Information Security Specialist

Canyon AeroConnectPrescott, ArizonaOn-siteFull-timeJunior, 1–2 yearsListed 1 hour ago

Apply now

About this role

This position must meet Export Control compliance requirements, therefore a “US Person” as defined by 22 C.F.R. § 120.15 is required. “US Person” includes US Citizen, lawful permanent resident, refugee, or asylee.  In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification form upon hire.

Canyon AeroConnect stands as one of the world’s leading suppliers of avionic-standard aircraft communications, navigation and audio/intercom systems. Canyon’s products have been widely adopted and proven in-service across a wide range of civilian, paramilitary and military fixed-wing and rotorcraft applications. Over the years, we’ve become known as the benchmark in aircraft tactical communication and audio equipment for Air Ambulance, Law Enforcement, SAR, EMS, Electronic News Gathering, Military and Marine applications. Products include digital and analog radio/audio management systems, Tac/Com, VHF/UHF radio systems, intercoms, data interface accessories, and aural warning.  We are seeking dynamic thinkers who could be integral team members for our high-tech avionics’ products.

Role purpose (position scope):

The Information Security Specialist (Information Systems Security Officer) helps build and operate the internal security program and technology operations. This hands-on role works across security operations, identity and access management, endpoint and network defense, vendor risk, compliance, and end-user enablement. The position works closely with IT, engineering, and business teams to keep the company secure without slowing it down and is intended for an individual who wants to grow into a senior internal security role over time.

Key Responsibilities:

· Support day-to-day security operations, including SIEM and EDR alert triage, log review, and incident-response investigations.

· Help administer identity and access management systems, including SSO, MFA, directory services, onboarding, transfers, offboarding, periodic access reviews, and cleanup of stale accounts and entitlements.

· Maintain and improve endpoint security, including EDR health, patch management, configuration baselines, and disk encryption.

· Assist with firewall rule reviews, VPN administration, network segmentation, and monitoring for misconfigurations.

· Support vulnerability scanning, prioritization, remediation coordination, and metric tracking.

· Support compliance activities such as CMMC and NIST by collecting evidence, maintaining policies, completing customer security questionnaires, and preparing for applicable audits.

· Support vendor risk management by reviewing third-party security documentation and tracking risk acceptances.

· Develop and deliver security awareness content, including phishing simulations, onboarding training, and internal guidance.

· Serve as a point of contact for security questions, suspicious emails, lost devices, and access requests.

· Document security processes, runbooks, and System Security Plan (SSP) so the program can scale as the company grows.

· Participate in the on-call rotation.

Required Qualifications:

· At least one year of experience in information security, IT operations, or a closely related field

· Solid fundamentals in networking, operating systems, and authentication protocols.

· Familiarity with compliance frameworks, especially CMMC and applicable European requirements such as Cyber Essentials.

· Ability to script in Python, PowerShell, or Bash for automation and ad hoc tasks.

· Strong written and verbal communication skills, including the ability to explain security concepts to non-technical audiences.

· Experience supporting and managing highly regulated and secured network systems.

· Self-directed and comfortable providing Tier 2 helpdesk support as well as working across teams in a fast-moving environment.

· Willingness to be part of the on-call rotation and respond to cyber incidents during evening or weekends.

· Ability to obtain industry certifications such as CCNA, CompTIA Security+, or Network+ within the next 12 months.

Preferred Qualifications:

· Three or more years of experience in information security, AI, or a closely related field, with hands-on exposure to multiple security domains.

· Working knowledge of SIEM, EDR, vulnerability scanners, identity providers such as Okta or Entra ID, and cloud platforms such as AWS, Azure, or GCP.

· Experience supporting or leading audits.

· Exposure to cloud security posture management.

· Familiarity with offensive security concepts and tooling highly regulated and secured network systems.

· Industry certification such as CISSP, CISM, CCIE, CCNP Security, CISA, CRISC, or similar.

Compliance Considerations:

The role may support applicable information-security and regulatory requirements identified for the business, including ITAR, CMMC, NIS2, Cyber Essentials and Cyber Essentials Plus, CMS, DCPP, and ISO/IEC 27001.

Work Environment:

· This is an on-site position at the designated company location.

Direct Reports

No direct reports. The position may provide technical direction, peer review, or mentoring consistent with the assigned level.

Physical Demands

- Tasks involve light physical effort in sedentary to light work and may involve lifting, carrying, pushing, or pulling objects or materials weighing 5-10 lb.

- Tasks may involve extended periods at a keyboard or workstation.

Work Environment

- Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

- While performing the job duties described above, the employee mainly works in an office, lab, or factory setting that is relatively quiet and has temperature-control systems.

This job description is not intended to be all inclusive of every job function, duty and responsibility. Duties may increase, decrease and/or change as deemed necessary to support the department operations.