Cybersecurity Engineer II

United StatesUnited States·Tx Orion Admin Services-Txoas - HoustonNormalmid
EngineeringSecurity Engineer
0 views0 saves0 applied

Quick Summary

Overview

POSITION SUMMARY The IT Cybersecurity Engineer II provides mid-level engineering support for the architecture, operation, automation,

Technical Tools
EngineeringSecurity Engineer

The IT Cybersecurity Engineer II provides mid-level engineering support for the architecture, operation, automation, and continuous improvement of Orion's cybersecurity posture across on-premises, cloud, and hybrid environments. This role is responsible for evaluating and strengthening the overall security architecture, and for enhancing and automating existing security tooling to improve detection, response, and operational efficiency. The role also owns the security and integrity of Orion's SIEM and SOAR environment, ensuring the platforms that detect and respond to threats are themselves properly access-controlled, hardened, and monitored. The position holds global ownership of endpoint security review and administration, ensuring consistent policy enforcement, coverage, and hardening across the environment.

While the primary focus of this role is cybersecurity engineering, the Cybersecurity Engineer II is expected to be well-rounded across core infrastructure disciplines. The role actively cross-trains and provides backup support with the Infrastructure team and participates in shared operational and on-call responsibilities. This role works under the direction of IT leadership while partnering with the Infrastructure team, Service Desk, Applications, and business stakeholders to maintain a secure, resilient, and well-documented technology environment.

This role supports cybersecurity technologies and services including endpoint detection and response (EDR/XDR), network detection and response (NDR), SIEM and SOAR platforms, identity security, email security, vulnerability management, security monitoring and alerting, and security automation, in addition to cross-functional support of virtualization, backup, and related on-premises infrastructure.

The incumbent must support Orion's guiding beliefs and core values centered on Safety, Quality, Delivery, and Teamwork, and most importantly, built upon the all-important foundation of Integrity.

Responsibilities

~1 min read
  • Evaluate Orion's overall cybersecurity architecture and posture, identifying gaps and recommending improvements aligned with security best practices and industry frameworks (for example, NIST, CIS Controls, Zero Trust principles).
  • Partner with IT leadership to design and evolve a layered security architecture across endpoint, network, identity, email, and cloud environments, informed by findings from penetration tests, vulnerability assessments, and audits.
  • Translate penetration test and assessment findings into prioritized remediation plans and architectural changes, tracking implementation through to closure.
  • Serve as the primary engineer responsible for enhancing, tuning, and automating Orion's core security platforms, including Darktrace and Microsoft Defender (Defender for Endpoint, Defender for Identity, Defender for Cloud Apps, Defender for Office 365).
  • Develop and maintain automation, scripts, and workflows (for example, PowerShell, KQL, Logic Apps/Sentinel automation, or equivalent) to streamline detection, alert triage, response actions, and reporting, reducing manual security operations effort.
  • Continuously tune detection rules, alert thresholds, and correlation logic to reduce false positives and improve signal quality across security platforms.
  • Evaluate emerging security tools and capabilities and recommend enhancements or additions to the security tooling stack.
  • Own the security, access control, and configuration integrity of Orion's SIEM and SOAR environment, ensuring the platforms responsible for detection, correlation, and automated response are themselves hardened against unauthorized access, tampering, or misconfiguration.
  • Administer role-based access, log source onboarding, and data retention within the SIEM to protect the confidentiality and integrity of security event data used for detection, investigation, and audit evidence.
  • Build, test, and maintain SOAR playbooks and automated response actions, applying change control and peer review to prevent unintended or unauthorized automated actions in production.
  • Monitor SIEM/SOAR platform health, log ingestion completeness, and playbook execution to ensure detection and response coverage is not silently degraded.
  • Own the global review, configuration, and administration of endpoint security, across all Orion locations, devices, and business units.
  • Monitor endpoint security coverage, policy compliance, and protection status; identify and remediate gaps in onboarding, policy application, or protection posture.
  • Manage endpoint security policies, attack surface reduction rules, device configuration baselines, and vulnerability management workflows tied to endpoint protection.
  • Review and respond to endpoint-related security alerts and incidents, coordinating containment, remediation, and root-cause analysis.
  • Monitor security alerts, logs, and telemetry from Darktrace, Microsoft Defender, the SIEM, and related platforms; investigate and respond to potential threats and security incidents.
  • Support incident response activities, including detection, containment, eradication, and post-incident documentation and lessons learned.
  • Perform vulnerability scanning, risk assessment, and remediation coordination across infrastructure and endpoint environments.
  • Support CMMC and NIST SP 800-171 compliance activities, including control implementation, evidence collection, audit support, and remediation of identified findings.
  • Maintain security documentation, including architecture diagrams, standard operating procedures, playbooks, and control evidence, to support auditability and operational consistency.
  • Assist with security risk assessments, policy development, and control reviews in coordination with IT leadership.
  • Cross-train and maintain working proficiency with core on-premises infrastructure platforms managed by the Infrastructure team, including VMware virtualization and Veeam backup and recovery.
  • Provide backup coverage for infrastructure operations as needed, including virtualization, backup/recovery, storage, and related on-premises systems, to reduce single points of knowledge given the size of the IT team.
  • Partner with the Infrastructure team on projects and changes that have security implications, ensuring security requirements are incorporated into infrastructure design and operations.
  • Maintain accurate technical documentation, including security architecture diagrams, configuration standards, runbooks, and change records.
  • Identify and communicate opportunities to improve security posture, tooling effectiveness, and operational efficiency; participate in continuous improvement initiatives.
  • Coordinate effectively with the Infrastructure team, Service Desk, Applications, vendors, and other stakeholders to resolve incidents, support projects, and ensure smooth handoffs.
  • Respond to off-hour security alerts, calls, emails, or notifications as needed to maintain security monitoring coverage and operational uptime.
  • Ensure incident response communications and handoffs are clear, timely, and documented.
  • Support broader IT and security projects and perform other related administrative and technical duties as assigned by IT leadership.

