IT Security Engineer
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Tech stack
+18 more
Job description
The IT Security Engineer (HR Title = Technology Infrastructure Engineer - Security) is a core practitioner within the security team, responsible for the day-to-day work that keeps the enterprise protected. This role spans incident response, identity and access management, hardware and software risk assessment, and threat and vulnerability management - requiring technical depth, the ability to think critically about risk in a dynamic environment, and superior communications and business skills to interact with stakeholders at all levels of our organization and subsidiaries. This is a role for someone who takes their craft seriously. The Security Engineer knows that security is not a checklist - it is a continuous practice which relies on learning and improving. They bring curiosity, precision, and a structured approach to investigation and remediation, and they contribute directly to the security posture that protects every firm in the enterprise. Beyond execution, this role is expected to continuously improve how security work is performed - identifying opportunities to reduce manual effort, increase consistency, and scale operations through thoughtful use of automation, integration, and emerging AI-enabled capabilities.
This is a regular (with benefits), salaried, exempt position that can be located near any SWCA office in a hybrid fashion. Highly qualified, remote (= distributed) employees will also be seriously considered. Submitting a cover letter with your resume is strongly encourged.
Application deadline: Our team will begin reviewing applications immediately, and interviews will be scheduled with qualified candidates on a rolling basis. The application process will remain open until we have received a robust pool of qualified candidates. Once we have identified suitable individuals, we may close the application process without prior notice. We appreciate the time and effort invested by all applicants and will carefully consider each submission.
What you will accomplish
Incident Response
- Monitors security alerts and events from outsourced MDR service and SIEM, EDR, email and other detection tools; triages, investigates, and responds to security incidents in accordance with standards, policies, best practices, and where applicable, established playbooks.
- Leads or supports incident response activities including containment, eradication, recovery, and post-incident documentation.
- Maintains and improves incident response playbooks, contributes to after-action reviews, lessons-learned processes, and continued improvement.
- Acts as an initial escalation point for security-related support tickets, working through the internal ticketing system to review, prioritize, and coordinate response to issues that require deeper technical investigation, risk evaluation, or security team involvement (Freshservice, ServiceNow, etc.).
Threat & Vulnerability Management
- Operates and maintains the vulnerability scanning program, with outsourced vendor support where applicable, across enterprise systems, cloud environments, and endpoints; tracks findings and coordinates remediation with security and IT teams.
- Monitors threat intelligence feeds and communicates relevant emerging threats, indicators of compromise, and attacker techniques to the security team and leadership.
- Prioritizes and tracks vulnerability remediation by severity, asset criticality, and risk exposure; reports program status and trends to the Security Manager.
Identity & Access Management
- Administers and monitors identity and access controls across the enterprise including Entra ID, remote access authentication, role-based access control, privileged access management, and conditional access policies.
- Conducts regular access reviews and maintains appropriate documentation.
- Supports onboarding and offboarding processes to ensure access is provisioned and deprovisioned accurately and in a timely manner.
Hardware, Software & Technology Risk Assessment
- Evaluates new hardware, software, and cloud services for security risk prior to procurement or deployment; provides risk assessment findings and recommendations to appropriate IT leadership.
- Contributes to vendor security assessments in coordination with the Security & Compliance Manager.
- Maintains a risk register for assessed technologies; tracks remediation commitments and monitors for changes in risk posture over time.
