Security Engineer

Sperry Rail, Inc.

Shelton (CT)

Hybrid

USD 120,000 - 180,000

Full time

26 hours ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Sperry Rail, Inc. is seeking a Security Engineer to own deployment, configuration, and monitoring of our vulnerability management across a predominantly Windows environment.

The role partners with our Global IT team to mature incident handling, asset inventories, and runbooks while building cloud and infrastructure security skills. You will manage identity and access in Microsoft 365 and Entra ID, support device management, and contribute to governance, compliance, and security metrics.

Qualifications

  • Five or more years in systems administration or IT infrastructure with a strong security focus.
  • Solid knowledge of Windows Server and desktop environments.
  • Hands-on cloud infrastructure experience in Azure or AWS, across both.
  • Experience with Microsoft 365 identity and access configuration.
  • Experience with enterprise security appliances (firewalls/routers).
  • Vulnerability management experience including remediation coordination.

Responsibilities

  • Own deployment, configuration, and monitoring of vulnerability management across Windows environment.
  • Monitor endpoint detection and response coverage and lead incident responses.
  • Perform root cause analysis on security incidents and drive corrective actions.
  • Scope and coordinate external penetration testing and remediation.
  • Maintain security runbooks, asset inventories, and incident logs.
  • Collaborate with infrastructure team to improve security posture.

Skills

Windows Server
Cloud infrastructure
Microsoft 365 Identity
Vulnerability management
Scripting (PowerShell/Python)
Security decision making

Education

Bachelor's degree in cybersecurity or related field

Tools

Rapid7
SentinelOne
ConnectWise Automate

Job description

Security Engineer
Sperry Rail, Inc. Shelton, Connecticut, United States
About this position
About Sperry:

Sperry Rail is on a mission-critical journey to revolutionize the Rail Flaw Detection industry. Through the continuous development of cutting-edge diagnostic technologies and AI-assisted analysis, we are transforming railway safety worldwide. Our global engineering teams work collaboratively to develop step-change technologies that define Sperry as the unparalleled market leader.

For nearly a century, we have repeatedly modernized and improved rail diagnostics through our relentless pursuit of improvement. Determined is an understatement. We are obsessed with advancing science and raising the bar on what’s possible with our ever-improving suite of products and service offerings.

Emboldened through the shared values of honesty, accountability, passion, integrity, and teamwork, we are driven by the challenge and bridging concepts with fruition. Each technologist entering Sperry imprints themselves into our brand and further galvanizes a culture of innovation and advancement. Allow us to be clear, Thought Leaders are welcome!

We are agile and hungry and invite those with similar passions to join us in challenging the status quo and bringing new ideas to the market. Fast-paced, high-touch with a distinct sense of purpose. We offer more than a job; we offer an opportunity to be part of something different.

Role Summary

Security at Sperry is run today by our Global IT team, alongside everything else that team carries. The tooling is in place and the practice around it is real. What it has not had is someone whose primary job it is, and that is the seat we are hiring. You will work across our security stack day to day: endpoint detection and response, vulnerability management, and the identity and access configuration across Microsoft 365 and Entra ID. You will also help mature the practice around those tools, including the runbooks, the asset inventory, the incident handling, and the measures that tell us whether any of it is working. This is a hybrid role by design, and worth being straightforward about. We run a lean Global IT team where everyone wears several hats. You will be our specialized hand on security, and you will also work side by side with the team on general infrastructure and endpoint administration. That breadth is part of the appeal: you will see the whole environment rather than one slice of it, and you will keep building your cloud and infrastructure skills while you are here. We are hiring experience deliberately. This seat carries real responsibility for the security posture of a company that inspects track for most of the major railroads in North America, and what we are looking for is someone who arrives with a view of how this should be done and is willing to challenge how we do it today.

What We Expect From You

We expect an exceptional level of drive and ambition. You think beyond today's work to what the team and organization need next, champion bold ideas, and see them through. Your hunger is infectious - it inspires those around you to aim higher. We are looking for someone with a genuine no-task-is-too-small attitude. On a small team, the person who investigates the alert is often the person who images the laptop, and we need someone equally willing to do both. This role requires a high degree of self-direction. You will manage complex work with minimal oversight, identify problems and solutions proactively, and may lead workstreams. You make well-reasoned technical decisions and escalat when there is genuine business impact. You should be able to question, challenge, and improve existing practice. You will find things here that were set up for a smaller and simpler company, and part of your value is saying so and then fixing them in a sensible order. Strong communication matters more in this seat than the job title suggests. You will be asking people across the business to work differently, and answering security questions from customers whose own standards we are measured against.

