Cybersecurity Engineer

HB Global

$100K — $120K *
US-Anywhere
+ 2 other locationsRemote
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • 5+ years in cybersecurity engineering or security operations.
  • Hands-on experience with CrowdStrike for EDR and SIEM.
  • Strong skills in identity and access management (Entra ID, Okta).
  • Proficient in securing Microsoft 365 and Azure environments.
  • Experience in incident response and threat hunting.

Responsibilities

  • Conduct daily threat hunting and incident response across security platforms.
  • Implement and manage security controls in Azure and on-premises systems.
  • Monitor and respond to phishing threats and manage email security policies.
  • Oversee vulnerability management and remediation efforts within the IT team.
  • Collaborate with divisions to maintain consistent enterprise security standards.

Benefits

  • Hybrid work environment with flexibility between remote and on-site work.
  • Opportunities for professional development and continuing education.
  • Engaging work culture that values teamwork, accountability, and communication.
  • Involvement in security-awareness programs and training.
Full Job Description
This position will report to HB Mechanical Group, LLC, a subsidiary of HB Global.

SUMMARY: The Cybersecurity Engineer is HB Global's dedicated, hands-on owner of cybersecurity operations and engineering across the enterprise. Reporting to the Director of IT, who owns the enterprise security strategy, and partnering with third-party solution architects where specialized design is required, this role translates strategy into working, well-managed security controls. It is a true generalist position: on any given week the engineer performs day-to-day threat hunting, monitoring, and incident response, then implements, configures, and manages the tools that protect the organization. This position operates in a multi-division enterprise environment in which divisions maintain autonomy in business decisions; the Cybersecurity Engineer maintains consistent enterprise security standards while adapting to each division's needs and supporting the integration of newly added business units.

To be successful you must possess these core value characteristics:

Trust: Clear Communication. Be committed. Accountable. Open. Honest.

Team: No "I". Do what's best. Assume the best. Be a leader. Celebrate wins.

Grit: Goal-focused. Be positive. Persevere. Show passion. Take ownership.

Growth: Lifelong learner. Forward-thinker. Self-aware. Curious. Open-minded.

WORK SCHEDULE & TRAVEL:

This is a full-time position with benefits. The role is a hybrid Remote-On Site position; we prefer candidates within driving distance of the HB Mechanical Group office in Camp Hill, PA or the Tamarac, FL office, and will consider strong candidates residing anywhere in the U.S. Eastern time zone. Hours may vary according to business needs. Occasional travel between HB Global offices and divisional worksites may be required. On-call availability for security incidents and urgent requests is required.

ESSENTIAL DUTIES and RESPONSIBILITIES:

Threat Detection, Hunting & Response
  • Perform day-to-day threat hunting, monitoring, and alert triage across the CrowdStrike Falcon platform (EDR, NG-SIEM, and Identity Threat Protection).
  • Investigate, contain, and remediate security incidents end to end; perform root-cause analysis and document findings and lessons learned.
  • Tune detections, correlation rules, and alerting to reduce noise and improve fidelity.
  • Monitor and respond to email-borne threats and user-reported phishing through Mimecast, managing quarantine and policy tuning.


Security Engineering, Implementation & Configuration
  • Implement, configure, and maintain security controls across Microsoft Azure and on-premises systems, coordinating with third-party architects on solution design where required.
  • Administer identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace, enforcing least privilege, MFA, and conditional access.
  • Manage endpoint protection and DNS-layer security (Cisco Umbrella), and support network security policy on Cisco Meraki in partnership with the Senior Network Administrator.
  • Own vulnerability management, including scanning, prioritization, and coordinating remediation within the IT team.
  • Partner with the Senior Systems Administrator - who administers our data protection and recovery tools (Druva, Veeam) - to validate and test backup integrity and to participate in disaster-recovery testing.
  • Manage the secrets and password platform (1Password) and champion strong credential hygiene across the organization.


