> Markdown version of [/jobs/ext/2635080-security-engineer](https://www.wearedevelopers.com/jobs/ext/2635080-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** McNees Wallace & Nurick LLC - **Location:** Pittsburgh, PA, United States (Remote available) - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Software System Penetration Testing, Microsoft Azure, Cloud Computing Security, CompTIA Security+, Cyber Security, Information Systems, Disaster Recovery, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Lightweight Directory Access Protocols (LDAP), OAuth, Windows PowerShell, Zero Trust Network Access, Security Assertion Markup Language (SAML), Security Information and Event Management, Single Sign-On, Software Vulnerability Management, Firewalls (Computer Science), Infrastructure Automation Frameworks, Information Technology, CIS Benchmarks, Vulnerability Analysis - **Published:** August 3, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=322ea6fab7c3202a ## About the Role * Bachelor's degree in Information Security, Information Technology, Information Systems, or a related field, or an equivalent combination of education and experience. * Five or more years of progressive experience in cybersecurity or information security, including responsibility for complex security programs and initiatives. * Strong knowledge of network security, operating system hardening, Azure security, and modern security architectures, including zero-trust principles. * Hands-on experience with SIEM platforms, vulnerability management tools, endpoint detection and response (EDR), firewalls, and IDS/IPS technologies. * Working knowledge of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, and SOC 2. * Understanding of identity and access management technologies and protocols, including SAML, OAuth, LDAP, and directory services. * Experience with scripting and automation tools such as PowerShell and Python. * Exceptional analytical, troubleshooting, and problem-solving abilities. * Strong written and verbal communication skills with the ability to present technical concepts to both technical and non-technical audiences. * Ability to manage multiple priorities, work independently, and maintain confidentiality in a professional services environment. * Industry certifications such as CISSP, CISM, CEH, GIAC, or CompTIA Security+ are strongly preferred. * Master's degree in Cybersecurity, Information Security, or a related discipline is preferred. #LI-REMOTE ## Description You will lead the design, implementation, and continuous improvement of the firm's cybersecurity program. This is a high-impact role for a security professional who thrives on solving complex challenges, strengthening organizational resilience, and partnering across teams to embed security into every aspect of technology operations. Reporting to the Chief Information Officer, the Security Engineer will serve as the firm's primary security expert, driving security strategy, incident response, risk management, and security architecture initiatives while helping to advance the overall capabilities of our IT team., * Design, implement, and maintain enterprise security infrastructure, including firewalls, intrusion detection and prevention systems (IDS/IPS), endpoint protection platforms, SIEM solutions, and application control technologies. * Lead the execution of the firm's cybersecurity strategy and roadmap, aligning security initiatives with business objectives and risk management priorities. * Monitor security systems, investigate alerts, and coordinate responses to security incidents, including high-severity events and forensic investigations. * Conduct vulnerability assessments and penetration testing activities while partnering with system owners to remediate identified risks. * Develop, maintain, and enforce security policies, standards, and procedures aligned with industry frameworks such as NIST CSF, CIS Controls, and ISO 27001. * Manage identity and access management solutions, including multi-factor authentication, single sign-on, privileged access management, and periodic access reviews. * Support security and privacy compliance initiatives, audits, risk assessments, and third-party vendor security reviews. * Administer and optimize security tools, including email security gateways, web filtering solutions, and cloud security technologies. * Lead incident response, business continuity, disaster recovery, and major security-focused projects such as platform migrations and zero-trust initiatives. * Collaborate with infrastructure, cloud, and business teams to integrate security requirements into new and existing technologies and processes. * Advise firm leadership on cybersecurity risks, security architecture, and strategic technology investments. * Track emerging threats and security trends, and prepare metrics, dashboards, and reports demonstrating the firm's security posture and program maturity. * Mentor colleagues, share technical expertise, and help foster a culture of security awareness across the organization. ## Related Videos - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [Cyber Security: Small, and Large!](https://www.wearedevelopers.com/videos/259-cyber-security-small-and-large) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [The Overflow: Security and Privacy](https://www.wearedevelopers.com/magazine/715-the-overflow-security-and-privacy) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)