Cybersecurity Engineer

Posted yesterday

kirkhillBrea (CA)

SENIORITY

Lead

Apply

About the role

Cybersecurity Engineer- Cloud & Network Infrastructure
Position Summary: We are seeking a Systems Administrator with strong Azure and networking expertise.
Key Responsibilities: Cloud Infrastructure Own and mature our Azure cloud environment: architecture, storage, identity (Entra ID), governance, cost management, and security posture Lead cloud migration and hybrid-cloud integration efforts for on-prem workloads where appropriate Implement and enforce cloud security configuration, CA policy, Defender security tooling, monitoring and logging Intune configurations, package deployment, and endpoint management Maintain monitoring, backup/DR, and patch/configuration management practices for cloud-hosted systems Use AI, copilot, and PowerShell to automate repetitive administration and security tasks Network Architecture Design, document, and continuously improve network architecture, including segmentation between CUI-scoped enclaves and general business networks Manage firewall, VLAN, and ACL configurations (including CUI subnet access control lists) and maintain accurate network documentation/diagrams Lead network hardening initiatives and access control requirements (e.g., AC, SC control families) Evaluate and implement zero-trust and micro-segmentation strategies Classified Environment (training provided) Maintain secure configurations, audits, and documentation for the classified workstations; Maintain active Security+ certification Maintain System Security Plans (SSPs), POA&Ms, and supporting documentation Support periodic government inspections, self-inspections, vulnerability scans, and audit log reviews for the classified system Serve as day-to-day POC for the classified environment, coordinating with the Facility Security Officer (FSO) and compliance team as needed General Systems Administration Administer Windows Server, Active Directory/Entra ID, endpoint management, and core virtual infrastructure services Participate in security assessments, incident response testing, risk assessments, and 3rd party audits Execute vulnerability scans, system patching, configuration deployments Support configuration and software management controls (e.g., application allow-listing, nonessential functionality restrictions) in coordination with compliance staff Participate in change management processes for IT systems affecting CUI/classified scope Prioritize and resolve escalated technical issues and mentor junior IT staff, manage ticketing systems, and address chronic or persistent issues Own and support all critical security incidents, interruptions/outages, and end-user issues with flexible evening/weekend work when required Maintain system documentation, diagrams, project plans, asset inventory
Required Qualifications:
  • Hands-on expertise in hybrid cloud migration, Microsoft Azure networking, cloud technologies, protocols, and authentication, and WAN network architecture
  • Experience administering Azure: identity (Entra ID), virtual machines, vnet, CA policy, Azure Foundry, Purview, Defender, Intune, etc.
  • Design and manage basic network architecture: routing, switching, segmentation, firewall/ACL configuration, VLANs, RADIUS, etc.
  • Excellent writing skills, conceptual thinking skills, and communication skills needed to learn/implement GenAI tools
  • Active Secret security clearanceU.S. citizenship required.
  • CompTIA Security+ (CE)
Preferred Qualifications:
  • Cloud or Microsoft Azure Certifications
  • Experience with cybersecurity compliance frameworks similar to CMMC/NIST 800-171 Implementing simple AI solutions in Azure Foundry and/or Copilot
  • Strong PowerShell skills
  • Work Environment
  • On-site role
  • Some after-hours/on-call availability required to support maintenance windows and incident response
Kirkhill, Inc. is proud to be an equal opportunity employer, and all qualified applicants will receive consideration for employment without regard to race, color, age, religion, sex, sexual orientation, gender identity, national origin, disability status, protected veteran status, or any other characteristic protected by law. All successful candidates must submit to post offer pre-employment physical examination, drug/alcohol screen and background check as a condition of employment.

Before you apply

Applying takes about a minute. These four things decide how fast it moves after that.

Your profile is current

It's what we read first. Occupations, seniority and locations matter more than a long history.

Two examples you can talk through

Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.

A number in mind

What you're on now and what would make you move. We negotiate better when we know both.

Your notice period

Employers plan around it, and it's the question that stalls offers most often.

Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.

More like this