MIDREX TECHNOLOGIES INC

Information Security Engineer

MIDREX TECHNOLOGIES INC Charlotte, North Carolina, United States

Industrial Machinery Manufacturing · 201-500 employees

Yesterday
security Mid (2-5 yrs) Full-time United States
Log in to apply, save this posting, or score it against your profile with AI.

About the role

The Information Security Engineer monitors, detects, and responds to cybersecurity threats across the global technology environment. They also manage security policies, conduct vulnerability assessments, and support the secure adoption of AI technologies.

What they look for

Cybersecurity Incident response Vulnerability management SIEM Endpoint protection Cloud security Data loss prevention Microsoft 365 Azure Networking Identity and access management Artificial intelligence Threat hunting Compliance Zero trust architecture Risk assessment

Requirements

Candidates must have a bachelor's degree in a relevant field and three to five years of cybersecurity or IT infrastructure experience. Proficiency in Microsoft-centric security environments and knowledge of security frameworks like NIST and ISO 27001 are required.

Benefits

401(k) matching Profit sharing Paid vacation Tuition reimbursement Half-day Fridays Flexible home/office work practices Paid volunteer time Employee recognition awards

Full description

Job DetailsJob Location: Corporate Office - Charlotte, NC 28208Position Type: Full TimeEducation Level: Bachelor DegreeTravel Percentage: Up to 10%Job Shift: DayJob Category: Information TechnologyAt Midrex, you will do work that matters alongside people who believe you matter. The work won’t be easy, but it will be worth it. You’ll be part of a great team—with plenty of autonomy—to bring out your best. And you’ll be well compensated and have a best-in-class benefits package. Take a look:

Competitive benefits effective from Day 1

Dollar-for-dollar 401(k) matching (up to 6%)

Profit sharing with 401(k) kicker

Generous overtime for qualified positions

4 weeks of paid vacation

Tuition reimbursement

Raffles for professional sports tickets

Half-day Fridays

Flexible home/office work practices

Paid time to volunteer

Employee recognition awards

 

Since 1987, Midrex has been the world leader in direct reduction technology, offering the best proven method for decarbonization in the iron and steel industry available today.  Our rapid growth is transforming the steel industry and our planet. And none of it would be possible without our people, who bring vision, compassion, and extraordinary expertise to this work every day.  So, if you’re looking to do big work in a small-team environment, Midrex is just the place for you.Qualifications 

The Information Security Engineer is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's global technology environment. This role supports the protection of company systems, networks, cloud services, applications, and data through continuous security monitoring, vulnerability management, security awareness initiatives, compliance activities, and implementation of security controls. The role increasingly leverages AI-enabled security tooling to accelerate threat detection, triage, and response, and supports the secure adoption of AI technologies across the organization.

 

The Information Security Engineer serves as a key member of the cybersecurity team and works closely with IT infrastructure, cloud, networking, application, and business teams to improve the organization's security posture. This position requires strong analytical abilities, attention to detail, problem-solving skills, and a commitment to continuous improvement.

 

The Information Security Engineer should demonstrate broad, hands-on security experience encompassing security investigations, endpoint and cloud security, vulnerability management, Data Loss Prevention (DLP), networking, security compliance, security tooling, and partnership with IT Operations.

 

The Information Security Engineer should be capable of independently handling security responsibilities while also serving as a security resource to infrastructure, networking, cloud, endpoint, and other IT teams.

This is NOT a SOC ticket-triage-only position.

 

Essential Duties and Responsibilities

Security Operations

Monitor security alerts, events, and incidents generated by security platforms including SIEM, endpoint protection, email security, cloud security, and network security systems. Investigate suspicious activity and coordinate incident response activities through resolution. Perform threat hunting and security investigations to identify potential risks and unauthorized activities. Document security incidents, findings, lessons learned, and remediation activities. Participate in on-call rotation and security incident escalations as required.

Vulnerability and Risk Management

Conduct vulnerability assessments and coordinate remediation efforts with system owners. Track and report remediation progress and risk reduction metrics. Support annual penetration testing activities and validation of remediation actions. Assist in risk assessments and implementation of corrective actions. Identify opportunities to reduce organizational cyber risk through technology, process, and control improvements.

Security Engineering and Administration

Assist with implementation, administration, and optimization of security technologies. Manage security policies and configurations across Microsoft 365, Azure, endpoint management, email security, and network security platforms. Support identity and access management controls including role-based access control, least privilege, and privileged account management. Assist with implementation and maintenance of Zero Trust security architecture initiatives. Manage SSL/TLS certificate lifecycle processes including acquisition, renewal, deployment, and documentation.

