Cybersecurity Engineer

Tech Inc
United States
8 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Compensation
$75,000.0 - $100,000.0
Working hours
Regular working hours
Job source

Tech stack

Microsoft Word Microsoft Excel Software System Penetration Testing CompTIA Security+ Cyber Security Microsoft Office Security Information and Event Management Software Vulnerability Management Firewalls (Computer Science) CIS Benchmarks Vulnerability Analysis

Job description

We are seeking a Cybersecurity & Compliance Specialist to strengthen our security posture across internal systems and customer environments while overseeing compliance efforts for both Vector Choice and our clients. This role is responsible for monitoring security threats, reviewing penetration testing results, maintaining compliance with security best practices and regulatory frameworks, supporting CyberGuard compliance initiatives, developing and maintaining Written Information Security Programs (WISPs), and ensuring clients meet requirements such as FTC Safeguards, CMMC, and other applicable standards.The ideal candidate has hands-on security experience, strong compliance knowledge, excellent communication skills, and holds at minimum a CompTIA Security+ certification.Key ResponsibilitiesSecurity Operations & Monitoring

  • Monitor security alerts, logs, and reports across customer and internal environments
  • Identify, analyze, and respond to security threats and vulnerabilities
  • Assist with incident response, investigation, and remediation efforts
  • Ensure security tools (EDR, MDR, SIEM, email security, firewall, etc.) are properly configured and functioning

Penetration Testing & Risk Management

  • Review penetration testing and vulnerability scan reports from third-party vendors
  • Translate technical findings into clear, customer-friendly explanations
  • Conduct post-pen-test review meetings with customers to explain risks, impact, and remediation steps
  • Track remediation progress and validate corrective actions

Compliance Program Management (Internal & Client)

  • Oversee and coordinate compliance efforts within Vector Choice and for external clients to ensure operational procedures and business processes comply with applicable laws, regulations, and contractual agreements
  • Develop, improve, and maintain company policies, standards, and procedures that outline ethical, safe, and efficient operations
  • Create, update, and execute the Compliance and Ethics Program Plan
  • Establish and reinforce a culture of compliance throughout the organization
  • Monitor and test policies and procedures to ensure they result in effective compliance
  • Perform risk assessments and compliance reviews to verify adherence
  • Recommend investigative procedures in response to alleged violations of rules, regulations, policies, procedures, or the Code of Conduct
  • Provide guidance on effective responses to detected problems and recommend corrective actions
  • Preside over and direct the work of the Compliance Committee (as applicable)
  • Govern reporting of misconduct/noncompliance, reporting pathways, and protection from retaliation
  • Stay current with changes in federal, state, and industry regulations and ensure the organization and clients remain informed and compliant

FTC Safeguards Rule Compliance

  • Ensure clients meet FTC requirements for protecting consumer data, including the development, implementation, and maintenance of appropriate safeguards
  • Perform regular audits and assessments to verify compliance with FTC regulations
  • Provide recommendations to enhance data protection and safeguard measures

CMMC Compliance

  • Guide clients through the CMMC certification process, ensuring they meet all required cybersecurity practices
  • Conduct gap analyses and readiness assessments to identify areas of non-compliance
  • Develop remediation plans and provide ongoing support to achieve and maintain CMMC certification

CyberGuard Compliance & WISP Development

  • Support CyberGuard compliance efforts, including related assessments, documentation, and ongoing compliance maintenance
  • Develop, write, update, and maintain Written Information Security Programs (WISPs) for internal use and customer environments

Compliance Audits, Assessments & Documentation

  • Perform routine compliance audits for clients to identify and address potential risks
  • Prepare comprehensive audit reports and present findings to clients with actionable recommendations
  • Maintain detailed records of compliance activities, assessments, and client communications
  • Develop and update compliance-related documentation, including policies, procedures, and training materials
  • Provide regular reports to management on compliance status, issues, and resolutions

Customer-Facing Engagement & Training

  • Act as a security and compliance subject-matter expert during customer meetings and reviews
  • Provide security and compliance recommendations aligned with industry best practices and frameworks (CIS Controls, NIST, HIPAA, PCI, FTC Safeguards, CMMC, etc.)
  • Assist account managers and engineers with security assessments, compliance proposals, and risk prioritization discussions
  • Provide clients with ongoing support in implementing and maintaining compliance measures
  • Develop and deliver training sessions for client teams on compliance best practices and regulatory changes
  • Serve as a primary point of contact for client inquiries regarding security and compliance issues

Security Governance & Continuous Improvement

  • Maintain and improve security standards, policies, and procedures
  • Recommend improvements to tools, processes, and security controls
  • Support audits, compliance initiatives, and security documentation when required
  • Stay current with emerging threats, vulnerabilities, and security trends

Requirements

  • CompTIA Security+ certification (required)
  • Bachelor’s Degree in Law, Finance, Business Administration, Information Security, or a related field
  • 2+ years of experience in cybersecurity, IT security, compliance, or related roles
  • Working knowledge of network and endpoint security, firewalls, MFA, EDR/MDR, email security, vulnerability management, and risk assessment
  • Experience with or strong understanding of FTC Safeguards Rule and CMMC requirements
  • Ability to clearly explain technical security and compliance concepts to non-technical users
  • Strong documentation, policy-writing, and communication skills (including WISP development)
  • Proficiency with Microsoft Office (Word, Excel, Email, Scheduling)
  • Ability to type at least 40 words per minute, * Additional certifications: CySA+, CEH, SSCP, CMMC-related credentials, or similar
  • Experience in an MSP or multi-tenant environment
  • Familiarity with compliance frameworks such as CIS Controls, NIST, HIPAA, PCI, SOC 2, and CyberGuard compliance processes
  • Hands-on experience developing or maintaining Written Information Security Programs (WISPs)
  • Experience reviewing third-party security assessments or penetration tests
  • Prior experience leading or supporting a Compliance Committee or ethics program

Soft Skills & Competencies

  • Strong analytical, problem-solving, and judgment skills
  • Excellent customer service and interpersonal skills; manages difficult situations professionally
  • Clear oral and written communication; speaks persuasively and writes informatively
  • Leadership presence with the ability to influence and motivate others
  • Detail-oriented with strong follow-through and organizational skills
  • Ability to balance multiple clients and priorities
  • Proactive, continuously learning mindset with a commitment to quality and ethics
  • Maintains confidentiality and works with integrity

Work Environment & Physical Demands

  • Remote in USA (or as determined by the organization)
  • Occasional after-hours work may be required for security incidents
  • Client-facing role requiring professionalism and clear communication
  • Must occasionally lift and/or move up to 10 pounds
  • Valid driver’s license with reliable transportation required
  • Noise level in the work environment is usually moderate

Benefits & conditions

$75,000 - $100,000 a year - Full-time, Pulled from the full job description

  • 401(k)
  • Health insurance
  • Paid time off
  • Vision insurance
  • Dental insurance, * Competitive salary: $75,000 - $100,000 based on experience and certifications
  • Training and certification reimbursement
  • Growth path into Senior Security Analyst, Security Engineer, or Compliance leadership roles
  • 401(k)
  • Dental, Health, and Vision insurance
  • Paid time off, * 401(k)
  • Dental insurance
  • Health insurance
  • Paid time off
  • Vision insurance

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.indeed.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · WWC 2022

3:58 min

Mitigating diverse browser quirks and unsupported clipboard metadata formats

Markus Over Markus Over

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · WWC 2022

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · WWC 2023

Videos

See all

Related articles

See all