via Rippling
$70K - 120K a year
Conduct technical security assessments, audits, penetration testing, manage incident response, enforce security policies, and monitor logs for threats.
Minimum three years of security engineering experience, bachelor's degree, proficiency in SIEM, penetration testing, and network security.
Security Engineer - Middle will conduct technical security assessments, audits, penetration testing, and forensic IT functions of client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems. In-depth experience configuring and managing one or more SIEM tools. Be able to identify current security infrastructure and define future programs, design and implementation of security related to IT systems. Must have a minimum of three (3) years of proven information systems security engineering experience. At minimum, an in-depth knowledge and management of one or more Security Incident and Event Management (SIEM) tools is required. Additionally, the Security Engineer - Middle shall possess hands-on experience in penetration testing and router/firewall management. This role requires one day onsite in Arlington, VA. Technical Skills: In-depth, hands-on configuration and management of one or more SIEM tools. Log collection, aggregation, normalization, and correlation from diverse sources (e.g., servers, network devices, and applications). Event monitoring, analysis, and reporting. Experience with conducting penetration testing and technical security assessments. Vulnerability and patch management. Automated and manual security testing techniques. Router and firewall management, including installation, configuration, and troubleshooting. Intrusion detection and prevention systems (IDS/IPS). Operating system security, including experience with Windows and Linux environments. Securing virtualized client/server systems. Database security. Coordinating and managing security incident response efforts. Forensic IT functions to investigate security breaches and determine root cause. Log analysis for security incidents. Defining, reviewing, and enforcing information security policies, standards, and guidelines. Ensuring compliance with relevant regulatory requirements. Knowledge of current security trends and threats. Researching new attack vectors. Thinking like a hacker to anticipate vulnerabilities. Familiarity with scripting languages (e.g., Python, Bash) for automating security tasks and managing systems. Experience with security automation frameworks. Responsibilities: Define, review, and enforce information security policy, standards and guidelines for business operations and technology implementations. Proactively speculate and identify IT security risks from technical and functional perspectives. Conduct technical security assessments as part of the enterprise vulnerability and patch management program. Conduct as needed technical security assessments, audits, penetration testing, and forensic IT functions of USMS client/server systems (native and virtual), databases, networks, and vehicle/appliance technology systems. Coordinate and conduct event collection, log management, event management, compliance automation, and identity monitoring activities for the USMS enterprise. Analyze data collected by the event monitoring system(s), identifying results that dictate immediate corrective action, trends that drive prompt action and areas that require continued monitoring and/or further analysis. Maintain awareness of current security trends and threats, respond to reported incidents to conclusion, and provide awareness to system users. Coordinate IT security matters such as incident response, intrusion detection management, and customer security advisories. Requirements: Required Education BS/BA in Computer Science, Information Systems, Engineering, Business, Physical Science, or other technology-related discipline. Required Skills • In-depth, hands-on configuration and management of one or more SIEM tools. • Log collection, aggregation, normalization, and correlation from diverse sources (e.g., servers, network devices, and applications). • Event monitoring, analysis, and reporting. • Experience with conducting penetration testing and technical security assessments. • Vulnerability and patch management. • Automated and manual security testing techniques. • Router and firewall management, including installation, configuration, and troubleshooting. • Intrusion detection and prevention systems (IDS/IPS). • Operating system security, including experience with Windows and Linux environments. • Securing virtualized client/server systems. • Database security. • Coordinating and managing security incident response efforts. • Forensic IT functions to investigate security breaches and determine root cause. • Log analysis for security incidents. • Defining, reviewing, and enforcing information security policies, standards, and guidelines. • Ensuring compliance with relevant regulatory requirements. • Knowledge of current security trends and threats. • Researching new attack vectors. • Thinking like a hacker to anticipate vulnerabilities. • Familiarity with scripting languages (e.g., Python, Bash) for automating security tasks and managing systems. • Experience with security automation frameworks.
This job posting was last updated on 8/4/2026