GXA isseekinga highly capableSecurity Engineerto support the delivery and operation of ourgShieldsecurity services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.
The Security Engineer serves as a Tier 3 escalation pointfor active security and technical issues and plays a key role in operating and improving the gShieldsecurity stack across client environments. This individual will work closely with theInfoSec Manager (vISM),vCISO, SOC, Centralized Services, onboarding teams, and internal technical leadershipto strengthen client security posture and support rapid, effective response to threats and technical issues.
This is an execution-focused role for someone who is comfortable working acrosssecurity and the underlying IT infrastructure that supports it. The ideal candidate understands how networks, servers, identity, endpoints, cloud services, and security controls work together and can troubleshoot across these layers when the root cause is notimmediatelyclear.
This person should be comfortable working in live security events, analyzing alerts and evidence, troubleshooting infrastructure and security issues,executingor supporting remediation, and helpingmaintainthe operational excellence of GXA’s security program.
Key Responsibilities
Incident Response
- Serve as a Tier 3 escalation point for active security incidents, includingbusiness email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
- Lead technical analysis during incident response and war room events, includinglog review, IOC hunting, attacker activity analysis, and lateral movement tracing.
- Execute containment anderadicationactions such asendpoint isolation, session revocation, credential resets, access restriction, and otherappropriate remediationactions.
- Troubleshoot incidents that may span multiple technical layers, includingidentity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
- Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
- Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
- Communicate clearly during active incidents, includingwhat is known, what has been investigated, what actions have been taken, what is being investigated next, and whereadditionalsupport is required.
- Produceaccurateincident timelines, technical findings, and evidence packages forvCISOreview and client-facing follow-up.
Tool Operations & Security Stack Support
- Operate daily within thegShieldtoolstack, including platforms such asHuntress, Microsoft Defender for Endpoint (MDE),Cyrisma,DNSFilter, SIEM, and related security technologies.
- Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
- Support SIEM operations includingquery development, alert review, log analysis, investigation, and rule tuning.
- Assistin tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
- Monitor forsecurity gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
- Correlate information acrossidentity, endpoint, network, server, and cloud sourceswhen investigating security issues.
- Work within established security standards, baselines, and operational policies defined by the security team andvITMs.
Infrastructure & Security Engineering
- Apply security principles acrosson-premises, cloud, and hybrid client environments.
- Troubleshoot security issues involving underlying infrastructure components such asActive Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
- Understand howidentity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
- Support security hardening ofWindows, endpoint, identity, network, and cloud environments.
- Assistwith identity and access security includingMFA, Conditional Access, privileged access, authentication, authorization, and account security.
- Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
- Work effectively with technologies that may be unfamiliar by researching, testing,validating, and documentingappropriate solutionswhile escalating appropriately whenadditionalexpertise is required.
Client Delivery Support
- Execute technical remediation itemsidentifiedthroughMRMMs, preventative actions, vulnerability reviews, and security recommendations.
- SupportgShielddeliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
- Assess vulnerabilities based not only on severity scores but also onasset criticality, exposure, exploitability, existing controls, and business impact.
- Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifyingappropriate compensatingcontrols when immediate remediation is not possible.
- Validate remediation and confirm that identified risks have been appropriately addressed.
- Act as a quality assurance resource for client onboarding into thegShieldtoolstack, while executionremainswith onboarding and Centralized Services teams.
- Assistwith client hardening efforts and follow-through on security improvement actions across managed environments.
- Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.
Internal Security Posture
- Support remediation of internal GXA security backlog items, includingPOA&M-related work.
- Assistwith rollout and support ofphishing-resistant MFA, passkeys, and other internal security initiatives.