition to base pay, Brooks employees may also be offered an annual bonus based on company performance.   
Perks- including product discounts, employee recognition, fitness discounts, volunteer and donation benefits. 

Location- You will spend 3 to 4 days per week in our Seattle offices, depending on your role, as we believe our organization flourishes when connections, collaboration, creativity, problem-solving, and celebrations happen in person.

At Brooks, we celebrate diversity & equity. We are committed to creating an inclusive environment, and encourage people of all backgrounds, perspectives, experiences, and skills to apply. Brooks is proud to be an equal employment opportunity employer. All employment decisions are made without regard to race, religion, creed, color, national origin, age, sex, gender, gender identity or expression, two-spirit identity, sexual orientation, genetic information, sensory, physical, or mental disability, marital status, pregnancy (including childbirth and related conditions), honorable discharge or military status, protected citizen status, actual or perceived victims of domestic violence, sexual assault or stalking, HIV or Hepatitis C infection, political ideology, use of a trained guide dog by a person with a disability, or on any other basis protected by federal, state or local law, or any other non-merit based factors.