What are the responsibilities and job description for the Senior IT Security Engineer position at Byte Brook Systems Inc?
JOverview
We are seeking an experienced Senior IT Security Engineer to design, implement, and support enterprise cybersecurity solutions across network, cloud, endpoint, identity, and governance environments.
The role will lead vulnerability management, threat monitoring, incident response, identity and access management, business continuity, and governance, risk, and compliance activities. The ideal candidate can translate complex security risks into practical technical and business recommendations.
Key Responsibilities
- Design and maintain enterprise cybersecurity architecture across network, cloud, server, endpoint, and mobile environments.
- Conduct cloud migration and XaaS security assessments.
- Manage vulnerability scanning, risk prioritization, remediation tracking, and reporting.
- Monitor security threats using SIEM, IDS/IPS, endpoint, network, and cloud security tools.
- Lead or support cybersecurity incident investigation, containment, recovery, and root-cause analysis.
- Implement identity, authentication, authorization, MFA, least-privilege, and access-control solutions.
- Develop and maintain cybersecurity policies, governance frameworks, risk assessments, and compliance documentation.
- Support business continuity, disaster recovery, incident preparedness, and testing.
- Recommend security risk-reduction strategies, tools, and controls.
- Develop cybersecurity awareness training and provide security guidance to technical and business teams.
Required Experience
- Five or more years of cybersecurity engineering or information security experience.
- Enterprise network, server, endpoint, and cloud security experience.
- Advanced experience with vulnerability management, threat monitoring, incident response, and security operations.
- Experience with identity and access management, authentication, authorization, and accountability controls.
- Knowledge of cybersecurity architecture, information assurance, data protection, and business continuity.
- Experience with governance, risk, and compliance processes and tools.
- Experience supporting public-sector, federal, state, or regulated environments is strongly preferred.
Technical Skills
- Microsoft 365 Defender, Exchange Online, Microsoft Purview DLP, Intune, and Entra ID
- AWS, Microsoft Azure, or Google Cloud
- Windows, Linux, iOS, and Android security
- Duo, Microsoft Authenticator, and other MFA technologies
- SIEM, network monitoring, IDS/IPS, endpoint security, and email security
- SOC operations and incident-response processes
- Certificate, encryption, and cryptographic key management
- Python, Bash, or PowerShell scripting
- Artificial intelligence security risks and attack techniques
Certifications
At least one of the following is required:
- CompTIA Security
- CompTIA CySA
- GIAC GCIA
- SSCP
Preferred certifications include CISSP, CISM, CCSP, CASP , GIAC GSEC, AWS Certified Solutions Architect, Azure Solutions Architect Expert, or Google Cloud Professional Cloud Architect.
Education
Bachelor’s degree in Information Technology, Cybersecurity, Information Assurance, Computer Science, Management Information Systems, or a related technical field.
Preferred Qualifications
- Knowledge of NIST Cybersecurity Framework, NIST SP 800-53, RMF, FISMA, FedRAMP, CIS Controls, and Zero Trust principles.
- Experience with cloud security, DevSecOps, security automation, and infrastructure as code.
- Strong communication, documentation, analytical, and problem-solving skills.
- Ability to communicate cybersecurity risks to technical and nontechnical stakeholders.
We are an equal opportunity employer and consider qualified applicants without regard to any legally protected status.
Pay: $50.00 - $55.00 per hour
Work Location: In person
Salary : $50 - $55