O
Cybersecurity Engineer II
Cloud Platforms
Cybersecurity Tools
Endpoint Security
Engineer
Identity and Access Management
Incident Response
Information Security
InfoSec
Microsoft Defender
Security Automation
Security Compliance
Security Information And Event Management
Security Monitoring
Security Operations
Security Standards
Security Testing
SOAR
Solution Architecture
Job Description
The IT Cybersecurity Engineer II position provides mid-level engineering support for the architecture, operation, automation, and continuous improvement of Orion Marine Group’s cybersecurity posture across on-premises, cloud, and hybrid environments.
Onsite Location
Houston, TX (onsite)
Key Responsibilities
- Assess Orion’s cybersecurity architecture and overall posture, identify gaps, and recommend improvements using security best practices and industry-aligned frameworks, including examples such as NIST, CIS Controls, and Zero Trust principles.
- Collaborate with IT leadership to design, evolve, and maintain layered security architecture across endpoint, network, identity, email, and cloud environments based on penetration testing, vulnerability assessments, and audit results.
- Convert penetration test and assessment findings into prioritized remediation plans and architectural changes, tracking progress through implementation and closure.
- Serve as the primary engineer for enhancement, tuning, and automation of core security platforms, including Darktrace and Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365).
- Create and maintain automation, scripts, and workflows (including examples such as PowerShell, KQL, and Logic Apps/Sentinel automation or equivalent) to streamline detection, alert triage, response actions, and reporting.
- Tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve security signal quality across platforms.
- Evaluate emerging security tools and capabilities and recommend enhancements or additions to the security tooling stack.
- Own security, access control, and configuration integrity of Orion’s SIEM and SOAR environment, ensuring detection, correlation, and automated response capabilities are hardened against unauthorized access, tampering, or misconfiguration.
- Administer role-based access, log source onboarding, and data retention in the SIEM to protect confidentiality and integrity of security event data used for detection, investigations, and audit evidence.
- Build, test, and maintain SOAR playbooks and automated response actions, applying change control and peer review to prevent unintended or unauthorized actions in production.
- Monitor SIEM/SOAR health, log ingestion completeness, and playbook execution to confirm detection and response coverage does not degrade silently.
- Own global endpoint security review, configuration, and administration across Orion locations, devices, and business units.
- Monitor endpoint security coverage, policy compliance, and protection status; identify and remediate gaps in onboarding, policy application, or protection posture.
- Manage endpoint security policies, attack surface reduction rules, device configuration baselines, and vulnerability management workflows tied to endpoint protection.
- Review and respond to endpoint-related alerts and incidents, coordinating containment, remediation, and root-cause analysis.
- Monitor security alerts, logs, and telemetry from Darktrace, Microsoft Defender, the SIEM, and related platforms; investigate potential threats and security incidents.
- Support incident response activities, including detection, containment, eradication, and post-incident documentation and lessons learned.
- Perform vulnerability scanning and risk assessment, coordinating remediation across infrastructure and endpoint environments.
- Support CMMC and NIST SP 800-171 compliance activities, including control implementation, evidence collection, audit support, and remediation of identified findings.
- Maintain security documentation (architecture diagrams, standard operating procedures, playbooks, and control evidence) to support auditability and operational consistency.
- Assist with security risk assessments, policy development, and control reviews in coordination with IT leadership.
- Cross-train and maintain proficiency with core on-premises infrastructure platforms managed by the Infrastructure team, including VMware virtualization and Veeam backup and recovery.
- Provide backup coverage for infrastructure operations as needed, including virtualization, backup/recovery, storage, and other on-premises systems, to reduce single points of knowledge within the IT team.
- Partner with the Infrastructure team on projects and changes with security implications to ensure security requirements are incorporated into infrastructure design and operations.
- Maintain accurate technical documentation, including security architecture diagrams, configuration standards, runbooks, and change records.
- Identify and communicate opportunities to improve security posture, tooling effectiveness, and operational efficiency, and participate in continuous improvement initiatives.
- Coordinate with the Infrastructure team, Service Desk, Applications, vendors, and other stakeholders to resolve incidents, support projects, and ensure smooth handoffs.
- Respond to off-hour security alerts, calls, emails, or notifications as needed to maintain security monitoring coverage and operational uptime.
- Ensure incident response communications and handoffs are clear, timely, and documented.
- Support broader IT and security projects and perform other related administrative and technical duties as assigned by IT leadership.
Requirements
- Demonstrated ability to deliver high-quality results with minimal supervision in a fast-paced environment.
- Strong communication, analytical, and problem-solving skills, including the ability to explain technical and security concepts to non-technical stakeholders.
- Proven ability to learn new technologies and threat landscapes quickly using research, self-directed learning, and hands-on experimentation.
- Strong documentation habits and attention to detail, including architecture diagrams, playbooks, and audit evidence.
- Bachelor’s degree in Computer Science, Information Technology, Cybersecurity, or a related field (or equivalent practical experience).
- Relevant certifications are preferred (examples: CompTIA Security+/CySA+, Microsoft SC-200/SC-100, CEH, GIAC, or equivalent).
- 4–8 years of hands-on experience in cybersecurity engineering or security operations, with experience designing, tuning, or automating security tooling.
- Strong understanding of cybersecurity architecture principles and security frameworks, with experience aligning to NIST SP 800-171 and supporting CMMC compliance readiness activities.
- Hands-on experience with Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365) and network detection and response platforms such as Darktrace, including tuning, automation, and reporting.
- Hands-on experience administering and securing a SIEM and SOAR environment, including access control, log source management, and building or maintaining automated response playbooks.
- Experience administering endpoint security at scale, including policy management, attack surface reduction, vulnerability management, and incident response.
- Working proficiency with scripting and automation (for example, PowerShell, KQL) to build repeatable security workflows, detections, and reporting.
- Working knowledge of virtualization and backup platforms (VMware and Veeam or equivalent) sufficient to cross-train and provide backup support with the Infrastructure team.
- Proficient with standard Microsoft productivity tools (Visio, Word, Excel, Outlook, PowerPoint) for documentation, diagrams, reporting, and communication.
- Experience supporting security audits, e-discovery technical requests, and handling sensitive data with confidentiality, documented procedures, and access controls is preferred.
Technologies and Frameworks
- Darktrace; Microsoft Defender; Defender for Endpoint; Defender for Identity; Defender for Cloud Apps; Defender for Office 365
- PowerShell; KQL; Logic Apps; Sentinel automation; SIEM; SOAR
- VMware; Veeam
- NIST; CIS Controls; Zero Trust principles; NIST SP 800-171
- CMMC; CMMC compliance readiness
- EDR/XDR; NDR; Identity security; Email security; Vulnerability management
- Security monitoring and alerting
Safety and Compliance
- Responsible and accountable for the incumbent’s safety.
- Responsible and accountable for the safety of co-workers and any other individuals encountered on the job.
- Authorized and obligated to stop work when an unsafe condition or situation is anticipated or observed.
- Complies with applicable laws, regulations, and Company policies and procedures, and is subject to disciplinary action (including dismissal) for failure to do so.
- Reports violations of applicable laws, regulations, and Company policies and procedures promptly, and is subject to disciplinary action (including dismissal) for failure to do so.
- Maintains confidentiality and does not disclose confidential, proprietary, or trade secret information belonging to the Company.
Physical and Mental Requirements
- Must be able to perform essential functions with or without reasonable workplace accommodation.
- Must be able to wear and properly use personal protective equipment if required to work or visit the job site (examples may include hard hat, safety glasses, respirators, ear plugs, steel-toed shoes, personal flotation devices, or other equipment as required).
- Must be able to remain calm during emergencies and respond appropriately as directed by the Safety Representative or other management personnel.
- Must be able to evacuate the work area promptly in the event of an emergency.