HB Global logo
HB GlobalPosted 2 weeks ago

Cybersecurity Engineer

RemoteUnited States or Camp Hill, Pennsylvania, United States

Full TimeStartup

Job Summary

Conduct day-to-day threat hunting, monitoring, and incident response across CrowdStrike Falcon, CrowdStrike NG-SIEM, and Identity Threat Protection. Investigate, contain, and remediate security incidents end to end while tuning detections and correlation rules to reduce noise. Implement, configure, and maintain security controls in Microsoft Azure and on-premises environments, administering identity and access security across Microsoft Entra ID, Okta, Microsoft 365, and Google Workspace. Manage endpoint protection, DNS-layer security via Cisco Umbrella, and vulnerability management, coordinating remediation within the IT team. Own the Mimecast security-awareness program, including scheduling quarterly trainings and phishing simulations. Produce clear, regular reporting on the organization's cybersecurity posture, translating technical detail into concise summaries for leadership. Partner with multiple semi-autonomous divisions to deliver consistent security protections while adapting to each division's operational needs. Maintain security configuration standards and hardening baselines aligned to enterprise strategy.

Required Qualifications

  • 5+ years of hands-on experience in cybersecurity engineering, security operations, or a blended security/IT role
  • Demonstrated ability to both build and operate security controls with minimal supervision as a security generalist
  • Hands-on experience with EDR/endpoint security and SIEM
  • Strong identity and access management experience (Entra ID / Active Directory, Okta, MFA, conditional access)
  • Experience securing Microsoft 365 and cloud environments (Microsoft Azure)
  • Practical incident-response and threat-hunting experience
  • Solid networking and firewall fundamentals
  • Experience working with outside security vendors/managed services and coordinating deliverables to timelines and quality expectations
  • Working knowledge of security frameworks and best practices (e.g., NIST Cybersecurity Framework, CIS Controls)
  • Ability to enforce data/access security policies
  • Scripting and automation ability (PowerShell and/or Python) for routine tasks and tool integrations
  • Strong analytical and problem-solving skills
  • Ability to communicate clearly with technical and non-technical stakeholders
  • Ability to pull data from multiple security platforms and present the organization's security posture in clear reports and dashboards for executive, non-technical audiences
  • Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security
  • Familiarity with email security, DNS security, and backup/disaster-recovery concepts
  • Familiarity with confidentiality requirements related to IT operations and network information
  • High School Diploma
  • BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
  • Must be able to lift up to 15 pounds at times
  • Ability to travel to divisions and worksites as needed
  • On-call availability for security incidents and urgent requests is required
  • Hours may vary according to business needs

Desired Qualifications

  • Relevant security certifications and continuing education
  • Industry certifications such as CISSP, SSCP, CompTIA Security+/CySA+, GIAC (GCIH, GCIA), or CrowdStrike / Microsoft Azure security certifications
  • Direct experience with our stack: CrowdStrike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, and 1Password
  • Experience standardizing security across multiple sites or business units within a growing, multi-entity organization
  • Experience integrating or supporting newly added business units
  • Experience in a multi-division or federated IT/security environment
  • Hands-on experience with EDR/endpoint security and SIEM (CrowdStrike strongly preferred)
  • Experience with CrowdStrike Falcon platform (EDR, NG-SIEM, and Identity Threat Protection)
  • Experience with Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace
  • Experience with Cisco Umbrella and Cisco Meraki
  • Experience with Druva and Veeam
  • Experience with Mimecast
  • Experience with 1Password
  • Experience managing quarantine and policy tuning for email-borne threats and user-reported phishing
  • Experience tuning detections, correlation rules, and alerting to reduce noise and improve fidelity
  • Experience performing root-cause analysis and documenting findings and lessons learned
  • Experience administering identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace
  • Experience enforcing least privilege, MFA, and conditional access
  • Experience managing endpoint protection and DNS-layer security
  • Experience supporting network security policy
  • Experience owning vulnerability management, including scanning, prioritization, and coordinating remediation
  • Experience validating and testing backup integrity
  • Experience participating in disaster-recovery testing
  • Experience managing the secrets and password platform
  • Experience championing strong credential hygiene across the organization
  • Experience maintaining security configuration standards and hardening baselines
  • Experience planning, tracking, and reporting on security initiatives using Zoho Projects
  • Experience managing day-to-day relationships with security vendors and managed-service providers
  • Experience owning the Mimecast security-awareness program, including scheduling and managing quarterly awareness trainings and quarterly phishing simulations
  • Experience reporting on progress and completion rates for security awareness programs
  • Experience producing clear, regular reporting on the organization's overall cybersecurity posture
  • Experience translating technical detail into concise summaries for leadership and executive audiences
  • Experience defining and tracking key security metrics and KPIs (such as detection and response times, vulnerability remediation, patch status, and phishing-test results)
  • Experience reporting on trends over time
  • Experience providing on-demand snapshots of the current security state
  • Experience clearly communicating risks, priorities, and recommendations to non-technical stakeholders
  • Experience partnering with multiple semi-autonomous divisions to deliver consistent security protections
  • Experience adapting engagement and communication to each division's operational needs
  • Experience maintaining enterprise standards and governance
  • Experience assessing the security posture of incoming environments
  • Experience building practical plans to consolidate identity, endpoint, email, network, and backup protections
  • Experience supporting compliance, audit, and cyber-insurance requirements with clear evidence and documentation
  • Experience partnering with leadership to turn security strategy into hands-on execution
  • Experience flagging risks and priorities as they emerge
  • Experience providing backup and cross-coverage for the network security function
  • Trust: Clear Communication
  • Be committed
  • Accountable
  • Open
  • Honest
  • Team: No "I"
  • Do what's best
  • Assume the best
  • Be a leader
  • Celebrate wins
  • Grit: Goal-focused
  • Be positive
  • Persevere
  • Show passion
  • Take ownership
  • Growth: Lifelong learner
  • Forward-thinker
  • Self-aware
  • Curious
  • Open-minded

Hiring someone like this?

Get your role in front of qualified candidates on Sorce.

Get started

Apply to this job in one click with Sorce

Apply on Sorce