We are seeking a Cybersecurity Engineer with 3-5 years of hands-on experience to join our growing cybersecurity team. In this role, you will be responsible for the day-to-day engineering, administration, and optimization of our security tools and infrastructure. You will work closely with the Cybersecurity Manager and the broader IT team to implement, monitor, and improve the security controls that protect our Microsoft Azure / M365 cloud environment, endpoints, and data. This is a hands-on technical role with meaningful exposure to compliance frameworks, incident response, and vendor management - making it an excellent opportunity for someone who wants to grow their career across the full breadth of cybersecurity in a regulated financial services environment. Primary Responsibilities: Security Engineering & Operations Deploy, configure, tune, and maintain enterprise security tools including EDR, SIEM, email security, DNS filtering, and endpoint management platforms. Monitor security alerts and events across the environment, performing triage, investigation, and escalation of potential incidents. Manage and optimize detection rules, alerting thresholds, and automated response workflows within SIEM and EDR platforms. Support the administration and enforcement of Conditional Access Policies, application control policies (AppLocker), and identity and access management configurations within Microsoft Entra ID (Azure AD). Assist with the deployment and management of mobile device management (MDM/MAM) policies through Microsoft Intune. Conduct vulnerability assessments and coordinate remediation efforts with IT infrastructure and application teams. Develop and maintain PowerShell or Python scripts to automate routine security tasks, reporting, and data collection. Vulnerability Management Manage the end-to-end vulnerability management lifecycle - scanning, prioritization, remediation tracking, and validation across servers, endpoints, and cloud resources. Coordinate and execute OS and third-party application patching across the environment, ensuring timely remediation of critical and high-severity vulnerabilities in alignment with established SLAs and maintenance windows. Triage vulnerability scan results and prioritize remediation based on exploitability, asset criticality, and environmental context - not just raw CVSS scores - while developing compensating controls and risk acceptance documentation for vulnerabilities that cannot be immediately patched. Monitor threat intelligence feeds and vendor advisories (Microsoft Patch Tuesday, CISA KEV catalog, vendor-specific bulletins) and track patching compliance metrics to support both proactive risk reduction and SOC 2 audit evidence requirements. Incident Response Participate in incident detection, investigation, containment, and remediation activities. Perform log analysis and forensic investigation across endpoint, network, identity, and cloud environments. Document incidents thoroughly, including root cause analysis, timeline reconstruction, and lessons learned. Coordinate with the managed SOC provider on alert escalation, tuning requests, and incident handoff procedures. Contribute to the development and testing of incident response playbooks and procedures. Compliance & Governance Support the ongoing maintenance of SOC 2 Type 2 compliance, including evidence collection, control testing, and audit coordination through our compliance automation platform (Drata) Assist with the development, review, and enforcement of cybersecurity policies, standards, and procedures. Contribute to vendor security assessments and due diligence reviews as part of our vendor risk management program. Support Business Continuity Plan (BCP) documentation, tabletop exercises, and testing activities. Help prepare materials and reporting for the Cyber Risk Steering Committee (CRSC) and other governance bodies. Security Awareness & Collaboration Support the development and delivery of security awareness training and phishing simulation campaigns. Serve as a knowledgeable security resource for IT colleagues and the broader organization, translating technical concepts into clear, actionable guidance Collaborate with cross-functional teams including IT infrastructure, compliance, and risk management to integrate security into business processes.
Stand Out From the Crowd
Upload your resume and get instant feedback on how well it matches this job.
Job Type
Full-time
Career Level
Mid Level
Number of Employees
501-1,000 employees