Cyber Security Engineer

Gotham Technology Group

New York (NY)

Hybrid

USD 120,000 - 180,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Gotham Technology Group in New York is seeking a Security Engineer to build, enforce, and mature security controls across our clients' endpoint, identity, and cloud environments. This is a hands-on engineering role for someone with genuine security depth who understands not just how to configure a platform, but why a control matters and how to validate it.

This position is for someone with a dedicated hands-on security engineering background within an enterprise environment and has developed

Qualifications

  • 4+ years in a dedicated information security role.
  • Strong understanding of Zero Trust and defense-in-depth concepts.
  • Hands-on with Microsoft security technologies (Intune, Defender, Entra ID).
  • Familiarity with CIS Benchmarks and MITRE ATT&CK framework.
  • Proven ability to secure endpoints, identities, and cloud resources.

Responsibilities

  • Design, implement, and maintain endpoint security controls and ASR rules.
  • Enforce least-privilege via LAPS and endpoint management solutions.
  • Define device compliance with Intune and Conditional Access.
  • Manage Entra Conditional Access policies and governance.
  • Support phishing-resistant authentication methods (FIDO2, Windows Hello).
  • Strengthen Entra ID security and Azure posture with Defender tools.
  • Collaborate with MDR/SOC providers and internal teams on remediation.
  • Contribute to security standards and repeatable operational processes.

Skills

Zero Trust
Defense in depth
Least privilege
Identity security
ATT&CK techniques
Analytical skills
SOC/MDR collaboration
Security certifications

Tools

Microsoft Intune
Defender for Endpoint
Defender for Office 365
Defender for Cloud
Entra ID / Azure AD
Conditional Access

Job description

Location: NYC hybrid schedule (3 days on-site), Will consider remote candidates

Full-Time role for an Investment Management firm

About the Role

Security Engineer to help build, enforce, and mature security controls across our clients endpoint, identity, and cloud environments. This is a hands-on engineering role for someone with genuine security depth who understands not just how to configure a platform, but why a control matters, how an attacker would attempt to bypass it, and how to validate that security controls are working effectively.

This position is for someone with a dedicated, hands-on security engineering background within an enterprise environment and has developed deep technical expertise in a corporate environment rather than supporting a large number of client environments.

Exciting initiatives:

Take ownership of reviewing, maintaining, and enhancing existing Conditional Access policies.

Develop and execute a prioritized vulnerability remediation plan in partnership with infrastructure teams.

Responsibilities

  • Design, implement, and maintain endpoint security controls by hardening Microsoft Defender for Endpoint, configuring attack surface reduction (ASR) rules, implementing CIS-aligned security baselines, and managing configuration drift.
  • Implement least-privilege strategies by eliminating standing local administrator access through Microsoft LAPS and endpoint privilege management solutions while maintaining user productivity.
  • Define and manage device compliance policies within Microsoft Intune and integrate compliance requirements with Conditional Access to ensure only trusted devices can access corporate resources
  • Design, test, deploy, and maintain Microsoft Entra Conditional Access policies, including report-only deployments, policy optimization, exception management, and ongoing governance
  • Support the rollout and expansion of phishing-resistant authentication methods such as FIDO2 security keys, Windows Hello for Business, and certificate-based authentication while helping migrate users away from legacy MFA methods
  • Strengthen Microsoft Entra ID security by improving authentication methods, identity protection, and access controls
  • Improve Azure security posture through Microsoft Defender for Cloud and Secure Score by identifying and remediating security misconfigurations
  • Develop and enforce secure configuration standards across Azure and Microsoft cloud services
  • Configure and optimize Microsoft Defender for Office 365 security controls, including anti-phishing, Safe Links, Safe Attachments, impersonation protection, and email threat prevention
  • Support security incident response activities by assisting with triage, containment, remediation, access revocation, and corrective actions while working closely with an external managed detection and response (MDR) provider
  • Partner with infrastructure and application teams to prioritize and remediate security vulnerabilities while validating that remediation efforts effectively reduce organizational risk
  • Participate in security projects from planning through implementation and validation while contributing to the development of security standards, documentation, hardened baselines, and repeatable operational processes

Qualifications

  • 4+ years of hands-on experience in a dedicated information security role
  • Strong understanding of security fundamentals including Zero Trust, defense-in-depth, least privilege, identity security, and common attacker techniques
  • Hands-on experience with Microsoft security technologies including Microsoft Intune, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud, Microsoft Entra ID, and Conditional Access
  • Familiarity with CIS Benchmarks, the MITRE ATT&CK Framework, and detection engineering concepts
  • Strong analytical, troubleshooting, and problem-solving skills with the ability to quickly learn new technologies
  • Experience supporting security initiatives and/or participating in technical security projects
  • Experience working with managed detection and response (MDR) or security operations center (SOC) providers
  • At least one Security certification such as; Security+, CISSP, SC-200, SC-300, AZ-500, or other security certifications are preferred but not required
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer
Senior Security Engineer

Friedman Williams • New York (NY)

On-site
USD 120,000 - 150,000
Cyber Security Engineer
Cyber Security Engineer

FutureRecruit.net • New York (NY)

Hybrid
USD 90,000 - 130,000
Senior Security Engineer
Senior Security Engineer

SourcePro Search • Los Angeles (CA)

On-site
USD 140,000 - 210,000
Sr. Security Engineer
Sr. Security Engineer

California Water Service • San Jose (CA)

On-site
USD 180,000 - 240,000
Security Engineer
Security Engineer

Liberty Personnel Services, Inc. • Feasterville-Trevose

Hybrid
USD 90,000 - 120,000
Cybersecurity/Info Security Engineer (Remote- 130K)
Cybersecurity/Info Security Engineer (Remote- 130K)

Merit Personnel & Consulting • New York (NY)

Remote
USD 117,000 - 143,000
Senior Security Engineer
Senior Security Engineer

Koitecc Solutions • New York (NY)

On-site
USD 140,000 - 210,000
Senior Cybersecurity Associate
Senior Cybersecurity Associate

Jobtailor • Colorado

On-site
USD 120,000 - 180,000
Security Engineer
Security Engineer

Franklin Fitch • Boston (MA)

On-site
USD 120,000 - 180,000
Security Engineer (ON-SITE in Wallingford, CT)
Security Engineer (ON-SITE in Wallingford, CT)

Systems Integration Inc. • Wallingford (CT)

On-site
USD 105,000 - 145,000