Cybersecurity Engineer; Troy, MI
Listed on 2026-07-25
-
IT/Tech
Cybersecurity
Job Summary
The Cybersecurity Engineer is responsible for implementing, maintaining, and continuously improving the organization's cybersecurity technologies, processes, and controls. This role investigates and remediates security threats, supports incident response activities, strengthens security posture across on‑premises and cloud environments, and collaborates closely with IT Infrastructure and Compliance teams to protect Bene Sys systems and data.
The Cybersecurity Department is a growing team focused on continuously maturing the organization's security program. As security standards and technologies evolve, the Cybersecurity Engineer must be adaptable, self‑motivated, and capable of delivering results in a fast‑paced environment while maintaining a collaborative approach. This position is expected to demonstrate professionalism, technical excellence, and sound judgment in representing both the department and Bene Sys.
Bene Sys maintains a substantial hybrid infrastructure consisting of on‑premises and cloud‑based systems that support the organization's Cybersecurity and IT Compliance programs. This position primarily requires onsite work, with occasional travel to company locations as business needs require.
Applicant must live in the Metro Detroit area of Michigan.
Essential Functions- Monitor, investigate, triage, and respond to alerts generated by enterprise security platforms, including:
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Security Information and Event Management (SIEM)
- Vulnerability management platforms
- Email security systems (malware, phishing, spam, blacklisting, and relay protection)
- External breach notifications and threat intelligence
- Deploy, configure, maintain, upgrade, and decommission cybersecurity software, hardware, and security appliances in collaboration with the IT Infrastructure team.
- Continuously optimize existing security tools and configurations to improve detection capabilities, align with industry best practices, and support business requirements.
- Assist with secure integration of third‑party applications and services, including Single Sign‑On (SSO), OAuth, and Microsoft Entra services.
- Design, implement, and continuously improve security controls across Microsoft Entra , Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, and Microsoft Defender for Cloud Apps.
- Administer and continuously enhance the organization's SIEM platform by developing analytics rules, dashboards, workbooks, data connectors, and monitoring content to improve visibility and detection fidelity.
- Develop and maintain Kusto Query Language (KQL) detection libraries, threat hunting queries, automation workflows, Logic Apps, playbooks, and other SOAR capabilities.
- Deploy and maintain endpoint security technologies, including Managed Detection and Response (MDR) solutions.
- Perform vulnerability assessments, prioritize remediation efforts, and coordinate corrective actions with the IT Infrastructure team.
- Support internal and external compliance initiatives, including security audits, penetration testing, risk assessments, and regulatory reviews.
- Investigate, document, and report cybersecurity incidents, including root cause analysis, impact assessments, and remediation activities.
- Assist in developing, maintaining, and improving cybersecurity policies, standards, procedures, and technical documentation.
- Research emerging cybersecurity threats, vulnerabilities, technologies, and industry trends, providing recommendations for improving the organization's security posture.
- Participate in security awareness training and provide technical guidance to IT staff and end users as needed.
- Maintain accurate operational documentation, security metrics, support logs, and incident records.
- Communicate project status, security incidents, operational metrics, and remediation progress to the Manager of Cybersecurity in a timely and professional manner.
- Demonstrate regular attendance, professionalism, accountability, and compliance with all company policies, procedures, and security standards.
- Regular and…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).