Preferred Location: Dallas, open to Remote (EST/CST) Columbus, Richmond, Cincinnati
Think Consulting is seeking a Sr. Cybersecurity Engineer to close the gap between Our Client's fast-scaling technology estate and its security controls. With an ERP consolidation, new data platform, AI assistant rollout, and expanding OT footprint across business units, security today runs on cloud-native tooling, a managed detection provider, and fractional vCISO oversight — but lacks a hands-on engineer who owns controls end to end.
This person will design, build, and operate preventive and detective controls across identity, endpoint, email, cloud, network, and data protection; harden new environments as they come online; lead technical incident response; and turn audit and insurance requirements into real implemented configuration. In this high-velocity, acquisition-driven environment, success means controls that are deployed, monitored, and evidenced — not policies or dashboards that sit unused.
What You'll Own
Security Architecture & Engineering
- Design and implement technical security architecture across identity, endpoint, email, network, cloud, and data — translating strategy into deployed, tested configuration.
- Serve as security engineering's design authority on major programs: ERP consolidation, enterprise data platform buildout, AI assistant deployment, CRM selection, and integration platform work.
- Build and maintain hardening standards and secure baselines for Windows, Linux, mobile, and cloud workloads — enforced through configuration management, not manual review.
- Define the secure-by-default reference patterns other IT teams build against: network segmentation, secrets management, logging, and third-party connectivity.
- Lead security engineering for acquisition integrations: assess the acquired estate, prioritize remediation, and bring new tenants and endpoints onto company standards.
- Own the technical relationship with the managed detection and response (MDR) provider — tuning detections, closing coverage gaps, validating alert quality, and holding the provider to response SLAs.
- Engineer detection content and log pipelines across a modern SIEM/XDR stack, including data source onboarding, analytics rules, and automated response playbooks.
- Act as technical incident commander during security incidents: containment, forensics, eradication, recovery, and post-incident review with tracked corrective actions.
- Run purple-team and tabletop exercises against realistic scenarios — ransomware, business email compromise, vendor compromise, OT disruption — and convert findings into engineering work.
- Own and continuously improve incident response runbooks, escalation paths, and evidence-handling procedures.
Identity & Access
- Engineer and operate the identity security stack — conditional access, MFA and phishing-resistant authentication, privileged identity management, and joiner-mover-leaver lifecycle automation.
- Drive least-privilege across cloud and on-prem: privileged access workstations, just-in-time elevation, service account governance, and periodic access recertification.
- Secure machine and workload identity for integrations, APIs, and automation, including secrets management and credential rotation.
- Partner with application teams so role design in ERP, CRM, and field-service platforms is enforceable and segregation-of-duties conflicts are caught before go-live.
Vulnerability & Risk Management
- Own the vulnerability management program end to end — discovery, prioritization by exploitability and business exposure, remediation tracking, and SLA reporting.
- Run internal and third-party penetration testing and red-team engagements, driving findings to closure with accountable technical owners.
- Maintain an accurate asset inventory across endpoints, servers, cloud resources, SaaS, and field devices.
- Assess and monitor third-party and supply chain risk for critical vendors, and set security requirements built into vendor selection and contracts.
- Quantify and report residual risk to leadership in terms of business impact, not raw finding counts.
Compliance, OT & Cross-Functional Partnership
- Translate cyber insurance, customer, and contractual security requirements into implemented controls with audit-ready evidence
- Support attestation and assessment work against recognized frameworks (e.g., NIST CSF, CIS Controls) as the technical subject matter expert.
- Extend appropriate controls into OT and field-service environments — facilities systems, shop floor, fleet telematics, connected field devices — with segmentation and monitoring suited to availability-sensitive systems.
- Partner with AI/data teams on securing assistant and model use: data exposure controls, prompt and output handling, and guardrails against shadow AI.
- Deliver security awareness and phishing simulation content that changes behavior, and coach IT and business unit staff on secure practice.
What You Bring
Required:
- Bachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.
- 7+ years in information security, with at least 3 in a hands-on security engineering role owning production controls.
- Deep, current expertise with a modern cloud security stack (identity, XDR, SIEM, data governance) — configuration, tuning, and troubleshooting at enterprise scale.
- Demonstrated incident response experience as a technical lead, from detection through containment, eradication, and post-incident review.
- Strong foundation in identity and access engineering: conditional access design, privileged access management, least-privilege enforcement.
- Practical experience running a vulnerability management program with measured remediation against defined SLAs.
- Working knowledge of a recognized control framework (NIST CSF, CIS Controls) and experience producing audit-grade evidence.
- Scripting and automation capability (PowerShell, Python, or equivalent) applied to security operations at scale.
- Ability to explain technical risk and remediation trade-offs clearly to IT leadership and non-technical executives.
Preferred:
- Industry certification: CISSP, GCIH, GCIA, GPEN, OSCP, or Microsoft security certifications.
- Experience securing multi-tenant or multi-business-unit environments and integrating acquisitions onto a common security standard.
- Experience in construction, specialty contracting, manufacturing, distribution, or field services, including OT/ICS exposure.
- Cloud security depth in Azure or AWS, including posture management, workload protection, and infrastructure-as-code review.
- Experience managing an MDR/SOC provider relationship to measurable outcomes.
- Familiarity with cyber insurance underwriting requirements and customer security questionnaire processes.
Who Thrives in This Role
- A hands-on engineer first — builds and operates controls rather than delegating them to documents.
- A risk-based prioritizer — distinguishes what's exploitable and material from what's merely reportable.
- Calm and decisive under incident pressure, with disciplined communication to leadership.
- Enables the business securely instead of defaulting to no — finds the controlled path to yes.
- Automates repeat work and measures control effectiveness continuously.
- Collaborative across IT pillars — infrastructure, applications, data, integration, and AI.
- Intellectually current on the threat landscape without chasing tooling for its own sake
This role suits a senior security engineer who wants ownership of a real controls environment during a period of rapid growth — not a governance seat, a builder's seat.
Equal Opportunity Employer, including disability and protected veteran status