Skip to main content
Loading
loadingbar
Loading, Please wait..!!

Security Engineer Level

  • Job type Posted on: Jul 24, 2026
  • Experience level My Tech
  • Employment type Harrisburg, Pennsylvania
  • Employment type Onsite
  • Salary CTC

Point Apply Here APPLY LATER

Curious about compensation?

Explore the historical salary trends, average pay, and estimated compensation for Security Engineer Level roles in Pennsylvania.

View Salary Guide →

Job Title :

Security Engineer Level

Job Type :

CTC

Job Location :

Harrisburg Pennsylvania United States

Remote :

No

Jobcon Logo Job Description :

Job Title: Security Engineer Level 2

Client: Scholorship America
Work Location: Hybrid in Mechanicsburg, PA OR Remote (Note: Remote consultants must be able to work the first 3 days onsite at the Mechanicsburg, PA office).

I. Summary / Purpose

The Security Engineer Level 2 is responsible for assisting with the design, implementation, and maintenance of enterprise security solutions across a hybrid cloud environment (on-premises and cloud). This role proactively strengthens the organization's security posture using NIST, the CIS Critical Security Controls (CIS CSC), SOC 2, and related frameworks.

The Security Engineer serves as a subject-matter expert (SME) on security best practices, compliance requirements, and risk mitigation. This role proactively shares and communicates on Security and Compliance topics within the organization and collaborates cross-functionally with IT, Cloud Operations, Sales, Legal, and executive leadership (including the vCISO) to improve security maturity, respond to customer security requirements, and assist with remediation efforts for vulnerabilities and incidents.

II. Essential Job Functions

Hybrid Cloud Security Architecture & Operations

  • Design, implement, configure, and support security solutions for cloud platforms (Azure, AWS) and on-premises infrastructure.
  • Secure integration of SaaS applications, IAM, SSO/MFA, and privileged access management solutions.
  • Configure and manage firewalls, WAFs, IDS/IPS, EDR, XDR, email security, DLP, MDM, and related tools.
  • Support infrastructure hardening using CIS Benchmarks for Windows, Mac, and Linux systems.
  • Perform regular user access reviews, firewall rule reviews, and security control health checks.
  • Manage security certificates and password vault systems.

Security Monitoring, Vulnerability Management & Incident Response

  • Implement and build out security controls.
  • Monitor logs, dashboards, alerts, network traffic, performance, and ensure data integrity for anomalous activity.
  • Ensure security controls are in place and operational to improve the organization's security posture.
  • Configure and manage core security services such as DLP.
  • Conduct vulnerability scans, assess findings, and implement remediation efforts.
  • Coordinate and assist in annual penetration testing and track remediation of findings.
  • Assist in the investigation and resolution of security incidents in collaboration with the SOC and third-party vendors.
  • Participate in on-call rotation and support incident escalation as needed.
  • Work independently on Security Assessment questionnaires.

Security Governance, Risk & Compliance

  • Develop, maintain, and enforce security policies, standards, and procedures.
  • Support SOC 2, NIST, CIS CSC, ISO, and other compliance initiatives.
  • Lead customer security assessments and coordinate remediation activities.
  • Partner with Sales and Legal teams to review and negotiate security requirements in customer agreements.
  • Prepare documentation and detailed technical responses for RFPs, audits, and client assessments.
  • Assist with third-party vendor risk assessments.

Automation & Continuous Improvement

  • Develop automation scripts (PowerShell, Bash) for patching, compliance validation, and security operations.
  • Apply infrastructure-as-code and automation principles to improve security processes.
  • Continuously evaluate tools, controls, and processes to strengthen security maturity. Recommend strategic improvements to infrastructure security and architecture.

Infrastructure & Systems Security

  • Harden and secure Windows Server and Linux environments.
  • Secure virtualization environments and physical server infrastructure.
  • Configure and secure Dell and Meraki networking equipment.
  • Manage patch management processes and remediation of CVEs.
  • Deploy and manage security features across Active Directory, Group Policy, Exchange/Outlook, and endpoint platforms.

