Cybersecurity Validation & Exposure Engineer

FLIR Systems, Inc.

Stillwater (OK)

On-site

USD 90,000 - 130,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Teledyne Technologies Incorporated is seeking a security-focused professional to work across enterprise information systems to validate controls, monitor external exposure, and drive remediation in collaboration with IT and business owners. You will synthesize findings into architecture-level risk themes, prioritize remediation, and support threat intelligence and incident response activities.

This role reports to the Sr.

Qualifications

  • Must have US citizenship and a degree or equivalent experience.
  • Progressive cybersecurity experience across network security, security engineering, or purple/red-team functions.
  • Hands-on experience reviewing firewall rule sets and network segmentation.
  • Knowledge of adversary TTPs and MITRE ATT&CK.
  • Experience with vulnerability management and external attack-surface monitoring tooling.
  • CTEM or attack-surface-management platforms knowledge.
  • Scripting/automation experience (Python or PowerShell).
  • Familiarity with CMMC/NIST SP 800-171 control environments.
  • Prior defense contractor or regulated infrastructure exposure.

Responsibilities

  • Validate detection and control effectiveness against current adversary TTPs across enterprise architecture.
  • Maintain situational awareness of enterprise network topology, cloud environments, and interdependencies.
  • Monitor external IP space for exposure and align with architecture baselines and firewall rules.
  • Review firewall rules regularly to remove overly permissive or misaligned rules.
  • Collaborate with vulnerability and patch teams to prioritize remediation of hygiene gaps.
  • Coordinate with networking to identify under-monitored segments and drive remediation ownership.
  • Develop and maintain a risk-ranked backlog of architecture weaknesses; brief leadership on trends and remediation.
  • Revalidate business justifications for firewall rules and adjust access as needed.
  • Document findings and remediation recommendations to guide detection engineering and architecture improvement.
  • Support incident response and threat intelligence with architectural context.

Skills

Cybersecurity expertise
Firewall rule review
Threat detection & incident response
Scripting & automation
Adversary TTPs & MITRE ATT&CK
CTEM / attack-surface management
Vulnerability management
Network security concepts
Regulatory frameworks (CMMC/NIST SP 80

Education

Bachelor's degree in Information Security, Computer Science, or related field

Tools

Python
PowerShell

Job description

Be visionary Teledyne Technologies Incorporated provides enabling technologies for industrial growth markets that require advanced technology and high reliability. These markets include aerospace and defense, factory automation, air and water quality environmental monitoring, electronics design and development, oceanographic research, deepwater oil and gas exploration and production, medical imaging and pharmaceutical research. We are looking for individuals who thrive on making an impact and want the excitement of being on a team that wins.

Job Summary

The person in this position works across the enterprise information system to continuously validate the effectiveness of deployed controls against realistic adversary tradecraft. This role bridges the vulnerability/patch management, cyber threat hunting, and cybersecurity engineering functions — synthesizing their tactical findings into architecture-level risk themes, monitoring the external perimeter for unexpected exposure, and conducting recurring review of firewall rule sets to identify access that has drifted from its original business justification. The role reports to the Sr. Director of Enterprise Security Architecture and partners closely with IT and business function owners to prioritize and drive remediation of identified weaknesses.

