The Senior Security Engineer assists in the design, implementation, and continuous improvement of security solutions that protect the organization's systems, networks, applications, and data. This role provides hands-on technical expertise and security leadership across infrastructure, cloud, endpoint, identity, and monitoring platforms. The Senior Security Engineer partners with technology, risk, compliance, and business stakeholders to reduce risk, respond to emerging threats, and ensure security controls support organizational objectives.
- Partner with the Managed IT provider to maintain and optimize enterprise security technologies, including firewalls, intrusion detection and prevention systems, endpoint protection, identity and access management tools, vulnerability management platforms, and security monitoring solutions, ensuring they remain current, effective, and aligned with organizational security requirements.
- Monitor security events, investigate alerts, perform incident triage, and support incident response from detection through containment, remediation, and lessons learned.
- Assists in vulnerability management activities, including assessment, prioritization, remediation coordination, and validation of risk reduction efforts.
- Develop and maintain security standards, secure configuration baselines, hardening guidelines, operational procedures, and technical documentation.
- Partner with IT and business teams to define security requirements for new systems, cloud services, applications, and technology initiatives.
- Support security architecture reviews and provide practical recommendations that promote secure design and implementation.
- Analyze threat intelligence, emerging vulnerabilities, and industry trends to recommend proactive security improvements.
- Support audits, regulatory reviews, risk assessments, and compliance activities by providing technical evidence and remediation support.
- Collaborate with team members and promote security knowledge sharing across the technology organization.
- Help educate employees on emerging threats, safe technology practices, and security awareness topics.
- Participate in after-hours support, incident response, and on-call rotation as needed.
Required:
- Education Bachelor's degree in information security, computer science, information technology, cybersecurity, or a related field, or equivalent professional experience.
- Five or more years of experience in cybersecurity, security engineering, network security, infrastructure security, or a related technical discipline.
- Strong knowledge of security principles, defense-in-depth strategies, secure configuration, vulnerability management, incident response, and risk reduction practices.
- Hands-on experience with security technologies such as SIEM, EDR, IDS/IPS, firewalls, vulnerability scanners, email security platforms, and identity management solutions.
- Working knowledge of networking concepts, including TCP/IP, DNS, VPN, routing, switching, segmentation, and secure network architecture.
- Experience securing Windows, Linux, cloud, and hybrid technology environments.
- Ability to assess complex security issues, communicate risk clearly, and recommend effective remediation actions.
- Strong documentation, analytical, problem-solving, collaboration, and communication skills.