Senior Cybersecurity Engineer

Amro Fabricating Corporation

Huntington Beach (CA)

On-site

USD 130,000 - 165,000

Full time

4 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, dental, and vision insurance
401(k) with company match
Paid time off
Health Savings Account (HSA) with公司贡献
Flexible Spending Accounts (FSA)
Company-paid life and AD&D insurance
Short‑ and long‑term disability

Job summary

Karman Space & Defense is seeking a Senior Cybersecurity Engineer to strengthen identity security, vulnerability management, and remediation across multi-site environments in Huntington Beach. You will work with Microsoft Entra ID, M365 GCC High, and cloud security to ensure secure access and compliant operations.

The role requires 7+ years in cybersecurity engineering, hands-on AD/Entra ID expertise, and experience with vulnerability programs, audits, and regulated controls in aerospace/defense

Qualifications

  • 7+ years of progressive experience in cybersecurity engineering or related roles.
  • Hands-on experience with AD, Entra ID, M365, MFA, conditional access, SSO, privileged access, and non-human identities.
  • Experience operating enterprise vulnerability-management tools and coordinating remediation.

Responsibilities

  • Engineer and mature identity security across AD, Entra ID, and Microsoft 365 environments.
  • Strengthen identity lifecycle, MFA, conditional access, RBAC, and non-human identities.
  • Manage vulnerability programs with authenticated scanning and remediation tracking.
  • Collaborate with Infrastructure to enhance endpoint, server, and cloud security.
  • Evaluate new Microsoft 365, SaaS, cloud, and AI capabilities for identity and data handling.
  • Administer security tools, investigate alerts, support containment, and incident hardening.
  • Support audits and regulatory control evidence (CMMC 2, NIST 800-171, DFARS, ITGC).
  • Mentor teams and document technical controls and remediation guides.

Skills

Identity & access management
Vulnerability management
Endpoint security
Active Directory
Microsoft Entra ID
Microsoft 365 GCC High
Cloud security
Security tooling (Defender, SIEM)

Education

Bachelor’s degree in cybersecurity/IT/CS/engineering

Tools

Tenable
Qualys
Rapid7
Defender

Job description

If you are unable to complete this application due to a disability, contact this employer to ask for an accommodation or an alternative application process.

Senior Cybersecurity Engineer

Full Time Professional Huntington Beach, CA, US

4 days ago Requisition ID: 3857

Salary Range: $130,000.00 To $165,000.00 Annually

Karman Space & Defense is a leader in the rapid design, development, and production of critical, next-generation system solutions that align with the U.S. Department of War and its allies’ core mission priorities, and meet the accelerating demand for access to space. Building on nearly 50 years of success, we deliver Payload & Protection Systems, Aero/Hydrodynamic Interstage Systems, and Propulsion & Launch Systems to more than 80 prime contractors supporting over 130 space and defense programs.

This role strengthens identity security, privileged access, vulnerability management, and technical remediation across Karman’s multi-site environment. You will engineer and continuously improve security controls across Microsoft platforms, endpoints, servers, cloud environments, site technologies, and specialized assets. Working closely with Infrastructure, Business Systems, site teams, and service providers, you will ensure clear ownership, reliable evidence, and sustainable remediation that supports regulated aerospace and defense requirements.

Responsibilities

  • Engineers and improves identity security across Active Directory, Microsoft Entra ID, Microsoft 365 GCC High, cloud platforms, business applications, and related services.
  • Strengthens identity lifecycle processes, access provisioning, privileged access, multifactor authentication (MFA), conditional access, role-based access control, and non-human identity protections.
  • Operates and matures enterprise vulnerability management, ensuring authenticated scanning, asset coverage, data quality, prioritization, remediation coordination, and validated closure.
  • Partners with Infrastructure to enhance endpoint, server, and cloud security through patching, encryption, device management, configuration baselines, detection capabilities, and Microsoft security tools.
  • Reviews new Microsoft 365, Software‑as‑a‑Service (SaaS), cloud, and AI-enabled capabilities for identity, access, logging, and data‑handling requirements.
  • Administers assigned security tools and investigates identity, endpoint, email‑security, vulnerability, and logging alerts; supports containment, evidence preservation, and post‑incident hardening.
  • Implements, validates, and documents technical controls supporting CMMC Level 2, NIST SP 800‑171, DFARS, Controlled Unclassified Information (CUI), and Sarbanes‑Oxley (SOX) Information Technology General Controls (ITGC).
  • Supports technical remediation of assessment findings, audit gaps, Plans of Action and Milestones (POA\&Ms), and control failures and participates in walkthroughs, reviews, and assessments.
  • Reviews technology projects, integrations, deployments, SaaS services, vendor solutions, and M\&A activities for identity, vulnerability, endpoint, and data‑exposure risks.
  • Maintains technical procedures, configurations, remediation guides, metrics, and automation opportunities and mentors IT and security teams to strengthen operating capability.

