> Markdown version of [/jobs/ext/1635928-it-security-engineer](https://www.wearedevelopers.com/jobs/ext/1635928-it-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # IT Security Engineer - **Company:** SWCA Environmental Consultants - **Location:** United States - **Experience:** Experienced - **Salary:** $79,000.0 - $104,457.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Active Directory, Application Programming Interfaces (APIs), Artificial Intelligence, User Authentication, Microsoft Azure, Software as a Service, Cloud Computing, CompTIA Security+, Cyber Security, Identity and Access Management, Issue Tracking Systems, IT Management, Operational Data Store, Role-Based Access Control, Remote Access Technology, Cloud Services, Security Information and Event Management, Systems Integration, Software Vulnerability Management, Diagnostic Tools, Scripting, Cloud Platform System, Mitre Att&ck, Information Technology, SentinelOne Expertise, Api Management, Security Orchestration, Automation & Response, Servicenow, Vulnerability Analysis - **Published:** July 7, 2026 - **Apply:** https://careers-swca.icims.com/jobs/14747/it-security-engineer/job?mode=apply&apply=yes&in_iframe=1&hashed=-336149107 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, or a related field. Equivalent experience and certifications considered * At least three (3) years of hands-on information security experience, with demonstrated involvement in incident response, IAM, or vulnerability management * Proficiency with SIEM platforms, EDR tools (CrowdStrike, SentinelOne, etc.), and identity security in a Microsoft 365 / Azure environment * Working knowledge of identity and access management principles and tools (Entra ID, Active Directory, PAM solutions) Preferred Qualifications * At least five (5) years of hands-on information security experience, with demonstrated involvement in incident response, IAM, or vulnerability management * Experience supporting or securing cloud and SaaS environments * Experience with security automation using scripting and API integrations * Familiarity with integrating security tools and automating operational workflows * Exposure to AI/ML or generative AI applications in cybersecurity operations, including the use of AI agents to automate or augment functional responsibilities * Certification in CompTIA Security+, CySA+, SC-200, or equivalent. CISSP, CEH, GCIH, or other incident response certifications valued. Knowledge, Skills and Abilities * Familiarity with vulnerability scanning tools (Tenable, Rapid7 or equivalent) * Structured, analytical approach to investigation with strong documentation and reporting discipline * Understanding of common threat frameworks (MITRE ATT&CK) and their application to detection and response ## Description The IT Security Engineer (HR Title = Technology Infrastructure Engineer - Security) is a core practitioner within the security team, responsible for the day-to-day work that keeps the enterprise protected. This role spans incident response, identity and access management, hardware and software risk assessment, and threat and vulnerability management - requiring technical depth, the ability to think critically about risk in a dynamic environment, and superior communications and business skills to interact with stakeholders at all levels of our organization and subsidiaries. This is a role for someone who takes their craft seriously. The Security Engineer knows that security is not a checklist - it is a continuous practice which relies on learning and improving. They bring curiosity, precision, and a structured approach to investigation and remediation, and they contribute directly to the security posture that protects every firm in the enterprise. Beyond execution, this role is expected to continuously improve how security work is performed - identifying opportunities to reduce manual effort, increase consistency, and scale operations through thoughtful use of automation, integration, and emerging AI-enabled capabilities. This is a regular (with benefits), salaried, exempt position that can be located near any SWCA office in a hybrid fashion. Highly qualified, remote (= distributed) employees will also be seriously considered. Submitting a cover letter with your resume is strongly encourged. Application deadline: Our team will begin reviewing applications immediately, and interviews will be scheduled with qualified candidates on a rolling basis. The application process will remain open until we have received a robust pool of qualified candidates. Once we have identified suitable individuals, we may close the application process without prior notice. We appreciate the time and effort invested by all applicants and will carefully consider each submission. What you will accomplish Incident Response * Monitors security alerts and events from outsourced MDR service and SIEM, EDR, email and other detection tools; triages, investigates, and responds to security incidents in accordance with standards, policies, best practices, and where applicable, established playbooks. * Leads or supports incident response activities including containment, eradication, recovery, and post-incident documentation. * Maintains and improves incident response playbooks, contributes to after-action reviews, lessons-learned processes, and continued improvement. * Acts as an initial escalation point for security-related support tickets, working through the internal ticketing system to review, prioritize, and coordinate response to issues that require deeper technical investigation, risk evaluation, or security team involvement (Freshservice, ServiceNow, etc.). Threat & Vulnerability Management * Operates and maintains the vulnerability scanning program, with outsourced vendor support where applicable, across enterprise systems, cloud environments, and endpoints; tracks findings and coordinates remediation with security and IT teams. * Monitors threat intelligence feeds and communicates relevant emerging threats, indicators of compromise, and attacker techniques to the security team and leadership. * Prioritizes and tracks vulnerability remediation by severity, asset criticality, and risk exposure; reports program status and trends to the Security Manager. Identity & Access Management * Administers and monitors identity and access controls across the enterprise including Entra ID, remote access authentication, role-based access control, privileged access management, and conditional access policies. * Conducts regular access reviews and maintains appropriate documentation. * Supports onboarding and offboarding processes to ensure access is provisioned and deprovisioned accurately and in a timely manner. Hardware, Software & Technology Risk Assessment * Evaluates new hardware, software, and cloud services for security risk prior to procurement or deployment; provides risk assessment findings and recommendations to appropriate IT leadership. * Contributes to vendor security assessments in coordination with the Security & Compliance Manager. * Maintains a risk register for assessed technologies; tracks remediation commitments and monitors for changes in risk posture over time. Automation, Integration & Continuous Improvement * Designs, implements, and maintains automation workflows to streamline security operations, particularly in areas such as alert triage, enrichment, response, and vulnerability tracking * Leverages scripting, APIs, and orchestration tools to reduce manual effort, improve consistency, and increase the speed of response * Leverages AI and automation to support post-escalation security workflows and operational response activities * Integrates security tools across the enterprise to enable coordinated response and improved visibility across systems * Identifies opportunities to improve efficiency and scalability of security processes through engineering and automation-first thinking Metrics, Reporting & Operational Effectiveness * Defines, tracks, and reports on key security operations metrics such as response times, alert quality, and remediation performance * Uses operational data and trends to continuously improve detection coverage, response effectiveness, and overall program maturity Collaboration * Works cross-functionally with IT, engineering, and business teams to embed security practices into enterprise systems and processes * Communicates risks, findings, and recommendations clearly to both technical and non-technical stakeholders ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Applying Agile Principles to Incident Management ](https://www.wearedevelopers.com/videos/101-applying-agile-principles-to-incident-management) - [JavaScript? No. Java Scripts! - Scripting with Java](https://www.wearedevelopers.com/videos/2094-javascript-no-java-scripts-scripting-with-java) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [AI in Production: applied AI & enterprise use cases](https://www.wearedevelopers.com/videos/100130-ai-in-production-applied-ai-enterprise-use-cases) - [Intermediate Bitcoin Script](https://www.wearedevelopers.com/videos/25-intermediate-bitcoin-script) ## Related Articles - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)