IT Security Engineer
IT Security Engineer responsible for designing, implementing, and maintaining enterprise security infrastructure including firewalls, SIEM monitoring, vulnerability management, IAM, and compliance. Requires 5+ years IT security experience, strong networking and cloud knowledge.
About the job
Responsibilities
- Design, implement, and maintain enterprise network security architecture, including firewalls, intrusion detection systems, VPNs, and DMZs.
- Develop and enforce security policies, standards and procedures across the organization.
- Conduct security assessments, vulnerability scans and penetration testing to identify and remediate security gaps.
- Monitor systems and networks 24/7 using security information and event management (SIEM) tools; investigate and respond to security incidents.
- Manage access controls, identity and access management (IAM), and multi-factor authentication (MFA) solutions.
- Establish and manage data loss prevention (DLP) and encryption protocols for sensitive data at rest and in transit.
- Perform security hardening of servers, workstations, and endpoints; manage patch management and system updates.
- Provide security awareness training and education to employees to foster a security-conscious culture.
- Conduct root cause analysis on security incidents and prepare incident response reports and recommendations.
- Ensure compliance with relevant regulations (CMMC, SOC 2, GDPR, PCI-DSS, or industry-specific standards as applicable).
Requirements
- Bachelor's degree in Computer Science, Information Security, or related field (or equivalent professional experience).
- 5+ years of professional IT security experience, with demonstrated expertise in at least two of the following domains: network security, systems security, or cybersecurity.
- Strong knowledge of TCP/IP, DNS, DHCP, and network protocols; experience with firewalls, proxies, and network segmentation.
- Hands-on experience with security tools such as Splunk, ELK Stack, Snort, Suricata, or similar SIEM and IDS/IPS platforms.
- Proficiency in systems security, including endpoint protection and vulnerability management.
- Experience with cloud security (AWS, Azure, or GCP) and containerized environments (Docker, Kubernetes).
- Understanding of common attack vectors and security frameworks (NIST, CIS Controls, OWASP Top 10).
- Excellent problem-solving skills with the ability to work independently and as part of a team.
- Strong communication skills to explain complex security concepts to non-technical stakeholders.
Nice-to-haves
- Security certifications such as CISSP, CISM, CEH, CCNA Security, Security+, or similar.
- Experience with security automation and Infrastructure as Code (Terraform, Ansible).
- Knowledge of application security testing (SAST/DAST) and secure development practices.
- Experience with incident response and forensics investigations.
- Familiarity with compliance frameworks and audit processes.
Skills
Network Security, SIEM, Splunk, Ids/Ips, IAM, MFA, Dlp, Cloud Security, AWS, Azure, GCP, Docker, Kubernetes, Terraform, Ansible
Similar jobs
Security Engineering jobsOwn network engineering and government cybersecurity compliance for on-site and field-deployed aerospace systems. The role requires 5+ years of experience, end-to-end IATT/ATO experience, strong networking skills, and familiarity with DoD security frameworks and tactical communications.
Conducts end-to-end security risk assessments for vendors, customers, and partners while maintaining risk tiering, remediation, reassessments, and reporting. The role also matures third-party risk processes and uses AI-assisted workflows to scale assessment operations.
The Security Engineer will secure AWS and Google Cloud environments, monitor infrastructure, and assess AI/LLM deployments, MCP integrations, and agentic workflows. The role requires 5+ years of security engineering experience, including 2+ years in AI/ML security, plus cloud security and compliance expertise.
The Security Engineer will lead application security across the SDLC, integrating DevSecOps controls, conducting threat modeling and secure code reviews, and managing application vulnerabilities. The role requires 3+ years of application security experience plus hands-on expertise with AWS, Kubernetes, IaC, CI/CD, and mobile or web security.
The Security GRC Analyst will manage security risks, policies, audits, control testing, and compliance reporting while partnering with technical and business stakeholders. The role requires 4+ years of GRC or security assurance experience and familiarity with major security frameworks.