Security Engineer Texas Stock Exchange | TXSE Group Inc
Were looking for a Security Engineer whos excited to work across the full security stack. You'll help us stand up and mature key capabilitiesincluding Vulnerability Management, Endpoint Security, SIEM / SOAR, Application Security, Incident Response, GRC, and Network Security.
This is a hands?on role : youll manage tools, build dashboards and automations, tune policies, and dive into investigations. If youre curious, collaborative, and love turning signal into action, we want to meet you.
The ideal candidate will have 2-4 years of working experience.
Key Responsibilities
Vulnerability Management
- Operate and administer the vulnerability management platform (e.g., Tenable / Qualys / Rapid7)
- Build dashboards and recurring reports (trending, SLAs, risk?based prioritization)
- Partner with IT / Engineering to align patching cycles with findings and verify remediation
Endpoint Security
Deploy, monitor, and tune EDR on Windows, macOS, and Linux across physical and cloud?hosted workloadsHarden policies and create exceptions safely; investigate and resolve sensor / telemetry issuesMaintain coverage / health reporting and onboarding / offboarding proceduresSIEM / SOAR
Ensure all relevant log sources (cloud, identity, endpoint, network, application) are ingesting and parsing correctlyWrite detections / queries and build SOAR playbooks to enrich alerts, automate triage, and reduce MTTRCreate runbooks for repeatable investigationsApplication Security
Help run SAST / DAST pipelines; support developers in shift?left practicesScan containers / images and third?party packages from npm, pip, and Homebrew; manage findings in backlogContribute to secure SDLC guidance and threat modeling for new featuresIncident Response
Act as an escalation partner to our managed SOC; assist with scoping, containment, eradication, and recoveryPreserve evidence, draft timelines, and document post?incident follow?upsNetwork Security
Apply Zero Trust principles in policy design and access toolingSupport DNS / DHCP hygiene and network segmentation efforts across cloud and campusCloud (Azure)
Support logs / detections and guardrails in Azure (e.g., Microsoft Sentinel / Defender, Azure AD / Entra, Policy)Help design least?privilege access, workload protections, and secure configurationsMust Haves
23 years in security / IT / DevOps or equivalent projects / certsSolid fundamentals : OS internals (Windows / Linux / macOS), networking (TCP / IP, DNS, DHCP), identity, and cloudFamiliarity with two or more : EDR, SIEM, SOAR, SAST / DAST, CNAPP, CSPM, Incident Response, GRC, or vulnerability managementComfort building queries / dashboards and writing clear documentationNice to Have
Azure experienceIaC experience Terraform and AnsibleExperience with tools like SentinelOne / CrowdStrike / Microsoft Defender for Endpoint; Tenable / Qualys / Rapid7; Microsoft Sentinel / Splunk; Logic Apps / Tines; CodeQL / Semgrep / OWASP ZAP; Trivy / Grype; GitHub / GitHub ActionsCertifications such as Security+, CySA+, SC?200, AZ?500, or GSECUnderstanding of Security Frameworks like NIST800.53r5 and CIS#J-18808-Ljbffr