Senior Security Engineer

VDart, Inc.
Jersey City, NJ, United States
2 days ago
Apply on www.careerjet.com
Prepare application

Role details

Contract type
Temporary to permanent
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
7 years minimum
Compensation
$141,400.0 - $171,100.0
Working hours
Regular working hours

Tech stack

Microsoft Windows Active Directory Application Integration Architecture Systems Engineering User Authentication Microsoft Azure Microsoft Online Services Cloud Computing Cloud Computing Security Cyber Security Information Systems Domain Name System (DNS)
+34 more
Multi-Factor Authentication Monitoring of Systems Identity and Access Management Intrusion Detection and Prevention Network Security Lightweight Directory Access Protocols (LDAP) Microsoft Software Windows Servers Windows PowerShell Role-Based Access Control Azure Active Directory Cloud Services Anti-Phishing Zero Trust Network Access Web Application Security Security Log Microsoft SharePoint Security Information and Event Management Software Vulnerability Management Enterprise Software Applications Okta Data Ingestion Mitre Att&ck Microsoft InTune Microsoft Onedrive Tanium Platform Expertise Information Technology CIS Benchmarks Operating System Security Network Server SentinelOne Expertise Qualys Vulnerability Analysis Vmware

Job description

Client is seeking a Senior Security Engineer who combines strong, hands-on systems engineering with operational cybersecurity engineering. This person will design, administer, secure, and support enterprise infrastructure across on-premises, cloud, and hybrid environments. The role spans Windows Server, Active Directory, Microsoft Entra ID, Microsoft 365, Azure, endpoint management, identity, security monitoring, vulnerability management, incident response, infrastructure hardening, and automation. The engineer will serve as a senior escalation resource and work closely with Infrastructure, Information Security, Network, Applications, End-User Support, and external vendors. The priority is a systems engineer who has also personally operated security platforms and driven security remediation. A background limited to security analysis, governance, or oversight will not cover the infrastructure ownership required here., Systems and Infrastructure Engineering

  • Design, implement, administer, and support enterprise server infrastructure across on-premises, virtual, cloud, and hybrid environments.
  • Administer Windows Server, Active Directory, Group Policy, DNS, file services, and related infrastructure.
  • Troubleshoot complex server, operating system, authentication, application, connectivity, and infrastructure issues.
  • Monitor availability, performance, capacity, and reliability; recommend and implement improvements.
  • Support upgrades, migrations, infrastructure modernization, and technology replacement initiatives, including VMware-to-Azure Local activities.
  • Maintain configuration standards, operating procedures, and technical documentation.

Identity and Access Management

  • Administer Microsoft Entra ID and on-premises Active Directory in a hybrid identity environment.
  • Design, deploy, and tune Conditional Access policies for device compliance, location, MFA, and phishing-resistant authentication.
  • Investigate high-risk sign-ins and potential account compromise.
  • Support hybrid Entra join and troubleshoot Primary Refresh Token and Service Connection Point issues.
  • Support Okta and other third-party identity federation and application integrations.
  • Manage AD delegation and least-privilege permissions for service accounts and automation.
  • Resolve complex authentication, authorization, identity, and remote-access issues.

Microsoft 365, Cloud, and Endpoint Engineering

  • Administer Exchange Online, SharePoint Online, Microsoft Teams, OneDrive, and their associated security controls.
  • Support Azure and Azure Local environments, including security configuration and post-migration validation.
  • Administer Intune, enterprise Group Policy, endpoint compliance, and security baselines.
  • Manage endpoint technologies including SentinelOne and Tanium.
  • Develop and maintain Windows workstation and server hardening standards.
  • Review configurations such as LDAP signing, password policies, and authentication settings.
  • Manage Office update channels and deployments through Group Policy, Intune, registry settings, and Tanium.

Security Monitoring and Incident Response

  • Operate and maintain SIEM, EDR, and monitoring technologies, including SentinelOne and Darktrace.
  • Onboard security log sources across identity, endpoints, cloud, and enterprise applications.
  • Build and maintain custom parsers, sensors, and detection logic aligned with MITRE ATT&CK.
  • Triage alerts, investigate incidents, and participate in containment, remediation, and recovery.
  • Monitor security-agent health and coverage and improve investigation workflows.

Vulnerability Management and Network Security

  • Support vulnerability scanning and remediation using Qualys.
  • Review findings, prioritize remediation, and coordinate fixes with Infrastructure, Network, Application, and security teams.
  • Develop server and operating system security standards and validate remediation.
  • Support Zscaler, secure web gateway configurations, traffic capture, and network security sensors.
  • Review segmentation and infrastructure changes for security impact.

Automation, Projects, and Vendor Coordination

  • Build PowerShell automation across AD, Azure, Exchange Online, SharePoint Online, DNS, endpoints, and other infrastructure services.
  • Develop scheduled reporting for compliance, vulnerability management, identity risk, and operations.
  • Automate repetitive administrative, account-management, and alert-handling tasks.
  • Serve as a senior technical resource for cloud, infrastructure, and security projects.
  • Coordinate with vendors and service providers, including Okta, Tanium, Zscaler, Qualys, SentinelOne, and Darktrace.
  • Participate in technology evaluations, proof-of-concepts, deployments, office buildouts, and internal knowledge-sharing., Are you ready to be part of something big? We’re hiring for the Commercial Solutions Engineer on our Sales Team! In this role, you’ll engage with key decision-makers, forge impac…
  • 9 hours ago, Are you ready to be part of something big? We’re hiring for the Commercial Solutions Engineer on our Sales Team! In this role, you’ll engage with key decision-makers, forge impac…
  • 9 hours ago +

Requirements

  • Bachelor’s degree in IT, Computer Science, Cybersecurity, Information Systems, or a related field, or equivalent professional experience.
  • 7+ years of progressively responsible systems, infrastructure, security, or infrastructure-security engineering experience.
  • Strong hands-on experience with Windows Server, Active Directory, Group Policy, DNS, Entra ID, Microsoft 365, Intune, and Azure.
  • Strong understanding of hybrid identity, authentication, least privilege, Conditional Access, and MFA.
  • Practical experience with endpoint security, security monitoring, vulnerability management, incident response, and infrastructure hardening.
  • Strong PowerShell scripting and automation skills.
  • Ability to troubleshoot enterprise issues spanning servers, identity, endpoints, cloud services, applications, and security tools.
  • Clear communication, documentation, independent prioritization, and collaboration skills.

Preferred Qualifications:

  • Azure Local/Azure Stack HCI and VMware-to-Azure Local migration experience.
  • Hands-on experience with SentinelOne, Darktrace, Tanium, Qualys, Zscaler, and/or Okta.
  • SIEM and EDR administration, security-log ingestion, and detection engineering.
  • Familiarity with MITRE ATT&CK.
  • Cloud or infrastructure migration experience and automated operational reporting.
  • CISSP, GIAC, Microsoft, Azure, cloud-security, or other relevant certifications.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.careerjet.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira · Coffee With Developers

1:40 min

Managing containerized infrastructure with Podman Desktop

Cedric Clyburn Cedric Clyburn +1 · World Congress 2025

2:33 min

Introduction to security advocacy and automation testing

Chris Heilmann Chris Heilmann +2 · LIVE

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

1:41 min

Parallels between cloud and legacy infrastructure lock-ins

Björn Stahl Björn Stahl · World Congress 2024

4:37 min

Architecting single sign-on flows across multiple application domains

Gift Egwuenu · World Congress 2023

Videos

See all

Related articles

See all