Software Finder

Security Engineer

Software Finder 201 District, Virginia, United States

IT Services and IT Consulting · 201-500 employees

Jul 10
security Senior (5-10 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

Design and implement enterprise security solutions across cloud and on-premises environments to protect business systems and data. Lead incident response, manage identity and access management, and ensure compliance with security frameworks.

What they look for

Cybersecurity Architecture Next-Generation Firewalls Zero Trust Architecture Incident Response Identity and Access Management Vulnerability Assessment Microsoft Entra ID SIEM Cloud Security Network Segmentation EDR/XDR Compliance Frameworks PowerShell Python Bash Security Hardening

Requirements

Requires a Bachelor's degree in a related field and over 5 years of hands-on experience in cybersecurity engineering. Must have strong expertise in enterprise security technologies, cloud platforms, and identity management solutions.

Full description

Senior Security Engineer

Software Finder is seeking an experienced Senior Security Engineer to strengthen and safeguard its enterprise technology environment. This role will focus on designing, implementing, and continuously improving cybersecurity architecture across cloud and on-premises environments while protecting business systems, applications, networks, and sensitive data.

The ideal candidate will lead security initiatives, manage enterprise security technologies, support incident response, strengthen identity and access management, and collaborate closely with Infrastructure, Cloud, DevOps, Engineering, and Product teams. This position requires strong technical expertise, sound security judgment, and the ability to promote security best practices across the organization.

Key Responsibilities

  • Design, implement, and maintain enterprise security solutions across cloud and on-premises environments.
  • Manage and optimize security technologies, including next-generation firewalls, VPNs, intrusion detection and prevention systems, web application firewalls, and endpoint detection and response platforms.
  • Implement secure network segmentation, Zero Trust architecture, and protected remote access solutions.
  • Develop and enforce security hardening standards for servers, endpoints, cloud infrastructure, applications, and network devices.
  • Monitor, investigate, and respond to security incidents, coordinating containment, eradication, recovery, and post-incident analysis.
  • Develop and maintain incident response playbooks, security procedures, and technical documentation.
  • Administer identity and access management solutions, including Microsoft Entra ID, multifactor authentication, single sign-on, Conditional Access, Privileged Identity Management, and identity governance.
  • Conduct vulnerability assessments, security reviews, and risk analyses, ensuring timely remediation of identified issues.
  • Support security audits and compliance initiatives aligned with ISO 27001, SOC 2, the NIST Cybersecurity Framework, CIS Controls, and other applicable standards.
  • Collaborate with Infrastructure, Cloud, DevOps, Engineering, and Product teams to integrate security into systems, applications, and operational processes.
  • Configure and optimize security information and event management platforms, endpoint protection tools, and security automation technologies.
  • Assess emerging cybersecurity threats and recommend proactive improvements to the organization’s security posture.
  • Develop and maintain security policies, standards, controls, and operational best practices.
  • Support secure cloud architecture, access controls, monitoring, and configuration management across relevant cloud platforms.
  • Prepare security dashboards, incident reports, risk assessments, and recommendations for technical and business stakeholders.
  • Mentor junior security team members and provide technical guidance across cross-functional teams.
  • Promote security awareness and support the adoption of secure working practices throughout the organization.
  • Contribute to additional cybersecurity, risk management, and infrastructure security initiatives as required.

Requirements

  • Bachelor’s degree in Computer Science, Information Security, Cybersecurity, Information Technology, or a related field.
  • At least four years of hands-on experience in cybersecurity, security engineering, or information security.
  • Strong expertise in enterprise security technologies, including next-generation firewalls, IDS/IPS, VPNs, WAFs, EDR/XDR, SIEM platforms, and endpoint protection.
  • Experience securing cloud infrastructure on Microsoft Azure, AWS, or Google Cloud Platform.
  • Hands-on experience with Microsoft Entra ID, identity and access management, multifactor authentication, single sign-on, Conditional Access, and Privileged Identity Management.
  • Strong understanding of Zero Trust architecture, network security, secure remote access, and infrastructure hardening.
  • Experience with security monitoring, incident response, threat detection, and forensic investigations.
  • Familiarity with vulnerability management tools, remediation processes, and security assessment methodologies.
  • Working knowledge of security and compliance frameworks, including ISO 27001, SOC 2, the NIST Cybersecurity Framework, and CIS Controls.
  • Strong analytical, troubleshooting, and problem-solving skills.
  • Excellent communication, documentation, and stakeholder management capabilities.
  • Ability to manage multiple priorities in a fast-paced environment.
  • Experience with scripting or automation using PowerShell, Python, or Bash is preferred.
  • Relevant certifications, such as CISSP, CISM, CEH, CompTIA Security+, SC-200, SC-300, AZ-500, CCSP, or GIAC certifications, are preferred.
  • Experience with security orchestration, automation, and response platforms is preferred.
  • Knowledge of DevSecOps practices and the secure software development lifecycle is preferred.
  • Experience securing containerized environments, Kubernetes, or cloud-native applications is preferred.
  • Familiarity with penetration testing methodologies and threat intelligence platforms is preferred.
  • Experience mentoring technical teams or leading enterprise security initiatives is preferred.
  • Strong understanding of security architecture, risk management, and governance is preferred.
  • Commitment to continuous learning and staying informed about emerging cybersecurity threats, technologies, and industry best practices.

Similar roles