Security Engineer

Sperry Rail

Shelton (CT)

Hybrid

USD 110,000 - 170,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Sperry Rail is seeking a Security Engineer to own and mature the security stack across Windows, cloud, and identity platforms in a hybrid role. You will drive vulnerability management, EDR coverage, and incident response while collaborating with the Global IT team on broader infrastructure tasks.

The ideal candidate has deep security experience, hands-on cloud skills (Azure/AWS), and strong communication to quantify security posture for leadership.

Qualifications

  • Five+ years in systems administration or IT infrastructure with a substantial security focus.
  • Strong Windows Server and desktop environments experience.
  • Hands-on cloud infrastructure experience in Azure and AWS.
  • Experience managing Microsoft 365 identity and access configuration (M365 IAM).
  • Experience with enterprise security appliances such as firewalls and routers.
  • Vulnerability management experience: scanning, prioritization, remediation.
  • Scripting for automation (PowerShell, Python, or similar).
  • Ability to explain security decisions to non-technical audiences.
  • Collaborative, team-first mindset aligned with security objectives.

Responsibilities

  • Own the deployment, configuration, and monitoring of vulnerability management across a Windows environment.
  • Monitor EDR coverage, tune, report, and lead incident response.
  • Root cause analysis on security incidents and implement corrective actions.
  • Coordinate penetration testing and remediation with external partners.
  • Maintain security runbooks, asset inventories, and incident logs.
  • Administer and harden Microsoft 365 and Entra ID security configuration.
  • Build and manage access models for third-party SaaS across enterprise systems.
  • Support device management and compliance across the fleet.
  • Align IT processes with ISO 27001 and other frameworks; support assessments.

Skills

Security-focused IT
Windows Server
Azure/AWS
M365 IAM
Security appliances
Vuln management
PowerShell/Python
Risk assessment
Team collaboration
Security leadership

Education

Cybersecurity degree

Tools

Rapid7
SentinelOne
ConnectWise Automate
Intune
ISO 27001

Job description

Role Summary

Security at Sperry is run today by our Global IT team, alongside everything else that team carries. The tooling is in place and the practice around it is real. What it has not had is someone whose primary job it is, and that is the seat we are hiring. You will work across our security stack day to day: endpoint detection and response, vulnerability management, and the identity and access configuration across Microsoft 365 and Entra ID. You will also help mature the practice around those tools, including the runbooks, the asset inventory, the incident handling, and the measures that tell us whether any of it is working. This is a hybrid role by design, and worth being straightforward about. We run a lean Global IT team where everyone wears several hats. You will be our specialized hand on security, and you will also work side by side with the team on general infrastructure and endpoint administration. That breadth is part of the appeal: you will see the whole environment rather than one slice of it, and you will keep building your cloud and infrastructure skills while you are here. We are hiring experience deliberately. This seat carries real responsibility for the security posture of a company that inspects track for most of the major railroads in North America, and what we are looking for is someone who arrives with a view of how this should be done and is willing to challenge how we do it today.

What We Expect From You

We expect an exceptional level of drive and ambition. You think beyond today’s work to what the team and organization need next, champion bold ideas, and see them through. Your hunger is infectious - it inspires those around you to aim higher. We are looking for someone with a genuine no-task-is-too-small attitude. On a small team, the person who investigates the alert is often the person who images the laptop, and we need someone equally willing to do both. This role requires a high degree of self-direction. You will manage complex work with minimal oversight, identify problems and solutions proactively, and may lead workstreams. You make well-reasoned technical decisions and escalate when there is genuine business impact. You should be able to question, challenge, and improve existing practice. You will find things here that were set up for a smaller and simpler company, and part of your value is saying so and then fixing them in a sensible order. Strong communication matters more in this seat than the job title suggests. You will be asking people across the business to work differently, and answering security questions from customers whose own standards we are measured against.