Required Qualifications

  • Bachelor’s degree in cybersecurity, information technology, computer science, engineering, or a related field; equivalent relevant experience may be considered.
  • 7+ years of progressive experience in cybersecurity engineering, identity and access management, vulnerability management, endpoint security, infrastructure security, or related roles.
  • Hands‑on experience with Active Directory, Microsoft Entra ID, Microsoft 365, MFA, conditional access, single sign‑on (SSO), privileged access, identity lifecycle processes, and non‑human identities.
  • Experience operating enterprise vulnerability‑management tools, establishing scan coverage, prioritizing risk, coordinating remediation, and validating closure.
  • Experience with endpoint protection, hardening, patching, device compliance, security monitoring, and the Microsoft security ecosystem.
  • Working knowledge of Windows endpoint and server security, cloud and network security, segmentation, secure configuration, logging, and incident response.
  • Experience producing technical control evidence and supporting audits, assessments, or regulated control environments.
  • Strong troubleshooting, documentation, communication, and cross‑functional coordination skills in a fast‑paced, multi‑site environment.

Preferred Qualifications

  • Experience in aerospace, defense, manufacturing, engineering, or another highly regulated environment.
  • Direct experience with CMMC Level 2, NIST SP 800‑171, DFARS, CUI, SOX ITGC, GCC High, or export‑controlled environments.
  • Experience with Microsoft 365 GCC High and tools such as Defender, Intune, Entra ID, Purview, Sentinel, Tenable, Qualys, Rapid7, or Defender Vulnerability Management.
  • Experience with privileged access management, password vaulting, security information and event management (SIEM), endpoint detection and response (EDR), email security, and security orchestration.
  • Experience with mergers and acquisitions (M\&A), site onboarding, identity consolidation, endpoint standardization, and post‑acquisition remediation.
  • Familiarity with firewalls, virtual private networks (VPN), network segmentation, Zero Trust, Center for Internet Security (CIS) benchmarks, specialized assets, and compensating‑control design.
  • Security+, Cybersecurity Analyst (CySA+), Systems Security Certified Practitioner (SSCP), Certified Information Systems Security Professional (CISSP), Certified Information Security Manager (CSM), GIAC Security Essentials Certification (GSEC), GIAC Certified Incident Handler (GCIH), Microsoft Security, Azure Security Engineer, or comparable certification.

This position requires U.S. person status under U.S. export control laws, including U.S. citizens and nationals, lawful permanent residents, refugees, and asylees.

  • Medical, dental, and vision insurance
  • 401(k) with company match
  • Paid time off
  • Health Savings Account (HSA) with company contribution
  • Flexible Spending Accounts (FSA)
  • Company‑paid life and AD\&D insurance
  • Short‑and long‑term disability coverage

Karman Space and Defense is an Equal Opportunity Employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, national origin, age, disability, genetic information, protected veteran status, or any other status protected by applicable law.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity GRC Analyst
Senior Cybersecurity GRC Analyst

Amro Fabricating Corporation • Huntington Beach (CA)

On-site
USD 120,000 - 136,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+1
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

AV • Washington

On-site
USD 111,000 - 170,000
Medical and dental coverage
401(k) with company matching
Paid holiday shutdown
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

AV • Pennsylvania

On-site
USD 111,000 - 170,000
Medical, dental, and vision benefits
401(k) with company matching
9/80 work schedule
+1
Senior Systems Engineer
Senior Systems Engineer

Amro Fabricating Corporation • Mukilteo (WA)

On-site
USD 135,000 - 160,000
Health insurance
401(k) with company match
Paid time off
+4
Senior Cybersecurity Engineer
Senior Cybersecurity Engineer

AV • North Carolina

On-site
USD 111,000 - 170,000
Medical, dental, vision benefits
401(k) with company matching
9/80 work schedule
+1
Senior EHS Specialist
Senior EHS Specialist

Karman Space & Defense • Corona (CA)

On-site
USD 90,000 - 120,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+4
Senior Engineering Manager
Senior Engineering Manager

Karman Space & Defense • Mukilteo (WA)

On-site
USD 150,000 - 230,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+1
Technical Program Manager (Active Clearance)
Technical Program Manager (Active Clearance)

Socket.dev • Mukilteo (WA)

On-site
USD 120,000 - 180,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+2
Senior Director, Capture and Growth Operations
Senior Director, Capture and Growth Operations

Karman Space & Defense • Huntington Beach (CA)

On-site
USD 190,000 - 220,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+4
Development Engineer III
Development Engineer III

Karman Space & Defense • Mukilteo (WA)

On-site
USD 110,000 - 140,000
Medical, dental, and vision insurance
401(k) with company match
Paid time off
+4