IT Security Engineer III
Listed on 2026-03-01
-
IT/Tech
Cybersecurity, Systems Engineer -
Engineering
Cybersecurity, Systems Engineer
Description
We are seeking a full-time IT Security Engineer to support and mature a compliance-driven security program in a hybrid, multi-site defense contracting environment. This role is responsible for designing, implementing, and operating security controls across on-premises infrastructure and Microsoft Azure Government (GCC High), while directly supporting regulatory requirements including CMMC Level 2, DFARS , ITAR, and NIST SP 800-171
.
This is a hands-on, engineering-focused position. The IT Security Engineer will work closely with IT, infrastructure, compliance, and operations teams to deploy and maintain technical security controls, enhance detection and response capabilities, and support internal and external audits and assessments. This position reports to the Security Manager.
U.S. Person required (as defined by ITAR, due to export-controlled information and technology).
Active U.S. security clearance is a plus, but not required.
- Design, deploy, and maintain security architecture and technical controls across on-premises infrastructure (Active Directory, servers, endpoints, network systems) and Microsoft Azure Government (GCC High) environments.
- Engineer secure solutions supporting multi-site operations, network segmentation and isolation, and regulated environments handling Controlled Unclassified Information (CUI) and export-controlled data.
- Lead and participate in security and architecture reviews for new systems, applications, vendors, SaaS platforms, and cloud services.
- Engineer and operate endpoint and identity security controls, including Microsoft Intune, device compliance, Conditional Access, Entra (Azure AD) hybrid identity, Privileged Identity Management (PIM), role‑based access control, and service account governance.
- Support Active Directory and Entra , consolidation, and identity security initiatives.
- Build and maintain detection and response capabilities using Microsoft Defender XDR, including KQL‑based detection engineering and threat hunting aligned to MITRE ATT&CK and regulatory requirements.
- Assist with incident response activities including investigation, triage, containment, remediation guidance, root cause analysis, and corrective action planning.
- Implement, validate, and document technical security controls aligned to NIST SP 800-171, CMMC Level 2, DFARS, and ITAR requirements.
- Produce technical documentation and engineering evidence to support internal assessments, external audits, customer reviews, and prime contractor security evaluations.
- Support firewall and perimeter security platforms, secure remote access, site-to-site connectivity, internal segmentation, vulnerability management, and centralized logging/SIEM integrations.
- Participate in vendor risk assessments and evaluate third‑party security posture and data handling practices.
- Develop and maintain security standards, configuration baselines, implementation guides, and hardening documentation.
- Support operational readiness through tabletop exercises, incident response testing, cyber recovery, and disaster recovery planning.
- Provide hands‑on technical guidance to IT and engineering teams to ensure secure configuration and deployment practices across regulated environments.
Education and Experience
- Bachelors Degree in Cybersecurity, Information Security, Information Technology, Computer Engineering or related field
- 5+ years of experience in information security engineering, infrastructure security, or security operations.
- Strong hands‑on experience with:
- Microsoft Defender XDR
- Microsoft Intune
- Entra / Azure AD (hybrid identity)
- Active Directory
- SIEM and log ingestion / syslog integration
- Enterprise networking fundamentals
- Experience engineering and operating security controls in a hybrid environment (on‑premises and cloud).
- Experience supporting regulated environments (defense, aerospace, manufacturing, government, or similar).
- Experience working within the Defense Industrial Base (DIB) or Maritime Industrial Base (MIB).
- Experience supporting ITAR‑regulated or export‑controlled environments.
- Experience operating security services in Microsoft Azure Government (GCC High).
- Experience…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).