Back to Jobs
GXA IT Consulting
Development 6h ago

Security Engineer

GXA IT Consulting
PakistanPakistan
Full-time
Not Disclosed
Senior-Level

Job Description

Key Skills Required

Master these to land this role

QA Engineer1h 50mFree Trial ✨
Start 10-Day Free Trial
DevOps1h 38mFree Trial ✨
Start 10-Day Free Trial
Backend42mFree Trial ✨
Start 10-Day Free Trial
CybersecurityAutomation Engineer

Want to know if you're a match for this job?

Calculate My Match Score

Key Responsibilities

Incident Response

  • Serve as a Tier 3 escalation point for active security incidents, including business email compromise (BEC), adversary-in-the-middle (AiTM), ransomware, account compromise, identity-based attacks, and other security events.
  • Lead technical analysis during incident response and war room events, including log review, IOC hunting, attacker activity analysis, and lateral movement tracing.
  • Execute containment and eradication actions such as endpoint isolation, session revocation, credential resets, access restriction, and other appropriate remediation actions.
  • Troubleshoot incidents that may span multiple technical layers, including identity, endpoints, servers, networking, cloud services, and security controls, to distinguish security events from underlying infrastructure issues.
  • Coordinate with SOC teams, infrastructure teams, and vendor threat intelligence teams during active investigations and containment efforts.
  • Maintain a calm and methodical approach during high-impact incidents, working through available evidence and technical dependencies rather than relying on assumptions.
  • Communicate clearly during active incidents, including what is known, what has been investigated, what actions have been taken, what is being investigated next, and where additional support is required.
  • Produce accurate incident timelines, technical findings, and evidence packages for vCISO review and client-facing follow-up.

Tool Operations & Security Stack Support

  • Operate daily within the gShield toolstack, including platforms such as Huntress, Microsoft Defender for Endpoint (MDE), Cyrisma, DNSFilter, SIEM, and related security technologies.
  • Perform alert triage, risk identification, scan issue resolution, investigation, and follow-through on issues surfaced by security tools.
  • Support SIEM operations including query development, alert review, log analysis, investigation, and rule tuning.
  • Assist in tuning detection logic, scan settings, and platform effectiveness in coordination with Centralized Services and security leadership.
  • Monitor for security gaps, suspicious activity, configuration weaknesses, and control failures across managed environments.
  • Correlate information across identity, endpoint, network, server, and cloud sources when investigating security issues.
  • Work within established security standards, baselines, and operational policies defined by the security team and vITMs.

Infrastructure & Security Engineering

  • Apply security principles across on-premises, cloud, and hybrid client environments.
  • Troubleshoot security issues involving underlying infrastructure components such as Active Directory, Microsoft Entra ID, Windows servers, endpoints, DNS, networking, firewalls, VPNs, virtualization, and cloud services.
  • Understand how identity, network connectivity, endpoints, servers, cloud platforms, and security controls interact, and use that understanding to troubleshoot complex issues.
  • Support security hardening of Windows, endpoint, identity, network, and cloud environments.
  • Assist with identity and access security including MFA, Conditional Access, privileged access, authentication, authorization, and account security.
  • Support endpoint and server security controls, patching, configuration improvements, and remediation activities.
  • Work effectively with technologies that may be unfamiliar by researching, testing, validating, and documenting appropriate solutions while escalating appropriately when additional expertise is required.

Client Delivery Support

  • Execute technical remediation items identified through MRMMs, preventative actions, vulnerability reviews, and security recommendations.
  • Support gShield deliverables through technical validation, evidence gathering, scan review, vulnerability analysis, and remediation validation.
  • Assess vulnerabilities based not only on severity scores but also on asset criticality, exposure, exploitability, existing controls, and business impact.
  • Work with client and internal technical teams to remediate vulnerabilities and security weaknesses, including identifying appropriate compensating controls when immediate remediation is not possible.
  • Validate remediation and confirm that identified risks have been appropriately addressed.
  • Act as a quality assurance resource for client onboarding into the gShield toolstack, while execution remains with onboarding and Centralized Services teams.
  • Assist with client hardening efforts and follow-through on security improvement actions across managed environments.
  • Support multiple client environments with different infrastructure, configurations, security tools, and levels of technical maturity.

Internal Security Posture

  • Support remediation of internal GXA security backlog items, including POA&M-related work.
  • Assist with rollout and support of phishing-resistant MFA, passkeys, and other internal security initiatives.
  • Contribute to security engineering efforts related to Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Help improve internal security controls, tool effectiveness, and technical enforcement mechanisms.
  • Support security hardening and remediation across internal identity, endpoint, server, network, and cloud environments where needed.

Documentation & Process Improvement

  • Write and maintain security engineering SOPs, runbooks, detection playbooks, troubleshooting procedures, and response procedures related to gShield operations and incident response.
  • Document technical findings, repeatable procedures, remediation steps, and lessons learned from incidents and tool operations.
  • Clearly document what was identified, what actions were taken, why those actions were taken, and what follow-up is required.
  • Collaborate with security leadership and technical stakeholders on process improvements, skill development, and automation opportunities.
  • Contribute technical depth to broader security documentation where needed, while recognizing that ownership of policy, standards, and governance documentation remains with security leadership and related functions.

Qualifications

  • 5–7+ years of experience across cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong technical foundation across IT infrastructure and security, with practical understanding of networking, servers, identity, endpoints, cloud services, and how these technologies interact.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of infrastructure technologies and concepts such as Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Strong hands-on experience with security engineering, threat detection, security operations, incident investigation, or incident response workflows.
  • Experience working with security platforms such as Microsoft Defender, Huntress, DNSFilter, SIEM solutions, vulnerability management tools, and endpoint security technologies.
  • Ability to investigate security alerts, analyze logs, trace attacker activity, determine scope, and support containment and remediation.
  • Familiarity with common attack types including phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Experience supporting security controls within Microsoft 365, Microsoft Entra ID, endpoint, and cloud environments.
  • Understanding of vulnerability management and remediation, including prioritization based on technical severity, exposure, asset criticality, and business risk.
  • Ability to independently troubleshoot technical problems, develop and test hypotheses, identify root causes, and recognize when escalation or additional expertise is appropriate.
  • Ability to remain calm, structured, and methodical during active incidents, outages, and technical escalations, including situations where the root cause is initially unknown.
  • Strong verbal and written communication skills, with the ability to provide concise technical updates explaining current status, actions completed, current investigation, and next steps.
  • Strong documentation skills and ability to write clear technical procedures and findings.
  • Ability to acknowledge knowledge gaps, research unfamiliar technologies, learn quickly, and apply new knowledge safely in production environments.
  • Strong collaboration skills with security, infrastructure, service delivery, leadership, and client stakeholders.

Preferred Qualifications

  • 1-2 years in a Cybersecurity role.
  • Experience in an MSP, MSSP, or multi-client environment.
  • Prior experience in systems administration, network engineering, infrastructure engineering, or a similarly hands-on IT role before or alongside cybersecurity responsibilities.
  • Experience supporting both traditional on-premises infrastructure and cloud environments.
  • Familiarity with Intune, Microsoft Defender, Microsoft Sentinel, AppLocker, ThreatLocker, and RMM-based scripting or automation.
  • Experience with Azure security and infrastructure; AWS or other cloud-platform experience is also valuable.
  • Experience with Windows Server, Active Directory, virtualization platforms such as VMware/Hyper-V, firewall technologies, and network troubleshooting.
  • Understanding of CIS benchmarks, security hardening standards, Zero Trust principles, and configuration drift monitoring.
  • Experience supporting vulnerability remediation and technical aspects of vCISO or managed security programs.
  • Experience with scripting or automation using technologies such as PowerShell, APIs, or RMM platforms.
  • Security certifications such as Security+, CySA+, SC-200, SC-300, AZ-500, GCIH, GCIA, or similar are a plus.
  • Infrastructure/network certifications or equivalent practical experience, such as CCNA, Microsoft infrastructure certifications, Azure Administrator, or similar, are also valuable.

Success in This Role Looks Like

  • Security incidents and technical escalations are handled quickly, accurately, calmly, and with strong technical discipline.
  • The engineer can troubleshoot across security, identity, endpoint, server, network, and cloud layers rather than relying solely on security tools or another technical team.
  • Alerts and risks surfaced by the toolstack are investigated and acted on consistently.
  • Client security remediation items are executed thoroughly, validated, and completed on time.
  • Vulnerabilities are evaluated based on actual risk and business context, and remediation is followed through to completion.
  • gShield tooling is tuned, effective, and operationally reliable.
  • Clients and internal stakeholders receive clear, concise updates during incidents and technical escalations, even when the root cause has not yet been determined.
  • Technical problems are approached methodically, with appropriate investigation, testing, documentation, and escalation when necessary.
  • The engineer demonstrates ownership, curiosity, sound technical judgment, and willingness to learn unfamiliar technologies rather than being limited to a narrow security specialty.
  • Documentation, SOPs, troubleshooting procedures, and response playbooks are clear, useful, and continuously improving.
  • Internal and client security posture improves through strong technical follow-through.

How would you rate this job post?

See what other professionals think about this role.

banner
logo

GXA IT Consulting

View Company Profile

GXA IT Consulting is a premier, award-winning IT services and cybersecurity firm fundamentally designed to act as a strategic technology partner for growth-focused businesses across Texas. Headquartered in Richardson, Texas, the company operates far beyond the traditional Managed Service Provider (MSP) model by delivering a complete "Virtual IT Department." Under the hood, GXA provides businesses with a Virtual Chief Information Officer (vCIO) for high-level technology roadmaps, a Virtual IT Manager (vITM) for daily operational stability, and a vCISO to lead robust security operations through their proprietary gShieldā„¢ framework. Their primary target audience spans highly regulated sectors—including healthcare, financial services, manufacturing, and professional services—typically generating $5M to $100M in revenue, who desperately need predictable IT budgets, SOC 2 Type II attested security, and seamless AI readiness. What sets GXA apart in the crowded IT support landscape is its strategic separation of executive IT leadership from day-to-day operations; ensuring clients receive proactive, visionary guidance instead of reactive helpdesk firefighting, all while driving community transformation through their philanthropic GXA Cares initiatives.

Safety First

  • Never pay for a job application.
  • Do not share sensitive bank info.
  • Verify the client before starting work.
Learn More