Cybersecurity Engineer

Cybersecurity Engineer

Vollzeit 63000 - 77000 € / Jahr (geschätzt) Homeoffice (teilweise)
H

Auf einen Blick

  • Aufgaben: Schütze die digitale Welt mit innovativen Sicherheitslösungen und reagiere auf Bedrohungen.
  • Unternehmen: HB Mechanical Group, ein Teil von HB Global, fördert eine wertschätzende Arbeitskultur.
  • Vorteile: Vollzeitstelle mit flexiblen Arbeitszeiten, Gesundheitsleistungen und Weiterbildungsmöglichkeiten.
  • Weitere Informationen: Entwickle deine Karriere in einem wachsenden Unternehmen mit vielfältigen Möglichkeiten.
  • Warum dieser Job: Werde Teil eines dynamischen Teams und schütze Unternehmen vor Cyber-Bedrohungen.
  • Qualifikationen: Mindestens 5 Jahre Erfahrung in der Cybersicherheit und starke Teamfähigkeiten.

Das prognostizierte Gehalt liegt zwischen 63000 - 77000 € pro Jahr.

This position will report to HB Mechanical Group, LLC, a subsidiary of HB Global.

We empower our employee owners to make this a great place to work and create value.

SUMMARY

The Cybersecurity Engineer is HB Global’s dedicated, hands-on owner of cybersecurity operations and engineering across the enterprise.

Reporting to the Director of IT, who owns the enterprise security strategy, and partnering with third-party solution architects where specialized design is required, this role translates strategy into working, well-managed security controls.

It is a true generalist position: on any given week the engineer performs day-to-day threat hunting, monitoring, and incident response, then implements, configures, and manages the tools that protect the organization.

This position operates in a multi-division enterprise environment in which divisions maintain autonomy in business decisions; the Cybersecurity Engineer maintains consistent enterprise security standards while adapting to each division’s needs and supporting the integration of newly added business units.

To be successful you must possess these core value characteristics

Trust: Clear Communication. Be committed. Accountable. Open. Honest.

Team: No "I". Do what's best. Assume the best. Be a leader. Celebrate wins.

Grit: Goal-focused. Be positive. Persevere. Show passion. Take ownership.

Growth: Lifelong learner. Forward-thinker. Self-aware. Curious. Open-minded.

WORK SCHEDULE & TRAVEL

This is a full-time position with benefits.

The role is a hybrid Remote-On Site position; we prefer candidates within driving distance of the HB Mechanical Group office in Camp Hill, PA or the Tamarac, FL office, and will consider strong candidates residing anywhere in the U.

Eastern time zone.

Hours may vary according to business needs.

Occasional travel between HB Global offices and divisional worksites may be required.

On-call availability for security incidents and urgent requests is required.

ESSENTIAL DUTIES and RESPONSIBILITIES

  • Threat Detection, Hunting & Response
  • Perform day-to-day threat hunting, monitoring, and alert triage across the Crowd Strike Falcon platform (EDR, NG-SIEM, and Identity Threat Protection).
  • Investigate, contain, and remediate security incidents end to end; perform root-cause analysis and document findings and lessons learned.
  • Tune detections, correlation rules, and alerting to reduce noise and improve fidelity.
  • Monitor and respond to email-borne threats and user-reported phishing through Mimecast, managing quarantine and policy tuning.
  • Security Engineering, Implementation & Configuration
  • Implement, configure, and maintain security controls across Microsoft Azure and on-premises systems, coordinating with third-party architects on solution design where required.
  • Administer identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace, enforcing least privilege, MFA, and conditional access.
  • Manage endpoint protection and DNS-layer security (Cisco Umbrella), and support network security policy on Cisco Meraki in partnership with the Senior Network Administrator.
  • Own vulnerability management, including scanning, prioritization, and coordinating remediation within the IT team.
  • Partner with the Senior Systems Administrator — who administers our data protection and recovery tools (Druva, Veeam) — to validate and test backup integrity and to participate in disaster-recovery testing.
  • Manage the secrets and password platform (1Password) and champion strong credential hygiene across the organization.
  • Security Operations & Management
  • Maintain security configuration standards and hardening baselines aligned to the strategy set by leadership.
  • Plan, track, and report on security initiatives using Zoho Projects.
  • Manage day-to-day relationships with security vendors and managed-service providers, holding third parties accountable to their commitments.
  • Own the Mimecast security-awareness program, including scheduling and managing quarterly awareness trainings and quarterly phishing simulations, and reporting on progress and completion rates.
  • Reporting, Metrics & Executive Communication
  • Produce clear, regular reporting on the organization’s overall cybersecurity posture, translating technical detail into concise summaries for leadership and executive audiences.
  • Pull and correlate data from across the security stack - Crowd Strike (EDR, NG-SIEM, Identity Threat Protection), Mimecast, Cisco Umbrella and Meraki, identity, and vulnerability tools - into clear, easy-to-understand reports and dashboards.
  • Define and track key security metrics and KPIs (such as detection and response times, vulnerability remediation, patch status, and phishing-test results) and report on trends over time.
  • Provide on-demand snapshots of the current security state and clearly communicate risks, priorities, and recommendations to non-technical stakeholders.
  • Business Partnership & Business-Unit Integration
  • Partner with multiple semi-autonomous divisions to deliver consistent security protections, adapting engagement and communication to each division’s operational needs while maintaining enterprise standards and governance.
  • As HB Global grows and brings new business units into the organization, onboard and standardize their security controls to HB Global’s baseline.
  • Assess the security posture of incoming environments and build practical plans to consolidate identity, endpoint, email, network, and backup protections.
  • Governance & Collaboration
  • Support compliance, audit, and cyber‑insurance requirements with clear evidence and documentation.
  • Partner with leadership to turn security strategy into hands‑on execution, and flag risks and priorities as they emerge.
  • Partner closely with the Senior Network Administrator — who is responsible for network security — to validate network security controls and to provide backup and cross‑coverage for the network security function.
  • Other
  • Perform other duties as assigned

