Cybersecurity Engineer II

Orion Marine Group

Houston (TX)

On-site

USD 90,000 - 130,000

Full time

46 hours ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

Orion Marine Group seeks an IT Cybersecurity Engineer II to support architecture, operation, automation, and continuous improvement of cybersecurity posture across on-premises, cloud, and hybrid environments. You will own SIEM/SOAR security, endpoint protection, and cross-train with Infrastructure teams to ensure a secure, resilient tech environment.

Responsibilities include tuning detections, building automation, and supporting NIST/CMMC compliance efforts, with collaboration across IT

Qualifications

  • Bachelor's degree in Computer Science, IT, Cybersecurity, or a related field.
  • Experience designing, tuning, or automating security tooling is preferred.
  • Hands-on experience with Defender suite and Darktrace is expected.

Responsibilities

  • Evaluate Orion's cybersecurity architecture and posture, identifying gaps and improvements.
  • Develop and maintain automation to streamline detection, alert triage, and response actions.
  • Own the security and configuration integrity of SIEM and SOAR environments.
  • Monitor endpoint security coverage, policy compliance, and vulnerability management workflows.
  • Provide backup coverage for core infrastructure operations and coordinate security implications with IT teams.
  • Support compliance activities including CMMC and NIST SP 800-171.

Skills

Strong communication
Analytical skills
Problem-solving
Documentation habits

Education

Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field

Tools

Microsoft Defender suite
Darktrace
SIEM/SOAR platforms
VMware
Veeam

Job description

The IT Cybersecurity Engineer II provides mid-level engineering support for the architecture, operation, automation, and continuous improvement of Orion's cybersecurity posture across on-premises, cloud, and hybrid environments. This role is responsible for evaluating and strengthening the overall security architecture, and for enhancing and automating existing security tooling to improve detection, response, and operational efficiency. The role also owns the security and integrity of Orion's SIEM and SOAR environment, ensuring the platforms that detect and respond to threats are themselves properly access-controlled, hardened, and monitored. The position holds global ownership of endpoint security review and administration, ensuring consistent policy enforcement, coverage, and hardening across the environment.

While the primary focus of this role is cybersecurity engineering, the Cybersecurity Engineer II is expected to be well-rounded across core infrastructure disciplines. The role actively cross-trains and provides backup support with the Infrastructure team and participates in shared operational and on-call responsibilities. This role works under the direction of IT leadership while partnering with the Infrastructure team, Service Desk, Applications, and business stakeholders to maintain a secure, resilient, and well-documented technology environment.

This role supports cybersecurity technologies and services including endpoint detection and response (EDR/XDR), network detection and response (NDR), SIEM and SOAR platforms, identity security, email security, vulnerability management, security monitoring and alerting, and security automation, in addition to cross-functional support of virtualization, backup, and related on-premises infrastructure.

The incumbent must support Orion's guiding beliefs and core values centered on Safety, Quality, Delivery, and Teamwork, and most importantly, built upon the all-important foundation of Integrity.

