Security Engineer
Vanderhouwen & Associates, Inc.
Portland, OR, United States
2 days ago
- Discuss this with your agent
- Open in Claude
- Open in ChatGPT
Apply on www.vanderhouwen.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Role details
Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours
Job source
Tech stack
Microsoft Access
Artificial Intelligence
Microsoft Azure
CompTIA Security+
Cyber Security
Information Systems
Database Security
Multi-Factor Authentication
Identity and Access Management
Networking Hardware
Intrusion Detection and Prevention
Network Security
+17 more
Log Analysis
Microsoft Security Essentials
Microsoft Office
Windows PowerShell
Cloud Services
Kusto Query Language
Zero Trust Network Access
Security Information and Event Management
Software Vulnerability Management
EndPointSecurity
Data Logging
Firewalls (Computer Science)
Microsoft InTune
Information Technology
Cybercrime
Microsoft Sentinel
GPT
Job description
- Support security policies, procedures, and technical documentation aligned to NIST 800-53 and NIST 800-171 standards.
- Help prepare for CMMC compliance by maintaining the System Security Plan and POA&M, scoping environments that handle CUI, gathering assessment evidence, and tracking remediation through completion.
- Monitor, triage, and investigate security alerts using Microsoft Sentinel and Defender XDR, performing log analysis and threat hunting with KQL.
- Configure, tune, and evaluate security tools across servers, endpoints, cloud services, and network devices, with a focus on the Microsoft security stack, including Entra ID and Intune.
- Advance Zero Trust initiatives by strengthening identity and device controls, including Conditional Access, multi-factor authentication, least-privilege access, and device compliance.
- Follow established incident response procedures, including containment, escalation, and documentation, and coordinate with internal teams and external security providers.
- Support governance and security for AI use across the organization, including tools such as ChatGPT, workflow automations, and internally built applications, by identifying unapproved use and applying access, data protection, and logging controls.
- Assess AI-related risks such as prompt injection, data exposure, and excessive permissions, and help develop monitoring and response playbooks for AI-enabled systems.
- Contribute to client and third-party security reviews and audits by collecting evidence and tracking remediation.
- Educate IT staff and end users on security best practices, and communicate threats and incidents clearly to technology leadership.
- Evaluate emerging security tools and automation, such as PowerShell or Azure Logic Apps, and recommend improvements to detection and response.
Requirements
- Two or more years of hands-on experience in at least three areas of security, such as endpoint protection, network security and monitoring, identity and access management, firewalls, intrusion detection, vulnerability management, or operating system and database security.
- Working knowledge of formal cybersecurity frameworks and standards, including NIST 800-53, NIST 800-171, and CMMC, ideally within a federal contracting environment. Familiarity with ISO 27000 is also valued.
- Hands-on experience with Microsoft security technologies, including Defender XDR and at least two other tools such as Defender for Endpoint, Defender for Office 365, Entra ID, or Intune.
- Experience with Microsoft Sentinel or a comparable SIEM platform, including alert investigation and querying security data. Proficiency in KQL, or the ability to develop it, is required.
- Solid understanding of incident response practices, including alert triage, containment, evidence preservation, and cross-team coordination.
- Experience with, or strong interest in, AI governance and security, including awareness of risks such as shadow AI, prompt injection, and sensitive data disclosure.
- Ability to critically validate AI-generated findings against source data and established procedures before taking action.
- Cybersecurity certifications such as Security+, CySA+, SSCP, GIAC, SC-200, AZ-500, or SC-300, or extensive relevant coursework.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or an equivalent combination of education, training, and experience.
- Experience supporting external audits, assessments, or a federal contractor environment is a plus.
- Strong written and verbal communication skills, with the ability to explain technical concepts to varied audiences.
- Ability to manage multiple priorities, work collaboratively, and occasionally respond to after-hours incidents or maintenance.
Apply for this position
This job is hosted externally. Click below to view the full posting and apply.
Apply on www.vanderhouwen.com
Prepare application
- Draft this with your agent
- Open in Claude
- Open in ChatGPT
Good distractions
Loading talks and stories from around this role…