Jobs · Information Technology · Pennsylvania

Senior Cybersecurity Engineer Specialist

Concurrent Technologies Corporation · Johnstown, PA · 1 mo ago
Information TechnologyFull-time

Key Responsibilities

  • Participate in incident response activities, continuous monitoring, and the development of security standards and procedures in collaboration with internal cyber, IT, development, and data security teams.
  • Perform threat hunting by analyzing threat feeds from various government and commercial sources and leveraging Rapid7 Insight VM and Microsoft Cloud tools to scan, prioritize, and remediate vulnerabilities across on-premises and cloud assets.
  • Administer endpoint security systems (Microsoft Defender for Endpoint, SentinelOne, Intune, EntraID, Azure) for threat detection, investigation, and automated response across enterprise devices with a focus on compliance policies, configuration profiles, and conditional access enforcement.
  • Support and harden Microsoft Entra ID configurations, including conditional access, multi-factor authentication, privileged identity management, and identity governance.
  • Apply, monitor, and enforce security best practices across AzureGov cloud services and Microsoft 365, ensuring alignment with government compliance frameworks (e.g., FedRAMP, NIST 800-171, CMMC as applicable).
  • Configure and manage Microsoft Purview data loss prevention (DLP), insider risk management and support compliance and eDiscovery initiatives, ensuring data governance policies are enforced across the M365 environment.
  • Collaborate with development and DevOps teams to embed security into the software development lifecycle (SDLC), including secure coding practices, code review, and dependency scanning.
  • Evaluate security considerations associated with the adoption of AI and generative AI tools, including data leakage, prompt injection, model misuse, and shadow AI risks while contributing to the development of AI usage guardrails and monitoring practices aligned with emerging federal AI security guidance.

Requirements

  • Education: Bachelor's or Master's degree in Cybersecurity, Computer Science, Information Technology, or a related field.
  • Experience: 4-6 years of hands-on experience in a Cyber Security analyst or related IT or cyber engineer role.
  • Ability to obtain and maintain Secret government security clearance.
  • Demonstrated experience with Microsoft M365, Azure, or AWS cloud security components (e.g. Defender for Identy and Endpoint, Purview, Intune, Azure, EntraID).
  • Strong grasp of networking, operating system security (Windows-centric), and cloud security fundamentals.
  • Excellent verbal and written communication skills with the ability to explain and document technical information for a non-technical audience.
  • Proven ability to approach complex problems with a structured, analytical, and inquisitive mindset.
  • Relevant certifications such as CISSP, CISM, Security+, Microsoft SC-200/SC-300/AZ-500, or CEH.
  • Experience operating in AzureGov or other government/regulated cloud environments.
  • Familiarity with DevSecOps practices and secure CI/CD pipeline tooling (SAST/DAST/SCA).
  • Experience with Linux, macOS, and Windows in a heterogeneous network environment.
  • Understanding of security frameworks such as NIST 800-171 or 800-53, NIST Cybersecurity Framework, and CIS Controls.
  • Knowledge of CMMC, FedRAMP, or NIST compliance requirements.
  • Experience assessing security risks associated with AI/generative AI technologies.
  • Background in incident response and threat hunting.

Qualifications

  • Hands-on experience in a Cyber Security analyst or related IT or cyber engineer role.
  • Strong understanding of Microsoft security technologies, Azure Government, Microsoft 365, and enterprise security operations.
  • Experience with scripting and using command line interfaces with PowerShell, Python, or similar language.
  • Experience with DevSecOps practices and secure CI/CD pipeline tooling (SAST/DAST/SCA).
  • Experience with Linux, macOS, and Windows in a heterogeneous network environment.
  • Experience with security frameworks such as NIST 800-171 or 800-53, NIST Cybersecurity Framework, and CIS Controls.
  • Experience with CMMC, FedRAMP, or NIST compliance requirements.
  • Experience with AI and generative AI technologies, including data leakage, prompt injection, model misuse, and shadow AI risks.
  • Experience with incident response and threat hunting.

Skills

  • Strong analytical and problem-solving skills.
  • Collaborative mindset.
  • Ability to communicate complex technical concepts to both technical and non-technical stakeholders.
  • Structured, analytical, and inquisitive mindset.
  • Relevant certifications such as CISSP, CISM, Security+, Microsoft SC-200/SC-300/AZ-500, or CEH.
  • Experience operating in AzureGov or other government/regulated cloud environments.
  • Familiarity with DevSecOps practices and secure CI/CD pipeline tooling (SAST/DAST/SCA).
  • Experience with Linux, macOS, and Windows in a heterogeneous network environment.
  • Understanding of security frameworks such as NIST 800-171 or 800-53, NIST Cybersecurity Framework, and CIS Controls.
  • Knowledge of CMMC, FedRAMP, or NIST compliance requirements.
  • Experience assessing security risks associated with AI/generative AI technologies.
  • Experience with incident response and threat hunting.

Benefits

Competitive salary and benefits package.

Pay

N/A

Schedule

N/A

Benefits

N/A

Staffing Requisition

SR#2026-0093

Similar jobs