openqareer

Cybersecurity Engineer

Kirkhill · Brea, CA 92821

# Cybersecurity Engineer **Kirkhill** · Brea, CA 92821 · `On-site` 🕒 **Статус:** *Опубликовано: 12 дней назад* · *Источник: Indeed* --- ### About the Role Cybersecurity Engineer - Cloud & Network Infrastructure Position Summary We are seeking a Systems Administrator with strong Azure and networking expertise . Key Responsibilities Cloud Infrastructure - Own and mature our Azure cloud environment: architecture, storage, identity (Entra ID), governance, cost management, and security posture - Lead cloud migration and hybrid-cloud integration efforts for on-prem workloads where appropriate - Implement and enforce cloud security configuration, CA policy, Defender security tooling, monitoring and logging - Intune configurations, package deployment, and endpoint management - Maintain monitoring, backup/DR, and patch/configuration management practices for cloud-hosted systems - Use AI, copilot, and PowerShell to automate repetitive administration and security tasks Network Architecture - Design, document, and continuously improve network architecture, including segmentation between CUI-scoped enclaves and general business networks - Manage firewall, VLAN, and ACL configurations (including CUI subnet access control lists) and maintain accurate network documentation/diagrams - Lead network hardening initiatives and access control requirements (e.g., AC, SC control families) - Evaluate and implement zero-trust and micro-segmentation strategies Classified Environment (training provided) - Maintain secure configurations, audits, and documentation for the classified workstations; - Maintain active Security+ certification - Maintain System Security Plans (SSPs), POA&Ms, and supporting documentation - Support periodic government inspections, self-inspections, vulnerability scans, and audit log reviews for the classified system - Serve as day-to-day POC for the classified environment, coordinating with the Facility Security Officer (FSO) and compliance team as needed General Systems Administration - Administer Windows Server, Active Directory/Entra ID, endpoint management, and core virtual infrastructure services - Participate in security assessments, incident response testing, risk assessments, and 3rd party audits - Execute vulnerability scans, system patching, configuration deployments - Support configuration and software management controls (e.g., application allow-listing, nonessential functionality restrictions) in coordination with compliance staff - Participate in change management processes for IT systems affecting CUI/classified scope - Prioritize and resolve escalated technical issues and mentor junior IT staff, manage ticketing systems, and address chronic or persistent issues - Own and support all critical security incidents, interruptions/outages, and end-user issues with flexible evening/weekend work when required - Maintain system documentation, diagrams, project plans, asset inventory Required Qualifications - Hands-on expertise in hybrid cloud migration, Microsoft Azure networking, cloud technologies, protocols, and authentication, and WAN network architecture - Experience administering Azure: identity (Entra ID), virtual machines, vnet, CA policy, Azure Foundry, Purview, Defender, Intune, etc. - Design and manage basic network architecture: routing, switching, segmentation, firewall/ACL configuration, VLANs, RADIUS, etc. - Excellent writing skills, conceptual thinking skills, and communication skills needed to learn/implement GenAI tools - Active Secret security clearance - U.S. citizenship required. - CompTIA Security+ (CE) Preferred Qualifications - Cloud or Microsoft Azure Certifications - Experience with cybersecurity compliance frameworks similar to CMMC/NIST 800-171 - Implementing simple AI solutions in Azure Foundry and/or Copilot - Strong PowerShell skills Work Environment - On-site role - Some after-hours/on-call availability required to support maintenance windows and incident response

Наблюдалась 2026-10-07, впервые 2026-09-24, источник — Indeed.

Открыть у работодателя