Key Responsibilities
Security engineering and operations
  • Own the deployment, configuration, and daily monitoring of our vulnerability management platform, and drive patching and remediation to closure across a predominantly Windows environment
  • Monitor, tune, and report on endpoint detection and response coverage, and lead the response when something is found
  • Perform root cause analysis on security incidents and see corrective actions through
  • Scope and coordinate penetration testing and remediation with external partners
  • Maintain security runbooks, asset inventories, and incident logs
Identity and access
  • Administer and harden Microsoft 365 and Entra ID, with a focus on secure configuration, conditional access, and mail security
  • Build the access model for third-party SaaS used across enterprise systems and engineering, so that permissions match roles rather than accumulate
  • Support device management and compliance across the fleet
Governance, compliance, and measurement
  • Align IT processes, documentation, and controls with ISO 27001 and other relevant frameworks
  • Support customer security assessments and questionnaires, and own the technical answers in them
  • Establish and maintain security posture KPIs that show whether the program is improving, and report them to IT and digital leadership
  • Contribute to security policy, including acceptable use of AI tools and SaaS
Infrastructure and IT operations
  • Own the configuration and maintenance of security appliances including firewalls and routers
  • Use our central IT management platform for software deployment, patching, scripting, and remote troubleshooting
  • Support provisioning, imaging, and deployment of Windows laptops and workstations
  • Assist with troubleshooting and user access provisioning for core business systems
  • Automate routine work rather than repeating it
Your First Year
  • Take on the vulnerability queue and establish a working remediation cycle with the infrastructure team
  • Stand up device management and compliance reporting across the fleet
  • Scope and run the external penetration testing program, and turn the findings into a prioritized plan
  • Take ownership of the technical response to customer security assessments
  • Establish security posture KPIs, put them in front of leadership, and define what good looks like for the year after
  • Move us toward ISO 27001 alignment, starting with the controls that matter most
Required Skills & Qualifications
  • Five or more years in systems administration or IT infrastructure with a substantial security focus, or a cybersecurity degree with equivalent hands‑on experience
  • Solid foundational knowledge of Windows Server and desktop environments
  • Hands‑on experience with cloud infrastructure in Azure or AWS, and comfort working across both
  • Experience managing and supporting users in Microsoft 365, including identity and access configuration
  • Experience with enterprise‑grade security appliances such as firewalls and routers
  • Practical vulnerability management experience: scanning, prioritization, and driving remediation with teams who do not report to you
  • Scripting for automation of routine tasks (PowerShell, Python, or similar)
  • Sound judgment about risk, and the ability to explain a security decision to a non‑technical audience
  • A collaborative, team‑first mindset aligned with our values of being Humble, Hungry, and Smart Qualifications and years of experience are indicative guidelines, not mandatory requirements. These criteria may be met through demonstrated competency or equivalent experience.
  • Direct experience with Rapid7, SentinelOne, or comparable vulnerability management and XDR platforms
  • Experience with central IT management platforms such as ConnectWise Automate
  • Working experience with ISO 27001; exposure to NIST, SOC 2, or ITIL is an asset
  • Security certifications (CISSP, CISM, Security+, AZ‑500, AWS Security Specialty, or similar)
  • Device management tooling (Intune or equivalent)
  • Experience as the dedicated security specialist on a small IT team
  • Experience in an operational or industrial environment where availability and safety carry weight
  • Experience in rail testing, NDT, or sensor‑based inspection industries (ultrasound, eddy current, electromagnetic, etc.)
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cloud Engineer
Cloud Engineer

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 120,000 - 160,000
Machine Learning Engineer
Machine Learning Engineer

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 120,000 - 180,000
Security Engineer — IT & Infrastructure (Industrial Rail)
Security Engineer — IT & Infrastructure (Industrial Rail)

Sperry Rail, Inc. • Shelton (CT)

Hybrid
USD 120,000 - 180,000
Lead Data Scientist, Rail Data and Risk
Lead Data Scientist, Rail Data and Risk

Sperry Rail, Inc. • Shelton (CT)

On-site
USD 140,000 - 190,000
Information Security Manager
Information Security Manager

Hampton North • Reston (VA)

Hybrid
USD 180,000 - 220,000
Cybersecurity Analyst
Cybersecurity Analyst

Jobtailor • Cincinnati (OH)

On-site
USD 110,000 - 140,000
Senior Security Engineer
Senior Security Engineer

Novacoast • Salt Lake City (UT)

On-site
USD 100,000 - 130,000
Staff Security Engineer (Product Security and Architecture)
Staff Security Engineer (Product Security and Architecture)

Compass • Ventura (CA)

On-site
USD 150,000 - 230,000
Security Development Engineering
Security Development Engineering

FSR, LLC. • Herndon (VA)

Hybrid
USD 90,000 - 130,000
Security Operations Engineer
Security Operations Engineer

Reserv • Atlanta (GA)

Hybrid
USD 80,000 - 100,000
Generous health-insurance package
401(k) retirement plan with employer matching
Competitive PTO policy
+1