Security Awareness and Training

Coordinate and administer the corporate Security Awareness Program. Develop and deliver security awareness communications, training campaigns, and phishing simulations. Analyze user participation metrics and identify improvement opportunities. Conduct coaching sessions with employees requiring additional phishing awareness training.

Compliance and Governance

Assist with maintaining compliance with ISO 27001, NIST Cybersecurity Framework, and corporate security policies. Support internal and external audits by collecting evidence and documenting security controls. Participate in policy development, standards creation, and security procedure improvements. Maintain accurate security documentation, inventories, and records.

Business Continuity and Disaster Recovery

Support backup, recovery, and disaster recovery processes. Participate in periodic testing of business continuity and disaster recovery plans. Assist in maintaining resilience and recoverability of critical technology services.

AI Security

Leverage AI-assisted security tools (e.g., Microsoft Security Copilot, CrowdStrike Charlotte AI) to accelerate alert triage, incident summarization, and threat investigations. Support monitoring and governance of enterprise AI usage, including detection of unauthorized (“shadow AI”) applications and enforcement of AI acceptable use policies. Assist with securing generative AI deployments, including Microsoft 365 Copilot data protection and Purview-based data governance and DLP controls for AI services. Help identify and analyze AI-enabled threats such as AI-generated phishing, deepfake, and social engineering campaigns, and incorporate these risks into security awareness content. Support AI risk assessments and contribute to AI governance activities aligned with emerging frameworks and standards.

Required Qualifications

Education

Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent professional experience.

Experience

Three to five years of cybersecurity, information security, or IT infrastructure experience. Experience supporting enterprise security technologies in a Microsoft-centric environment. Experience investigating security events and coordinating remediation activities.

Required Technical Knowledge

CrowdStrike Falcon / Next-Gen SIEM Microsoft Defender Security Suite Security Operations Center (SOC) processes and methodologies Incident response and breach investigation Vulnerability management and remediation Microsoft 365 and Azure security fundamentals Endpoint Detection and Response (EDR/XDR) platforms Security Information and Event Management (SIEM) Email security technologies and phishing protection Implementation and / or Administration of security compliance frameworks including ISO 27001 and NIST Networking fundamentals including TCP/IP, DNS, DHCP, HTTP/S, TLS, VPN, and wireless security Artificial Intelligence (AI) security fundamentals, including generative AI and large language model (LLM) risk concepts Common AI threat vectors such as prompt injection, data leakage, model manipulation, and AI-generated phishing (e.g., OWASP Top 10 for LLM Applications) Familiarity with AI-assisted security operations tools for alert triage, investigation, and reporting Awareness of AI governance and risk frameworks such as the NIST AI Risk Management Framework (AI RMF) Identity and Access Management (IAM) Encryption, certificate management, and key management principles Windows security administration and endpoint hardening

 

 

Preferred Qualifications

Technical Experience

Microsoft Intune Cisco Umbrella / Secure Access Palo Alto, Cisco, and Meraki security platforms KnowBe4 Security Awareness platform Abnormal Email Security platform Microsoft Entra ID Security automation and scripting with PowerShell or Python Microsoft Security Copilot or similar AI-assisted security operations tools AI-powered threat detection and email security platforms (e.g., behavioral AI phishing detection) Applying DLP and data governance controls to generative AI services (e.g., Microsoft Purview for Copilot) Cloud security tools and monitoring platforms Data Loss Prevention (DLP) Microsoft Purview

Certifications

One or more of the following:

CompTIA Security+ Microsoft Security Certifications SC-200 SC-300 SC-900 AI-900 (Microsoft Azure AI Fundamentals) SSCP GSEC CEH CISSP (preferred but not required)

 

Core Competencies

Analytical thinking Problem solving Attention to detail Technical troubleshooting Communication and presentation skills Collaboration and teamwork Customer service orientation Initiative and ownership Continuous learning mindset

Physical Requirements

Ability to sit and work at a computer for extended periods. Ability to occasionally lift and move equipment up to 50 pounds. Ability to travel domestically and internationally when required.

Travel Requirements

Up to 10% domestic and international travel.

 

 

Other Duties

Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties or responsibilities that are required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.

 

Midrex is an equal opportunity employer and is committed to providing employment opportunities to all qualified individuals without regard to race, color, religion, sex, national origin, age, disability, or any other protected status in accordance with all applicable laws. In compliance with the Americans with Disabilities Act, Midrex will provide reasonable accommodations to qualified individuals with disabilities and encourages both prospective and current employees to discuss potential accommodations with the People and Culture department.

Similar roles