EDUCATION, EXPERIENCE and SKILLS

Education

  • High School Diploma
  • BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
  • Relevant security certifications and continuing education preferred

Experience (Required)

  • 5+ years of hands‑on experience in cybersecurity engineering, security operations, or a blended security/IT role.
  • Demonstrated ability to both build and operate security controls with minimal supervision as a security generalist.
  • Hands‑on experience with EDR/endpoint security and SIEM (Crowd Strike strongly preferred).
  • Strong identity and access management experience (Entra ID / Active Directory, Okta, MFA, conditional access).
  • Experience securing Microsoft 365 and cloud environments (Microsoft Azure).
  • Practical incident‑response and threat‑hunting experience, with solid networking and firewall fundamentals.
  • Experience working with outside security vendors/managed services and coordinating deliverables to timelines and quality expectations.

Skills & Technical Knowledge

  • Working knowledge of security frameworks and best practices (e. g., NIST Cybersecurity Framework, CIS Controls) and the ability to enforce data/access security policies.
  • Scripting and automation ability (Power Shell and/or Python) for routine tasks and tool integrations.
  • Strong analytical and problem‑solving skills; able to communicate clearly with technical and non‑technical stakeholders.
  • Ability to pull data from multiple security platforms and present the organization’s security posture in clear reports and dashboards for executive, non‑technical audiences.
  • Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security.
  • Familiarity with email security, DNS security, and backup/disaster‑recovery concepts.
  • Familiarity with confidentiality requirements related to IT operations and network information.

PREFERRED QUALIFICATIONS

  • Industry certifications such as CISSP, SSCP, Comp TIA Security+/Cy SA+, GIAC (GCIH, GCIA), or Crowd Strike / Microsoft Azure security certifications.
  • Direct experience with our stack: Crowd Strike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, and 1Password.
  • Experience standardizing security across multiple sites or business units within a growing, multi‑entity organization.
  • Experience integrating or supporting newly added business units.
  • Experience in a multi‑division or federated IT/security environment.

PHYSICAL REQUIREMENTS

  • Prolonged periods sitting at a desk and working on a computer
  • Must be able to lift up to 15 pounds at times
  • Ability to travel to divisions and worksites as needed
  • #J-18808-Ljbffr

Cybersecurity Engineer Arbeitgeber: HB Mechanical Group, LLC

HB Mechanical Group, LLC bietet eine dynamische und unterstützende Arbeitsumgebung, in der Mitarbeiter als Eigentümer geschätzt werden und aktiv zur Schaffung eines großartigen Arbeitsplatzes beitragen. Mit einem starken Fokus auf Teamarbeit, persönliches Wachstum und kontinuierliche Weiterbildung fördert das Unternehmen eine Kultur des Vertrauens und der Verantwortung. Die hybride Arbeitsweise ermöglicht Flexibilität, während die Möglichkeit zur Zusammenarbeit mit verschiedenen Abteilungen und die Integration neuer Geschäftseinheiten spannende Herausforderungen und Entwicklungschancen bieten.

H

Kontaktdaten:

HB Mechanical Group, LLC Recruiting-Team

StudySmarter Expertenrat🤫

Wir sind der Meinung, dass du so Cybersecurity Engineer erhalten könntest

Werde sichtbar in der IT-Sicherheits-Community

In der IT-Sicherheit gibt’s eine Menge Fachkreise und Konferenzen, die super für Networking sind. Schau dir Events wie die "IT-Security Convention" oder regionale Meetups an, um Gleichgesinnte und potenzielle Arbeitgeber wie HB Mechanical Group, LLC kennenzulernen!

