Cybersecurity Engineer
Job Description
HB Mechanical Group, LLC (HB Global) is seeking a hands-on Cybersecurity Engineer to serve as the day-to-day owner of cybersecurity operations and engineering across the enterprise. This role translates security strategy into managed controls, with direct involvement in monitoring, threat hunting, incident response, and the implementation and upkeep of security tooling across multiple divisions.
Based in Florida for a hybrid setup, this position blends operational security work with control standardization, reporting, and cross-division onboarding as HB Global grows.
Key Responsibilities
- Conduct day-to-day threat hunting, monitoring, and alert triage using the CrowdStrike Falcon platform, including EDR, NG-SIEM, and Identity Threat Protection.
- Investigate, contain, and remediate incidents end to end, completing root-cause analysis and documenting findings and lessons learned.
- Tune detections, correlation rules, and alerting to reduce noise and improve alert fidelity.
- Monitor and respond to email-borne threats and user-reported phishing through Mimecast, including quarantine management and policy tuning.
- Implement, configure, and maintain security controls across Microsoft Azure and on-premises systems, coordinating with third-party architects when solution design requires it.
- Administer identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace, enforcing least privilege, MFA, and conditional access.
- Manage endpoint protection and DNS-layer security with Cisco Umbrella, and support Cisco Meraki network security policy in partnership with the Senior Network Administrator.
- Own vulnerability management, including scanning, prioritization, and coordination of remediation within the IT team.
- Partner with the Senior Systems Administrator for data protection and recovery tools (Druva, Veeam) to validate backup integrity and participate in disaster-recovery testing.
- Manage secrets and credential platforms with 1Password, promoting strong credential hygiene across the organization.
- Maintain security configuration standards and hardening baselines aligned to leadership strategy.
- Plan, track, and report on security initiatives using Zoho Projects.
- Manage day-to-day relationships with security vendors and managed-service providers, holding third parties accountable to commitments.
- Own the Mimecast security-awareness program, including quarterly training scheduling and management and quarterly phishing simulations, with progress and completion reporting.
- Produce clear reporting on overall cybersecurity posture, translating technical detail into concise summaries for leadership and executive audiences.
- Pull and correlate data from the security stack (including CrowdStrike, Mimecast, Cisco Umbrella and Meraki, identity, and vulnerability tools) into reports and dashboards.
- Define and track security metrics and KPIs such as detection and response times, vulnerability remediation, patch status, and phishing-test results, reporting trends over time.
- Provide on-demand snapshots of security state and communicate risks, priorities, and recommendations clearly to non-technical stakeholders.
- Work with multiple semi-autonomous divisions to deliver consistent security protections while adapting engagement and communication to division operational needs and maintaining enterprise standards.
- As HB Global grows, onboard and standardize security controls for new business units into the HB Global baseline.
- Assess security posture of incoming environments and build practical plans to consolidate identity, endpoint, email, network, and backup protections.
- Support compliance, audit, and cyber-insurance requirements with clear evidence and documentation.
- Partner with leadership to convert security strategy into hands-on execution and flag emerging risks and priorities.
- Coordinate closely with the Senior Network Administrator to validate network security controls and provide backup and cross-coverage for the network security function.
- Perform other duties as assigned.
Required Qualifications
- 5+ years of hands-on experience in cybersecurity engineering, security operations, or a blended security/IT role.
- Proven ability to both build and operate security controls with minimal supervision as a security generalist.
- Hands-on experience with EDR/endpoint security and SIEM (with CrowdStrike strongly preferred).
- Strong identity and access management experience across Entra ID / Active Directory, Okta, MFA, and conditional access.
- Experience securing Microsoft 365 and cloud environments (including Microsoft Azure).
- Practical incident response and threat hunting, with solid networking and firewall fundamentals.
- Experience working with outside security vendors and managed services, coordinating deliverables for timelines and quality.
- Working knowledge of security frameworks and best practices (including NIST Cybersecurity Framework and CIS Controls) and the ability to enforce data and access security policies.
- Scripting and automation ability using PowerShell and/or Python.
- Strong analytical and problem-solving skills, including clear communication to technical and non-technical stakeholders.
- Ability to pull data from multiple security platforms and present cybersecurity posture in clear reports and dashboards for executive audiences.
- Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security.
- Familiarity with email security, DNS security, and backup/disaster-recovery concepts.
- Familiarity with confidentiality requirements related to IT operations and network information.
Technology Experience
- CrowdStrike Falcon (EDR, NG-SIEM, Identity Threat Protection)
- Mimecast
- Microsoft Azure
- Microsoft Entra ID, Active Directory, Microsoft 365, Okta
- Google Workspace
- Cisco Umbrella, Cisco Meraki
- Druva, Veeam
- 1Password
- Zoho Projects
- PowerShell, Python
- NIST Cybersecurity Framework, CIS Controls
- Security frameworks/certifications mentioned: CISSP, SSCP, CompTIA Security+, CompTIA CySA+, GIAC (GCIH, GCIA)
Education
- BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
- High School Diploma
Benefits
- Full-time position with benefits
Work Schedule & Travel
- Full-time position with benefits
- Hybrid Remote–On Site: prefer candidates within driving distance of the HB Mechanical Group office in Camp Hill, PA or the Tamarac, FL office, and consider strong candidates residing anywhere in the U.S. Eastern time zone
- Hours may vary according to business needs
- Occasional travel between HB Global offices and divisional worksites may be required
- On-call availability for security incidents and urgent requests is required
Preferred Qualifications
- Industry certifications such as CISSP, SSCP, CompTIA Security+/CySA+, GIAC (GCIH, GCIA), or CrowdStrike / Microsoft Azure security certifications
- Direct experience with the stack: CrowdStrike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, 1Password
- Experience standardizing security across multiple sites or business units within a growing, multi-entity organization
- Experience integrating or supporting newly added business units
- Experience in a multi-division or federated IT/security environment
Physical Requirements
- Prolonged periods sitting at a desk and working on a computer
- Must be able to lift up to 15 pounds at times
- Ability to travel to divisions and worksites as needed