Unknown Company

Cyber Security Engineer

new york, ny • Posted 3 days ago
Remote Full Time IT & Technology

Location: NYC hybrid schedule (3 days on-site), Will consider remote candidates

Full-Time role for an Investment Management firm

About the Role

Security Engineer to help build, enforce, and mature security controls across our clients endpoint, identity, and cloud environments. This is a hands-on engineering role for someone with genuine security depth who understands not just how to configure a platform, but why a control matters, how an attacker would attempt to bypass it, and how to validate that security controls are working effectively.

This position is for someone with a dedicated, hands-on security engineering background within an enterprise environment and has developed deep technical expertise in a corporate environment rather than supporting a large number of client environments.

Exciting initiatives:

Take ownership of reviewing, maintaining, and enhancing existing Conditional Access policies.

Develop and execute a prioritized vulnerability remediation plan in partnership with infrastructure teams.

Responsibilities

  • Design, implement, and maintain endpoint security controls by hardening Microsoft Defender for Endpoint, configuring attack surface reduction (ASR) rules, implementing CIS-aligned security baselines, and managing configuration drift.
  • Implement least-privilege strategies by eliminating standing local administrator access through Microsoft LAPS and endpoint privilege management solutions while maintaining user productivity.
  • Define and manage device compliance policies within Microsoft Intune and integrate compliance requirements with Conditional Access to ensure only trusted devices can access corporate resources
  • Design, test, deploy, and maintain Microsoft Entra Conditional Access policies, including report-only deployments, policy optimization, exception management, and ongoing governance
  • Support the rollout and expansion of phishing-resistant authentication methods such as FIDO2 security keys, Windows Hello for Business, and certificate-based authentication while helping migrate users away from legacy MFA methods
  • Strengthen Microsoft Entra ID security by improving authentication methods, identity protection, and access controls
  • Improve Azure security posture through Microsoft Defender for Cloud and Secure Score by identifying and remediating security misconfigurations
  • Develop and enforce secure configuration standards across Azure and Microsoft cloud services
  • Configure and optimize Microsoft Defender for Office 365 security controls, including anti-phishing, Safe Links, Safe Attachments, impersonation protection, and email threat prevention
  • Support security incident response activities by assisting with triage, containment, remediation, access revocation, and corrective actions while working closely with an external managed detection and response (MDR) provider
  • Partner with infrastructure and application teams to prioritize and remediate security vulnerabilities while validating that remediation efforts effectively reduce organizational risk
  • Participate in security projects from planning through implementation and validation while contributing to the development of security standards, documentation, hardened baselines, and repeatable operational processes

Qualifications

  • 4+ years of hands-on experience in a dedicated information security role
  • Strong understanding of security fundamentals including Zero Trust, defense-in-depth, least privilege, identity security, and common attacker techniques
  • Hands-on experience with Microsoft security technologies including Microsoft Intune, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud, Microsoft Entra ID, and Conditional Access
  • Familiarity with CIS Benchmarks, the MITRE ATT&CK Framework, and detection engineering concepts
  • Strong analytical, troubleshooting, and problem-solving skills with the ability to quickly learn new technologies
  • Experience supporting security initiatives and/or participating in technical security projects
  • Experience working with managed detection and response (MDR) or security operations center (SOC) providers
  • At least one Security certification such as; Security+, CISSP, SC-200, SC-300, AZ-500, or other security certifications are preferred but not required

#J-18808-Ljbffr
Back to Job Search