Kollaboriere an Open-Source-Projekten

Zeig dein Können und engagiere dich in Open-Source-Projekten, die auf IT-Sicherheit abzielen. Das ist nicht nur eine tolle Möglichkeit, praktische Erfahrungen zu sammeln, sondern auch, um dein Portfolio zu erweitern und Sichtbarkeit in der Branche zu gewinnen.

Nutze spezielle Jobportale für IT-Sicherheit

Schau auf spezialisierten Jobportalen wie "heise jobs" oder "StepStone" nach offenen Stellen in der IT-Sicherheit. Hier findest du viele Angebote, die nicht immer auf den großen Plattformen gelistet sind. Vergiss nicht, dich direkt auf der Website von HB Mechanical Group, LLC zu bewerben!

Halte deine Skills up-to-date

In der IT-Sicherheit bleibt nichts stehen, also bleib am Ball! Investiere Zeit in Weiterbildung und besuche Online-Kurse oder Webinare zu aktuellen Sicherheitsthemen. Das zeigt nicht nur dein Engagement, sondern stärkt auch dein Profil bei HB Mechanical Group, LLC.

Wir glauben, dass du diese Fähigkeiten brauchst, um Cybersecurity Engineer mit Bravour zu bestehen

Cybersecurity Operations
Threat Hunting
Incident Response
Security Engineering
Microsoft Azure
Identity and Access Management
EDR/Endpoint Security

Einige Tipps für deine Bewerbung 🫡

Zeig deine technischen Skills!:Im Bereich IT-Sicherheit ist es wichtig, dass du deine technischen Fähigkeiten klar kommunizierst. Stelle sicher, dass dein Lebenslauf relevante Zertifikate (wie CEH oder CISSP) sowie praktische Erfahrungen bei Sicherheitsprojekten oder Penetrationstests zeigt. Dies wird uns helfen, einen besseren Eindruck von deinem Fachwissen zu bekommen.

Präsentiere dein Wissen über aktuelle Trends:Wir möchten sehen, dass du über die neuesten Entwicklungen im Bereich IT-Sicherheit informiert bist. In deinem Anschreiben kannst du beispielsweise auf ein aktuelles Sicherheitsproblem oder einen neuen Standard eingehen, den du für relevant hältst. Dadurch zeigst du uns, dass du dich aktiv mit dem Thema auseinandersetzt und für die Position brennst.

Mach deine Leidenschaft deutlich:Da es sich um eine Vollzeitposition handelt, ist es wichtig, dass du uns in deinem Anschreiben zeigst, warum du in der IT-Sicherheit arbeiten möchtest. Erzähl uns von deinen Erfahrungen, wie du zur Cyber-Security gekommen bist und was dich motiviert, in dieser Branche zu arbeiten. Deine Motivation spielt eine große Rolle bei der Auswahl!

Referenzen oder Projekte anfügen:Wenn du bereits an interessanten Projekten gearbeitet hast oder relevante Referenzen hast, die deine Fähigkeiten unterstreichen, füge diese in deine Bewerbung hinzu. Das gibt uns einen Einblick in deine praktische Erfahrung und zeigt, was du wirklich drauf hast. Ein Link zu einem GitHub-Profil oder Sicherheitsanalysen, die du durchgeführt hast, wäre hier super hilfreich!

Wie man sich auf ein Vorstellungsgespräch bei HB Mechanical Group, LLC vorbereitet

Sicherheitsprotokolle dominiert!

Mach dich mit den neuesten Sicherheitsprotokollen und -standards vertraut. Bei HB Mechanical Group, LLC könnte es sein, dass du in technisch anspruchsvollen Fragen zu Netzwerksicherheit und Schwachstellenmanagement gefordert wirst – zeig, dass du die Grundlagen und die aktuellen Trends im Bereich IT-Sicherheit beherrschst!

Praktische Erfahrung zählt!

Bereite dich darauf vor, über frühere Projekte oder Erfahrungen im Bereich IT-Sicherheit zu sprechen. Es ist wichtig, Beispiele zu haben, wie du Sicherheitslücken identifiziert und behoben hast oder welche Tools du verwendet hast, um Systeme abzusichern. HB Mechanical Group, LLC sucht nach jemandem, der die Theorie auch anwenden kann!

Teamarbeit nicht vergessen!

IT-Sicherheit ist oft Teamarbeit. Sei bereit, Fragen zu beantworten, wie du in einem Team umgehst, um Sicherheitsprobleme zu lösen. Denk auch an Beispiel-Situationen, in denen du optimal mit anderen zusammengearbeitet hast – das könnte einen großen Unterschied machen!

Motivation und Lernbereitschaft zeigen!

Da es sich um eine Vollzeitstelle handelt, wird HB Mechanical Group, LLC auch wissen wollen, wie motiviert du bist und welche Schritte du unternimmst, um dein Wissen in der sich ständig weiterentwickelnden Welt der IT-Sicherheit auf dem neuesten Stand zu halten. Das könnte in einem Gespräch über deine Weiterbildung oder zertifikatsbezogenen Pläne relevant sein!