Security Engineer Level 2

MY3TECH INC
Harrisburg, PA, United States
16 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Amazon Web Services Macintosh Computers Software System Penetration Testing Microsoft Azure Bash Shell Microsoft Outlook Software as a Service Cloud Computing Cyber Security Computer Networks
+34 more
Data Integrity Linux Hyper-V Identity and Access Management Networking Hardware Intrusion Detection Systems PostgreSQL Linux System Administration Microsoft SQL Server Windows Servers MongoDB MySQL Oracle (Applications) Password Management Windows PowerShell Azure Active Directory Phishing Single Sign-On Virtualization Technology Software Vulnerability Management Scripting Internet Protocol Telephony Okta Cyberark HybridCloud Firewalls (Computer Science) Information Technology Hashicorp Patch Management Enterprise Integration Hardware Infrastructure CIS Benchmarks Terraform Vulnerability Analysis

Job description

The Security Engineer Level 2 is responsible for assisting with the design, implementation, and maintenance of enterprise security solutions across a hybrid cloud environment (on-premises and cloud). This role proactively strengthens the organization’s security posture using NIST, the CIS Critical Security Controls (CIS CSC), SOC 2, and related frameworks. The Security Engineer serves as a subject-matter expert (SME) on security best practices, compliance requirements, and risk mitigation. This role proactively shares and communicates on Security and Compliance topics within the organization and collaborates cross-functionally with IT, Cloud Operations, Sales, Legal, and executive leadership (including the vCISO) to improve security maturity, respond to customer security requirements, and assist with remediation efforts for vulnerabilities and incidents. II. Essential Job Functions Hybrid Cloud Security Architecture & Operations

  • Design, implement, configure, and support security solutions for cloud platforms (Azure, AWS) and on-premises infrastructure.
  • Secure integration of SaaS applications, IAM, SSO/MFA, and privileged access management solutions.
  • Configure and manage firewalls, WAFs, IDS/IPS, EDR, XDR, email security, DLP, MDM, and related tools.
  • Support infrastructure hardening using CIS Benchmarks for Windows, Mac, and Linux systems.
  • Perform regular user access reviews, firewall rule reviews, and security control health checks.
  • Manage security certificates and password vault systems.

Security Monitoring, Vulnerability Management & Incident Response

  • Implement and build out security controls.
  • Monitor logs, dashboards, alerts, network traffic, performance, and ensure data integrity for anomalous activity.
  • Ensure security controls are in place and operational to improve the organization’s security posture.
  • Configure and manage core security services such as DLP.
  • Conduct vulnerability scans, assess findings, and implement remediation efforts.
  • Coordinate and assist in annual penetration testing and track remediation of findings.
  • Assist in the investigation and resolution of security incidents in collaboration with the SOC and third-party vendors.
  • Participate in on-call rotation and support incident escalation as needed.
  • Work independently on Security Assessment questionnaires.

Security Governance, Risk & Compliance

  • Develop, maintain, and enforce security policies, standards, and procedures.
  • Support SOC 2, NIST, CIS CSC, ISO, and other compliance initiatives.
  • Lead customer security assessments and coordinate remediation activities.
  • Partner with Sales and Legal teams to review and negotiate security requirements in customer agreements.
  • Prepare documentation and detailed technical responses for RFPs, audits, and client assessments.
  • Assist with third-party vendor risk assessments.

Automation & Continuous Improvement

  • Develop automation scripts (PowerShell, Bash) for patching, compliance validation, and security operations.
  • Apply infrastructure-as-code and automation principles to improve security processes.
  • Continuously evaluate tools, controls, and processes to strengthen security maturity. Recommend strategic improvements to infrastructure security and architecture.

Infrastructure & Systems Security

  • Harden and secure Windows Server and Linux environments.
  • Secure virtualization environments and physical server infrastructure.
  • Configure and secure Dell and Meraki networking equipment.
  • Manage patch management processes and remediation of CVEs.
  • Deploy and manage security features across Active Directory, Group Policy, Exchange/Outlook, and endpoint platforms.

Security Awareness & Training

  • Deliver security awareness programs and phishing simulations (KnowBe4).
  • Provide guidance and training to staff on emerging threats and best practices.
  • Develop security documentation and operational standards.

(Note: These essential and additional job functions are not to be construed as a complete statement of all duties performed. Employees will be required to perform other job-related marginal duties as assigned.) III. Candidate Skills and Qualifications

Requirements

  • Minimum of 3 years of experience in security engineering or advanced systems administration.
  • 2+ years of IT systems administration experience.
  • Strong knowledge of security frameworks (NIST, CIS CSC, SOC 2, ISO, FedRAMP).
  • Working knowledge in a business setting of:

  • Firewalls, IDS/IPS, EDR, XDR, IAM, SSO/MFA, PAM
  • Vulnerability management and penetration testing tools
  • Email security, DLP, MDM
  • Patch management systems
  • Experience securing hybrid cloud environments (Azure, AWS).
  • Proficiency in PowerShell, Bash, and automation scripting.
  • Ability to analyze logs, dashboards, and network traffic.
  • Strong documentation and communication skills.
  • Highly organized with strong analytical and problem-solving abilities; able to work collaboratively and independently.
  • Ability to drive assigned tasks to completion on time and with a high level of quality and integrity.
  • Demonstrates a strong sense of ownership and accountability for tasks, decisions, and outcomes.
  • Makes sound, timely decisions after considering relevant input to provide recommendations to stakeholders while aligning business objectives and security compliance.

Preferred Skills and Experience:

  • Bachelor’s degree in information technology or related field.
  • Security certifications such as AWS Certified Security Specialty, Microsoft AZ-500 + SC-200, GIAC GSEC or GCIH, HashiCorp Terraform Associate, Okta Certified Administrator, or CyberArk Defender.
  • Experience with:

  • Microsoft 365 / Azure AD
  • AWS security services
  • Hyper-V virtualization
  • SQL Server, PostgreSQL, MySQL, MongoDB, Oracle
  • VoIP systems
  • Dell, HP, and Meraki platforms

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

52 sec

Running persistent Linux environments directly on Windows

Ben Breard Ben Breard · WWC 2025

2:18 min

Scaling MySQL databases for massive user growth

Johannes Nicolai Johannes Nicolai +1 · LIVE

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann +2 · LIVE

8:22 min

Simulating a Linux terminal and running Spring Boot

Jakov Semenski · LIVE

3:55 min

Demonstrating .NET installation on Debian and Azure Linux

Silvano Coriani Silvano Coriani · Europe 2026 Virtual

Videos

See all

Related articles

See all