In Demand

Information Security Engineers

In 2016, the Central Bank of Bangladesh suffered one of the largest bank heists in history: a criminal gang managed to steal $81 million from the country's largest bank, which was guarded by tight security forces. This gang didn't storm the bank or fire a single shot like you'd see in the movies -- instead, it was an online theft. A group of internet hackers managed to breach the bank's computer systems and transfer $81 million from its accounts into other accounts belonging to them. That incident wasn't the first of its kind, or even the last. Every day, thousands of financial institutions and businesses around the world face hacking attempts on their websites and accounts, aimed at theft, ransom demands, or sometimes even cyberterrorism meant to disrupt the operations of a country's sovereign institutions. For example, in 2022 dozens of American airports suffered website outages as a result of hacker attacks. Today, companies and institutions in every country around the world realize they urgently need to equip their networks and computers with highly advanced protection technologies and software capable of preventing hacking and breaches. That's why they hire specialists called "information security engineers" to handle this task. Information security engineers have advanced skills in computer science and cybersecurity that let them identify the security vulnerabilities hackers exploit, and based on that, they develop advanced protection software and systems to prevent any potential cyberattacks. In the next section, you'll learn in detail about the nature of their work.

Meet the Writer: Waleed Abo Omiraa

Annual Salary
$108,970/ year
Median wage · BLS🇺🇸 USA

What You'll Actually Do

The core tasks and responsibilities that fill a typical day.

  • Assess the quality of security controls, using performance indicators.
  • Conduct investigations of information security breaches to identify vulnerabilities and evaluate the damage.
  • Coordinate documentation of computer security or emergency measure policies, procedures, or tests.
  • Coordinate monitoring of networks or systems for security breaches or intrusions.
  • Coordinate vulnerability assessments or analysis of information security systems.
  • Develop information security standards and best practices.
  • Develop or implement software tools to assist in the detection, prevention, and analysis of security threats.
  • Develop or install software, such as firewalls and data encryption programs, to protect sensitive information.
  • Develop response and recovery strategies for security breaches.
  • Identify or implement solutions to information security problems.
  • Identify security system weaknesses, using penetration tests.
  • Oversee development of plans to safeguard computer files against accidental or unauthorized modification, destruction, or disclosure or to meet emergency data processing needs.
  • Oversee performance of risk assessment or execution of system tests to ensure the functioning of data processing activities or security measures.
  • Provide technical support to computer users for installation and use of security products.
  • Recommend information security enhancements to management.
  • Review security assessments for computing environments or check for compliance with cybersecurity standards and regulations.
  • Scan networks, using vulnerability assessment tools to identify vulnerabilities.
  • Train staff on, and oversee the use of, information security standards, policies, and best practices.
  • Troubleshoot security and network problems.
  • Write reports regarding investigations of information security breaches or network evaluations.