SPECIFIC RESPONSIBILITIES
Cybersecurity architecture and posture
  • Evaluate Orion's overall cybersecurity architecture and posture, identifying gaps and recommending improvements aligned with security best practices and industry frameworks (for example, NIST, CIS Controls, Zero Trust principles).
  • Partner with IT leadership to design and evolve a layered security architecture across endpoint, network, identity, email, and cloud environments, informed by findings from penetration tests, vulnerability assessments, and audits.
  • Translate penetration test and assessment findings into prioritized remediation plans and architectural changes, tracking implementation through to closure.
Security tooling enhancement and automation
  • Serve as the primary engineer responsible for enhancing, tuning, and automating Orion's core security platforms, including Darktrace and Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365).
  • Develop and maintain automation, scripts, and workflows (for example, PowerShell, KQL, Logic Apps/Sentinel automation, or equivalent) to streamline detection, alert triage, response actions, and reporting, reducing manual security operations effort.
  • Continuously tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve signal quality across security platforms.
  • Evaluate emerging security tools and capabilities and recommend enhancements or additions to the security tooling stack.
SIEM and SOAR platform security
  • Own the security, access control, and configuration integrity of Orion's SIEM and SOAR environment, ensuring the platforms responsible for detection, correlation, and automated response are themselves hardened against unauthorized access, tampering, or misconfiguration.
  • Administer role-based access, log source onboarding, and data retention within the SIEM to protect the confidentiality and integrity of security event data used for detection, investigation, and audit evidence.
  • Build, test, and maintain SOAR playbooks and automated response actions, applying change control and peer review to prevent unintended or unauthorized automated actions in production.
  • Monitor SIEM/SOAR platform health, log ingestion completeness, and playbook execution to ensure detection and response coverage is not silently degraded.
Endpoint security ownership
  • Own the global review, configuration, and administration of endpoint security, across all Orion locations, devices, and business units.
  • Monitor endpoint security coverage, policy compliance, and protection status; identify and remediate gaps in onboarding, policy application, or protection posture.
  • Manage endpoint security policies, attack surface reduction rules, device configuration baselines, and vulnerability management workflows tied to endpoint protection.
  • Review and respond to endpoint-related security alerts and incidents, coordinating containment, remediation, and root-cause analysis.
Security monitoring, detection, and incident response
  • Monitor security alerts, logs, and telemetry from Darktrace, Microsoft Defender, the SIEM, and related platforms; investigate and respond to potential threats and security incidents.
  • Support incident response activities, including detection, containment, eradication, and post-incident documentation and lessons learned.
  • Perform vulnerability scanning, risk assessment, and remediation coordination across infrastructure and endpoint environments.
Compliance, audit, and governance support
  • Support CMMC and NIST SP 800-171 compliance activities, including control implementation, evidence collection, audit support, and remediation of identified findings.
  • Maintain security documentation, including architecture diagrams, standard operating procedures, playbooks, and control evidence, to support auditability and operational consistency.
  • Assist with security risk assessments, policy development, and control reviews in coordination with IT leadership.
Cross-training and infrastructure support
  • Cross-train and maintain working proficiency with core on-premises infrastructure platforms managed by the Infrastructure team, including VMware virtualization and Veeam backup and recovery.
  • Provide backup coverage for infrastructure operations as needed, including virtualization, backup/recovery, storage, and related on-premises systems, to reduce single points of knowledge given the size of the IT team.
  • Partner with the Infrastructure team on projects and changes that have security implications, ensuring security requirements are incorporated into infrastructure design and operations.
Documentation and continuous improvement
  • Maintain accurate technical documentation, including security architecture diagrams, configuration standards, runbooks, and change records.
  • Identify and communicate opportunities to improve security posture, tooling effectiveness, and operational efficiency; participate in continuous improvement initiatives.
  • Coordinate effectively with the Infrastructure team, Service Desk, Applications, vendors, and other stakeholders to resolve incidents, support projects, and ensure smooth handoffs.
After-hours response and operational readiness
  • Respond to off-hour security alerts, calls, emails, or notifications as needed to maintain security monitoring coverage and operational uptime.
  • Ensure incident response communications and handoffs are clear, timely, and documented.
Broader IT support and other duties
  • Support broader IT and security projects and perform other related administrative and technical duties as assigned by IT leadership.
POSITION REQUIREMENTS
Non-Technical
  • Demonstrated ability to deliver high-quality results with minimal supervision in a fast-paced environment.
  • Strong communication, analytical, and problem‑solving skills with the ability to explain technical and security concepts to non-technical stakeholders.
  • Proven ability to learn new technologies and threat landscapes quickly through research, self‑directed learning, and hands‑on experimentation.
  • Strong documentation habits and attention to detail, including architecture diagrams, playbooks, and audit evidence.
Technical
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent practical experience. Relevant certifications are preferred (examples: CompTIA Security+/CySA+, Microsoft SC-200/SC-100, CEH, GIAC, or equivalent).
  • 4-8 years of hands‑on experience in cybersecurity engineering or security operations, with demonstrated experience designing, tuning, or automating security tooling.
  • Strong understanding of cybersecurity architecture principles and security frameworks, with experience aligning to NIST SP 800-171 and supporting CMMC compliance readiness activities.
  • Hands‑on experience with Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365) and network detection and response platforms such as Darktrace, including tuning, automation, and reporting.
  • Hands‑on experience administering and securing a SIEM and SOAR environment, including access control, log source management, and building/maintaining automated response playbooks.
  • Experience administering endpoint security at scale, including policy management, attack surface reduction, vulnerability management, and incident response.
  • Working proficiency with scripting and automation (for example, PowerShell, KQL) to build repeatable security workflows, detections, and reporting.
  • Working knowledge of virtualization and backup platforms (VMware and Veeam or equivalent) sufficient to cross‑train and provide backup support with the Infrastructure team.
  • Proficient with standard Microsoft productivity tools (Visio, Word, Excel, Outlook, PowerPoint) for documentation, diagrams, reporting, and communication.
  • Experience supporting security audits, e‑discovery technical requests, and handling sensitive data with confidentiality, documented procedures, and access controls is preferred.
EMPLOYEE SAFETY AND COMPLIANCE
  • Responsible and accountable for the incumbent's safety.
  • Responsible and accountable for the safety of all co-workers and any other incumbent encounters.
  • Authorized and obligated to stop work on any task or series of tasks whenever an unsafe condition or situation is anticipated or observed.
  • Complies with all applicable laws, regulations, and Company policies and procedures and is subject to appropriate disciplinary action (including dismissal) for failure to do so.
  • Reports any violations of applicable laws, regulations or Company policies and procedures promptly, and is subject to appropriate disciplinary action (including dismissal) for failure to do so.
  • All employees, current and former, must maintain confidentiality by not disclosing to others any confidential, proprietary, or trade secret information belonging to the Company.
PHYSICAL/MENTAL REQUIREMENTS

