Patriot Maritime logo
Patriot MaritimePosted 1 month ago

Cybersecurity Analyst/Engineer

$31,200–$31,200 year

HybridHouston, Texas, United States

ContractMasters DegreeMedium

Job Summary

Operate Microsoft Sentinel and Defender for Endpoint to tune detection rules, triage alerts, and lead incident response while managing identity security events and privileged access via Microsoft Entra ID. Conduct regular vulnerability scanning across hybrid Azure and on-premises resources, coordinate remediation pipelines, and maintain documented evidence for ISO 27001, NIST, and CMMC compliance audits. Develop and test Incident Response and Disaster Recovery plans, lead tabletop exercises, and serve as the primary contact for security incidents. Enforce Conditional Access policies, MFA, and endpoint baselines, while monitoring financial and payroll systems for business email compromise and invoice fraud indicators. Partner with Finance and HR to deliver targeted anti-fraud training, configure email authentication controls, and investigate suspected fraud incidents. Produce recurring executive security dashboards translating technical risk into business language for leadership review.

Required Qualifications

  • 3–5+ years of hands-on experience in cybersecurity or information security engineering
  • mid-to-senior level background
  • Prior experience with CMMC framework requirements
  • Hands-on proficiency with the Microsoft security stack: Sentinel (SIEM/SOAR), Defender for Endpoint, Defender for Cloud, Entra ID, and Conditional Access
  • Working knowledge of Azure security services
  • Working knowledge of cloud posture management (CSPM)
  • Working knowledge of hybrid infrastructure environments
  • Working knowledge of NIST CSF
  • Working knowledge of ISO 27001
  • Working knowledge of DFARS 252.204-7012
  • Working knowledge of CMMC 2.0 framework requirements
  • Ability to maintain audit-ready documentation
  • Ability to maintain evidence libraries
  • Ability to maintain control mapping artifacts
  • Strong written and oral communication skills
  • Ability to translate technical risk into business-level language for executive audiences
  • Demonstrated experience identifying, investigating, and mitigating cyber-enabled fraud
  • Demonstrated experience with business email compromise (BEC)
  • Demonstrated experience with invoice fraud
  • Demonstrated experience with payment diversion schemes

Desired Qualifications

  • Demonstrated experience in a federal government contractor, defense, or similarly regulated environment
  • CISSP certification
  • CISM certification
  • CompTIA Security+ certification
  • Microsoft SC-200 certification
  • Microsoft SC-300 certification
  • Experience with vulnerability scanning platforms (e.g., Nessus, Qualys, Defender Vulnerability Management)
  • Experience with endpoint management via Intune/MEM
  • Familiarity with ERP security configurations
  • Experience supporting an active ERP migration environment
  • Experience in a maritime, transportation, or DoD-adjacent operating environment
  • Certified Fraud Examiner (CFE) credential
  • equivalent fraud investigation/financial crimes credential
  • Security clearance eligibility
  • Secret clearance

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce