Apply Edge Start your job search

Cyber Security Engineer

Gotham Technology Group · New York, NY

Apply & track with Apply Edge
Security EngineerLocation: NYC hybrid schedule (3 days on-site), Will consider remote candidatesFull-Time role for an Investment Management firm About the RoleSecurity Engineer to help build, enforce, and mature security controls across our clients endpoint, identity, and cloud environments. This is a hands-on engineering role for someone with genuine security depth who understands not just how to configure a platform, but why a control matters, how an attacker would attempt to bypass it, and how to validate that security controls are working effectively.The primary focus of this role is endpoint and device security, including securing devices with Intune, hardening endpoints, controlling browser security, and eliminating standing local administrator rights. The role also extends into identity and access management, Azure cloud security, email security, vulnerability remediation, and incident response, providing the opportunity to contribute to the growth and maturity of the organization's security program.This position is for someone with a dedicated, hands-on security engineering background within an enterprise environment and has developed deep technical expertise in a corporate environment rather than supporting a large number of client environments.Exciting initiatives:Take ownership of reviewing, maintaining, and enhancing existing Conditional Access policies.Develop and execute a prioritized vulnerability remediation plan in partnership with infrastructure teams.Implement browser security improvements, strengthen endpoint protections, and reduce standing local administrator privileges across the environment.ResponsibilitiesDesign, implement, and maintain endpoint security controls by hardening Microsoft Defender for Endpoint, configuring attack surface reduction (ASR) rules, implementing CIS-aligned security baselines, and managing configuration drift.Develop and enforce browser security policies for Microsoft Edge and Google Chrome, including browser configuration, extension management, download restrictions, and other controls to reduce browser-based threats.Implement least-privilege strategies by eliminating standing local administrator access through Microsoft LAPS and endpoint privilege management solutions while maintaining user productivity.Define and manage device compliance policies within Microsoft Intune and integrate compliance requirements with Conditional Access to ensure only trusted devices can access corporate resourcesDesign, test, deploy, and maintain Microsoft Entra Conditional Access policies, including report-only deployments, policy optimization, exception management, and ongoing governanceSupport the rollout and expansion of phishing-resistant authentication methods such as FIDO2 security keys, Windows Hello for Business, and certificate-based authentication while helping migrate users away from legacy MFA methodsStrengthen Microsoft Entra ID security by improving authentication methods, identity protection, and access controlsImprove Azure security posture through Microsoft Defender for Cloud and Secure Score by identifying and remediating security misconfigurationsDevelop and enforce secure configuration standards across Azure and Microsoft cloud servicesConfigure and optimize Microsoft Defender for Office 365 security controls, including anti-phishing, Safe Links, Safe Attachments, impersonation protection, and email threat preventionSupport security incident response activities by assisting with triage, containment, remediation, access revocation, and corrective actions while working closely with an external managed detection and response (MDR) providerPartner with infrastructure and application teams to prioritize and remediate security vulnerabilities while validating that remediation efforts effectively reduce organizational riskParticipate in security projects from planning through implementation and validation while contributing to the development of security standards, documentation, hardened baselines, and repeatable operational processesQualifications4+ years of hands-on experience in a dedicated information security roleStrong understanding of security fundamentals including Zero Trust, defense-in-depth, least privilege, identity security, and common attacker techniquesHands-on experience with Microsoft security technologies including Microsoft Intune, Microsoft Defender for Endpoint, Microsoft Defender for Office 365, Microsoft Defender for Cloud, Microsoft Entra ID, and Conditional AccessExperience implementing endpoint hardening, browser security, vulnerability remediation, and identity security controlsFamiliarity with CIS Benchmarks, the MITRE ATT&CK Framework, and detection engineering conceptsStrong analytical, troubleshooting, and problem-solving skills with the ability to quickly learn new technologiesExperience supporting security initiatives and/or participating in technical security projectsExperience working with managed detection and response (MDR) or security operations center (SOC) providersAt least one Security certification such as; Security+, CISSP, SC-200, SC-300, AZ-500, or other security certifications are preferred but not required