Cybersecurity Engineer
Job Description
Environmental Science Associates is strengthening and evolving its cybersecurity program with a Microsoft security stack, combining real-world threat detection with Zero Trust practices and AI-aware security. This hybrid role in Bend, OR (with onsite days in Portland, OR and/or Seattle, WA) focuses on protecting systems and data while helping the organization maintain NIST-based controls in a federal contracting environment.
What you’ll do
- Evaluate, configure, and continuously improve security across endpoints, servers, cloud services, identities, and networks.
- Work extensively in ESA’s Microsoft security ecosystem, including Microsoft Sentinel, Defender XDR, Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud, Entra ID, and Intune.
- Monitor and investigate suspicious activity using Sentinel and Defender XDR, performing alert triage, log analysis, and threat hunting.
- Use Kusto Query Language (KQL) and Advanced Hunting to investigate security telemetry, tune detections for improved signal quality, and partner with ESA’s Security Operations Center on escalated incidents.
- Strengthen identity and device security using Conditional Access, multi-factor authentication, least-privilege access, device compliance, and identity monitoring aligned with NIST and CISA Zero Trust principles.
- Develop, test, and execute security incident response procedures and playbooks, supporting investigation, containment, evidence preservation, escalation, endpoint isolation, and disabling compromised accounts as needed.
- Support secure adoption of AI systems, agents, models, MCP servers, connectors, and related technologies, focusing on emerging AI cybersecurity risks such as shadow AI, prompt injection, and sensitive-data disclosure.
- Develop monitoring and incident-response approaches for AI-enabled systems and use AI-assisted security tools, including Microsoft Security Copilot, while validating AI-generated findings against authoritative source data and security telemetry.
- Maintain ESA’s NIST-based cybersecurity program for environments involving FCI and CUI.
- Support control mapping and assessment activities, including NIST SP 800-53 and NIST SP 800-171 mapping, System Security Plans, POA&Ms, evidence collection and remediation tracking, CUI scoping, CMMC readiness, and SPRS assessment activities.
- Evaluate emerging tools and automation opportunities that improve detection and response, and translate complex security topics into practical guidance for internal education and awareness.
Requirements
- 3–5 years of progressively responsible cybersecurity experience, including hands-on security operations or security engineering.
- Experience across areas such as endpoint security, identity and access management, cloud security, network security and monitoring, vulnerability management, SIEM/log analysis, incident response, secure configuration, or security automation.
- Hands-on experience with Microsoft Defender XDR and at least two Microsoft security technologies such as Defender for Endpoint, Defender for Office 365, Defender for Identity, Defender for Cloud Apps, Defender for Cloud, Entra ID, or Microsoft Intune.
- Experience with Microsoft Sentinel (or comparable SIEM), including alert investigation, telemetry review, and support for analytics and detection rules.
- Ability to use Kusto Query Language (KQL) or quickly develop proficiency.
- Working knowledge of NIST SP 800-53, NIST SP 800-171, and CMMC within a federal contracting environment, including CUI scoping, System Security Plans, POA&Ms, and evidence collection.
- Working knowledge of security incident response, including alert triage, containment, escalation, evidence preservation, documentation, and coordination with internal and external teams.
- Awareness of emerging AI cybersecurity risks, plus the judgment to validate AI-generated findings against source telemetry, authoritative guidance, and established security procedures.
- Ability to manage competing priorities and respond appropriately to occasional after-hours security incidents, audits, or maintenance activities.
- Bachelor’s degree in Cybersecurity, Computer Science, Information Systems, or equivalent education, professional training, certifications, and relevant experience.
Hybrid work location
This is a hybrid role with onsite work a few days per week in either ESA’s Portland, OR and/or Seattle, WA offices.
Preferred qualifications
- Cybersecurity certifications such as CompTIA Security+, CySA+, SSCP, GIAC, or comparable credentials.
- Microsoft certifications such as SC-200, AZ-500, or SC-300.
- Experience supporting federal contracting or organizations subject to CMMC, FAR, DFARS, NIST SP 800-171, or related federal cybersecurity requirements.
- Experience supporting CMMC or NIST assessment activities, penetration tests, tabletop exercises, external assessments, or third-party audits.
- Experience with CUI asset inventories, data-flow documentation, security-control assessments, SPRS submissions, assessment evidence, or federal cyber-incident reporting.
- Hands-on experience with Entra Conditional Access, MFA, Privileged Identity Management, device-compliance policies, DLP, or Microsoft Purview sensitivity labels.
- Experience with vulnerability management and security automation using technologies such as Microsoft Defender Vulnerability Management, PowerShell, or Azure Logic Apps.
- Familiarity with the NIST AI Risk Management Framework, NIST Generative AI Profile, or OWASP guidance for generative AI and LLM applications.
- Familiarity with secure software-development practices including threat modeling, secrets management, dependency and code scanning, API security, and CI/CD security.
Compensation
USD 110,000 - 135,000 per year.
Application notes
Unsolicited resumes: ESA does NOT accept unsolicited resumes from agencies.
Reasonable accommodation: If you need a reasonable accommodation to complete any part of the application process, or cannot use the online application system, contact Human Resources at [email protected].