Cybersecurity Engineer
Job Description
This onsite role in Pittsburgh, PA focuses on defending enterprise infrastructure, leading incident response, and maintaining Microsoft 365 security with cross environment regulatory compliance.
Responsibilities
- Secure enterprise infrastructure, respond to cyber threats, administer Microsoft 365 security, and help ensure regulatory compliance across cloud and on‑prem environments.
- Implement and maintain enterprise security controls across cloud and on‑premises environments.
- Manage security compliance programs and assist in security policy creation.
- Monitor and respond to security alerts, incidents, phishing attempts, malware, and suspicious activity.
- Perform vulnerability assessments, remediation tracking, and security hardening activities.
- Administer endpoint protection systems, email security, MFA, Conditional Access, and identity security controls.
- Configure and maintain SIEM, logging, and monitoring platforms to detect and respond to threats.
- Conduct threat hunting and proactive security reviews to identify gaps.
- Microsoft 365 and cloud security: manage tools including Microsoft Defender, Entra ID (Azure AD), Conditional Access, Intune, Purview, and Exchange Online Protection.
- Implement data loss prevention, retention policies, and email security controls.
- Secure remote access, mobile devices, and hybrid cloud infrastructure for a robust security posture.
- Harden network security across firewalls, VPNs, wireless networks, switches, and servers; regularly review firewall rules and network segmentation.
- Support backup, disaster recovery, and business continuity initiatives.
- Assist with patch management and establish secure configuration baselines.
- Provide escalation support for security related help desk issues and lead response efforts during incidents and outages.
- Conduct user security awareness training and phishing simulations to improve organizational readiness.
Requirements
- Must‑have domain experience: HUD or similar public housing programs, civilian US federal agencies outside defense/intelligence, or highly regulated industries such as insurance, banking, or healthcare.
- Experience implementing security controls from scratch, with hands‑on ability to determine what to implement and how to execute it effectively.
- 5+ years of hands‑on IT security / cybersecurity engineering experience.
- Strong experience with Microsoft 365 security technologies specifically.
- Experience with firewalls and VPN technologies.
- Proficiency with Endpoint Detection & Response (EDR).
- Experience with email security platforms.
- Familiarity with vulnerability management tools.
- Knowledge of Windows Server and Hybrid Active Directory.
- Understanding of cybersecurity frameworks and relevant compliance standards.
Technologies
- Microsoft Defender
- Entra ID (Azure AD)
- Conditional Access
- Intune
- Purview
- Exchange Online Protection
- SIEM
- Data Loss Prevention (DLP)
- Windows Server
- Hybrid Active Directory
- Firewalls
- VPN technologies
- Endpoint Detection & Response (EDR)
- Email security platforms
- Vulnerability management tools
- Microsoft 365 security tools
Benefits
- Full benefits