Senior Cybersecurity Engineer (Azure and GRC heavy)
Hyliion · Austin, TX · Today
On-siteInformation TechnologyFull-time
About the role
Hyliion is committed to creating innovative solutions that enable clean, flexible and affordable electricity production. The Company’s primary focus is to develop distributed power generators that can operate on various fuel sources to future-proof against an ever-changing energy economy.
The Senior Cybersecurity Engineer owns Hyliion’s overall day-to-day cybersecurity operations — endpoint security, identity and Conditional Access, cloud/SaaS security posture, and AI governance — across a cloud-native, Microsoft-centric technology environment.
Responsibilities
- Own and maintain Hyliion’s overall day-to-day cybersecurity posture across the enterprise, spanning identity, endpoint, cloud/SaaS, and AI governance.
- Maintain the System Security Plan (SSP) and control implementation for Hyliion’s CMMC Level 2 (C3PAO)-certified enclave, sustaining NIST 800-171 compliance and annual affirmation in SPRS for that defined scope.
- Administer and continuously optimize Microsoft Entra ID (Azure AD) Conditional Access policies, identity protection, and Privileged Identity Management (PIM) to enforce least-privilege and zero-trust principles.
- Own endpoint security end-to-end — patch management, vulnerability remediation, EDR fleet health, and compliance baselines across Windows, macOS, and mobile endpoints — using Microsoft Defender for Endpoint and Intune.
- Manage the broader Microsoft Defender suite (Defender for Office 365, Defender for Cloud Apps, Defender for Identity), including policy tuning, alert triage, and threat response.
- Serve as the primary point of contact for the Red Canary Managed Detection and Response (MDR) partnership, coordinating incident escalations, tuning detections, and reviewing threat intelligence reports.
- Administer Mobile Device Management (MDM)/Intune enrollment, compliance policies, and configuration across corporate and BYOD devices.
- Own security posture and governance across Hyliion’s growing SaaS application footprint (SaaS Security Posture Management), including OAuth/app permission reviews, shadow IT discovery, and third-party app risk assessment.
- Govern the secure and compliant use of enterprise AI platforms — monitoring usage, enforcing acceptable-use and data-handling policies, assessing AI vendor risk, and identifying unsanctioned (“shadow AI”) tool adoption.
- Monitor, triage, and respond to day-to-day cybersecurity incidents and alerts, ensuring timely containment, remediation, and documentation.
- Maintain and update security policies, procedures, and control documentation supporting NIST 800-171, CMMC, SOX IT general controls, and other applicable frameworks.
- Support recurring internal and third-party audits, evidence collection, and control testing, including SOX ITGC, CMMC annual affirmation, and cyber insurance renewal questionnaires.
- Partner with business leaders across departments to assess and mitigate information security risk in new projects, vendor relationships, SaaS adoption, and AI tool deployments.
- Maintain and enhance the executive-level cybersecurity dashboard and reporting cadence, translating technical risk into business-relevant metrics for leadership and the Board Audit Committee.
- Contribute to and maintain the company’s incident response, business continuity, and disaster recovery plans, participating in periodic tabletop exercises.
- Stay current on emerging threats and regulatory changes — including AI/LLM-specific risks (e.g., OWASP Top 10 for LLM applications, data leakage, prompt injection) and DFARS/CMMC/NIST developments — and recommend proactive improvements.
Qualifications
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- 5+ years of IT experience with a focus on cybersecurity operations and compliance.
- CISSP, CISM, Security+, Azure Security Engineer Associate (AZ-500), Microsoft SC-200, or other relevant security certification preferred.
Skills
- Hands-on administration experience with Microsoft Azure/Entra ID, including Conditional Access, Identity Protection, and Privileged Identity Management (PIM).
- Experience with endpoint security operations — patch management, vulnerability remediation, and EDR administration (Microsoft Defender for Endpoint or equivalent).
- Experience managing the Microsoft Defender suite and Microsoft Purview/Compliance Center.
- Experience working with a Managed Detection and Response (MDR) provider (e.g., Red Canary, CrowdStrike), including alert triage and incident response coordination.
- Experience administering MDM/Intune for endpoint compliance and device management.
- Familiarity with SaaS Security Posture Management (SSPM) or CASB concepts and experience securing a cloud-native, SaaS-first technology environment.
- Familiarity with AI/LLM security considerations (e.g., OWASP Top 10 for LLM Applications, data leakage prevention, shadow AI risk) and experience governing enterprise AI tool usage (e.g., Copilot, Claude, ChatGPT Enterprise).
- Working knowledge of NIST 800-171, CMMC 2.0, DFARS, SOX IT general controls, or similar regulatory/compliance frameworks.
- Ability to handle multiple competing priorities in a fast-paced environment.
- Ability to work well under minimal supervision.
- Manufacturing industry experience (preferred).
Benefits
- Medical Plans, with PPO or HDHP options
- Dental Plans, with buy-up option
- Vision Plan
- Life Insurance and Accidental Death & Dismemberment Plans, with buy-up options
- Short Term Disability, paid for by the company
- Long Term Disability, paid for by the company
- Flexible Spending Accounts (FSA)
- Health Savings Account (HSA)
- 401k/Roth 401k
- Voluntary Accident Plans
- Voluntary Critical Illness Plans
- Hospital Indemnity Plan