> Markdown version of [/jobs/ext/3658074-security-engineer](https://www.wearedevelopers.com/jobs/ext/3658074-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Vanderhouwen & Associates, Inc. - **Location:** Portland, OR, United States - **Experience:** Experienced - **Contract:** Permanent contract - **Skills:** Microsoft Access, Artificial Intelligence, Microsoft Azure, CompTIA Security+, Cyber Security, Information Systems, Database Security, Multi-Factor Authentication, Identity and Access Management, Networking Hardware, Intrusion Detection and Prevention, Network Security, Log Analysis, Microsoft Security Essentials, Microsoft Office, Windows PowerShell, Cloud Services, Kusto Query Language, Zero Trust Network Access, Security Information and Event Management, Software Vulnerability Management, EndPointSecurity, Data Logging, Firewalls (Computer Science), Microsoft InTune, Information Technology, Cybercrime, Microsoft Sentinel, GPT - **Published:** October 9, 2026 - **Apply:** https://www.vanderhouwen.com/job_posting/security-engineer-73438/ ## About the Role * Two or more years of hands-on experience in at least three areas of security, such as endpoint protection, network security and monitoring, identity and access management, firewalls, intrusion detection, vulnerability management, or operating system and database security. * Working knowledge of formal cybersecurity frameworks and standards, including NIST 800-53, NIST 800-171, and CMMC, ideally within a federal contracting environment. Familiarity with ISO 27000 is also valued. * Hands-on experience with Microsoft security technologies, including Defender XDR and at least two other tools such as Defender for Endpoint, Defender for Office 365, Entra ID, or Intune. * Experience with Microsoft Sentinel or a comparable SIEM platform, including alert investigation and querying security data. Proficiency in KQL, or the ability to develop it, is required. * Solid understanding of incident response practices, including alert triage, containment, evidence preservation, and cross-team coordination. * Experience with, or strong interest in, AI governance and security, including awareness of risks such as shadow AI, prompt injection, and sensitive data disclosure. * Ability to critically validate AI-generated findings against source data and established procedures before taking action. * Cybersecurity certifications such as Security+, CySA+, SSCP, GIAC, SC-200, AZ-500, or SC-300, or extensive relevant coursework. * Bachelor's degree in Cybersecurity, Computer Science, Information Systems, or an equivalent combination of education, training, and experience. * Experience supporting external audits, assessments, or a federal contractor environment is a plus. * Strong written and verbal communication skills, with the ability to explain technical concepts to varied audiences. * Ability to manage multiple priorities, work collaboratively, and occasionally respond to after-hours incidents or maintenance. ## Description * Support security policies, procedures, and technical documentation aligned to NIST 800-53 and NIST 800-171 standards. * Help prepare for CMMC compliance by maintaining the System Security Plan and POA&M, scoping environments that handle CUI, gathering assessment evidence, and tracking remediation through completion. * Monitor, triage, and investigate security alerts using Microsoft Sentinel and Defender XDR, performing log analysis and threat hunting with KQL. * Configure, tune, and evaluate security tools across servers, endpoints, cloud services, and network devices, with a focus on the Microsoft security stack, including Entra ID and Intune. * Advance Zero Trust initiatives by strengthening identity and device controls, including Conditional Access, multi-factor authentication, least-privilege access, and device compliance. * Follow established incident response procedures, including containment, escalation, and documentation, and coordinate with internal teams and external security providers. * Support governance and security for AI use across the organization, including tools such as ChatGPT, workflow automations, and internally built applications, by identifying unapproved use and applying access, data protection, and logging controls. * Assess AI-related risks such as prompt injection, data exposure, and excessive permissions, and help develop monitoring and response playbooks for AI-enabled systems. * Contribute to client and third-party security reviews and audits by collecting evidence and tracking remediation. * Educate IT staff and end users on security best practices, and communicate threats and incidents clearly to technology leadership. * Evaluate emerging security tools and automation, such as PowerShell or Azure Logic Apps, and recommend improvements to detection and response.