Information Security Engineer
Charlotte, Mecklenburg County, North Carolina, 28245, USA
Listed on 2026-09-11
-
IT/Tech
Cybersecurity, Information Security & Data Protection, Network Security, IT Consultant
Job Details
Job Location:
Corporate Office - Charlotte, NC 28208
Position Type:
Full Time
Education Level: Bachelor Degree
Travel Percentage:
Up to 10%
Job Shift: Day
Job Category:
Information Technology
At Midrex, you will do work that matters alongside people who believe you matter. The work won't be easy, but it will be worth it. You'll be part of a great team with plenty of autonomy to bring out your best. And you'll be well compensated and have a best-in-class benefits package. Take a look:
Competitive benefits effective from Day 1- Dollar-for-dollar 401(k) matching (up to 6%)
- Profit sharing with 401(k) kicker
- Generous overtime for qualified positions
- 4 weeks of paid vacation
- Tuition reimbursement
- Raffles for professional sports tickets
- Half-day Fridays
- Flexible home/office work practices
- Paid time to volunteer
- Employee recognition awards
Since 1987, Midrex has been the world leader in direct reduction technology, offering the best proven method for decarbonization in the iron and steel industry available today. Our rapid growth is transforming the steel industry and our planet. And none of it would be possible without our people, who bring vision, compassion, and extraordinary expertise to this work every day. So, if you're looking to do big work in a small-team environment, Midrex is just the place for you.
QualificationsThe Information Security Engineer is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's global technology environment. This role supports the protection of company systems, networks, cloud services, applications, and data through continuous security monitoring, vulnerability management, security awareness initiatives, compliance activities, and implementation of security controls. The role increasingly leverages AI-enabled security tooling to accelerate threat detection, triage, and response, and supports the secure adoption of AI technologies across the organization.
The Information Security Engineer serves as a key member of the cybersecurity team and works closely with IT infrastructure, cloud, networking, application, and business teams to improve the organization's security posture. This position requires strong analytical abilities, attention to detail, problem-solving skills, and a commitment to continuous improvement.
The Information Security Engineer should demonstrate broad, hands-on security experience encompassing security investigations, endpoint and cloud security, vulnerability management, Data Loss Prevention (DLP), networking, security compliance, security tooling, and partnership with IT Operations.
The Information Security Engineer should be capable of independently handling security responsibilities while also serving as a security resource to infrastructure, networking, cloud, endpoint, and other IT teams.
This is NOT a SOC ticket-triage-only position.
Essential Duties and Responsibilities Security Operations- Monitor security alerts, events, and incidents generated by security platforms including SIEM, endpoint protection, email security, cloud security, and network security systems.
- Investigate suspicious activity and coordinate incident response activities through resolution.
- Perform threat hunting and security investigations to identify potential risks and unauthorized activities.
- Document security incidents, findings, lessons learned, and remediation activities.
- Participate in on-call rotation and security incident escalations as required.
- Conduct vulnerability assessments and coordinate remediation efforts with system owners.
- Track and report remediation progress and risk reduction metrics.
- Support annual penetration testing activities and validation of remediation actions.
- Assist in risk assessments and implementation of corrective actions.
- Identify opportunities to reduce organizational cyber risk through technology, process, and control improvements.
- Assist with implementation, administration, and optimization of security technologies.
- Manage security policies and configurations across Microsoft 365, Azure, endpoint management, email security, and network security platforms.
- Support identity and access management controls including role-based access control, least privilege, and privileged account management.
- Assist with implementation and maintenance of Zero Trust security architecture initiatives.
- Manage SSL/TLS certificate lifecycle processes including…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).