Primary Duties & Responsibilities
  • Conducts collaborative environment assessments of enterprise architecture to validate detection and control effectiveness against current adversary TTPs.
  • Maintains current situational awareness of enterprise network topology, cloud environments, and business-system interdependencies across the full architecture.
  • Monitors external-facing IP address space for unexpected or unauthorized exposure and correlates findings against approved architecture baselines and firewall rule sets.
  • Reviews firewall rule sets on a recurring cadence to identify overly permissive, stale, or business-need-misaligned rules, and evaluates unintended capability introduced by point-in-time exception requests.
  • Partners with vulnerability and patch management teams to prioritize remediation of systemic hygiene gaps, translating asset-level findings into architecture-level risk themes.
  • Partners with the networking team to identify under-monitored network segments, orphaned assets, and other "dark corners," and drives remediation ownership to the appropriate team.
  • Develops and maintains a prioritized, risk-ranked backlog of architecture and control weaknesses; briefs leadership and cross-functional stakeholders on trend and remediation status.
  • Coordinates with IT and business function owners to revalidate the business justification behind existing firewall rules and access paths, and right-sizes access when justification no longer applies.
  • Documents findings, methodology, and remediation recommendations to inform detection-engineering priorities and continuous improvement of the security architecture.
  • Supports incident response and threat intelligence functions with architecture context during active investigations.
Job Qualifications
  • Must be a U.S. Citizen.
  • Bachelor's degree in Information Security, Computer Science, or related field, or equivalent experience.
  • Progressive cybersecurity experience spanning network security, security engineering, or purple/red-team functions.
  • Hands-on experience reviewing and administering firewall rule sets and network segmentation.
  • Working knowledge of adversary TTPs and purple-team/adversary-emulation methodology (MITRE ATT&CK).
  • Experience with vulnerability management and external attack-surface monitoring tooling.
  • Broad technical knowledge, extensive knowledge of current and upcoming IT security technologies and techniques that cover all levels of IT architecture, including those that affect business processes, data, applications, & networked systems infrastructure, as well as their effects on a diverse computing environment and a passion to stay abreast of emerging technologies.
Other Qualifications
  • Industry Certifications: CISSP, CISA, OSCP, GPEN, GCPN, CEH.
  • Experience with Continuous Threat Exposure Management (CTEM) or attack-surface-management platforms.
  • Scripting/automation experience (Python or PowerShell) for exposure and rule-hygiene analytics.
  • Familiarity with CMMC/NIST SP 800-171 control environments.
  • Prior experience in a defense contractor or regulated critical-infrastructure environment.
  • Knowledge of network infrastructure, including routers, switches, firewalls, and associated network protocols and concepts.
  • Experience with modern networking and security technologies.

Teledyne and all of our employees are committed to conducting business with the highest ethical standards. We require all employees to comply with all applicable laws, regulations, rules and regulatory orders. Our reputation for honesty, integrity and high ethics is as important to us as our reputation for making innovative sensing solutions. Teledyne is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability or veteran status, age, or any other characteristic or non-merit based factor made unlawful by federal, state, or local laws. You may not realize it, but Teledyne enables many of the products and services you use every day. Teledyne provides enabling technologies to sense, transmit and analyze information for industrial growth markets, including aerospace and defense, factory automation, air and water quality environmental monitoring, electronics design and development, oceanographic research, energy, medical imaging and pharmaceutical research.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Validation & Exposure Engineer
Cybersecurity Validation & Exposure Engineer

Relha LLC • Stillwater (OK)

On-site
USD 90,000 - 120,000
Cybersecurity Validation & Exposure Engineer
Cybersecurity Validation & Exposure Engineer

Teledyne Technologies Incorporated • Garland (TX)

On-site
USD 120,000 - 180,000
Cybersecurity Validation & Exposure Engineer
Cybersecurity Validation & Exposure Engineer

Teledyne Technologies Incorporated • Huntsville (AL)

On-site
USD 120,000 - 180,000
Cybersecurity Validation & Exposure Engineer
Cybersecurity Validation & Exposure Engineer

Teledyne Technologies Incorporated • Stillwater (OK)

On-site
USD 110,000 - 160,000
Cybersecurity Exposure & Validation Engineer
Cybersecurity Exposure & Validation Engineer

Relha LLC • Stillwater (OK)

On-site
USD 90,000 - 120,000
Cybersecurity Validation & Exposure Architect
Cybersecurity Validation & Exposure Architect

FLIR Systems, Inc. • Stillwater (OK)

On-site
USD 90,000 - 130,000
Cyber Exposure Validation Engineer
Cyber Exposure Validation Engineer

Teledyne Technologies Incorporated • Stillwater (OK)

On-site
USD 110,000 - 160,000
Senior Cloud Engineer
Senior Cloud Engineer

Teledyne Technologies Incorporated • Stillwater (OK)

On-site
USD 120,000 - 150,000
Cybersecurity Exposure & Validation Engineer
Cybersecurity Exposure & Validation Engineer

Teledyne Technologies Incorporated • Garland (TX)

On-site
USD 120,000 - 180,000
Senior Cloud Engineer
Senior Cloud Engineer

Teledyne Technologies Incorporated • Huntsville (AL)

On-site
USD 120,000 - 150,000