IT Security Engineer

Gravity Hair Salon, LLC
Salt Lake City, UT, United States
12 days ago
Apply on www.gravityitresources.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Compensation
$100,000.0 - $125,000.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Microsoft Antivirus Microsoft Azure Cloud Computing Cloud Computing Security CompTIA Security+ Cyber Security Multi-Factor Authentication Identity and Access Management Python (Programming Language) Network Security Microsoft Security Essentials
+11 more
Windows PowerShell Azure Active Directory Zero Trust Network Access Security Information and Event Management Software Engineering Software Vulnerability Management Scripting Software Troubleshooting Microsoft InTune Information Technology CIS Benchmarks

Job description

A Senior IT Security Engineer in Operations & Engineering supports the design, implementation, and operation of enterprise cybersecurity technologies and services. They are responsible for strengthening the organization’s security posture through the deployment, administration, and optimization of security controls across on-premises, cloud, and hybrid environments. They serve as a technical leader within the Cybersecurity team, partnering closely with IT Infrastructure, Network Engineering, Cloud Operations, Application Development, and Security Operations teams to ensure security controls are effectively implemented and maintained. This role supports both operational security activities and strategic security initiatives, helping to reduce risk through automation, engineering excellence, and continuous improvement. This position requires a strong technical foundation across multiple security domains, including endpoint security, identity and access management, cloud security, network security, vulnerability management, and security monitoring. The ideal candidate can balance engineering, operational support, and project execution while driving security best practices throughout the organization. Responsibilities Security Engineering & Architecture:

  • Design, implement, and maintain cybersecurity technologies across endpoint, network, cloud, and identity platforms
  • Evaluate, deploy, and optimize security tools and controls to improve the organization’s security posture
  • Support the development and implementation of cybersecurity standards, architectures, and technical roadmaps
  • Partner with IT teams to ensure security controls are integrated into infrastructure and application designs

Security Operations & Incident Response:

  • Support security monitoring, threat detection, and incident response activities
  • Investigate security alerts, identify root causes, and assist with containment and remediation efforts
  • Develop and maintain operational procedures, runbooks, and response documentation
  • Participate in incident response exercises and continuous improvement initiatives

Identity & Access Management (IAM):

  • Implement and support IAM capabilities, including identity lifecycle management, authentication, authorization, and privileged access controls
  • Manage role-based access controls, multifactor authentication, conditional access, and identity governance processes
  • Support periodic access reviews, entitlement management, and segregation of duties initiatives
  • Partner with application and infrastructure teams to integrate IAM solutions and automate identity processes

Vulnerability & Security Risk Management:

  • Support the vulnerability management program through assessment, prioritization, tracking, and remediation validation
  • Collaborate with system owners to remediate vulnerabilities and reduce cyber risk
  • Analyze security findings and recommend appropriate compensating controls or risk reduction measures
  • Track remediation progress and support risk reporting activities

Cloud & Infrastructure Security:

  • Design and implement security controls for Microsoft Azure, Microsoft 365, and hybrid environments
  • Support cloud security monitoring, configuration reviews, and hardening efforts
  • Evaluate cloud architectures and services to ensure alignment with security requirements
  • Implement security best practices for infrastructure, applications, and data protection

Automation, Reporting & Continuous Improvement:

  • Identify opportunities to automate security processes and improve operational efficiency
  • Develop metrics, dashboards, and reporting to support cybersecurity decision-making
  • Maintain technical documentation, standards, and operational procedures
  • Stay current on emerging threats, technologies, and industry best practices

Requirements

  • Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, or related field
  • 5-8 years of experience in cybersecurity engineering, security operations, or infrastructure security
  • Experience managing and supporting enterprise security technologies, including EDR, SIEM, IAM, vulnerability management, and cloud security platforms
  • Strong knowledge of Microsoft security technologies, including Microsoft Defender, Entra ID (Azure AD), Intune, and Azure security services
  • Experience supporting incident response, vulnerability management, and security investigations
  • Knowledge of cybersecurity frameworks and best practices such as NIST CSF, CIS Controls, and Zero Trust principles
  • Experience scripting or automating security processes using PowerShell, Python, or similar technologies preferred
  • Strong troubleshooting, analytical, and problem-solving skills
  • Excellent communication and collaboration skills with both technical and non-technical stakeholders
  • Industry certifications such as CISSP, GSEC, Security+, Azure Security Engineer (AZ-500), or similar preferred, * Bachelor’s Degree in Cybersecurity, Information Technology, Computer Science, or related field
  • 5-8 years of experience in cybersecurity engineering, security operations, or infrastructure security
  • Experience managing and supporting enterprise security technologies, including EDR, SIEM, IAM, vulnerability management, and cloud security platforms
  • Strong knowledge of Microsoft security technologies, including Microsoft Defender, Entra ID (Azure AD), Intune, and Azure security services
  • Experience supporting incident response, vulnerability management, and security investigations
  • Knowledge of cybersecurity frameworks and best practices such as NIST CSF, CIS Controls, and Zero Trust principles
  • Experience scripting or automating security processes using PowerShell, Python, or similar technologies preferred
  • Strong troubleshooting, analytical, and problem-solving skills
  • Excellent communication and collaboration skills with both technical and non-technical stakeholders
  • Industry certifications such as CISSP, GSEC, Security+, Azure Security Engineer (AZ-500), or similar preferred

Employment Eligibility: Gravity cannot transfer nor sponsor a work visa for this position. Applicants must be eligible to work in the U.S. for any employer directly (we are not open to contract or “corp to corp” agreements).

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.gravityitresources.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

4:11 min

Introduction to cloud-native application developer security

Micah Silverman · World Congress 2022

2:15 min

Auditing container configurations against CIS benchmark security standards

Madhu Akula · LIVE

1:04 min

Introduction to Bitcoin script parsing tools

Steve Shadders · LIVE

3:44 min

Current industry adoption and future security initiatives

Alexander Allmendinger · LIVE

3:39 min

Validating data queries and infrastructure security configurations

Philipp Krenn · World Congress 2023

Videos

See all

Related articles

See all