Security Engineer
GXA isseekinga highly capableSecurity Engineerto support the delivery and operation of ourgShieldsecurity services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.
The Security Engineer serves as aTier 3 escalation pointfor active security and technical issues and plays a key role in operating and improving thegShieldsecurity stack across client environments. This individual will work closely with theInfoSec Manager (vISM),vCISO, SOC, Centralized Services, onboarding teams, and internal technical leadershipto strengthen client security posture and support rapid, effective response to threats and technical issues.
This is an execution-focused role for someone who is comfortable working acrosssecurity and the underlying IT infrastructure that supports it.The ideal candidate understands how networks, servers, identity, endpoints, cloud services, and security controls work together and can troubleshoot across these layers when the root cause is notimmediatelyclear.
This person should be comfortable working in live security events, analyzing alerts and evidence, troubleshooting infrastructure and security issues,executingor supporting remediation, and helpingmaintainthe operational excellence of GXA's security program.
Key Responsibilities
Incident Response
- Serve as a Tier 3 escalation point for active security incidents, includingbusiness email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
- Lead technical analysis during incident response and war room events, includinglog review, IOC hunting, attacker activity analysis, and lateral movement tracing.
- Execute containment anderadicationactions such asendpoint isolation, session revocation, credential resets, access restriction, and otherappropriate remediationactions.
- Troubleshoot incidents that may span multiple technical layers, includingidentity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
- Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
- Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
- Communicate clearly during active incidents, includingwhat is known, what has been investigated, what actions have been taken, what is being investigated next, and whereadditionalsupport is required.
- Produceaccurateincident timelines, technical findings, and evidence packages forvCISOreview and client-facing follow-up.
Tool Operations & Security Stack Support
- Operate daily within thegShieldtoolstack, including platforms such asHuntress, Microsoft Defender for Endpoint (MDE),Cyrisma,DNSFilter, SIEM, and related security technologies.
- Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
- Support SIEM operations includingquery development, alert review, log analysis, investigation, and rule tuning.
- Assistin tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
- Monitor forsecurity gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
- Correlate information acrossidentity, endpoint, network, server, and cloud sourceswhen investigating security issues.
- Work within established security standards, baselines, and operational policies defined by the security team andvITMs.
Infrastructure & Security Engineering
- Apply security principles acrosson-premises, cloud, and hybrid client environments.
- Troubleshoot security issues involving underlying infrastructure components such asActive Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
- Understand howidentity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
- Support security hardening ofWindows, endpoint, identity, network, and cloud environments.
- Assistwith identity and access security includingMFA, Conditional Access, privileged access, authentication, authorization, and account security.
- Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
- Work effectively with technologies that may be unfamiliar by researching, testing,validating, and documentingappropriate solutionswhile escalating appropriately whenadditionalexpertise is required.
Client Delivery Support
- Execute technical remediation itemsidentifiedthroughMRMMs, preventative actions, vulnerability reviews, and security recommendations.
- SupportgShielddeliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
- Assess vulnerabilities based not only on severity scores but also onasset criticality, exposure, exploitability, existing controls, and business impact.
- Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifyingappropriate compensatingcontrols when immediate remediation is not possible.
- Validate remediation and confirm that identified risks have been appropriately addressed.
- Act as a quality assurance resource for client onboarding into thegShieldtoolstack, while executionremainswith onboarding and Centralized Services teams.
- Assistwith client hardening efforts and follow-through on security improvement actions across managed environments.
- Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.
Internal Security Posture
- Support remediation of internal GXA security backlog items, includingPOA&M-related work.
- Assistwith rollout and support ofphishing-resistant MFA, passkeys, and other internal security initiatives.
- Contribute to security engineering efforts related toIntune, Defender,ThreatLocker, AppLocker, and RMM scripting.
- Help improve internal security controls,tooleffectiveness, and technical enforcement mechanisms.
- Support security hardening and remediation across internalidentity, endpoint, server, network, and cloud environmentswhere needed.
Documentation & Process Improvement
- Write andmaintainsecurity engineeringSOPs, runbooks, detection playbooks, troubleshooting procedures, and response proceduresrelated togShieldoperations and incident response.
- Document technical findings, repeatable procedures, remediation steps, and lessons learned from incidents and tool operations.
- Clearly documentwhat wasidentified, what actions were taken, why those actions were taken, and what follow-up isrequired.
