Security Engineer

Posted 16hrs ago

Employment Information

Education
Salary
Experience
Job Type

Report this job

Job expired or something wrong with this job?

Job Description

Security Engineer at Soteria providing specialized cybersecurity assessments and advisory services. Communicating with clients to align security strategies with business objectives while maintaining strong professional relationships.

Responsibilities:

  • Communicate with prospective and existing clients to understand their security needs and develop engagement plans to satisfy their requirements.
  • Lead and perform cloud and infrastructure technical security assessments (Microsoft 365, Microsoft Azure, Google Workspace, AWS, Active Directory, etc.)
  • Translate organizational security documentation into operational practices.
  • Perform hands-on keyboard remediation activities in response to security-focused assessments.
  • Develop detailed reports with actionable recommendations to address security gaps and ensure remediation efforts align with organization needs and service level objectives.
  • Understand and apply security framework controls aligning to industry frameworks such as NIST, CIS, ISO, or MITRE ATT&CK.
  • Design, evaluate, and implement secure network architectures.
  • Provide assessments of emerging technology to facilitate solutions and recommendations for future architectural requirements that are cost effective and reduce risk while enhancing security.
  • Document and present findings and recommendations to clients, including C-Suite and board-level executives, in a professional manner.
  • Maintain relationships with clients post-assessment in order to assist and advise as they continue to build and improve their security.
  • Create, collaborate, and/or assist in maintaining internal tooling to enhance or assist in performing duties, as appropriate.
  • Train and mentor other employees in order to build the company's overall capacity and capability.
  • Perform business development tasks from the initial call with a referral or repeat client, through the proposal stage, and finally, to contract execution.

Requirements:

  • 5+ years of industry experience with Microsoft 365 productivity and enterprise tools
  • Microsoft Defender for Endpoint or similar security tools
  • Entra ID, Active Directory, Conditional Access Policies, and Group Policy
  • Identity Providers, Single-Sign On and Multifactor Authentication technologies
  • Next-generation Firewall technologies and configurations
  • Network architecture
  • Zero-Trust Network Access technologies and architectures are considered a plus
  • Securing workloads and data within Cloud environments (Microsoft Azure, AWS, or Google Cloud Platform)
  • Knowledge and understanding of common regulatory and compliance requirements such as HIPAA, PCI-DSS, CMMC, GDPR, etc.
  • Knowledge and understanding of control frameworks such as CIS, STIG, and NIST.
  • Relevant certifications such as CISSP, CCNA or higher, MCSE, VCP, RHCSA or higher, AWS SysOps Admin, Solutions Architect, Advanced Networking or Security, MCAA (Azure Administrator), MCASA, or MCASEA.