IT Security Engineer

Kens Foods

Marlborough (MA)

On-site

USD 120,000 - 130,000

Full time

2 days ago
Be an early applicant
Application generator

Stand out for this role — generate a tailored resume and cover letter in about a minute.

Get past ATS filters

Job summary

Kens Foods seeks a highly technical IT Security Engineer to build and mature its cybersecurity program in a food & beverage manufacturing environment. You’ll be the primary hands-on technical resource supporting cybersecurity initiatives and collaborating with IT, OT teams and MSSP SOC.

Role focuses on hardening Windows servers and endpoints, securing networks, and leading vulnerability remediation. Experience with SOC alerts and OWASP Top 10 is valuable.

Qualifications

  • 5–8+ years in IT security engineering, SOC, or incident response roles.
  • Strong hands-on experience with Windows Server and client security; network/firewall security; endpoint security tools; MFA and identity systems.
  • Strong knowledge of Active Directory and identity security best practices.
  • Experience hardening servers, endpoints, and network devices.
  • Familiarity with log analysis and security event triage.
  • Comfort working directly with SOC alerts and vulnerability scan reports.
  • Understanding of security frameworks (NIST CSF, CIS Controls, SOC 2).
  • Strong documentation habits and process-oriented mindset.

Responsibilities

  • Review alerts and escalations from the MSSP to validate severity, impact, and actions.
  • Conduct technical investigations and support containment, eradication, and recovery activities.
  • Harden and secure Windows servers, clients, VMs, and IT infrastructure.
  • Ensure secure configuration and management of endpoint protection (SentinelOne).
  • Collaborate with IT infrastructure to secure firewall, switches, and network segments.
  • Support network security improvements such as segmentation and least privilege access.
  • Perform firewall rule reviews and contribute to network hardening.
  • Support secure configuration of identity platforms and RBAC.
  • Enforce privileged access hygiene and identity hardening standards.
  • Coordinate remediation with system and network teams; lead patching for high-risk assets.
  • Work with developers to identify and fix security issues (OWASP Top 10).
  • Conduct security reviews of applications and servers.
  • Collaborate with OT engineers on legacy systems, PLCs, and OT network segmentation.

Skills

Windows security
Network security
Endpoint security
MFA & identity
Active Directory security
SOC alert handling
Vulnerability management
Security frameworks
Documentation

Tools

SentinelOne
Active Directory
Firewall & network config
Vulnerability scanners

Job description

Summary We are seeking a highly technical, hands–on IT Security Engineer to help build and mature the cybersecurity program of a food & beverage manufacturing organization. This role is ideal for a driven, detail–oriented engineer who enjoys hardening systems, securing networks, performing technical investigations, and working side–by–side with IT and OT teams to improve our security posture. You will be the primary "hands–on keyboard" technical resource supporting cybersecurity initiatives and will partner closely with our IT teams, and our MSSP SOC.

Key Responsibilities
  • Review alerts and escalations from the MSSP to validate severity, impact, and required actions.
  • Conduct technical investigation steps and support containment, eradication, and recovery activities.
  • Harden and secure Windows servers, Windows clients, virtual machines, and other IT infrastructure.
  • Ensure secure configuration, deployment, and management of endpoint protection (SentinelOne).
  • Collaborate with the IT infrastructure team to ensure secure configurations across firewalls, switches, and network segments.
  • Support network security improvements such as segmentation, least privilege network access, and secure remote access.
  • Perform firewall rule reviews and contribute to network hardening efforts.
  • Support secure configuration of identity platforms.
  • Enforce role–based access controls, privileged access hygiene, and identity hardening standards.
  • Work with the MSSP to ensure vulnerability scans are properly executed and tuned.
  • Validate findings, prioritize risk, and coordinate remediation work with system and network teams.
  • Lead patching and configuration remediation efforts for high–risk assets.
  • Work with developers to identify, prioritize, and fix security issues (OWASP Top 10).
  • Conduct security reviews of applications and servers.
  • Collaborate with OT engineers to understand legacy systems, PLCs, and plant–floor constraints and assist in implementation of OT network segmentation and ICT security controls.
  • Actively monitor emerging threats affecting OT and IT environments.
  • Conduct periodic threat modeling for high–risk applications and systems.
Required Qualifications
  • 5–8+ years of experience in IT security engineering, SOC, or incident response roles.
  • Strong hands–on experience with: Windows Server and client security; Network and firewall security; Endpoint security tools; MFA and identity systems.
  • Strong knowledge of Active Directory and identity security best practices.
  • Practical experience hardening servers, endpoints, and network devices.
  • Familiarity with log analysis and security event triage.
  • Comfort working directly with SOC alerts and vulnerability scan reports.
  • Understanding of security frameworks (NIST CSF, CIS Controls, SOC 2).
  • Strong documentation habits and process–oriented mindset.
Preferred Qualifications
  • Experience in manufacturing, industrial, or OT/ICS environments.
  • Working knowledge of PLCs, or ISA/IEC 62443 principles.
  • Familiarity with Office 365 security configuration and best practices.
  • Experience automating workflows using PowerShell or Python.
  • Exposure to segmentation projects or Zero Trust principles.
  • Relevant certifications: GSEC, GCED, GCIH, GDSA, GDAT, GICSP, GCIP, and GRID.

Work Authorization Notice: Please note that we do not provide visa sponsorship or immigration support for this position. Applicants must already be authorized to work in the United States on a full–time, permanent basis without the need for current or future sponsorship.

The salary for this position is determined by a combination of experience, skills, and education level. The compensation range is $120K–130k annually.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

IT Security Engineer
IT Security Engineer

Ken’s Foods, Inc. • Marlborough (MA)

On-site
USD 120,000 - 130,000
Security Engineer – Operational Technology
Security Engineer – Operational Technology

TriCom Technical Services • Kansas City (KS)

On-site
USD 90,000 - 120,000
Medical/Dental Benefits
Paid time off
Paid Holidays
+1
IT/OT Security Engineer & Incident Response Manager
IT/OT Security Engineer & Incident Response Manager

1440 Foods Manufacturing • New York (NY)

On-site
USD 120,000 - 190,000
IT/OT Security Engineer & Incident Response Manager
IT/OT Security Engineer & Incident Response Manager

1440 Foods • New York (NY)

On-site
USD 120,000 - 170,000
Cyber Security Engineer
Cyber Security Engineer

Qualibar • United States

Hybrid
USD 120,000 - 180,000
OT Security Architect
OT Security Architect

Motion Recruitment Partners LLC • Philadelphia

On-site
USD 140,000 - 180,000
Bonus 15%
Medical Insurance
Dental Insurance
+2
Information Security Engineer
Information Security Engineer

eTrepid • Mechanicsville (MD)

On-site
USD 90,000 - 130,000
Information Technology Security Engineer
Information Technology Security Engineer

DoubleLine • California (MO)

On-site
USD 130,000 - 150,000
Annual discretionary bonus
Comprehensive benefits package
OT Cybersecurity Architect
OT Cybersecurity Architect

Plexus Corp. • Neenah (WI)

On-site
USD 129,500 - 194,300
Industrial Cybersecurity Engineer – OT/IT Focus
Industrial Cybersecurity Engineer – OT/IT Focus

Kens Foods • Marlborough (MA)

On-site
USD 120,000 - 130,000