Security Awareness & Training

  • Deliver security awareness programs and phishing simulations (KnowBe4).
  • Provide guidance and training to staff on emerging threats and best practices.
  • Develop security documentation and operational standards.

(Note: These essential and additional job functions are not to be construed as a complete statement of all duties performed. Employees will be required to perform other job-related marginal duties as assigned.)

III. Candidate Skills and Qualifications

Required Skills and Experience:

  • Minimum of 3 years of experience in security engineering or advanced systems administration.
  • 2+ years of IT systems administration experience.
  • Strong knowledge of security frameworks (NIST, CIS CSC, SOC 2, ISO, FedRAMP).
  • Working knowledge in a business setting of:
    • Firewalls, IDS/IPS, EDR, XDR, IAM, SSO/MFA, PAM
    • Vulnerability management and penetration testing tools
    • Email security, DLP, MDM
    • Patch management systems
  • Experience securing hybrid cloud environments (Azure, AWS).
  • Proficiency in PowerShell, Bash, and automation scripting.
  • Ability to analyze logs, dashboards, and network traffic.
  • Strong documentation and communication skills.
  • Highly organized with strong analytical and problem-solving abilities; able to work collaboratively and independently.
  • Ability to drive assigned tasks to completion on time and with a high level of quality and integrity.
  • Demonstrates a strong sense of ownership and accountability for tasks, decisions, and outcomes.
  • Makes sound, timely decisions after considering relevant input to provide recommendations to stakeholders while aligning business objectives and security compliance.

Preferred Skills and Experience:

  • Bachelor's degree in information technology or related field.
  • Security certifications such as AWS Certified Security Specialty, Microsoft AZ-500 + SC-200, GIAC GSEC or GCIH, HashiCorp Terraform Associate, Okta Certified Administrator, or CyberArk Defender.
  • Experience with:
    • Microsoft 365 / Azure AD
    • AWS security services
    • Hyper-V virtualization
    • SQL Server, PostgreSQL, MySQL, MongoDB, Oracle
    • VoIP systems
    • Dell, HP, and Meraki platforms

Jobcon Logo Position Details

Posted:

Jul 24, 2026

Reference Number:

30207-13017

Employment:

CTC

Salary:

Not Available

City:

Harrisburg

Job Origin:

CIEPAL_ORGANIC_FEED

Share this job:

  • linkedin

Jobcon Logo
A job sourcing event
In Dallas Fort Worth
Aug 19, 2017 9am-6pm
All job seekers welcome!

Security Engineer Level    Apply

Click on the below icons to share this job to Linkedin, Twitter!

Job Title: Security Engineer Level 2

Client: Scholorship America
Work Location: Hybrid in Mechanicsburg, PA OR Remote (Note: Remote consultants must be able to work the first 3 days onsite at the Mechanicsburg, PA office).

I. Summary / Purpose

The Security Engineer Level 2 is responsible for assisting with the design, implementation, and maintenance of enterprise security solutions across a hybrid cloud environment (on-premises and cloud). This role proactively strengthens the organization's security posture using NIST, the CIS Critical Security Controls (CIS CSC), SOC 2, and related frameworks.

The Security Engineer serves as a subject-matter expert (SME) on security best practices, compliance requirements, and risk mitigation. This role proactively shares and communicates on Security and Compliance topics within the organization and collaborates cross-functionally with IT, Cloud Operations, Sales, Legal, and executive leadership (including the vCISO) to improve security maturity, respond to customer security requirements, and assist with remediation efforts for vulnerabilities and incidents.

II. Essential Job Functions

Hybrid Cloud Security Architecture & Operations

  • Design, implement, configure, and support security solutions for cloud platforms (Azure, AWS) and on-premises infrastructure.
  • Secure integration of SaaS applications, IAM, SSO/MFA, and privileged access management solutions.
  • Configure and manage firewalls, WAFs, IDS/IPS, EDR, XDR, email security, DLP, MDM, and related tools.
  • Support infrastructure hardening using CIS Benchmarks for Windows, Mac, and Linux systems.
  • Perform regular user access reviews, firewall rule reviews, and security control health checks.
  • Manage security certificates and password vault systems.