The engineer must be able to perform the job's essential functions with or without reasonable workplace accommodation.

The individual must also be able to wear and properly utilize appropriate personal protective equipment if required to work or visit the job site. This may include a hard hat, safety glasses, respirators, ear plugs, steel-toed shoes, personal flotation devices, or other equipment as required by the work performed and the location where the work is being done.

The incumbent must possess the ability to remain calm during emergencies and respond appropriately as dictated by the circumstance of the incident and as directed by the Safety Representative or other management personnel. Must be capable of evacuating the work area promptly should an emergency arise.

EEO is the Law

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer II
Cybersecurity Engineer II

Cybersecurity Jobs • Houston (TX)

On-site
USD 90,000 - 120,000
Security Engineer II
Security Engineer II

Healthcare Outcomes Performance Co. (HOPCo) • Phoenix (AZ)

On-site
USD 120,000 - 170,000
Engineer, Cyber Security
Engineer, Cyber Security

Memorial Physician Practices • Brentwood (TN)

On-site
USD 80,000 - 110,000
Sr. Infrastructure Security Engineer
Sr. Infrastructure Security Engineer

NOW Health Group INC • Bloomingdale (IL)

On-site
USD 110,000 - 160,000
Cyber Security Engineer
Cyber Security Engineer

Pride Veteran Staffing Inc • Whippany (NJ)

On-site
USD 85,000 - 125,000
Information Systems Security Professional
Information Systems Security Professional

Vytwo • Dallas (TX)

Hybrid
USD 120,000 - 180,000
Cyber Security Engineer
Cyber Security Engineer

empirical Foods • North Sioux City (SD)

On-site
USD 100,000 - 140,000
Health benefits
Dental insurance
Vision insurance
+5
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000
Security Architect - Consultant with Min 10yrs exp (Webcam or In Person Interview)(REMOTE_Anywhere in USA)
Security Architect - Consultant with Min 10yrs exp (Webcam or In Person Interview)(REMOTE_Anywhere in USA)

NextGen Solutions Corporation • New York (NY)

Remote
USD 140,000 - 190,000
Remote work
On-call rotation
Engineer, Security
Engineer, Security

11:11 Systems • United States

On-site
USD 120,000 - 160,000