Security Operations & Management
  • Maintain security configuration standards and hardening baselines aligned to the strategy set by leadership.
  • Plan, track, and report on security initiatives using Zoho Projects.
  • Manage day-to-day relationships with security vendors and managed-service providers, holding third parties accountable to their commitments.
  • Own the Mimecast security-awareness program, including scheduling and managing quarterly awareness trainings and quarterly phishing simulations, and reporting on progress and completion rates.


Reporting, Metrics & Executive Communication
  • Produce clear, regular reporting on the organization's overall cybersecurity posture, translating technical detail into concise summaries for leadership and executive audiences.
  • Pull and correlate data from across the security stack - CrowdStrike (EDR, NG-SIEM, Identity Threat Protection), Mimecast, Cisco Umbrella and Meraki, identity, and vulnerability tools - into clear, easy-to-understand reports and dashboards.
  • Define and track key security metrics and KPIs (such as detection and response times, vulnerability remediation, patch status, and phishing-test results) and report on trends over time.
  • Provide on-demand snapshots of the current security state and clearly communicate risks, priorities, and recommendations to non-technical stakeholders.


Business Partnership & Business-Unit Integration
  • Partner with multiple semi-autonomous divisions to deliver consistent security protections, adapting engagement and communication to each division's operational needs while maintaining enterprise standards and governance.
  • As HB Global grows and brings new business units into the organization, onboard and standardize their security controls to HB Global's baseline.
  • Assess the security posture of incoming environments and build practical plans to consolidate identity, endpoint, email, network, and backup protections.


Governance & Collaboration
  • Support compliance, audit, and cyber-insurance requirements with clear evidence and documentation.
  • Partner with leadership to turn security strategy into hands-on execution, and flag risks and priorities as they emerge.
  • Partner closely with the Senior Network Administrator - who is responsible for network security - to validate network security controls and to provide backup and cross-coverage for the network security function.


Other
  • Perform other duties as assigned


EDUCATION, EXPERIENCE and SKILLS:

Education
  • High School Diploma
  • BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
  • Relevant security certifications and continuing education preferred


Experience (Required)
  • 5+ years of hands-on experience in cybersecurity engineering, security operations, or a blended security/IT role.
  • Demonstrated ability to both build and operate security controls with minimal supervision as a security generalist.
  • Hands-on experience with EDR/endpoint security and SIEM (CrowdStrike strongly preferred).
  • Strong identity and access management experience (Entra ID / Active Directory, Okta, MFA, conditional access).
  • Experience securing Microsoft 365 and cloud environments (Microsoft Azure).
  • Practical incident-response and threat-hunting experience, with solid networking and firewall fundamentals.
  • Experience working with outside security vendors/managed services and coordinating deliverables to timelines and quality expectations.


Skills & Technical Knowledge
  • Working knowledge of security frameworks and best practices (e.g., NIST Cybersecurity Framework, CIS Controls) and the ability to enforce data/access security policies.
  • Scripting and automation ability (PowerShell and/or Python) for routine tasks and tool integrations.
  • Strong analytical and problem-solving skills; able to communicate clearly with technical and non-technical stakeholders.
  • Ability to pull data from multiple security platforms and present the organization's security posture in clear reports and dashboards for executive, non-technical audiences.
  • Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security.
  • Familiarity with email security, DNS security, and backup/disaster-recovery concepts.
  • Familiarity with confidentiality requirements related to IT operations and network information.


PREFERRED QUALIFICATIONS:
  • Industry certifications such as CISSP, SSCP, CompTIA Security+/CySA+, GIAC (GCIH, GCIA), or CrowdStrike / Microsoft Azure security certifications.
  • Direct experience with our stack: CrowdStrike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, and 1Password.
  • Experience standardizing security across multiple sites or business units within a growing, multi-entity organization.
  • Experience integrating or supporting newly added business units.
  • Experience in a multi-division or federated IT/security environment.


PHYSICAL REQUIREMENTS:
  • Prolonged periods sitting at a desk and working on a computer
  • Must be able to lift up to 15 pounds at times
  • Ability to travel to divisions and worksites as needed

Similar Jobs

More Jobs at HB Global

More Information Technology Jobs

Find similar Cybersecurity Engineer jobs: