This is an onsite role, 5 days a week. Competitive compensation and benefits. Sponsorship is not available for this role.
Overview :
The Senior Cybersecurity Engineer will act as the primary architect of our organization’s digital defense, bridging the gap between Enterprise IT, Cloud Development, and Operational Technology (OT). This role is responsible for operationalizing our security strategy, advising our software development pipeline, and advising on the protection of industrial control systems. This role leads the technical implementation of CMMC 2.0 compliance while ensuring our manufacturing and cloud applications remain resilient against modern threats.
Responsibilities :
- Secure Microsoft Azure environments by managing Entra ID (Identity), Defender for Cloud, and Sentinel. Configure and audit conditional access policies and resource grouping
- Own the roadmap to CMMC Level 2 assessment readiness. Manage the System Security Plan (SSP) and Plan of Action and Milestones (POAMs) specifically for Defense Industrial Base (DIB) requirements
- Conduct continuous security risk assessments, bridging the gap between technical vulnerabilities (CVSS scores) and business impact
- Oversee the lifecycle of vulnerability management, from scanning to patch verification, working closely with infrastructure teams to minimize downtime
- Develop and enforce policies regarding the use of Generative AI tools (LLMs) within the enterprise to prevent data leakage and IP loss
- Collaborate with development teams to integrate security scanners (SAST / DAST) into the CI / CD pipeline, ensuring Security by Design
- Translate complex cyber metrics into a "Risk Scorecard" for leadership, highlighting ROI on security investments and current threat levels
- Champion security awareness training, running phishing simulations and tabletop exercises to build organizational resilience
- Engage with key stakeholders in the development of contingency plans, business continuity strategies, and disaster recovery efforts, ensuring our organization's resilience
Basic Qualifications :
Bachelor’s degree in computer science, information systems, or related degreeMinimum 6 years of technical security experienceMinimum 2 years specifically managing cloud security (Azure preferred)Proven experience preparing an organization for CMMC, NIST 800-171, or ISO 27001 auditsQualifications and Experience :
Expert knowledge of NIST 800-171, CMMC 2.0, and SOC 2 standardsDirect experience securing Microsoft Azure infrastructureAbility to manage risk assessments and threat modelingSkilled in writing technical policies, procedures, and SSPsExperience coordinating third-party audits and external assessmentsKnowledge of DevSecOps pipelines and OT / Industrial securityAbility to work both independently and collaboratively, and handle ambiguityExcellent communication skills and ability to succinctly present recommendationsStrong ability to prioritize competing deadlines in a fast-paced environmentAdaptability to perform additional duties as business needs evolveWe are an Equal Opportunity Employer and consider all qualified applicants for employment without discrimination based on race, color, religion, gender, gender identity or expression, sexual orientation, national origin, ethnicity, genetic background, age, marital status, veteran status, disability, or any other legally protected status. When needed, reasonable accommodation will be made to help individuals with disabilities fulfill essential responsibilities.