Managed Security Engineer II
Job Description
One Step Secure IT is hiring a Managed Security Engineer II onsite in Phoenix to design security controls, lead incident response, and support client risk management.
Responsibilities
- Design and implement security controls and security architectures aligned to client environments
- Embed cybersecurity best practices into development and deployment workflows
- Maintain security tools, processes, and policies based on industry standards, including NIST, CIS, ISO 27001, HIPAA, and PCI DSS
- Lead vulnerability assessments and penetration testing; manage end-to-end remediation efforts
- Oversee incident response, including stakeholder communication, compliance with Arizona breach notification laws, and post-incident reviews
- Develop, update, and publish security policies; deliver training for internal staff and clients
- Monitor security alerts and events using SIEM and related tools
- Investigate and report on potential vulnerabilities or suspected breaches
- Support patch management across client environments
- Prepare regular security reports for senior management and clients
- Assist with audits and regulatory compliance activities
- Collaborate with sales and account management to evaluate client security needs and design solutions
- Implement automation and advanced security tools (e.g., MFA, encryption) to scale security across multiple clients
- Mentor junior security engineers and oversee security-related projects
- Integrate and maintain security for network services and systems, including components using TCP/IP, HTTP, and DNS
Requirements
- 4+ years of experience in security engineering or a related role
- Bachelor’s degree in Computer Science, Information Security, or a related field, or equivalent experience
- Strong analytical and problem-solving skills
- Excellent communication skills, including the ability to explain security concepts to technical and non-technical audiences
- Strong collaboration and client-facing skills
- Familiarity with security frameworks: NIST, CIS, ISO 27001
- Cloud security knowledge: AWS, Azure
- Understanding of attack vectors and mitigation techniques (e.g., phishing, malware)
- Knowledge of compliance standards including HIPAA and PCI DSS
- Experience with automation in multi-client environments
Technologies
- NIST, CIS, ISO 27001, HIPAA, PCI DSS
- SIEM
- MFA, encryption
- AWS, Azure
- TCP/IP, HTTP, DNS
- Firewalls, IDS/IPS
- Windows, Linux, MacOS
- Arizona data breach notification laws: A.R.S. §§ 18-551, 18-552
Preferred Background
- Relevant certifications such as Security+, CEH, CASP, SSCP, CISSP, or CISM
- 4–6 years of cybersecurity experience, including at least 2 years as a Security Engineer
- Experience in an MSP or other multi-client environment
- Familiarity with Arizona data breach notification laws (A.R.S. §§ 18-551, 18-552)
- Experience with firewalls, IDS/IPS, and vulnerability management tools
- Knowledge of network protocols (TCP/IP, HTTP, DNS)
- Operating systems knowledge (Windows, Linux, MacOS)
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Vision insurance
Job Details
- Job type: Full-time
- Work location: In person
- Commute/Location: Phoenix, AZ 85027 (Required)