Stand out for this role — generate a tailored resume and cover letter in about a minute.
Qualibar is seeking a Cyber Security Engineer to join the Infrastructure team in the United States. This hands-on role focuses on hardening a distributed enterprise across offices, remote sites, and cloud workloads, configuring, tuning, and defending controls.
You will own audit and certification readiness, partner with development and platform teams on secure pipelines, and apply an offensive mindset to validate defenses through testing.
Cyber Security Engineer to join the Infrastructure organization and work alongside the Network and Security team. The technical work is primary: this is a hands-on engineering seat, not a policy desk. The person in this position will help harden a distributed enterprise environment that spans corporate offices, remote sites, and cloud workloads, and will spend most of their time configuring, tuning, and defending the controls that protect it.
Around that engineering core the role carries three further responsibilities. It owns the technical side of our audit and certification readiness, so the person who configures a control is also the one who can produce the evidence for it. It partners with development and platform teams on secure delivery pipelines and modern application practices. And it brings an offensive mindset to the environment, validating our defenses through testing rather than assuming they hold.
The role reports to the Manager of Network and Security and works closely with systems engineering, network engineering, and application teams. We are looking for an engineer who is comfortable owning a problem end to end, communicating clearly with non-security colleagues, and improving the environment steadily rather than waiting for a project to be handed over.
Hands-on experience in information security, network engineering, or systems engineering with substantial security responsibility.
Demonstrated production experience with enterprise firewalls and VPN, endpoint detection and response, and email security controls.
Working knowledge of TCP/IP, routing and switching, DNS, VLANs, and network segmentation, with the ability to read a packet capture and reason about traffic.
Practical experience securing Microsoft environments: Active Directory, Entra ID, Microsoft 365, and Windows Server.
Hands-on Linux and UNIX administration and hardening, including shell fluency, SSH and key management, service and file permissions, system logging, and patching.
Experience with vulnerability management tooling and with driving remediation across teams that do not report to you.
Understanding of penetration testing methodology and common offensive tooling, sufficient to validate a finding and reproduce it rather than only read the report.
Working familiarity with CI/CD pipelines and modern delivery practices, including source control workflow, build automation, containers, and secrets handling.
Direct experience supporting security audits or a certification effort, including evidence collection, control mapping, and working with external assessors.
Familiarity with a recognized security framework such as NIST CSF, CIS Controls, or ISO 27001, and the ability to translate a control into a concrete configuration change.
Clear written and verbal communication, including the ability to explain risk and remediation to business stakeholders and to write an audit-quality narrative.
Willingness to participate in an on-call rotation and to respond outside business hours during a security incident.
Bachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.
Additional certifications such as OSCP, CySA+, GCIH, GCIA, GWAPT, CISSP, CISA, or a vendor certification in the firewall or endpoint platform they have used.
Experience carrying an organization through a formal certification such as ISO 27001, SOC 2, or a comparable attestation from readiness assessment to audit.
Hands-on Azure security experience, including conditional access, Defender for Cloud, and log analytics.
Experience securing a mixed estate where Linux and Windows systems share authentication and logging, or with Linux-based network and security appliances.
Scripting or automation skill for reporting, log parsing, pipeline integration, and repetitive response tasks.
Experience with DevSecOps tooling in a real pipeline, such as dependency scanning, container image scanning, or policy as code.
Experience in energy, fuel distribution, logistics, or another operationally distributed industry.
Exposure to OT or industrial control environments, or to card and payment data requirements such as PCI DSS.