> Markdown version of [/jobs/ext/135514-security-engineer](https://www.wearedevelopers.com/jobs/ext/135514-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Qarbon Aerospace Inc - **Location:** Red Oak, TX, United States - **Experience:** Starter - **Contract:** Internship / Graduate position - **Skills:** Microsoft Windows, Active Directory, Software System Penetration Testing, Configuration Management Databases, Software Documentation, CompTIA Security+, Cyber Security, Computer Networks, Information Leak Prevention, Linux, Domain Name System (DNS), Identity and Access Management, Virtual Private Networks (VPN), Azure Active Directory, Phishing, Security Information and Event Management, TCP/IP, Data Classification, QRadar, Firewalls (Computer Science), Information Technology, Nessus, Microsoft Sentinel, CIS Benchmarks, Splunk, Qualys, Vulnerability Analysis - **Published:** May 21, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=c5018f19e1935a79 ## About the Role Do you have experience in Windows?, Do you have a Bachelor's degree?, * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field - OR equivalent work experience / military service. * 0-3 years of experience in an IT, security, or compliance-related role (internships and co-ops count). * Foundational understanding of networking concepts (TCP/IP, DNS, VPN, firewalls) and operating systems (Windows, Linux). * Familiarity with cybersecurity frameworks (NIST CSF, NIST 800-171, ISO 27001) at a conceptual level. * Strong written and verbal communication skills - this role produces a significant volume of documentation. * High attention to detail; ability to manage multiple tasks and track open items to closure. * U.S. Citizenship required (position requires access to controlled unclassified information / CUI). Preferred: * CMMC Certified Assessor (CCA) or CMMC Registered Practitioner (RP) credential - highly preferred. * Industry certifications: CompTIA Security+, CompTIA CySA+, (ISC)² CC or SSCP, EC-Council CEH. * Hands-on experience with Microsoft Purview (DLP, Compliance Manager, Sensitivity Labels). * Hands-on experience with Netwrix Auditor or similar file/directory auditing tools. * Experience with vulnerability scanners (Nessus/Tenable, Qualys, OpenVAS). * Familiarity with SIEM platforms (Microsoft Sentinel, Splunk, QRadar). * Prior experience preparing documentation for CMMC, FedRAMP, SOC 2, or similar audits. * Experience with identity and access management platforms (Active Directory, Azure AD / Entra ID). * An active security clearance is highly preferred. Candidates without an active clearance may still be considered but must be eligible to obtain and maintain one. ## Description The Security Engineer is a foundational, high-impact role within the Cybersecurity, Compliance & Governance team. This is an entry-level position intentionally designed as a ground-floor opportunity - the expectation is that the right candidate will grow with the organization as its security posture matures. The individual in this role will serve as an all-encompassing security practitioner, supporting risk management, system hardening, compliance documentation (with emphasis on CMMC), data loss prevention, identity and access governance, and day-to-day security operations. This is a rare opportunity for a motivated early-career professional to build deep expertise across multiple security domains, work alongside experienced compliance and governance professionals, and position themselves for rapid advancement into senior security engineering, compliance, or security architecture roles., Risk Management & Security Assessments * Assist in the identification, evaluation, and documentation of cybersecurity risks across systems, processes, and vendors. * Support the development and maintenance of the organization's risk register. * Participate in security assessments, vulnerability scans, and penetration test follow-ups; track remediation activities. * Help evaluate third-party and supply chain security risks. CMMC Compliance & Documentation * Maintain and update System Security Plans (SSPs), Plans of Action & Milestones (POA&Ms), and related artifacts required for CMMC compliance. * Assist in mapping organizational controls to NIST SP 800-171 and CMMC Level 2 (and Level 3 where applicable) requirements. * Participate in internal CMMC readiness reviews and support coordination with Certified Third-Party Assessment Organizations (C3PAOs). * Support audit preparation activities and maintain audit trails and evidence packages. * Keep configuration and system documentation current, accurate, and audit-ready. Data Loss Prevention - Microsoft Purview & Netwrix * Assist in the administration and tuning of DLP policies within Microsoft Purview to protect sensitive and controlled unclassified information (CUI). * Monitor DLP alerts, investigate policy violations, and escalate incidents as needed. * Support Netwrix deployments for file activity monitoring, data classification, and access auditing. * Maintain documentation for DLP configurations, policy exceptions, and incident response activities. Identity, Access & Account Governance * Review and analyze user account permissions, group memberships, and privileged access rights across systems and applications. * Support user access reviews (UARs) and assist in the enforcement of least-privilege principles. * Assist in the management and auditing of service accounts, shared accounts, and administrative credentials. * Monitor for dormant accounts, over-provisioned permissions, and access anomalies; escalate and remediate findings. * Support identity lifecycle management processes including provisioning, modification, and de-provisioning. Security Configuration & Hardening * Maintain and review baseline security configurations (CIS Benchmarks, STIG guidance) for endpoints, servers, and cloud assets. * Support CMDB hygiene and ensure system documentation remains current and accurate. * Assist in tracking deviations from approved baselines and follow through on remediation. Security Operations Support * Monitor security tooling dashboards and escalate alerts per defined procedures. * Assist in the development and maintenance of security policies, procedures, and standards documentation. * Support incident response activities including evidence collection, timeline development, and post-incident reporting. * Participate in security awareness training coordination and phishing simulation programs. ## Related Videos - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy)