Information Security Engineer II

VEIC

Winooski (VT)

On-site

USD 90,000 - 100,000

Full time

3 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Benefits offered by this job

Ergonomic assessments
Flexible work arrangements
Wellness program

Job summary

VEIC is seeking an Information Security Engineer II to join our security operations team. This generalist role focuses on blue team security, incident response, and security engineering to protect VEIC data and systems.

The Engineer II will monitor, triage, investigate, respond to incidents, and implement security technologies such as SIEM content and automation. You will collaborate with IT colleagues and business units to strengthen controls and manage risks across the organization.

Qualifications

  • 3+ years in information security operations or security engineering
  • Proficiency with Microsoft 365 security products including Defender for Endpoint, Purview, Entra ID and Intune
  • Scripting or programming: PowerShell and Python
  • Familiarity with security technologies: vulnerability scanning, event log management, endpoint security, firewalls, WAFs
  • Willingness to obtain entry-to mid-level information security certification within six months

Responsibilities

  • Lead independently monitors, triages, and responds to security alerts and incidents
  • Coordinate containment, eradication, and recovery activities
  • Engineer, implement, and maintain information security technologies and SIEM content
  • Own security engineering projects end-to-end from design to operation
  • Collaborate with IT and business units on security improvements
  • Develop security automation capabilities including AI-assisted tools
  • Provide training and guidance on information security risks
  • Support governance and policy activities with evidence collection

Skills

Security incident response
Blue team security
PowerShell
Python
Analytical thinking
Communication
Independent project work

Education

CompTIA Security+ or CySA+ or GSEC certification

Tools

Splunk ES
Microsoft 365 Defender
Purview
Entra ID
Intune
Defender for Endpoint
Proofpoint

Job description

VEIC is seeking a dedicated Information Security Engineer II. This position is a generalist role focused on blue team security operations and security engineering. The Engineer II independently monitors, triages, investigates, and responds to information security incidents and engineers, implements, and maintains the information security technologies used by VEIC to ensure confidentiality, integrity, and availability of company data and information systems, consistent with VEIC’s information security policies, guidelines, standards, and controls.

The Information Security Engineer II operates with a moderate degree of autonomy, owning security engineering projects from design through implementation and taking an active, hands‑on role in responding to security incidents. The Engineer II works closely with the Manager, Information Security as a day-to-day partner on investigations, digital forensics, governance, and policy-related initiatives.

The Information Security Engineer II advises the Information Security Team on emerging vulnerabilities and newly identified risks to company systems and takes a proactive approach to continually assessing the security of company systems throughout their lifecycle. This role provides recommendations to strengthen security controls and adapt to evolving threats and vulnerabilities.

The Information Security Engineer II promotes a culture of information security across the organization.

Essential Functions
  • Lead Independently monitors, triages, and responds to security alerts and incidents across the security stack, escalating and documenting activities as appropriate.
  • Coordinates response efforts for security incidents, including containment, eradication, and recovery activities.
  • Engineers, implements, and maintains information security technologies, including SIEM content, detection rules, data onboarding, and automation.
  • Owns security engineering projects end‑to‑end, from scoping and design through implementation and operational handoff, with minimal oversight.
  • Serves as a point of contact within Information Technology for information security technologies, processes, and procedures.
  • Works closely with Information Technology colleagues on technology and process improvement initiatives.
  • Partners with teams across the organization to support the security of the technologies and systems they use, extending beyond the core IT environment.
  • Maintains a strong working knowledge of VEIC’s IT systems and their business value.
  • Collaborates with internal stakeholders, providing support and guidance on issues of moderate to high complexity.
  • Proactively identifies and escalates security issues, risks, and operational performance concerns.
  • Performs investigative tasks of moderate complexity and partners with the Manager, Information Security on digital forensics and other investigative efforts.
  • Works closely with the Manager, Information Security on governance and policy activities, including policy maintenance, control reviews, and audit evidence collection.
  • Advises business units across the organization on cyber risk, helping ensure processes remain both practical and secure.
  • Collaborates with technologists across the organization, providing guidance on security best practices.
  • Explores and develops security automation capabilities, including AI‑assisted tools, to enhance security operations.
  • Provides training and guidance to VEIC staff and teams on information security risks in support of organizational and departmental initiatives.
  • Promotes a culture of information security across the organization.
  • Supports the work of other VEIC staff as necessary to achieve organizational goals and objectives.
  • Performs administrative tasks, reporting, and stakeholder communications as needed.
  • Participates in on‑call and after‑hours response activities as needed for security incidents, including on‑site response for events requiring a physical presence.
  • Other duties as assigned.
Knowledge and Experience
  • Strong personal commitment to the mission, vision, goals, and values of VEIC.
  • Strong professional interest in and commitment to the information security field.
  • Strong understanding of information security concepts and principles.
  • 3 or more years of experience in information security operations and/or security engineering within a professional environment, or an equivalent combination of education and experience from which comparable knowledge and skills have been acquired.
  • Demonstrated proficiency in securing and administering Microsoft 365 security products, including Defender for Endpoint, Purview, Entra ID, and Intune.
  • Proficiency with core infrastructure technologies, including enterprise operating systems such as Windows and Linux, TCP/IP networking, storage systems, virtualization, and containerization.
  • Proficiency in scripting or programming languages such as PowerShell and Python.
  • Working knowledge of security technologies including vulnerability scanning, event log management, endpoint security, firewalls, and web application firewalls.
  • Working knowledge of cloud technologies and concepts.
  • Experience with Splunk, including Splunk Enterprise Security (ES), is a plus.
  • Experience with Proofpoint email security products is a plus.
  • Familiarity with digital forensics tools, techniques, and procedures.
  • Familiarity with physical security concepts and practices.
  • Familiarity with offensive security concepts is a plus.
  • Familiarity with Mac Endpoint security is a plus.
  • Demonstrated ability to work independently and manage projects from initiation through completion.
  • Strong interpersonal, written, and verbal communication skills, with a customer service‑oriented approach.
  • Strong analytical, critical thinking, and problem‑solving skills.
  • Ability to remain organized, detail‑oriented, and accurate while managing multiple tasks and competing priorities in a dynamic, fast‑paced environment.
  • Ability to communicate complex technical concepts to non‑technical audiences in a clear and user‑friendly manner.
  • Commitment to continuous learning and professional development.
  • Possess, or be willing to obtain, an entry‑to mid‑level information security certification such as CompTIA Security+, CySA+, or GSEC within the first six months of employment.
  • All positions at VEIC are subject to criminal background checks. This screening is conducted in compliance with applicable laws and is a standard part of our hiring process to ensure the safety and security of our employees, clients, and contractual obligations.
Work Environment and Physical Requirements

