Security Engineer

Vanderhouwen & Associates, Inc.
Portland, OR, United States
2 days ago
Apply on www.vanderhouwen.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Experienced
Experience required
2 years minimum
Working hours
Regular working hours

Tech stack

Microsoft Access Artificial Intelligence Microsoft Azure CompTIA Security+ Cyber Security Information Systems Database Security Multi-Factor Authentication Identity and Access Management Networking Hardware Intrusion Detection and Prevention Network Security
+17 more
Log Analysis Microsoft Security Essentials Microsoft Office Windows PowerShell Cloud Services Kusto Query Language Zero Trust Network Access Security Information and Event Management Software Vulnerability Management EndPointSecurity Data Logging Firewalls (Computer Science) Microsoft InTune Information Technology Cybercrime Microsoft Sentinel GPT

Job description

  • Support security policies, procedures, and technical documentation aligned to NIST 800-53 and NIST 800-171 standards.
  • Help prepare for CMMC compliance by maintaining the System Security Plan and POA&M, scoping environments that handle CUI, gathering assessment evidence, and tracking remediation through completion.
  • Monitor, triage, and investigate security alerts using Microsoft Sentinel and Defender XDR, performing log analysis and threat hunting with KQL.
  • Configure, tune, and evaluate security tools across servers, endpoints, cloud services, and network devices, with a focus on the Microsoft security stack, including Entra ID and Intune.
  • Advance Zero Trust initiatives by strengthening identity and device controls, including Conditional Access, multi-factor authentication, least-privilege access, and device compliance.
  • Follow established incident response procedures, including containment, escalation, and documentation, and coordinate with internal teams and external security providers.
  • Support governance and security for AI use across the organization, including tools such as ChatGPT, workflow automations, and internally built applications, by identifying unapproved use and applying access, data protection, and logging controls.
  • Assess AI-related risks such as prompt injection, data exposure, and excessive permissions, and help develop monitoring and response playbooks for AI-enabled systems.
  • Contribute to client and third-party security reviews and audits by collecting evidence and tracking remediation.
  • Educate IT staff and end users on security best practices, and communicate threats and incidents clearly to technology leadership.
  • Evaluate emerging security tools and automation, such as PowerShell or Azure Logic Apps, and recommend improvements to detection and response.

Requirements

  • Two or more years of hands-on experience in at least three areas of security, such as endpoint protection, network security and monitoring, identity and access management, firewalls, intrusion detection, vulnerability management, or operating system and database security.
  • Working knowledge of formal cybersecurity frameworks and standards, including NIST 800-53, NIST 800-171, and CMMC, ideally within a federal contracting environment. Familiarity with ISO 27000 is also valued.
  • Hands-on experience with Microsoft security technologies, including Defender XDR and at least two other tools such as Defender for Endpoint, Defender for Office 365, Entra ID, or Intune.
  • Experience with Microsoft Sentinel or a comparable SIEM platform, including alert investigation and querying security data. Proficiency in KQL, or the ability to develop it, is required.
  • Solid understanding of incident response practices, including alert triage, containment, evidence preservation, and cross-team coordination.
  • Experience with, or strong interest in, AI governance and security, including awareness of risks such as shadow AI, prompt injection, and sensitive data disclosure.
  • Ability to critically validate AI-generated findings against source data and established procedures before taking action.
  • Cybersecurity certifications such as Security+, CySA+, SSCP, GIAC, SC-200, AZ-500, or SC-300, or extensive relevant coursework.
  • Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or an equivalent combination of education, training, and experience.
  • Experience supporting external audits, assessments, or a federal contractor environment is a plus.
  • Strong written and verbal communication skills, with the ability to explain technical concepts to varied audiences.
  • Ability to manage multiple priorities, work collaboratively, and occasionally respond to after-hours incidents or maintenance.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.vanderhouwen.com
Prepare application

Good distractions

Loading talks and stories from around this role…