Cyber Security Engineer

PowerGrid Services, LLC

Hartselle, Northern (AL, KY)

Hybrid

USD 80,000 - 110,000

Full time

28 hours ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

PowerGrid Services, LLC in Alabama is seeking a cybersecurity engineer to run and tune vulnerability scans, prioritize findings, and drive remediation with IT owners.

You will investigate alerts from Defender/SentinelOne, build detection rules, lead incident response, threat hunting, and ensure secure configurations with Intune and AD. On-call rotation may be required.

Qualifications

  • 3–5 years of hands-on experience in cybersecurity engineering, security operations or a closely related IT security role.
  • Working experience with Rapid7 (InsightVM and/or InsightIDR) or a comparable vulnerability management or SIEM platform.
  • Hands-on administration of SentinelOne or another enterprise EDR such as CrowdStrike or Defender for Endpoint.
  • Experience with Barracuda or another email security gateway such as Checkpoint, Proofpoint or Mimecast, plus email authentication (SPF, DKIM, DMARC).
  • Strong knowledge of the Microsoft ecosystem: Active Directory, Entra ID, Microsoft 365, Intune and Windows Server.
  • Solid understanding of networking (TCP/IP, DNS, firewalls, VPN) and common attack techniques mapped to MITRE ATT&CK.
  • Experience investigating incidents and documenting findings clearly for technical and non-technical audiences.
  • Scripting ability in PowerShell; Python is a plus.
  • Bachelor's degree in cybersecurity, computer science, IT or a related field, or equivalent experience.

Responsibilities

  • Run and tune Rapid7 InsightVM scans, maintain asset coverage and scan schedules, and keep credentialed scanning healthy.
  • Prioritize findings by risk and exploitability, track remediation with IT owners, and report on SLA performance.
  • Validate patches and configuration fixes, and manage exceptions through a documented risk-acceptance process.
  • Investigate and respond to alerts from Rapid7 InsightIDR, SentinelOne and Microsoft Defender.
  • Build and tune detection rules, alert thresholds and automated response actions to reduce noise and improve fidelity.
  • Lead or support incident response: scoping, containment, eradication, recovery and post-incident review.
  • Perform threat hunting using endpoint telemetry, identity logs and network data.
  • Administer the SentinelOne console: policies, exclusions, device groups, agent deployment and upgrade health.
  • Coordinate endpoint policy with Intune and Defender to avoid gaps and conflicts.

Skills

Cybersecurity engineering
Security operations
Vulnerability management
Incident response
Threat hunting
PowerShell
Python
Active Directory
Intune
Microsoft 365

Education

Bachelor's degree in cybersecurity, computer science, IT or related field

Tools

Rapid7 InsightVM/InsightIDR
SentinelOne
Barracuda Email Protection
Microsoft Defender for Endpoint
Microsoft Defender for Office 365
Intune
Azure AD
MITRE ATT&CK

