Managed Security Engineer II
Job Description
One Step Secure IT is hiring a Managed Security Engineer II to design, implement, and maintain security solutions for its clients onsite in Phoenix, AZ.
Responsibilities
- Design and implement security controls and architectures tailored to client environments
- Embed cybersecurity best practices into development and deployment processes
- Maintain security tools, processes, and policies aligned with industry standards including NIST, CIS, ISO 27001, HIPAA, and PCI DSS
- Lead vulnerability assessments and penetration testing, including coordination of remediation efforts
- Oversee incident response: stakeholder communication, compliance with Arizona data breach notification laws, and post-incident reviews
- Develop and update security policies; deliver training for internal staff and clients
- Mentor junior security engineers and oversee security-related projects
- Monitor security alerts and events using SIEM and related tools
- Support patch management across client environments
- Investigate and report potential vulnerabilities or suspected breaches
- Prepare regular security reports for senior management and clients
- Assist with audits and regulatory compliance activities
- Collaborate with sales and account management to assess client security needs and design solutions
- Implement automation and advanced tools (e.g., MFA, encryption) to scale protections across multiple clients
Requirements
- 4+ years of experience in cybersecurity
- Strong analytical and problem-solving skills
- Excellent communication skills, including the ability to explain security concepts to technical and non-technical audiences
- Strong collaboration and client-facing capability
- Familiarity with security frameworks: NIST, CIS, ISO 27001
- Cloud security knowledge: AWS, Azure
- Understanding of attack vectors and mitigation techniques (e.g., phishing, malware)
- Knowledge of compliance standards: HIPAA, PCI DSS
- Experience with automation in multi-client environments
Technology & Compliance Exposure
- Security frameworks: NIST, CIS, ISO 27001
- Compliance standards: HIPAA, PCI DSS
- Monitoring and security tooling: SIEM
- Security controls and techniques: MFA, encryption
- Cloud: AWS, Azure
- Network and service knowledge: TCP/IP, HTTP, DNS
- Security infrastructure: firewalls, IDS/IPS
- Operating systems: Windows, Linux, MacOS
- Arizona breach notification laws: A.R.S. §§ 18-551, 18-552
Education
- Bachelor’s degree in Computer Science, Information Security, or related field (or equivalent experience)
Benefits
- 401(k)
- 401(k) matching
- Dental insurance
- Flexible spending account
- Health insurance
- Health savings account
- Life insurance
- Paid time off
- Vision insurance
Preferred Background
- Relevant certifications such as Security+, CEH, CASP, SSCP, CISSP, or CISM
- 4–6 years of cybersecurity experience, including at least 2 years as a Security Engineer
- Knowledge of network protocols (TCP/IP, HTTP, DNS)
- Experience with firewalls, IDS/IPS, and vulnerability management tools
- Background in an MSP or multi-client environment highly desirable
- Familiarity with Arizona data breach notification laws (A.R.S. §§ 18-551, 18-552) a plus
Job Type & Location
- Full-time
- Onsite in Phoenix, AZ (Phoenix, AZ 85027 required)