Security Engineer: Cloud & Endpoint Hardening

AGS LLC

Atlanta (GA)

On-site

USD 110,000 - 150,000

Full time

2 days ago
Be an early applicant
Application generator

A complete application in a minute — tailored resume and cover letter, ready to send.

Get past ATS filters

Job summary

AGS LLC in Atlanta, GA is seeking a Security Engineer to own secure configuration, hardening, and ongoing operation of the security control set protecting critical systems. You will ensure documented security policy and standards match what is deployed and remediate drift across Windows, Linux, and cloud environments.

This hands-on role collaborates with Infrastructure, Network, and Business Systems teams, uses PowerShell and KQL to automate tasks, and supports audits and incident response.

Qualifications

  • Bachelor’s degree in Computer Science, Information Security, IT, or equivalent.
  • At least 3 years of experience in security or systems engineering with security responsibilities.
  • Hands-on experience hardening Windows and Linux to recognized baselines.
  • Experience administering enterprise security tools (EDR/XDR, email security, access control).
  • Experience reconciling policy with live configurations and closing gaps.
  • Experience in hybrid on-premise and cloud environments.
  • Familiarity with NIST, CIS, ISO 27001; translate to technical configuration.
  • Ability to balance strong security controls with user experience.
  • Relevant certifications (CompTIA Security+, CySA+, SSCP, GSEC) preferred.

Responsibilities

  • Lead system and platform hardening across servers, endpoints, network devices, and cloud services using baselines.
  • Validate that configurations align to policy and technical standards, and remediate deviations.
  • Identify, document, and remediate misconfigurations across infrastructure, identity, and tooling.
  • Implement and monitor configuration drift detection and drive corrective action where baselines have decayed.
  • Enforce endpoint baseline hardening and device compliance policies through enterprise endpoint management tooling.
  • Operate security platforms including endpoint protection, email security, and access control tooling.
  • Maintain security tooling coverage and health, and resolve gaps in agent deployment or policy application.
  • Support vulnerability remediation by implementing patches, configuration changes, and compensating controls.
  • Implement changes required to keep the environment aligned with evolving industry standards and vendor guidance.
  • Implement and maintain security controls for hybrid environments combining on-premises and cloud-based systems.
  • Use scripting and automation (PowerShell, KQL, Graph API) to reduce manual configuration work and enforce consistency.
  • Maintain accurate technical documentation for configuration standards, operational procedures, and control implementation.
  • Partner with systems, network, database, and application teams to implement security requirements with minimal disruption.
  • Provide technical evidence supporting internal and external audit, certification, and regulatory assessment activities.
  • Participate in the incident response lifecycle as assigned, including containment, eradication, and recovery support.
  • Balance security requirements with user experience needs to maintain productivity alongside a strong security posture.

Skills

Secure config
Endpoint management
Security tooling
Configuration drift remediation
Patch & vulnerability
Hybrid infrastructure
Scripting automation
Documentation discipline
Audit support
Travel flexibility

Education

Bachelor's Degree in Computer Science, Information Security, IT, or equivalent

Tools

EDR/XDR
Email security
Access control tools

Job description

AGS LLC in Atlanta, GA is seeking a Security Engineer to own secure configuration, hardening, and ongoing operation of the security control set protecting critical systems. You will ensure documented security policy and standards match what is deployed and remediate drift across Windows, Linux, and cloud environments.

This hands-on role collaborates with Infrastructure, Network, and Business Systems teams, uses PowerShell and KQL to automate tasks, and supports audits and incident response.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer - Cloud & Endpoint Hardening
Security Engineer - Cloud & Endpoint Hardening

AGS LLC • Duluth (GA)

On-site
USD 110,000 - 140,000
Security Engineer: Harden & Safeguard Hybrid Infra
Security Engineer: Harden & Safeguard Hybrid Infra

Jobvite, Inc. • Duluth (GA)

Hybrid
USD 120,000 - 210,000
Security Engineer - Cloud & On-Prem Hardening
Security Engineer - Cloud & On-Prem Hardening

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 100,000 - 150,000
Security Engineer
Security Engineer

AGS LLC • Duluth (GA)

On-site
USD 110,000 - 140,000
Security Engineer
Security Engineer

AGS LLC • Atlanta (GA)

On-site
USD 110,000 - 150,000
Security Engineer
Security Engineer

Talentify • Duluth (GA)

On-site
USD 110,000 - 140,000
Security Engineer
Security Engineer

AGS - American Gaming Systems • Atlanta (GA)

On-site
USD 100,000 - 150,000
Senior Security Engineer: Identity & Threat Defense Lead
Senior Security Engineer: Identity & Threat Defense Lead

Jobvite, Inc. • Atlanta (GA)

On-site
USD 140,000 - 190,000
Senior Security Engineer: IAM, SIEM & Threat Response
Senior Security Engineer: IAM, SIEM & Threat Response

AGS LLC • Duluth (GA)

On-site
USD 120,000 - 180,000
Senior Security Engineer
Senior Security Engineer

AGS LLC • Atlanta (GA)

Hybrid
USD 110,000 - 170,000