Security Engineer

Job not on LinkedIn

🔥 0 minutes ago

Apply Now
Find Similar Remote Jobs

📊 Check your resume score for this job

Improve your chances of getting an interview by checking your resume score before you apply.

Logo of GXA

GXA

11 - 50 employees

Founded 2004

💼 Consulting

📦 Logistics

📣 Marketing

Consulting • Logistics • Marketing

GXA is an IT services company based in the Dallas-Fort Worth Metroplex, Texas, providing comprehensive solutions such as managed IT, cybersecurity, network security, and IT consulting. With 16 years of experience, GXA serves various industries including charter schools, commercial real estate, manufacturing, and nonprofits. The company emphasizes customized IT solutions to help businesses manage their IT operations effectively and securely. GXA is committed to high standards in information security, holding certifications like SOC 2 Type II and ISO 9001, to ensure the protection and efficiency of their client's technology infrastructures. Serving both commercial and government clients, GXA strives to improve technology experiences and resolve IT challenges, enhancing the productivity and security of Texas businesses.

📋 Description

• Serve as a Tier 3 escalation point for active security incidents, including BEC, AiTM, ransomware, account compromise, identity-based attacks, and other security events • Lead technical analysis during incident response and war room events, including log review, IOC hunting, attacker activity analysis, and lateral movement tracing • Execute containment and eradication actions such as endpoint isolation, session revocation, credential resets, and access restriction • Troubleshoot incidents across identity, endpoints, servers, networking, cloud services, and security controls • Coordinate with SOC, infrastructure, and vendor threat intelligence teams during investigations and containment • Communicate incident status, actions taken, next steps, and support requirements clearly • Produce incident timelines, technical findings, and evidence packages for vCISO review and client follow-up • Operate the gShield security toolstack, including Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and related technologies • Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through • Support SIEM operations through query development, alert review, log analysis, investigation, and rule tuning • Tune detection logic, scan settings, and platform effectiveness • Monitor security gaps, suspicious activity, configuration weaknesses, and control failures • Correlate identity, endpoint, network, server, and cloud data during investigations • Apply security principles across on-premises, cloud, and hybrid client environments • Troubleshoot Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services • Support security hardening, identity and access security, endpoint and server controls, patching, configuration improvements, and remediation • Research, test, validate, and document solutions for unfamiliar technologies • Execute technical remediation from MRMMs, preventative actions, vulnerability reviews, and security recommendations • Support gShield deliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation • Assess vulnerabilities using severity, asset criticality, exposure, exploitability, existing controls, and business impact • Collaborate with client and internal technical teams on vulnerability remediation and compensating controls • Validate that identified risks have been addressed • Provide quality assurance for client onboarding into the gShield toolstack • Assist with client hardening and security improvement actions across multiple managed environments • Support remediation of internal GXA security backlog and POA&M-related work • Assist with phishing-resistant MFA, passkeys, and other internal security initiatives

🎯 Requirements

Apply Now