> Markdown version of [/jobs/ext/1336229-security-engineer](https://www.wearedevelopers.com/jobs/ext/1336229-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Sentant, LLC - **Location:** United States (Remote available) - **Experience:** Expert - **Salary:** $95,000.0 - $110,000.0 - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Domainkeys Identified Mail, Domain-Based Message Authentication Reporting and Conformance (DMARC), Identity and Access Management, Intrusion Detection and Prevention, Network Security, Automation of Marketing, Network Segmentation, Phishing, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, Scripting, Microsoft InTune, Sender Policy Framework (SPF), Patch Management, Cloudflare, Casper Suite, Gsuite, Qualys, Security Orchestration, Automation & Response, Vulnerability Analysis - **Published:** July 18, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=84ba3d5fcb299632 ## About the Role * 5+ years of Security Engineering experience, ideally supporting multiple client or business-unit environments. * Hands-on experience with endpoint detection and response (EDR) at production scale. * Experience with email security and DMARC/SPF/DKIM configuration. * Experience with vulnerability management and RMM/patch management tooling. * Familiarity with Zero Trust network access concepts and identity/access management practices. * Familiarity with NIST and CIS frameworks. * Strong troubleshooting and analytical skills, with the ability to work independently in a remote environment. * Strong documentation and communication skills, including the ability to explain technical issues to non-technical stakeholders., * Direct experience with platforms such as CrowdStrike, Avanan, Qualys, NinjaOne, Cloudflare Zero Trust, JAMF, Microsoft Intune, or similar tools across the domains above. * Experience with SIEM platforms and security automation or scripting. * AWS security experience. * Experience in an MSP or multi-tenant security environment. * Relevant certifications tied to any of the domains above (e.g., vendor-specific EDR, cloud, or Zero Trust certifications). ## Description The Security Engineer is responsible for designing, deploying, and maintaining security controls across a diverse portfolio of managed services clients. This role spans the full breadth of a modern security stack - endpoint protection, email security, identity and access management, network security and Zero Trust access, vulnerability management, backup and recovery, security monitoring, and compliance automation., The Security Engineer is responsible for designing, deploying, and maintaining security controls across a diverse portfolio of managed services clients. This role spans the full breadth of a modern security stack - endpoint protection, email security, identity and access management, network security and Zero Trust access, vulnerability management, backup and recovery, security monitoring, and compliance automation. You will work with the specific platforms Sentant has standardized on for each of these domains, while also helping evaluate and refine that stack as client needs and the threat landscape evolve. This role is ideal for someone who enjoys solving complex security problems, building repeatable processes, and communicating effectively with both technical and non-technical stakeholders. This position offers significant upward mobility, including a potential long-term path toward leading a security team or department., * Deploy, tune, and maintain endpoint detection and response (EDR) coverage across client environments. * Administer mobile device management (MDM) and endpoint configuration policies. * Monitor endpoint alerts, investigate detections, and drive remediation to closure., * Configure and maintain email security platforms, including phishing and malware protection. * Manage DMARC, SPF, and DKIM policies and guide domains toward full enforcement. * Support identity and access management, including MFA, privileged account controls, and identity threat detection and response. * Administer password/secrets management tooling for client and internal use., * Deploy and manage Zero Trust Network Access (ZTNA) policies and access groups. * Collaborate with infrastructure and network teams to improve network segmentation and access controls. * Troubleshoot connectivity and policy issues across Zero Trust and network security tooling., * Perform vulnerability scanning and analysis, and build practical remediation plans. * Administer RMM and patch management tooling to keep client environments current and compliant. * Track remediation items through completion and escalate overdue or high-risk findings. Monitoring, Backup & Compliance Tooling * Monitor security event and log data (SIEM) for signs of compromise, and tune detection rules to reduce noise while preserving coverage. * Configure and maintain backup and recovery solutions (endpoint, Google Workspace/M365, and other data sources) to support business continuity. * Support compliance automation platforms used to track controls and evidence for frameworks such as SOC 2, HIPAA, NIST, and ISO 27001. Incident Response & Documentation * Monitor, investigate, and respond to security incidents across all the domains above. * Develop security playbooks, runbooks, and operational documentation for each part of the organizational stack. * Assist with implementing and mapping frameworks such as NIST and CIS. * Communicate technical issues and findings clearly to both technical and non-technical stakeholders., This position operates remotely within the United States, with a preference for Mountain or West Coast time zones to align with client and team coverage needs. The employee must maintain a reliable internet connection, work securely with confidential client information, and remain available during assigned working hours. Occasional travel or onsite work may be required for incidents or client engagements. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Skynet wants your Passwords! The Role of AI in Automating Social Engineering](https://www.wearedevelopers.com/videos/770-skynet-wants-your-passwords-the-role-of-ai-in-automating-social-engineering) - [MFA? Game over! Watch your protection collapse – live](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)