- Collaborate with security leadership and technical stakeholders on process improvements, skill development, and automation opportunities.
- Contribute technical depth to broader security documentation where needed, while recognizing that ownership of policy, standards, and governance documentationremainswith security leadership and related functions.
Qualifications
- 5–7+ years of experienceacross cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
- Strong technical foundation acrossIT infrastructure and security, with practical understanding of networking, servers, identity, endpoints, cloud services, and how these technologies interact.
- Hands-on experience troubleshootingon-premises, cloud, or hybrid environments.
- Working knowledge of infrastructure technologies and concepts such asActive Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
- Strong hands-on experience withsecurity engineering, threat detection, security operations, incident investigation, or incident response workflows.
- Experience working with security platforms such asMicrosoft Defender,Huntress,DNSFilter, SIEM solutions, vulnerability management tools, and endpoint security technologies.
- Ability to investigate security alerts, analyze logs, trace attacker activity,determinescope, and support containment and remediation.
- Familiarity with common attack types includingphishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
- Experience supporting security controls withinMicrosoft 365, Microsoft Entra ID, endpoint, and cloud environments.
- Understanding ofvulnerability management and remediation, including prioritization based on technical severity, exposure, asset criticality, and business risk.
- Ability to independently troubleshoot technical problems, develop and test hypotheses,identifyroot causes, and recognize when escalation oradditionalexpertise isappropriate.
- Ability to remaincalm, structured, and methodical during active incidents, outages, and technical escalations, including situations where the root cause is initially unknown.
- Strong verbal and written communication skills, with the ability to provide concise technical updates explainingcurrent status, actions completed, current investigation, and next steps.
- Strong documentation skills and ability to write clear technical procedures and findings.
- Ability to acknowledge knowledge gaps, research unfamiliar technologies, learn quickly, and apply new knowledge safely in production environments.
- Strong collaboration skills with security, infrastructure, service delivery, leadership, and client stakeholders.
Preferred Qualifications
- 1-2years in a Cybersecurity role.
- Experience in anMSP, MSSP, or multi-client environment.
- Prior experience insystems administration, network engineering, infrastructure engineering, or a similarly hands-on IT rolebefore or alongside cybersecurity responsibilities.
- Experience supporting bothtraditional on-premises infrastructure and cloud environments.
- Familiarity withIntune, Microsoft Defender, Microsoft Sentinel, AppLocker,ThreatLocker, and RMM-based scripting or automation.
- Experience withAzuresecurity and infrastructure; AWS or other cloud-platform experience is also valuable.
- Experience withWindows Server, Active Directory, virtualization platforms such as VMware/Hyper-V,firewalltechnologies, and network troubleshooting.
- Understanding ofCIS benchmarks, security hardening standards, Zero Trust principles, and configuration drift monitoring.
- Experience supporting vulnerability remediation and technical aspects ofvCISOor managed security programs.
- Experience with scripting or automation using technologies such asPowerShell, APIs, or RMM platforms.
- Security certifications such asSecurity+,CySA+, SC-200, SC-300, AZ-500, GCIH, GCIA, or similarare a plus.
- Infrastructure/network certifications or equivalent practical experience, such asCCNA, Microsoft infrastructure certifications, Azure Administrator, or similar, are also valuable.
Success in This Role Looks Like
- Security incidents and technical escalations are handledquickly, accurately, calmly, and with strong technical discipline.
- The engineer can troubleshoot acrosssecurity, identity, endpoint, server, network, and cloud layersrather than relying solely on security tools or another technical team.
- Alerts and risks surfaced by thetoolstackare investigated andacted onconsistently.
- Client security remediation items areexecuted thoroughly,validated, and completed on time.
- Vulnerabilities are evaluated based onactual risk and business context, and remediation is followed through to completion.
- gShieldtooling is tuned, effective, and operationally reliable.
- Clients and internal stakeholders receiveclear, concise updates during incidents and technical escalations, even when the root cause has not yet beendetermined.
- Technical problems are approached methodically, withappropriate investigation, testing, documentation, and escalation when necessary.
- The engineerdemonstratesownership, curiosity, sound technical judgment, and willingness to learn unfamiliar technologiesrather than being limited to a narrow security specialty.
- Documentation, SOPs, troubleshooting procedures, and response playbooks are clear, useful, and continuously improving.
- Internal and client security posture improves through strong technical follow-through.