About the company
GXA is seeking a highly capable Security Engineer to support the delivery and operation of our gShield security services. This role is hands-on and technical, focused on security engineering, incident response, security tool operations, remediation execution, client security support, infrastructure security, and internal security improvement initiatives.
Responsibilities
- Serve as a Tier 3 escalation point for active security incidents, including business email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
- Lead technical analysis during incident response and war room events, including log review, IOC hunting, attacker activity analysis, and lateral movement tracing.
- Execute containment and eradication actions such as endpoint isolation, session revocation, credential resets, access restriction, and other appropriate remediation actions.
- Troubleshoot incidents that may span multiple technical layers, including identity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
- Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
- Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
- Communicate clearly during active incidents, including what is known, what has been investigated, what actions have been taken, what is being investigated next, and where additional support is required.
- Produce accurate incident timelines, technical findings, and evidence packages for vCISO review and client-facing follow-up.
- Operate daily within the gShield toolstack, including platforms such as Huntress, Microsoft Defender for Endpoint (MDE), Cyrisma, DNSFilter, SIEM, and related security technologies.
- Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
- Support SIEM operations including query development, alert review, log analysis, investigation, and rule tuning.
- Assist in tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
- Monitor for security gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
- Correlate information across identity, endpoint, network, server, and cloud sources when investigating security issues.
- Work within established security standards, baselines, and operational policies defined by the security team and vITMs.
- Apply security principles across on-premises, cloud, and hybrid client environments.
- Troubleshoot security issues involving underlying infrastructure components such as Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
- Understand how identity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
- Support security hardening of Windows, endpoint, identity, network, and cloud environments.
- Assist with identity and access security including MFA, Conditional Access, privileged access, authentication, authorization, and account security.
- Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
- Work effectively with technologies that may be unfamiliar by researching, testing, validating, and documenting appropriate solutions while escalating appropriately when additional expertise is required.
- Execute technical remediation items identified through MRMMs, preventative actions, vulnerability reviews, and security recommendations.
- Support gShield deliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
- Assess vulnerabilities based not only on severity scores but also on asset criticality, exposure, exploitability, existing controls, and business impact.
- Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifying appropriate compensating controls when immediate remediation is not possible.
- Validate remediation and confirm that identified risks have been appropriately addressed.
- Act as a quality assurance resource for client onboarding into the gShield toolstack, while execution remains with onboarding.