Cyber Security Engineer
qualibarDenver (CO)
About the role
Job Title: Cyber Security Engineer
Location: Remote
Duration: Contract to Hire
Position Summary:
Cyber Security Engineer to join the Infrastructure organization and work alongside the Network and Security team. The technical work is primary: this is a hands-on engineering seat, not a policy desk. The person in this position will help harden a distributed enterprise environment that spans corporate offices, remote sites, and cloud workloads, and will spend most of their time configuring, tuning, and defending the controls that protect it. Around that engineering core the role carries three further responsibilities. It owns the technical side of our audit and certification readiness, so the person who configures a control is also the one who can produce the evidence for it. It partners with development and platform teams on secure delivery pipelines and modern application practices. And it brings an offensive mindset to the environment, validating our defenses through testing rather than assuming they hold. The role reports to the Manager of Network and Security and works closely with systems engineering, network engineering, and application teams. We are looking for an engineer who is comfortable owning a problem end to end, communicating clearly with non-security colleagues, and improving the environment steadily rather than waiting for a project to be handed over.
Required Qualifications:
Hands-on experience in information security, network engineering, or systems engineering with substantial security responsibility. Demonstrated production experience with enterprise firewalls and VPN, endpoint detection and response, and email security controls. Working knowledge of TCP/IP, routing and switching, DNS, VLANs, and network segmentation, with the ability to read a packet capture and reason about traffic. Practical experience securing Microsoft environments: Active Directory, Entra ID, Microsoft 365, and Windows Server. Hands-on Linux and UNIX administration and hardening, including shell fluency, SSH and key management, service and file permissions, system logging, and patching. Experience with vulnerability management tooling and with driving remediation across teams that do not report to you. Understanding of penetration testing methodology and common offensive tooling, sufficient to validate a finding and reproduce it rather than only read the report. Working familiarity with CI/CD pipelines and modern delivery practices, including source control workflow, build automation, containers, and secrets handling. Direct experience supporting security audits or a certification effort, including evidence collection, control mapping, and working with external assessors. Familiarity with a recognized security framework such as NIST CSF, CIS Controls, or ISO 27001, and the ability to translate a control into a concrete configuration change. Clear written and verbal communication, including the ability to explain risk and remediation to business stakeholders and to write an audit-quality narrative. Willingness to participate in an on-call rotation and to respond outside business hours during a security incident.
Preferred Qualifications:
Bachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience. Additional certifications such as OSCP, CySA+, GCIH, GCIA, GWAPT, CISSP, CISA, or a vendor certification in the firewall or endpoint platform they have used. Experience carrying an organization through a formal certification such as ISO 27001, SOC 2, or a comparable attestation from readiness assessment to audit. Hands-on Azure security experience, including conditional access, Defender for Cloud, and log analytics. Experience securing a mixed estate where Linux and Windows systems share authentication and logging, or with Linux-based network and security appliances. Scripting or automation skill for reporting, log parsing, pipeline integration, and repetitive response tasks. Experience with Dev Sec Ops tooling in a real pipeline, such as dependency scanning, container image scanning, or policy as code. Experience in energy, fuel distribution, logistics, or another operationally distributed industry. Exposure to OT or industrial control environments, or to card and payment data requirements such as PCI DSS.
Before you apply
Applying takes about a minute. These four things decide how fast it moves after that.
Your profile is current
It's what we read first. Occupations, seniority and locations matter more than a long history.
Two examples you can talk through
Not a portfolio — just two pieces of work where you can explain the decisions and what you'd change.
A number in mind
What you're on now and what would make you move. We negotiate better when we know both.
Your notice period
Employers plan around it, and it's the question that stalls offers most often.
Once you apply, someone reads it and calls you before anything reaches the employer — usually within two working days.
More like this