Security Monitoring, Vulnerability Management & Incident Response

  • Implement and build out security controls.
  • Monitor logs, dashboards, alerts, network traffic, performance, and ensure data integrity for anomalous activity.
  • Ensure security controls are in place and operational to improve the organization's security posture.
  • Configure and manage core security services such as DLP.
  • Conduct vulnerability scans, assess findings, and implement remediation efforts.
  • Coordinate and assist in annual penetration testing and track remediation of findings.
  • Assist in the investigation and resolution of security incidents in collaboration with the SOC and third-party vendors.
  • Participate in on-call rotation and support incident escalation as needed.
  • Work independently on Security Assessment questionnaires.

Security Governance, Risk & Compliance

  • Develop, maintain, and enforce security policies, standards, and procedures.
  • Support SOC 2, NIST, CIS CSC, ISO, and other compliance initiatives.
  • Lead customer security assessments and coordinate remediation activities.
  • Partner with Sales and Legal teams to review and negotiate security requirements in customer agreements.
  • Prepare documentation and detailed technical responses for RFPs, audits, and client assessments.
  • Assist with third-party vendor risk assessments.

Automation & Continuous Improvement

  • Develop automation scripts (PowerShell, Bash) for patching, compliance validation, and security operations.
  • Apply infrastructure-as-code and automation principles to improve security processes.
  • Continuously evaluate tools, controls, and processes to strengthen security maturity. Recommend strategic improvements to infrastructure security and architecture.

Infrastructure & Systems Security

  • Harden and secure Windows Server and Linux environments.
  • Secure virtualization environments and physical server infrastructure.
  • Configure and secure Dell and Meraki networking equipment.
  • Manage patch management processes and remediation of CVEs.
  • Deploy and manage security features across Active Directory, Group Policy, Exchange/Outlook, and endpoint platforms.

Security Awareness & Training

  • Deliver security awareness programs and phishing simulations (KnowBe4).
  • Provide guidance and training to staff on emerging threats and best practices.
  • Develop security documentation and operational standards.

(Note: These essential and additional job functions are not to be construed as a complete statement of all duties performed. Employees will be required to perform other job-related marginal duties as assigned.)

III. Candidate Skills and Qualifications

Required Skills and Experience:

  • Minimum of 3 years of experience in security engineering or advanced systems administration.
  • 2+ years of IT systems administration experience.
  • Strong knowledge of security frameworks (NIST, CIS CSC, SOC 2, ISO, FedRAMP).
  • Working knowledge in a business setting of:
    • Firewalls, IDS/IPS, EDR, XDR, IAM, SSO/MFA, PAM
    • Vulnerability management and penetration testing tools
    • Email security, DLP, MDM
    • Patch management systems
  • Experience securing hybrid cloud environments (Azure, AWS).
  • Proficiency in PowerShell, Bash, and automation scripting.
  • Ability to analyze logs, dashboards, and network traffic.
  • Strong documentation and communication skills.
  • Highly organized with strong analytical and problem-solving abilities; able to work collaboratively and independently.
  • Ability to drive assigned tasks to completion on time and with a high level of quality and integrity.
  • Demonstrates a strong sense of ownership and accountability for tasks, decisions, and outcomes.
  • Makes sound, timely decisions after considering relevant input to provide recommendations to stakeholders while aligning business objectives and security compliance.

Preferred Skills and Experience:

  • Bachelor's degree in information technology or related field.
  • Security certifications such as AWS Certified Security Specialty, Microsoft AZ-500 + SC-200, GIAC GSEC or GCIH, HashiCorp Terraform Associate, Okta Certified Administrator, or CyberArk Defender.
  • Experience with:
    • Microsoft 365 / Azure AD
    • AWS security services
    • Hyper-V virtualization
    • SQL Server, PostgreSQL, MySQL, MongoDB, Oracle
    • VoIP systems
    • Dell, HP, and Meraki platforms

Loading
Please wait..!!