This position primarily involves desk‑based work with extensive collaboration and communication responsibilities. Physical requirements include:

  • Ability to remain stationary at a workstation for extended periods (typically 6-8 hours per day with regular breaks)
  • Regular use of computer, keyboard, mouse, and telephone/headset requiring fine motor skills and repetitive hand/wrist movements
  • Visual acuity to view digital screens, documents, and presentations for prolonged periods
  • Verbal communication abilities are sufficient for clear articulation during in‑person and virtual meetings, presentations, and discussions
  • Auditory capabilities to participate effectively in conversations, conference calls, and virtual collaboration sessions
  • Cognitive focus for simultaneous management of multiple communication streams, projects, and stakeholder relationships
  • Occasional movement between meeting spaces, collaboration areas, and individual workstations
  • Minimal lifting requirements (typically under 15 pounds) for office supplies, equipment, or materials

VEIC provides ergonomic assessments and appropriate accommodation to support team members in this collaborative environment, if needed. Our commitment to wellness includes encouraging regular movement breaks and supporting flexible work arrangements that promote sustainable productivity aligned with our core values.

Travel Requirements
No Travel Required

This position does not require regular travel. Occasional in‑person attendance at company events or meetings (typically 0–2 times per year) may be encouraged, but participation is often optional or available virtually.

$90,000 - $100,000 a year

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cyber Security Specialist
Cyber Security Specialist

Vensure Employer Solutions • Duluth (GA)

On-site
USD 80,000 - 100,000
Health Insurance
401(k) Retirement Plan
Paid Time Off
IT Security Engineer II
IT Security Engineer II

MedImpact Healthcare Systems Inc. • San Diego (CA)

On-site
USD 110,982 - 199,769
Medical, Dental, Vision, and Wellness
401K with Company match
PTO and Holidays
+4
Senior Operations Manager
Senior Operations Manager

VEIC • United States

Remote
USD 120,000 - 160,000
Flexible work arrangements
Comprehensive medical benefits
403(b) eligibility with match
+2
IT Security Analyst II
IT Security Analyst II

VC3, Inc. • Northern (KY)

Hybrid
USD 95,000 - 130,000
401K matching
Comprehensive benefits
Junior Endpoint Protection Analyst
Junior Endpoint Protection Analyst

VIATEQ Corporation • Washington

Hybrid
USD 90,000 - 120,000
Medical insurance
Dental insurance
Vision insurance
+5
Information Engineer
Information Engineer

VTG Defense • Chantilly (VA)

On-site
USD 74,000 - 164,000
16267 Senior Cyber Security Specialist
16267 Senior Cyber Security Specialist

Socket.dev • Duluth (GA)

On-site
USD 110,000 - 150,000
Health Insurance
401(k) Plan
Paid Time Off
+1
Enterprise - Information Systems Security Engineer - DIACAP, TCP/IP, STIGs
Enterprise - Information Systems Security Engineer - DIACAP, TCP/IP, STIGs

Erias Ventures • Columbia (MD)

Hybrid
USD 150,000 - 250,000
Above market pay
401k with vesting
Spot bonuses
+11
Information Engineer
Information Engineer

Socket.dev • United States

On-site
USD 74,000 - 164,000
Sr. Security Operations Analyst
Sr. Security Operations Analyst

enVista • Carmel (IN)

Hybrid
USD 120,000 - 150,000
Competitive pay bonuses
Comprehensive health coverage
PTO and sabbatical programme
+3