Cybersecurity Engineer II
Job Description
Orion Marine Group is hiring a mid-level Cybersecurity Engineer II to support the design, operation, automation, and ongoing improvement of the organization’s cybersecurity posture across on-premises, cloud, and hybrid environments. This onsite role in Houston, TX focuses on strengthening security monitoring and automated response, owning the security and integrity of SIEM/SOAR capabilities, and administering endpoint security across global locations and business units.
In this position, you will evaluate Orion’s cybersecurity architecture and help evolve a layered security approach spanning endpoints, network, identity, email, and cloud. You will also translate assessment results into prioritized remediation plans, tune detection logic to improve signal quality, and support compliance activities tied to CMMC and NIST SP 800-171.
Responsibilities
- Assess Orion’s cybersecurity architecture and overall posture, identify gaps, and recommend improvements aligned to security best practices and frameworks such as NIST, CIS Controls, and Zero Trust principles.
- Partner with IT leadership to design and evolve layered security across endpoint, network, identity, email, and cloud environments, using findings from penetration tests, vulnerability assessments, and audits.
- Convert penetration test and assessment findings into prioritized remediation plans and architectural changes, tracking progress through implementation to closure.
- Act as the primary engineer for enhancing, tuning, and automating Orion’s security platforms, including Darktrace and Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365).
- Develop and maintain automation, scripts, and workflows (for example, PowerShell, KQL, and Logic Apps/Sentinel automation or equivalents) to streamline detection, alert triage, response actions, and reporting.
- Continuously tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve signal quality across security platforms.
- Evaluate emerging security tools and capabilities and recommend improvements to the security tooling stack.
- Own security, access control, and configuration integrity of the SIEM and SOAR environment to ensure detection, correlation, and automated response are protected from unauthorized access, tampering, or misconfiguration.
- Administer role-based access, log source onboarding, and data retention within the SIEM to protect the confidentiality and integrity of security event data used for detection, investigation, and audit evidence.
- Build, test, and maintain SOAR playbooks and automated response actions, applying change control and peer review to reduce the risk of unintended automated actions in production.
- Monitor SIEM/SOAR health, log ingestion completeness, and playbook execution to help ensure detection and response coverage is not degraded.
- Own global endpoint security review, configuration, and administration across Orion locations, devices, and business units.
- Monitor endpoint security coverage, policy compliance, and protection status, identify gaps, and remediate onboarding, policy application, or protection posture issues.
- Manage endpoint security policies, attack surface reduction rules, device configuration baselines, and vulnerability management workflows tied to endpoint protection.
- Review and respond to endpoint-related security alerts and incidents, coordinating containment, remediation, and root-cause analysis.
- Monitor security alerts, logs, and telemetry from Darktrace, Microsoft Defender, the SIEM, and related platforms, investigating and responding to potential threats and incidents.
- Support incident response activities including detection, containment, eradication, and post-incident documentation and lessons learned.
- Perform vulnerability scanning and risk assessment, and coordinate remediation across infrastructure and endpoint environments.
- Support CMMC and NIST SP 800-171 compliance activities, including control implementation, evidence collection, audit support, and remediation of identified findings.
- Maintain security documentation such as architecture diagrams, standard operating procedures, playbooks, and control evidence to support auditability and consistent operations.
- Assist with security risk assessments, policy development, and control reviews in coordination with IT leadership.
- Cross-train and maintain working proficiency with core on-premises infrastructure platforms managed by the Infrastructure team, including VMware virtualization and Veeam backup and recovery.
- Provide backup coverage for infrastructure operations as needed, including virtualization, backup/recovery, storage, and related on-premises systems, to reduce single points of knowledge within the IT team.
- Partner with the Infrastructure team on projects and changes with security implications to ensure security requirements are incorporated into infrastructure design and operations.
- Maintain accurate technical documentation including security architecture diagrams, configuration standards, runbooks, and change records.
- Identify and communicate opportunities to improve security posture, tooling effectiveness, and operational efficiency, participating in continuous improvement initiatives.
- Coordinate with the Infrastructure team, Service Desk, Applications, vendors, and other stakeholders to resolve incidents, support projects, and ensure smooth handoffs.
- Respond to off-hour security alerts, calls, emails, or notifications as needed to maintain security monitoring coverage and operational uptime.
- Ensure incident response communications and handoffs are clear, timely, and documented.
- Support broader IT and security projects and perform other duties as assigned by IT leadership.
Requirements
- Demonstrated ability to deliver high-quality results with minimal supervision in a fast-paced environment.
- Strong communication, analytical, and problem-solving skills, including the ability to explain technical and security concepts to non-technical stakeholders.
- Proven ability to learn new technologies and threat landscapes quickly through research, self-directed learning, and hands-on experimentation.
- Strong documentation habits and attention to detail, including architecture diagrams, playbooks, and audit evidence.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or related field (or equivalent practical experience).
- Relevant certifications are preferred, such as CompTIA Security+/CySA+, Microsoft SC-200/SC-100, CEH, GIAC, or equivalent.
- 4–8 years of hands-on experience in cybersecurity engineering or security operations, including experience designing, tuning, or automating security tooling.
- Strong understanding of cybersecurity architecture principles and security frameworks, including alignment to NIST SP 800-171 and support for CMMC compliance readiness.
- Hands-on experience with Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365) and network detection and response platforms such as Darktrace, including tuning, automation, and reporting.
- Hands-on experience administering and securing a SIEM and SOAR environment, including access control, log source management, and building/maintaining automated response playbooks.
- Experience administering endpoint security at scale, including policy management, attack surface reduction, vulnerability management, and incident response.
- Working proficiency with scripting and automation such as PowerShell and KQL to build repeatable security workflows, detections, and reporting.
- Working knowledge of virtualization and backup platforms such as VMware and Veeam (or equivalent) sufficient to cross-train and provide backup support with the Infrastructure team.
- Proficiency with standard Microsoft productivity tools including Visio, Word, Excel, Outlook, and PowerPoint.
- Experience supporting security audits, e-discovery technical requests, and handling sensitive data with confidentiality is preferred.
Technologies
- Darktrace
- Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365)
- PowerShell, KQL, Logic Apps, Sentinel automation
- SIEM, SOAR
- VMware, Veeam
- NIST, CIS Controls, Zero Trust principles
- NIST SP 800-171, CMMC, CMMC compliance readiness
- EDR/XDR, NDR, Identity security, Email security
- Vulnerability management
- Security monitoring and alerting
Safety, Compliance, and Confidentiality
- Responsible and accountable for the incumbent’s safety, as well as the safety of co-workers and other individuals encountered.
- Authorized and obligated to stop work on any task whenever an unsafe condition or situation is anticipated or observed.
- Complies with applicable laws, regulations, and Company policies and procedures; failure to do so may result in disciplinary action, including dismissal.
- Reports violations of applicable laws, regulations, or Company policies and procedures promptly; failure to do so may result in disciplinary action, including dismissal.
- Maintains confidentiality and does not disclose confidential, proprietary, or trade secret information belonging to the Company.
Physical and Mental Requirements
- Able to perform essential job functions with or without reasonable workplace accommodation.
- Can wear and properly use appropriate personal protective equipment if required for job site activities.
- May include hard hat, safety glasses, respirators, ear plugs, steel-toed shoes, personal flotation devices, or other equipment as required.
- Can remain calm during emergencies and respond appropriately as directed by the Safety Representative or other management personnel.
- Capable of evacuating the work area promptly in the event of an emergency.