Senior Cybersecurity Engineer
Job Description
Geoengineers Inc is hiring a Senior Cybersecurity Engineer to design, implement, and manage enterprise security capabilities across compliance, Microsoft 365 security, vulnerability management, and incident response.
Responsibilities
- Assist with CMMC Level 1 and CMMC Level 2 compliance initiatives, including implementation, documentation, assessment preparation, and ongoing control management
- Administer and enhance Microsoft 365 security capabilities using tools such as Microsoft Purview, Microsoft Defender, and eDiscovery with related compliance tooling
- Act as a primary information security point of contact, supporting security awareness, risk identification, and system security requirements
- Engineer, implement, and monitor security controls to protect computer systems, networks, applications, and organizational information
- Design security architecture and produce detailed security designs aligned to organizational needs and industry best practices
- Maintain and update documentation for core security functions, operational processes, and standard operating procedures
- Configure, maintain, and troubleshoot security infrastructure devices and related systems
- Develop and implement technical security solutions and tools to identify, reduce, and mitigate vulnerabilities
- Lead incident response, forensic analysis, and post-incident investigation activities for security events and suspected compromises
- Build and maintain tools, processes, and infrastructure to support automation of incident response activities
- Create comprehensive reports summarizing assessment findings, outcomes, risks, and recommendations for security improvement
- Support third-party audit activities by preparing evidence, coordinating responses, and assisting with remediation efforts
- Collaborate with internal teams across GeoEngineers to deploy security tools, improve processes, and standardize security practices
- Serve as Incident Response and Crisis Management Lead during declared security incidents
- Manage vulnerability mitigation strategies and maintain vulnerability scanning efforts across internal and external resources
- Provide support for network engineering and administration activities as needed
Requirements
- Experience with Arctic Wolf, Cisco Meraki, KnowBe4, Cisco Umbrella, Cisco DUO, and Nexpose
- Bachelor’s degree in computer science, Information Technology, Cybersecurity, or related field from an accredited college or university (equivalent combinations of education, certification, and relevant work experience may be considered)
- 5+ years of related IT experience, including at least two years in an information security-focused role (corporate or professional services environment preferred)
- One or more recognized industry certifications preferred (examples: CCNA, CISSP, Security+, or similar)
- Strong technical expertise implementing security solutions aligned with current principles, techniques, protocols, and best practices
- Demonstrated experience building and maintaining security systems such as firewalls, intrusion detection and prevention, endpoint protection, authentication platforms, log management, and content filtering
- Solid foundation in higher-level information security concepts, assessment methodologies, and integration of security practices into an organization
- Knowledge of network and web protocols including TCP/IP, UDP, IPSEC, HTTP, TLS, SSL, and BGP
- Experience across information security technologies/processes including intrusion detection systems, web application firewalls, centralized logging, endpoint security, data loss prevention, SIEM, content delivery, load balancers, single sign-on, cloud platforms, threat intelligence, event correlation, virtualization technologies, and system/application vulnerability assessment tools
- Ability to work effectively under pressure with strong problem-solving, analytical, and decision-making skills
- Excellent interpersonal and written and verbal communication skills
- Availability to participate in 24/7 incident response
Technologies
- Microsoft 365, Microsoft Purview, Microsoft Defender, eDiscovery
- Arctic Wolf, Cisco Meraki, KnowBe4, Cisco Umbrella, Cisco DUO, Nexpose
- CMMC Level 1, CMMC Level 2
- TCP/IP, UDP, IPSEC, HTTP, TLS, SSL, BGP
- Intrusion detection and prevention systems, firewalls, endpoint protection, authentication platforms, log management, content filtering
- Web application firewalls, data loss prevention systems, SIEM, content delivery platforms, load balancers, single sign-on systems
- Cloud platforms, threat intelligence, event correlation, virtualization technologies, system and application vulnerability assessment tools
- Security awareness, incident response, incident response and crisis management
Benefits
- Healthcare (with travel benefit for care not locally available)
- 401(k) with company match
- Short-term and long-term disability
- Life insurance
- Wellbeing benefits
- Paid vacation and sick time
- Paid holidays
- Annual year-end bonus (subject to program eligibility requirements)
Work Environment / Physical Requirements
- Normal office environment with moderate noise levels
- Occasional lifting up to 25 lbs
- Prolonged sitting and regular walking, bending, standing, and reaching
- Ability to perform consistent work on a PC with prolonged view of a monitor/screen
- Willingness and ability to travel occasionally as needed
Location: Redmond, WA (onsite) | Salary: USD 98,000 - 169,000 per year