Key Responsibilities
Security engineering and operations
  • Own the deployment, configuration, and daily monitoring of our vulnerability management platform, and drive patching and remediation to closure across a predominantly Windows environment
  • Monitor, tune, and report on endpoint detection and response coverage, and lead the response when something is found
  • Perform root cause analysis on security incidents and see corrective actions through
  • Scope and coordinate penetration testing and remediation with external partners
  • Maintain security runbooks, asset inventories, and incident logs
Identity and access
  • Administer and harden Microsoft 365 and Entra ID, with a focus on secure configuration, conditional access, and mail security
  • Build the access model for third-party SaaS used across enterprise systems and engineering, so that permissions match roles rather than accumulate
  • Support device management and compliance across the fleet
Governance, compliance, and measurement
  • Align IT processes, documentation, and controls with ISO 27001 and other relevant frameworks
  • Support customer security assessments and questionnaires, and own the technical answers in them
  • Establish and maintain security posture KPIs that show whether the program is improving, and report them to IT and digital leadership
  • Contribute to security policy, including acceptable use of AI tools and SaaS
Infrastructure and IT operations
  • Own the configuration and maintenance of security appliances including firewalls and routers
  • Use our central IT management platform for software deployment, patching, scripting, and remote troubleshooting
  • Support provisioning, imaging, and deployment of Windows laptops and workstations
  • Assist with troubleshooting and user access provisioning for core business systems
  • Automate routine work rather than repeating it
Your First Year

The early work is already identified, so you will not spend a quarter looking for a place to start:

  • Take on the vulnerability queue and establish a working remediation cycle with the infrastructure team
  • Stand up device management and compliance reporting across the fleet
  • Scope and run the external penetration testing program, and turn the findings into a prioritized plan
  • Take ownership of the technical response to customer security assessments
  • Establish security posture KPIs, put them in front of leadership, and define what good looks like for the year after
  • Move us toward ISO 27001 alignment, starting with the controls that matter most
Required Skills & Qualifications
  • Five or more years in systems administration or IT infrastructure with a substantial security focus, or a cybersecurity degree with equivalent hands‑on experience
  • Solid foundational knowledge of Windows Server and desktop environments
  • Hands‑on experience with cloud infrastructure in Azure or AWS, and comfort working across both
  • Experience managing and supporting users in Microsoft 365, including identity and access configuration
  • Experience with enterprise‑grade security appliances such as firewalls and routers
  • Practical vulnerability management experience: scanning, prioritization, and driving remediation with teams who do not report to you
  • Scripting for automation of routine tasks (PowerShell, Python, or similar)
  • Sound judgment about risk, and the ability to explain a security decision to a non-technical audience
  • A collaborative, team‑first mindset aligned with our values of being Humble, Hungry, and Smart Qualifications and years of experience are indicative guidelines, not mandatory requirements. These criteria may be met through demonstrated competency or equivalent experience.
Desirable Skills
  • Direct experience with Rapid7, SentinelOne, or comparable vulnerability management and XDR platforms
  • Experience with central IT management platforms such as ConnectWise Automate
  • Working experience with ISO 27001; exposure to NIST, SOC 2, or ITIL is an asset
  • Security certifications (CISSP, CISM, Security+, AZ‑500, AWS Security Specialty, or similar)
  • Device management tooling (Intune or equivalent)
  • Experience as the dedicated security specialist on a small IT team
  • Experience in an operational or industrial environment where availability and safety carry weight
  • Experience in rail testing, NDT, or sensor‑based inspection industries (ultrasound, eddy current, electromagnetic, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 110,000 - 170,000
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Analyst, Security
Analyst, Security

Southern Star Central Gas Pipeline • Owensboro (KY)

On-site
USD 70,000 - 110,000
Medical
Vision
Dental
+7
Information Security Manager
Information Security Manager

Hampton North • Reston (VA)

Hybrid
USD 180,000 - 220,000
Sr Cybersecurity Engineer
Sr Cybersecurity Engineer

Think Consulting • United States

On-site
USD 120,000 - 160,000
Security Engineer
Security Engineer

RouteOne • Farmington Hills (MI)

On-site
USD 85,000 - 115,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

On-site
USD 100,000 - 130,000
Competitive salary
Employer-contributed health benefits
Access to a company cell phone plan
+1
Security Operations Engineer
Security Operations Engineer

Janestreet • New York (NY)

On-site
USD 90,000 - 130,000
Cloud Engineer
Cloud Engineer

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 120,000 - 160,000