Security Engineer I
S.P. Richards Company Atlanta, Georgia, United States
Manufacturing · 11-50 employees
About the role
The Security Engineer I supports the design, implementation, and continuous improvement of security controls to protect organizational systems and data. This role involves managing security technologies, performing vulnerability assessments, and collaborating with IT teams to ensure compliance and effective threat response.
What they look for
Requirements
Candidates should have 3–5 years of experience in security engineering or related IT roles and a bachelor's degree in a relevant field. Strong technical knowledge of security principles, vulnerability management, and common security platforms is required.
Full description
The Security Engineer I supports the design, implementation, and continuous improvement of security controls that protect the organization’s systems, networks, applications, and data. This role partners with IT and business teams to assess risk, strengthen identity and access controls, improve threat detection and response, and maintain compliance with applicable standards and regulations. The Security Engineer I helps evaluate, test, and deploy security tools and contributes to security documentation, monitoring, and operational readiness.
Essential Duties and Responsibilities include the following:
- Contribute to security engineering projects by defining requirements, coordinating tasks, maintaining timelines, and documenting outcomes.
- Implement and administer security technologies and services (e.g., endpoint protection/EDR, vulnerability scanning, email/web security, DLP, network security controls, and security logging/monitoring platforms).
- Support identity and access management (IAM) practices including least privilege, role-based access, privileged access reviews, and access lifecycle processes.
- Perform vulnerability management activities: run scans, validate findings, assess risk, coordinate remediation with system owners, and verify closure.
- Assist with security monitoring and incident response by triaging alerts, gathering evidence, supporting containment/eradication activities, and documenting lessons learned.
- Conduct periodic security assessments and risk reviews; help maintain risk registers, control evidence, and remediation tracking.
- Partner with infrastructure, application, and DevOps teams to integrate security into system design and delivery (secure configuration, hardening, patching, and change management).
- Help develop and maintain security standards, procedures, and technical documentation (e.g., configuration baselines, password/MFA standards, logging requirements).
- Support compliance efforts (e.g., SOX and other applicable frameworks) through control testing support, evidence collection, and continuous control monitoring.
- Perform basic security testing (e.g., configuration reviews, vulnerability validation, and approved penetration testing support) and report findings with recommended corrective actions.
- Automate repeatable security tasks and reporting using scripting and tooling to improve consistency and efficiency.
- Maintain awareness of emerging threats, vulnerabilities, and security best practices through training, vendor engagement, and professional development.
Supervisory Responsibilities: This job has no supervisory responsibilities.
Other Qualifications:
- Working knowledge of security principles and controls across identity, endpoint, network, application, and data security.
- Foundational understanding of vulnerability management concepts (CVE/CVSS), remediation workflows, and secure configuration practices.
- Experience or familiarity with security monitoring concepts (log sources, alert triage) and common platforms such as SIEM and EDR.
- Basic understanding of cloud and SaaS security concepts (e.g., shared responsibility model, IAM, logging, and configuration hardening).
- Ability to communicate clearly with both technical and non-technical stakeholders; strong documentation skills.
- Strong problem-solving and troubleshooting skills; able to learn new tools quickly with minimal guidance.
- Comfortable working in a fast-paced environment, managing multiple priorities, and collaborating across teams.
- Familiarity with scripting/automation (e.g., PowerShell, Python, etc.) is a plus.
- Understanding incident response and forensics concepts is a plus.
Education and/or Experience:
- Bachelor’s degree in Information Security, Computer Science, Information Systems, or a related field, or equivalent practical experience.
- 3–5 years of experience in security engineering, systems administration, network engineering, or a related IT role with a security focus.
- Experience with one or more of the following: vulnerability scanning tools, endpoint protection/EDR, SIEM/log management, IAM administration, or network security controls.
- Familiarity with common frameworks and compliance concepts (e.g., NIST, ISO 27001, SOX) is a plus.
- Security certifications are preferred (e.g., CompTIA Security+, CEH, SSCP, CISSP Associate, or relevant vendor/cloud certifications).
Core Competencies
- Communication & stakeholder collaboration
- Customer and partner focus
- Analytical problem-solving and troubleshooting
- Decision-making and sound technical judgment
- Results-driven execution
- Project coordination and prioritization
- Teamwork and cross-functional collaboration
Soft Skills & Work Style
- Ability to work under pressure in time-sensitive environments
- Strong organizational and documentation skills
- Adaptability in dynamic technical environments
- Comfortable managing multiple priorities and competing deadlines
- Willingness to participate in a rotating on-call support schedule
Language Skills:
Ability to read, analyze, and interpret general business periodicals, professional journals, technical procedures, or governmental regulations. Ability to write reports, business correspondence, and procedure manuals. Ability to effectively present information and respond to questions from groups of managers, clients, customers.
Reasoning Ability:
Ability to solve practical problems and deal with a variety of concrete variables in situations where only limited standardization exists. Ability to interpret a variety of instructions furnished in written, oral, diagram, or schedule form
Physical Demands:
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job.
Work Environment:
The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job.
Similar roles
-
GNMA IAISO Cybersecurity Program Manager
Crest Security Assurance $150K–$160K/yr
-
Cyber Security Engineer I
Durango Casino & Resort Las Vegas, Nevada, United States
-
IT Security Engineer / Penetration Tester 60% - 100% (m/w/d)
KastGroup GmbH Wallisellen, Zurich, Switzerland
-
Cybersecurity Compliance Analyst
RCG Suitland, Maryland, United States · $115K–$125K/yr
-
Cybersecurity Analyst
Michigan Schools and Government Credit Union Troy, Michigan, United States · $79K/yr
-
Senior Cyber Security Engineer - Network Security (CISSP)
H&M Group Stockholm, Stockholm, Sweden