Security Engineer
RemoteUnited States
Job Summary
Design, implement, and maintain enterprise security infrastructure including firewalls, IDS/IPS, endpoint protection, SIEM, and application control technologies. Lead the firm's cybersecurity strategy, roadmap, and risk management initiatives while coordinating incident response, forensic investigations, and business continuity plans. Conduct vulnerability assessments, penetration testing, and access reviews to remediate risks, ensuring compliance with NIST CSF, CIS Controls, and ISO 27001 frameworks. Administer identity and access management solutions, optimize security tools, and advise leadership on security architecture and strategic investments. Track emerging threats, prepare security posture metrics, and mentor colleagues to foster a culture of security awareness. Report to the Chief Information Officer with a focus on embedding security into all technology operations.
Required Qualifications
- Bachelor's degree in Information Security, Information Technology, Information Systems, or a related field, or an equivalent combination of education and experience
- Five or more years of progressive experience in cybersecurity or information security, including responsibility for complex security programs and initiatives
- Strong knowledge of network security, operating system hardening, Azure security, and modern security architectures, including zero-trust principles
- Hands-on experience with SIEM platforms, vulnerability management tools, endpoint detection and response (EDR), firewalls, and IDS/IPS technologies
- Working knowledge of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, and SOC 2
- Understanding of identity and access management technologies and protocols, including SAML, OAuth, LDAP, and directory services
- Experience with scripting and automation tools such as PowerShell and Python
- Exceptional analytical, troubleshooting, and problem-solving abilities
- Strong written and verbal communication skills with the ability to present technical concepts to both technical and non-technical audiences
- Ability to manage multiple priorities, work independently, and maintain confidentiality in a professional services environment
Desired Qualifications
- Industry certifications such as CISSP, CISM, CEH, GIAC, or CompTIA Security+
- Master's degree in Cybersecurity, Information Security, or a related discipline
Hiring someone like this?
Get your role in front of qualified candidates on Sorce.