Requirements

~1 min read

The engineer must be able to perform the job's essential functions with or without reasonable workplace accommodation.

The individual must also be able to wear and properly utilize appropriate personal protective equipment if required to work or visit the job site. This may include a hard hat, safety glasses, respirators, ear plugs, steel-toed shoes, personal flotation devices, or other equipment as required by the work performed and the location where the work is being done.

The incumbent must possess the ability to remain calm during emergencies and respond appropriately as dictated by the circumstance of the incident and as directed by the Safety Representative or other management personnel. Must be capable of evacuating the work area promptly should an emergency arise.

  • Demonstrated ability to deliver high-quality results with minimal supervision in a fast-paced environment.
  • Strong communication, analytical, and problem-solving skills with the ability to explain technical and security concepts to non-technical stakeholders.
  • Proven ability to learn new technologies and threat landscapes quickly through research, self-directed learning, and hands-on experimentation.
  • Strong documentation habits and attention to detail, including architecture diagrams, playbooks, and audit evidence.
  • Bachelor's degree in Computer Science, Information Technology, Cybersecurity, or related field, or equivalent practical experience. Relevant certifications are preferred (examples: CompTIA Security+/CySA+, Microsoft SC-200/SC-100, CEH, GIAC, or equivalent).
  • 4–8 years of hands-on experience in cybersecurity engineering or security operations, with demonstrated experience designing, tuning, or automating security tooling.
  • Strong understanding of cybersecurity architecture principles and security frameworks, with experience aligning to NIST SP 800-171 and supporting CMMC compliance readiness activities.
  • Hands-on experience with Microsoft Defender (Endpoint, Identity, Cloud Apps, Office 365) and network detection and response platforms such as Darktrace, including tuning, automation, and reporting.
  • Hands-on experience administering and securing a SIEM and SOAR environment, including access control, log source management, and building/maintaining automated response playbooks.
  • Experience administering endpoint security at scale, including policy management, attack surface reduction, vulnerability management, and incident response.
  • Working proficiency with scripting and automation (for example, PowerShell, KQL) to build repeatable security workflows, detections, and reporting.
  • Working knowledge of virtualization and backup platforms (VMware and Veeam or equivalent) sufficient to cross-train and provide backup support with the Infrastructure team.
  • Proficient with standard Microsoft productivity tools (Visio, Word, Excel, Outlook, PowerPoint) for documentation, diagrams, reporting, and communication.
  • Experience supporting security audits, e-discovery technical requests, and handling sensitive data with confidentiality, documented procedures, and access controls is preferred.
  • Responsible and accountable for the incumbent's safety.
  • Responsible and accountable for the safety of all co-workers and any other incumbent encounters.
  • Authorized and obligated to stop work on any task or series of tasks whenever an unsafe condition or situation is anticipated or observed.
  • Complies with all applicable laws, regulations, and Company policies and procedures and is subject to appropriate disciplinary action (including dismissal) for failure to do so.
  • Reports any violations of applicable laws, regulations or Company policies and procedures promptly, and is subject to appropriate disciplinary action (including dismissal) for failure to do so.
  • All employees, current and former, must maintain confidentiality by not disclosing to others any confidential, proprietary, or trade secret information belonging to the Company.

Location & Eligibility

Where is the job
Tx Orion Admin Services-Txoas - Houston, United States
On-site at the office
Who can apply
US

Listing Details

First seen
September 29, 2026
Last seen
September 29, 2026

Posting Health

Days active
0
Repost count
0
Trust Level
57%
Scored at
September 29, 2026

Signal breakdown

freshnesssource trustcontent trustemployer trust
Newsletter

Stay ahead of the market

Get the latest job openings, salary trends, and hiring insights delivered to your inbox every week.

A
B
C
D
Join 12,000+ marketers

No spam. Unsubscribe at any time.

Cybersecurity Engineer II