The Security Engineer is responsible for the secure configuration, hardening, and ongoing operation of the AGS security control set and the systems those controls protect. The role ensures that documented security policy and technical standards match what is actually configured in the environment, identifies and remediates configuration drift and misconfiguration, and keeps the technical estate aligned to current industry baselines as they evolve. This is a hands‑on engineering role focused on sustained operational quality, taking ownership of the platforms and standards the security team implements and keeping them healthy, current, and effective over time. The role receives technical direction from the Senior Security Engineer and partners closely with Infrastructure, Network, Enterprise Apps, and Business Systems teams.
Responsibilities
- Lead system and platform hardening across servers, endpoints, network devices, and cloud services using recognized configuration baselines such as CIS Benchmarks and vendor security baselines.
- Validate that logical configuration across the environment aligns to documented security policy and technical standards, and remediate deviations.
- Identify, document, and remediate misconfigurations across infrastructure, identity, and security tooling.
- Implement and monitor configuration drift detection and drive corrective action where baselines have decayed.
- Enforce endpoint baseline hardening and device compliance policies through enterprise endpoint management tooling.
- Operationalize device control, application control, and disk encryption policies.
- Administer day‑to‑day operation, tuning, and lifecycle maintenance of enterprise security platforms, including endpoint protection, email security, and access control tooling.
- Maintain security tooling coverage and health, and resolve gaps in agent deployment or policy application.
- Support vulnerability remediation by implementing patches, configuration changes, and compensating controls in coordination with IT operations.
- Implement changes required to keep the environment aligned with evolving industry standards, vendor guidance, and control framework updates.
- Implement and maintain security controls for hybrid environments combining on‑premises infrastructure and cloud‑based systems.
- Use scripting and automation (PowerShell, KQL, Graph API) to reduce manual configuration work and enforce consistency.
- Maintain accurate technical documentation for configuration standards, operational procedures, and control implementation.
- Partner with systems, network, database, and application teams to implement security requirements without unnecessary disruption to operations.
- Provide technical evidence supporting internal and external audit, certification, and regulatory assessment activities.
- Participate in the incident response lifecycle as assigned, including containment, eradication, and recovery support.
- Balance security requirements with user experience needs to maintain productivity alongside a strong security posture.
- Occasional travel throughout the United States.
Qualifications
- Secure configuration and hardening: CIS Benchmarks, DISA STIGs, or vendor security baselines across Windows and Linux systems.
- Endpoint management and compliance: MDM/MAM tooling, compliance policies, security baselines, device and application control.
- Enterprise security platform administration: endpoint protection (EDR/XDR), email security, access control tooling.
- Configuration drift detection and remediation, and reconciling documented policy against live configuration.
- Patch and vulnerability remediation execution, including compensating control design.
- Hybrid infrastructure fundamentals: virtualization, enterprise directory services, and cloud service configuration.
- Scripting and automation (PowerShell, KQL, Graph API); configuration management or infrastructure‑as‑code preferred.
- Working understanding of network segmentation and access control concepts.
- Strong documentation discipline and attention to detail.
Skills/Requirements
- Bachelor's Degree in Computer Science, Information Security, Information Technology, or equivalent work experience.
- At least 3 years of experience in security engineering, systems engineering, or infrastructure operations with meaningful security responsibility.
- Demonstrated hands‑on experience hardening Windows and Linux systems against recognized configuration baselines.
- Practical experience administering enterprise security tooling such as endpoint protection, email security, or access control platforms.
- Experience reconciling documented policy against live system configuration and closing the resulting differences.
- Experience working in hybrid environments with a mix of on‑premises and cloud‑based systems.
- Familiarity with industry frameworks (NIST, CIS, ISO 27001) and how framework requirements translate into technical configuration.
- Demonstrated ability to balance robust security controls with positive user experience and business enablement.
- Relevant technical certifications required or strongly preferred: CompTIA Security+, CySA+, SSCP, GSEC, or equivalent.
Preferred Certification
- Professional technical certifications such as CompTIA Security+, CySA+, CEH, SSCP, or GSEC, with demonstrated progression toward a senior‑level technical certification. Platform‑specific certifications are considered supplemental to demonstrated hands‑on capability.
Note: All offers are contingent upon successful completion of a background check
*Posted positions are not open to third party recruiters and unsolicited resume submissions will be considered free referrals.