Senior Cybersecurity Engineer (Azure heavy)

Hyliion

Austin (TX)

On-site

USD 140,000 - 190,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

Hyliion is seeking a Senior Cybersecurity Engineer to own and elevate the company’s security posture across identity, endpoints, cloud/SaaS, and AI governance. You will maintain the SSP for a CMMC Level 2 enclave, sustain NIST 800-171 compliance, and manage Microsoft Entra ID/Defender, Intune, and MDR partnerships.

You will lead vulnerability remediation, policy tuning, and third-party risk assessments while coordinating incident response with the Red Canary MDR.

Qualifications

  • Bachelor’s degree or higher in a related field.
  • 5+ years of IT/cybersecurity operations and compliance experience.
  • CISSP, CISM, Security+ or Azure security certs preferred.

Responsibilities

  • Own Hyliion’s day-to-day cybersecurity posture across identity, endpoint, cloud/SaaS, and AI governance.
  • Maintain SSP and control implementation for a CMMC Level 2 enclave with NIST 800-171 compliance.
  • Administer and optimize Microsoft Entra ID Conditional Access, Identity Protection, and PIM.
  • Oversee endpoint security, patching, vulnerability remediation, and EDR via Defender/Intune.
  • Manage Defender suite and related policies, alert triage, and threat response.
  • Coordinate with MDR provider (Red Canary) for detections and incident response.
  • Administer MDM/Intune enrollment and device compliance.
  • Govern SaaS security posture and third-party app risk assessments.
  • Monitor and enforce AI platform security and data-handling policies.
  • Maintain security policies, procedures, and evidence for audits (SOX ITGC, CMMC, NIST).
  • Contribute to incident response, business continuity, and disaster recovery plans.
  • Collaborate with leaders to mitigate security risks in new projects and vendor relationships.
  • Produce executive dashboards translating risk into business metrics.
  • Stay current on AI/LLM risks and regulatory changes, proposing improvements.

Skills

Azure Entra ID
Conditional Access
PIM
Endpoint security
Microsoft Defender
Intune
MDR coordination
SSPM / CASB concepts
AI/LLM security
NIST 800-171
CMMC 2.0
SOX ITGC
Regulatory compliance

Education

Bachelor’s degree in Computer Science / Information Systems / related field
5+ years IT/cybersecurity operations and compliance

Tools

Microsoft Entra ID
Defender suite
Intune
Red Canary MDR

Job description

***This is an onsite role M-F due to importance of role. Sponsorship is not available for this role.

Job Purpose

The Senior Cybersecurity Engineer owns Hyliion’s overall day-to-day cybersecurity operations — endpoint security, identity and Conditional Access, cloud/SaaS security posture, and AI governance — across a cloud-native, Microsoft-centric technology environment. This includes maintaining the System Security Plan (SSP) and control set for Hyliion’s CMMC Level 2 certified enclave, sustaining NIST 800-171 compliance . Beyond the enclave, the role administers Microsoft Entra ID Conditional Access, the Microsoft Defender suite, endpoint management (patching, EDR, and device compliance), our Red Canary Managed Detection and Response (MDR) partnership, and the security and governance of our growing SaaS and enterprise AI footprint across the broader organization.

At Hyliion, AI is core to how we work. We equip every team member with leading AI tools and count on you to use them — to move faster, solve harder problems, and help us realize the full potential of KARNO technology for the world.

Duties and Responsibilities

  • Own and maintain Hyliion’s overall day-to-day cybersecurity posture across the enterprise, spanning identity, endpoint, cloud/SaaS, and AI governance.
  • Maintain the System Security Plan (SSP) and control implementation for Hyliion’s CMMC Level 2 (C3PAO)-certified enclave, sustaining NIST 800-171 compliance and annual affirmation in SPRS for that defined scope.
  • Administer and continuously optimize Microsoft Entra ID (Azure AD) Conditional Access policies, identity protection, and Privileged Identity Management (PIM) to enforce least-privilege and zero-trust principles.
  • Own endpoint security end-to-end — patch management, vulnerability remediation, EDR fleet health, and compliance baselines across Windows, macOS, and mobile endpoints — using Microsoft Defender for Endpoint and Intune.
  • Manage the broader Microsoft Defender suite (Defender for Office 365, Defender for Cloud Apps, Defender for Identity), including policy tuning, alert triage, and threat response.
  • Serve as the primary point of contact for the Red Canary Managed Detection and Response (MDR) partnership, coordinating incident escalations, tuning detections, and reviewing threat intelligence reports.
  • Administer Mobile Device Management (MDM)/Intune enrollment, compliance policies, and configuration across corporate and BYOD devices.
  • Own security posture and governance across Hyliion’s growing SaaS application footprint (SaaS Security Posture Management), including OAuth/app permission reviews, shadow IT discovery, and third-party app risk assessment.
  • Govern the secure and compliant use of enterprise AI platforms — monitoring usage, enforcing acceptable-use and data-handling policies, assessing AI vendor risk, and identifying unsanctioned (“shadow AI”) tool adoption.
  • Monitor, triage, and respond to day-to-day cybersecurity incidents and alerts, ensuring timely containment, remediation, and documentation.
  • Maintain and update security policies, procedures, and control documentation supporting NIST 800-171, CMMC, SOX IT general controls, and other applicable frameworks.
  • Support recurring internal and third-party audits, evidence collection, and control testing, including SOX ITGC, CMMC annual affirmation, and cyber insurance renewal questionnaires.
  • Partner with business leaders across departments to assess and mitigate information security risk in new projects, vendor relationships, SaaS adoption, and AI tool deployments.
  • Maintain and enhance the executive-level cybersecurity dashboard and reporting cadence, translating technical risk into business-relevant metrics for leadership and the Board Audit Committee.
  • Contribute to and maintain the company’s incident response, business continuity, and disaster recovery plans, participating in periodic tabletop exercises.
  • Stay current on emerging threats and regulatory changes — including AI/LLM-specific risks (e.g., OWASP Top 10 for LLM applications, data leakage, prompt injection) and DFARS/CMMC/NIST developments — and recommend proactive improvements.
  • Additional duties and responsibilities as assigned, needed, or required for the business.