Job description

  • Run and tune Rapid7 InsightVM scans, maintain asset coverage and scan schedules, and keep credentialed scanning healthy.
  • Prioritize findings by risk and exploitability, track remediation with IT owners, and report on SLA performance.
  • Validate patches and configuration fixes, and manage exceptions through a documented risk-acceptance process.
Detection and Response
  • Investigate and respond to alerts from Rapid7 InsightIDR, SentinelOne and Microsoft Defender.
  • Build and tune detection rules, alert thresholds and automated response actions to reduce noise and improve fidelity.
  • Lead or support incident response: scoping, containment, eradication, recovery and post-incident review.
  • Perform threat hunting using endpoint telemetry, identity logs and network data.
  • Administer the SentinelOne console: policies, exclusions, device groups, agent deployment and upgrade health.
  • Investigate threats with SentinelOne Deep Visibility and Storyline data, and perform remediation and rollback when needed.
  • Coordinate endpoint policy with Intune and Defender to avoid gaps and conflicts.
Email Security
  • Administer Barracuda Email Protection: filtering policies, quarantine management, impersonation and phishing protection, and allow/block lists.
  • Investigate reported phishing and suspicious messages, and remove malicious email from affected mailboxes.
  • Tune Barracuda and Microsoft 365 email controls together (SPF, DKIM, DMARC, Defender for Office 365) to cut false positives without opening gaps.
  • Support security awareness efforts with phishing trends and simulation results.
  • Strengthen Entra ID and Active Directory security: Conditional Access, MFA, privileged access and identity protection.
  • Improve Microsoft Secure Score and apply CIS benchmarks across Windows, Microsoft 365 and Azure.
  • Protect Microsoft 365 data with DLP and sensitivity labels.
  • Partner with infrastructure teams on secure configuration of servers, Group Policy and cloud workloads.
Program and Documentation
  • Write and maintain runbooks, incident playbooks, standards and architecture documentation.
  • Support audits and compliance requests with evidence collection and control testing.
  • Produce metrics and clear status reports for IT leadership.
  • Participate in an on-call rotation for security incidents.
What You Bring
  • 3–5 years of hands-on experience in cybersecurity engineering, security operations or a closely related IT security role.
  • Working experience with Rapid7 (InsightVM and/or InsightIDR) or a comparable vulnerability management or SIEM platform.
  • Hands-on administration of SentinelOne or another enterprise EDR such as CrowdStrike or Defender for Endpoint.
  • Experience with Barracuda or another email security gateway such as Checkpoint, Proofpoint or Mimecast, plus email authentication (SPF, DKIM, DMARC).
  • Strong knowledge of the Microsoft ecosystem: Active Directory, Entra ID, Microsoft 365, Intune and Windows Server.
  • Solid understanding of networking (TCP/IP, DNS, firewalls, VPN) and common attack techniques mapped to MITRE ATT&CK.
  • Experience investigating incidents and documenting findings clearly for technical and non-technical audiences.
  • Scripting ability in PowerShell; Python is a plus.
  • Bachelor's degree in cybersecurity, computer science, IT or a related field, or equivalent experience.
Nice to Have
  • Familiarity with NERC CIP requirements or other critical-infrastructure compliance frameworks.
  • Exposure to OT/ICS environments and how securing them differs from enterprise IT.
  • Familiarity with AI governance frameworks such as the NIST AI Risk Management Framework (AI RMF), ISO/IEC 42001 or the EU AI Act, and experience helping write AI acceptable-use policies.
  • Understanding of AI and LLM security risks, including prompt injection, data leakage, insecure plugins and model misuse, using references such as the OWASP Top 10 for LLM Applications and MITRE ATLAS.
  • Experience securing enterprise AI tools such as Microsoft 365 Copilot, Claude Enterprise and Azure OpenAI, including data access permissions, sensitivity labels and Microsoft Purview controls for AI usage.
  • Experience finding and managing unsanctioned AI apps (shadow AI) with tools such as Microsoft Defender for Cloud Apps, and assessing the security of AI vendors and AI features in third-party products.
  • Experience with Microsoft Sentinel, KQL or SOAR automation.
  • Knowledge of NIST CSF, NIST 800-53 or CIS Controls.
  • Certifications such as Security+, CySA+, GCIH, GSEC, SC-200, AZ-500 or CISSP (or progress toward one).

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws.For further information, please review the Know Your Rights notice from the Department of Labor.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Engineer
Cyber Security Engineer

EXOS • Indianapolis (IN)

On-site
USD 100,000 - 140,000
Senior Cloud Security Engineer
Senior Cloud Security Engineer

Maestro Technologies, Inc. • Santa Monica (CA)

Hybrid
USD 150,000 - 210,000
Security Engineer
Security Engineer

Eleven Recruiting • San Francisco (CA)

On-site
USD 120,000 - 160,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Cyber Security Administrator
Cyber Security Administrator

System Soft Technologies • Rosemont (IL)

On-site
USD 90,000 - 140,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
Sr. Analyst - Security Operations
Sr. Analyst - Security Operations

Solomon Page • Village of Great Neck (NY)

On-site
USD 120,000 - 140,000
Information Security Analyst
Information Security Analyst

Cisive • Maryland

On-site
USD 80,000 - 110,000
Director, Cybersecurity
Director, Cybersecurity

Cybersecurity Jobs • Atlanta (GA)

On-site
USD 180,000 - 230,000
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

Warehouse-Specialists,-LLC-2 • Appleton (WI)

On-site
USD 120,000 - 165,000
Medical, Dental, Vision
401(k) Plan
Paid Time Off