Automation, Integration & Continuous Improvement
- Designs, implements, and maintains automation workflows to streamline security operations, particularly in areas such as alert triage, enrichment, response, and vulnerability tracking
- Leverages scripting, APIs, and orchestration tools to reduce manual effort, improve consistency, and increase the speed of response
- Leverages AI and automation to support post-escalation security workflows and operational response activities
- Integrates security tools across the enterprise to enable coordinated response and improved visibility across systems
- Identifies opportunities to improve efficiency and scalability of security processes through engineering and automation-first thinking
Metrics, Reporting & Operational Effectiveness
- Defines, tracks, and reports on key security operations metrics such as response times, alert quality, and remediation performance
- Uses operational data and trends to continuously improve detection coverage, response effectiveness, and overall program maturity
Collaboration
- Works cross-functionally with IT, engineering, and business teams to embed security practices into enterprise systems and processes
- Communicates risks, findings, and recommendations clearly to both technical and non-technical stakeholders
Requirements
- Bachelor’s degree in Cybersecurity, Information Technology, or a related field. Equivalent experience and certifications considered
- At least three (3) years of hands-on information security experience, with demonstrated involvement in incident response, IAM, or vulnerability management
- Proficiency with SIEM platforms, EDR tools (CrowdStrike, SentinelOne, etc.), and identity security in a Microsoft 365 / Azure environment
- Working knowledge of identity and access management principles and tools (Entra ID, Active Directory, PAM solutions)
Preferred Qualifications
- At least five (5) years of hands-on information security experience, with demonstrated involvement in incident response, IAM, or vulnerability management
- Experience supporting or securing cloud and SaaS environments
- Experience with security automation using scripting and API integrations
- Familiarity with integrating security tools and automating operational workflows
- Exposure to AI/ML or generative AI applications in cybersecurity operations, including the use of AI agents to automate or augment functional responsibilities
- Certification in CompTIA Security+, CySA+, SC-200, or equivalent. CISSP, CEH, GCIH, or other incident response certifications valued.
Knowledge, Skills and Abilities
- Familiarity with vulnerability scanning tools (Tenable, Rapid7 or equivalent)
- Structured, analytical approach to investigation with strong documentation and reporting discipline
- Understanding of common threat frameworks (MITRE ATT&CK) and their application to detection and response
Benefits & conditions
An employee in this corporate based position can expect an annual salary of $79,000.00-$104,457.00/year. Actual pay within this range may depend on experience, qualifications, geographic location, client requirements where applicable, and other factors permitted by law. Regular-status employees are also eligible for performance bonuses. Candidates are also encouraged to consider SWCA’s Total Rewards package, which includes a competitive benefits package (https://www.swca.com/careers/benefits-wellness/), forward-thinking workplace flexibility, outstanding corporate culture, award-winning career development, and more.
About the company
SWCA Environmental Consultants is a growing employee-owned firm, providing a full-spectrum of environmental services. Our Vision (the North Star) is to make SWCA the best workplace and industry leader in sustainability, bringing sound science and creative solutions to global environmental challenges while maintaining a dedication to employee-ownership. We live our core values: we collaborate as #OneSWCA; we are #AlwaysLearning, we #NeverSettle, and we #GiveBack.
We are 100% employee-owned, and we build our success together. With offices across the United States, SWCA is one of the largest environmental compliance firms and ranks among Engineering News-Record’s Top 200 Environmental Firms. We offer a supportive, team-oriented work environment and competitive wages and benefits, including an 100% employee stock ownership plan (retirement).
At SWCA, we support our team members in developing their careers to make them leaders in their industry. Our Career Landscape initiative is a process and guide designed to help develop chart rewarding career paths for employees at SWCA. We encourage professional conference attendance, internal and external professional development and training programs, education reimbursement, a Science and Leadership Program, and bonuses for publications meeting certain criteria. All regular status employees are eligible to participate in SWCA medical, dental, vision, employee assistance, wellness, life and disability plans, and are eligible to participate in the SWCA 401(k) Profit Sharing Plan and Trust.
SWCA Environmental Consultants is a growing employee-owned firm, providing a full spectrum of environmental services. With offices across the United States, SWCA is one of the largest environmental compliance firms and ranks among Engineering News-Record’s Top 200 Environmental Firms., SWCA is committed to salary equity and salary transparency for all its employees. In alignment with this commitment, SWCA posts good faith pay ranges in all its advertised job postings to promote pay equity and transparency., SWCA continues to invest deeply in career development programs, delivering our award-winning Career Landscape support resources to accelerate the growth of our staff. We recognize the valuable skills and experiences our internal team members bring to SWCA’s continued success. Qualified internal candidates are encouraged to apply and will be seriously considered for this position. We believe in promoting from within, where possible, providing our existing employees with compelling opportunities to advance their careers.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on careers-swca.icims.comGood distractions
Talks and stories from around this role — technically off-topic, practically not.
Moments
Explore playlistsVideos
See allRelated articles
See all
Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.
9 Ways to Make Money Hacking
What Are The Top Skills Required For Azure Developers?
Walking Into The Era of Supply Chain Risks