Qualifications

Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.

Qualifications include:

  • Education, Experience and Certifications
  • Bachelor’s degree in Computer Science, Information Systems, or related field.
  • 5+ years of IT experience with a focus on cybersecurity operations and compliance.
  • CISSP, CISM, Security+, Azure Security Engineer Associate (AZ-500), Microsoft SC-200, or other relevant security certification preferred.
  • Skills and Abilities
  • Hands-on administration experience with Microsoft Azure/Entra ID, including Conditional Access, Identity Protection, and Privileged Identity Management (PIM).
  • Experience with endpoint security operations — patch management, vulnerability remediation, and EDR administration (Microsoft Defender for Endpoint or equivalent).
  • Experience managing the Microsoft Defender suite and Microsoft Purview/Compliance Center.
  • Experience working with a Managed Detection and Response (MDR) provider (e.g., Red Canary, CrowdStrike), including alert triage and incident response coordination.
  • Experience administering MDM/Intune for endpoint compliance and device management.
  • Familiarity with SaaS Security Posture Management (SSPM) or CASB concepts and experience securing a cloud-native, SaaS-first technology environment.
  • Familiarity with AI/LLM security considerations (e.g., OWASP Top 10 for LLM Applications, data leakage prevention, shadow AI risk) and experience governing enterprise AI tool usage (e.g., Copilot, Claude, ChatGPT Enterprise).
  • Working knowledge of NIST 800-171, CMMC 2.0, DFARS, SOX IT general controls, or similar regulatory/compliance frameworks.
  • Ability to handle multiple competing priorities in a fast-paced environment.
  • Ability to work well under minimal supervision.
  • Manufacturing industry experience (preferred).
  • Additional duties and responsibilities as assigned, needed, or required for the business.

Role Classification and Working Conditions

This is a salaried, exempt-level position. This position typically works in an office environment; and given the nature of our business is also exposed to operations/warehouses/production environments.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Cybersecurity Engineer (Azure and GRC heavy)
Senior Cybersecurity Engineer (Azure and GRC heavy)

Hyliion • Austin (TX)

On-site
USD 150,000 - 210,000
Medical Plans
Dental Plans
Vision Plan
+3
Senior Cybersecurity Engineer (Azure and GRC heavy)
Senior Cybersecurity Engineer (Azure and GRC heavy)

Cedarparktexasedc • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Cybersecurity Engineer - AI & Cloud Security Lead
Senior Cybersecurity Engineer - AI & Cloud Security Lead

Hyliion • Austin (TX)

On-site
USD 140,000 - 190,000
Senior Cybersecurity Engineer: Azure, GRC & AI Security
Senior Cybersecurity Engineer: Azure, GRC & AI Security

Hyliion • Austin (TX)

On-site
USD 150,000 - 210,000
Medical Plans
Dental Plans
Vision Plan
+3
Cybersecurity Engineer
Cybersecurity Engineer

Hirebridge • Chicago (IL)

Hybrid
USD 85,000 - 120,000
Security Engineer
Security Engineer

Cortavo, Inc. • Atlanta (GA)

Hybrid
USD 100,000 - 130,000
Competitive salary
Health benefits
Company cell phone plan
+2
Senior Azure Security Engineer — GRC & AI Governance
Senior Azure Security Engineer — GRC & AI Governance

Cedarparktexasedc • Austin (TX)

On-site
USD 140,000 - 190,000
Cyber Network Analyst
Cyber Network Analyst

Park Lawn Corporation • Houston (TX)

On-site
USD 80,000 - 110,000
Network & Security Engineer
Network & Security Engineer

Citadel Aviation • Dallas (TX)

On-site
USD 120,000 - 180,000
Multisite Network & Security Architect
Multisite Network & Security Architect

Citadel Aviation • Dallas (TX)

On-site
USD 120,000 - 180,000