We are looking for an IT Security Engineer to lead security operations and assist with maintaining our IT infrastructure. This role covers both security program operations and day-to-day administration across Windows, Linux, and cloud environments. Knowledge of NIST SP 800-171 is desired, along with hands-on technical experience.
Responsibilities:- Maintain the System Security Plan.
- Serve as primary point of contact for assessments and external audits.
- Collect and organize audit evidence for NIST 800-171 and ISO 27001 controls.
- Conduct security hygiene activities including access management, configuration management, change control and incident response.
- Review security logs, investigate anomalies, and escalate findings as needed.
- Coordinate vulnerability scanning and remediation.
- Provide support for Linux-based systems and servers, including installation, maintenance, and troubleshooting.
- Configure and manage Microsoft 365, Exchange, Teams, and SharePoint to ensure security and compliance.
- Manage XDR and other security tooling.
- Document system configurations, procedures, and security-related processes.
Requirements: - 2+ years of IT experience with hands-on security responsibilities.
- Experience with logging, vulnerability scanning, and identity and access management tools.
- Experience with audits, compliance documentation, and evidence collection.
- Strong knowledge of Active Directory, Group Policy, and Microsoft 365 administration.
- Hands-on experience with Linux (Ubuntu, Red Hat, or similar distributions).
- Familiarity with cloud platforms (AWS and Azure).
- Knowledge of networking principles and protocols.
- Strong attention to detail and responsibility.
- Clear communication skills and ability to explain technical issues to a non-technical audience.
Desired: - Working knowledge of ISO 27001 or NIST SP 800-171 requirements.
- Experience supporting formal assessments (CMMC, ISO 27001, SOC 2).
- Knowledge of virtualization technologies and containerization.
- Relevant certifications: Windows Server, CISSP, CISM, CompTIA Security+, CompTIA. Linux+, or Certified CMMC Professional (CCP).
Citizenship or lawful permanent resident required due to federal position.