Cybersecurity Engineer
Job Description
HB Mechanical Group, LLC is hiring a dedicated Cybersecurity Engineer to own hands-on security operations and engineering across the enterprise. This is a role built for someone who can translate security strategy into working, managed controls, partnering with internal admins and external vendors to keep protections effective across multiple divisions.
Work model: hybrid Remote–On Site. Candidates within driving distance of the HB Mechanical Group office in Camp Hill, PA or the Tamarac, FL office are preferred. Strong candidates residing in the U.S. Eastern time zone will be considered. Hours may vary based on business needs, with occasional travel between HB Global offices and divisional worksites. On-call availability for security incidents and urgent requests is required.
Responsibilities
In this role, you will be the day-to-day owner of threat detection and response, detection tuning, and security control operations across the stack. Key duties include:
- Conduct day-to-day threat hunting, monitoring, and alert triage across the CrowdStrike Falcon platform (EDR, NG-SIEM, and Identity Threat Protection).
- Investigate, contain, and remediate security incidents end to end, including root-cause analysis and documenting findings and lessons learned.
- Tune detections, correlation rules, and alerting to reduce noise and improve fidelity.
- Monitor and respond to email-borne threats and user-reported phishing using Mimecast, including quarantine management and policy tuning.
- Implement, configure, and maintain security controls across Microsoft Azure and on-premises systems, coordinating with third-party architects when required.
- Administer identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace, enforcing least privilege, MFA, and conditional access.
- Own endpoint protection and DNS-layer security using Cisco Umbrella, and support network security policy on Cisco Meraki in partnership with the Senior Network Administrator.
- Own vulnerability management, including scanning, prioritization, and coordinating remediation within the IT team.
- Partner with the Senior Systems Administrator to validate and test backup integrity and participate in disaster-recovery testing for tools administered by that role (Druva, Veeam).
- Manage secrets and password platform 1Password and champion strong credential hygiene across the organization.
- Maintain security configuration standards and hardening baselines aligned to leadership strategy.
- Plan, track, and report on security initiatives using Zoho Projects.
- Manage day-to-day relationships with security vendors and managed-service providers and hold third parties accountable to deliverables.
- Own the Mimecast security-awareness program, including quarterly awareness trainings, quarterly phishing simulations, and progress/completion reporting.
- Produce clear, regular reporting on overall cybersecurity posture for leadership and executive audiences, translating technical detail into concise summaries.
- Pull and correlate data from the security stack (CrowdStrike, Mimecast, Cisco Umbrella and Meraki, identity, and vulnerability tools) into reports and dashboards.
- Define and track key security metrics and KPIs (detection and response times, vulnerability remediation, patch status, phishing-test results) and report trends over time.
- Provide on-demand snapshots of security state and communicate risks, priorities, and recommendations to non-technical stakeholders.
- Support multiple semi-autonomous divisions with consistent enterprise standards and governance while adapting to each division’s operational needs.
- As HB Global grows, onboard and standardize security controls for new business units to the HB Global baseline.
- Assess security posture of incoming environments and build plans to consolidate identity, endpoint, email, network, and backup protections.
- Support compliance, audit, and cyber-insurance requirements with clear evidence and documentation.
- Partner with leadership to turn security strategy into hands-on execution and flag emerging risks and priorities.
- Provide backup and cross-coverage for network security controls alongside the Senior Network Administrator.
- Perform other duties as assigned.
Requirements
- 5+ years of hands-on experience in cybersecurity engineering, security operations, or a blended security/IT role.
- Proven ability to build and operate security controls with minimal supervision as a security generalist.
- Hands-on experience with EDR/endpoint security and SIEM (CrowdStrike strongly preferred).
- Strong identity and access management experience (Entra ID / Active Directory, Okta, MFA, conditional access).
- Experience securing Microsoft 365 and cloud environments (Microsoft Azure).
- Practical incident-response and threat-hunting experience, including solid networking and firewall fundamentals.
- Experience working with outside security vendors/managed services and coordinating deliverables to timelines and quality expectations.
- Working knowledge of security frameworks and best practices (e.g., NIST Cybersecurity Framework, CIS Controls) and the ability to enforce data/access security policies.
- Scripting and automation ability (PowerShell and/or Python) for routine tasks and tool integrations.
- Strong analytical and problem-solving skills with clear communication to both technical and non-technical stakeholders.
- Ability to pull data from multiple security platforms and present security posture in clear reports and dashboards for executive audiences.
- Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security.
- Familiarity with email security, DNS security, and backup/disaster-recovery concepts.
- Familiarity with confidentiality requirements related to IT operations and network information.
Technologies
- CrowdStrike Falcon (EDR, NG-SIEM, Identity Threat Protection)
- Mimecast
- Microsoft Azure; Microsoft Entra ID; Active Directory; Microsoft 365; Google Workspace
- Okta; least privilege; MFA; conditional access
- Cisco Umbrella; Cisco Meraki
- Vulnerability management
- Druva; Veeam
- 1Password
- Zoho Projects
- PowerShell; Python
- NIST Cybersecurity Framework; CIS Controls
- CISSP; SSCP; CompTIA Security+; CompTIA CySA+; GIAC (GCIH, GCIA)
Education
- High School Diploma
- BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
- Relevant security certifications and continuing education preferred
Preferred Qualifications
- Industry certifications such as CISSP, SSCP, CompTIA Security+/CySA+, GIAC (GCIH, GCIA), or CrowdStrike / Microsoft Azure security certifications.
- Direct experience with the stack: CrowdStrike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, and 1Password.
- Experience standardizing security across multiple sites or business units within a growing, multi-entity organization.
- Experience integrating or supporting newly added business units.
- Experience in a multi-division or federated IT/security environment.
Benefits
- Full-time position with benefits
Physical Requirements
- Prolonged periods sitting at a desk and working on a computer
- Must be able to lift up to 15 pounds at times
- Ability to travel to divisions and worksites as needed