About the role
The Security Engineer will serve as a Tier 3 escalation point for active security incidents and lead technical analysis during response efforts. They are responsible for operating the gShield security stack, executing remediation, and improving the security posture of client environments.
What they look for
Requirements
The role requires a hands-on technical professional with deep expertise in troubleshooting complex infrastructure, including identity, endpoints, and cloud services. Candidates must be comfortable working in live security events and possess strong analytical skills to distinguish security threats from infrastructure issues.
Full description
GXA is seeking a highly capable Security Engineer to support the delivery and operation of our gShield security services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.
The Security Engineer serves as a Tier 3 escalation point for active security and technical issues and plays a key role in operating and improving the gShield security stack across client environments. This individual will work closely with the InfoSec Manager (vISM), vCISO, SOC, Centralized Services, onboarding teams, and internal technical leadership to strengthen client security posture and support rapid, effective response to threats and technical issues.
This is an execution-focused role for someone who is comfortable working across security and the underlying IT infrastructure that supports it. The ideal candidate understands how networks, servers, identity, endpoints, cloud services, and security controls work together and can troubleshoot across these layers when the root cause is not immediately clear.
This person should be comfortable working in live security events, analyzing alerts and evidence, troubleshooting infrastructure and security issues, executing or supporting remediation, and helping maintain the operational excellence of GXA's security program.
Key Responsibilities
Incident Response
- Serve as a Tier 3 escalation point for active security incidents, including business email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
- Lead technical analysis during incident response and war room events, including log review, IOC hunting, attacker activity analysis, and lateral movement tracing.
- Execute containment and eradication actions such as endpoint isolation, session revocation, credential resets, access restriction, and other appropriate remediation actions.
- Troubleshoot incidents that may span multiple technical layers, including identity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
- Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
- Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
- Communicate clearly during active incidents, including what is known, what has been investigated, what actions have been taken, what is being investigated next, and where additional support is required.
- Produce accurate incident timelines, technical findings, and evidence packages for vCISO review and client-facing follow-up.
Tool Operations & Security Stack Support
- Operate daily within the gShield toolstack, including platforms such as Huntress, Microsoft Defender for Endpoint (MDE), Cyrisma, DNSFilter, SIEM, and related security technologies.
- Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
- Support SIEM operations including query development, alert review, log analysis, investigation, and rule tuning.
- Assist in tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
- Monitor for security gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
- Correlate information across identity, endpoint, network, server, and cloud sources when investigating security issues.
- Work within established security standards, baselines, and operational policies defined by the security team and vITMs.
Infrastructure & Security Engineering
- Apply security principles across on-premises, cloud, and hybrid client environments.
- Troubleshoot security issues involving underlying infrastructure components such as Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
- Understand how identity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
- Support security hardening of Windows, endpoint, identity, network, and cloud environments.
- Assist with identity and access security including MFA, Conditional Access, privileged access, authentication, authorization, and account security.
- Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
- Work effectively with technologies that may be unfamiliar by researching, testing, validating, and documenting appropriate solutions while escalating appropriately when additional expertise is required.
Client Delivery Support
- Execute technical remediation items identified through MRMMs, preventative actions, vulnerability reviews, and security recommendations.
- Support gShield deliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
- Assess vulnerabilities based not only on severity scores but also on asset criticality, exposure, exploitability, existing controls, and business impact.
- Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifying appropriate compensating controls when immediate remediation is not possible.
- Validate remediation and confirm that identified risks have been appropriately addressed.
- Act as a quality assurance resource for client onboarding into the gShield toolstack, while execution remains with onboarding and Centralized Services teams.
- Assist with client hardening efforts and follow-through on security improvement actions across managed environments.
- Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.
Internal Security Posture
- Support remediation of internal GXA security backlog items, including POA&M-related work.
- Assist with rollout and support of phishing-resistant MFA, passkeys, and other internal security initiatives.
Similar roles
-
Lead Strategic Services Consultant (Application Security)
Black Duck Software, Inc. Burlington, Massachusetts, United States · $124K–$185K/yr
-
Cybersecurity & Governance Engineer
CALIBRE Systems, Inc. Washington, District of Columbia, United States · $125K–$145K/yr
-
Cybersecurity Project Manager
Sancorp Consulting LLC Arlington, Virginia, United States · $110K–$170K/yr
-
Lead Application Security/Information Security Engineer
VBest Software Inc Charlotte, North Carolina, United States · $156K–$166K/yr
-
Cybersecurity Specialist (RMF/IL-6) - ACWS
Data Systems Analysts, Inc. Fort Dix, New Jersey, United States · $160K–$170K/yr
-
College Co-Op Cybersecurity
Synovus Columbus, Georgia, United States