Security Engineer

GXA

United States

Remote

USD 120,000 - 180,000

Full time

14 days+
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

GXA is seeking a highly capable Security Engineer to support the delivery and operation of our gShield security services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.

The Security Engineer serves as a Tier 3 escalation point for active security issues and plays a key role in operating and improving the

Qualifications

  • Experience in security incident response and escalation.
  • Hands-on security engineering across on-prem and cloud.
  • Experience with security tooling and SIEMs.

Responsibilities

  • Serve as a Tier 3 escalation point for active security incidents.
  • Lead technical analysis during incident response and war rooms.
  • Operate daily within the gShield toolstack (Huntress, MDE, Cyrisma, DNSFilter, SIEM).
  • Troubleshoot security issues across identity, endpoints, servers, networking, and cloud.
  • Support remediation and validation of vulnerabilities and security controls.
  • Assist with client onboarding and security improvements across managed environments.

Skills

Incident Response
Tool Operations
Security Engineering
Threat Hunting
Log Analysis

Tools

Huntress
MDE
Cyrisma
DNSFilter
SIEM

Job description

GXA isseekinga highly capableSecurity Engineerto support the delivery and operation of ourgShieldsecurity services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.

The Security Engineer serves as a Tier 3 escalation pointfor active security and technical issues and plays a key role in operating and improving the gShieldsecurity stack across client environments. This individual will work closely with theInfoSec Manager (vISM),vCISO, SOC, Centralized Services, onboarding teams, and internal technical leadershipto strengthen client security posture and support rapid, effective response to threats and technical issues.

This is an execution-focused role for someone who is comfortable working acrosssecurity and the underlying IT infrastructure that supports it. The ideal candidate understands how networks, servers, identity, endpoints, cloud services, and security controls work together and can troubleshoot across these layers when the root cause is notimmediatelyclear.

This person should be comfortable working in live security events, analyzing alerts and evidence, troubleshooting infrastructure and security issues,executingor supporting remediation, and helpingmaintainthe operational excellence of GXA’s security program.

Key Responsibilities
Incident Response
  • Serve as a Tier 3 escalation point for active security incidents, includingbusiness email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
  • Lead technical analysis during incident response and war room events, includinglog review, IOC hunting, attacker activity analysis, and lateral movement tracing.
  • Execute containment anderadicationactions such asendpoint isolation, session revocation, credential resets, access restriction, and otherappropriate remediationactions.
  • Troubleshoot incidents that may span multiple technical layers, includingidentity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
  • Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
  • Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
  • Communicate clearly during active incidents, includingwhat is known, what has been investigated, what actions have been taken, what is being investigated next, and whereadditionalsupport is required.
  • Produceaccurateincident timelines, technical findings, and evidence packages forvCISOreview and client-facing follow-up.
Tool Operations & Security Stack Support
  • Operate daily within thegShieldtoolstack, including platforms such asHuntress, Microsoft Defender for Endpoint (MDE),Cyrisma,DNSFilter, SIEM, and related security technologies.
  • Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
  • Support SIEM operations includingquery development, alert review, log analysis, investigation, and rule tuning.
  • Assistin tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
  • Monitor forsecurity gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
  • Correlate information acrossidentity, endpoint, network, server, and cloud sourceswhen investigating security issues.
  • Work within established security standards, baselines, and operational policies defined by the security team andvITMs.
Infrastructure & Security Engineering
  • Apply security principles acrosson-premises, cloud, and hybrid client environments.
  • Troubleshoot security issues involving underlying infrastructure components such asActive Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
  • Understand howidentity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
  • Support security hardening ofWindows, endpoint, identity, network, and cloud environments.
  • Assistwith identity and access security includingMFA, Conditional Access, privileged access, authentication, authorization, and account security.
  • Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
  • Work effectively with technologies that may be unfamiliar by researching, testing,validating, and documentingappropriate solutionswhile escalating appropriately whenadditionalexpertise is required.
Client Delivery Support
  • Execute technical remediation itemsidentifiedthroughMRMMs, preventative actions, vulnerability reviews, and security recommendations.
  • SupportgShielddeliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
  • Assess vulnerabilities based not only on severity scores but also onasset criticality, exposure, exploitability, existing controls, and business impact.
  • Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifyingappropriate compensatingcontrols when immediate remediation is not possible.
  • Validate remediation and confirm that identified risks have been appropriately addressed.
  • Act as a quality assurance resource for client onboarding into thegShieldtoolstack, while executionremainswith onboarding and Centralized Services teams.
  • Assistwith client hardening efforts and follow-through on security improvement actions across managed environments.
  • Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.
Internal Security Posture
  • Support remediation of internal GXA security backlog items, includingPOA&M-related work.
  • Assistwith rollout and support ofphishing-resistant MFA, passkeys, and other internal security initiatives.
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Incident Response & Infra Security
Security Engineer - Incident Response & Infra Security

GXA • United States

Remote
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

Talentify • Duluth (GA)

On-site
USD 120,000 - 180,000
Security Analyst
Security Analyst

AGS - American Gaming Systems • Las Vegas (NV)

On-site
USD 90,000 - 120,000
Security Engineer
Security Engineer

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 100,000 - 150,000
Security Engineer
Security Engineer

Talentify • Duluth (GA)

On-site
USD 110,000 - 140,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Security Analyst
Security Analyst

Talentify • Duluth (GA)

On-site
USD 85,000 - 110,000
IT Security Specialist
IT Security Specialist

ibex • Palestine (TX)

On-site
USD 90,000 - 130,000
Engineer II, Security Engineering
Engineer II, Security Engineering

ivision • United States

On-site
USD 90,000 - 130,000