Manage your virtual, in-person, and hybrid events seamlessly with the world’s only insight-driven platform.
Cybersecurity Engineer
Location
Utah
Posted
3 days ago
Salary
0
Seniority
Senior
Job Description
Cybersecurity Engineer
RainFocus
• Safeguard organization's digital assets and ensure information systems' confidentiality, integrity, and availability. • Identify and mitigate security vulnerabilities. • Monitor security incidents. • Contribute to developing security policies and procedures.
Job Requirements
- All candidates must be a US citizen.
- 3–5 years of dedicated experience in a technical cybersecurity role (e.g., Security Engineer, AppSec Engineer, or Senior Security Analyst, etc.).
- Strong familiarity with the OWASP Top 10, web application security testing, and reviewing secure code dependencies (SCA).
- Proven experience running enterprise vulnerability scanners, interpreting results, and driving remediation across cross-functional teams.
- Foundational knowledge of cloud environments (specifically AWS) and securing cloud-native applications.
- Excellent collaboration skills with ability to understand developers' goals and help fix security bugs.
Benefits
- Competitive salaries
- Competitive benefits
- 401k
- Generous PTO
- Countless team building activities
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Perform holistic tabletop reviews covering both technical and non-technical risk across OT environments • Analyze for areas of negative impact, high risk, and single points of failure (SPOF) within sensitive, legacy networks • Identify vulnerabilities and weaknesses across Operational Technology environments, including Industrial Control Systems (ICS), SCADA, and field devices • Assess legacy and sensitive networks where conventional testing methods carry unacceptable operational risk • Support OT clients with security program improvements, identifying which critical controls are needed • Contribute to the maturity of Packetlabs' OT testing methodology and practice • Help raise the standard of OT security work across the firm
• Collaborate with Security Engineering and Infrastructure teams to identify, remediate, and prevent security, configuration, and architectural issues across the customer's Active Directory environment.
• Plan and execute end-to-end hardware penetration tests on embedded and IoT devices, against a defined scope and rules of engagement • Identify, access, and exploit on-board debug interfaces: JTAG, SWD, UART, and similar, to gain code execution or memory access • Extract firmware via debug ports, in-circuit flash reads (SPI / I2C / NAND), or chip-off when required, and analyze it for vulnerabilities • Intercept and analyze data on common embedded buses (SPI, I2C, UART, CAN, USB) using logic analyzers and protocol decoders • Where in scope, perform side-channel analysis and fault injection (power analysis, voltage/clock glitching) to bypass secure boot, readout protection, or authentication • Reverse engineer firmware and embedded binaries (Ghidra, IDA, Binwalk, etc.) to find logic flaws, hardcoded secrets, and exploitable conditions • Assess physical attack surface, tamper resistance, and key/secret storage • Write high-quality technical reports and present findings to client stakeholders, both technical and non-technical • Advise on practical, prioritized remediation that clients can act on • Build and maintain lab tooling, test rigs, and internal methodology • Help raise the standard of hardware security work across the firm
Microsoft Security Engineer
GuidePoint SecurityWe help organizations make smarter cybersecurity decisions that minimize risk.
Role Description We are seeking a security first, Microsoft focused engineer to join our Microsoft Cloud Security Team. This role will be primarily delivering hands-on security engagements for clients ranging from small businesses to large enterprises. Your work centers on Microsoft Entra ID (identity and access management) and Microsoft Purview (data protection), with supporting work in Intune and Defender XDR. You'll partner with architects and principal consultants across varied industries and environments. You'll own your technical delivery independently (80% billable target), managing your time and communication within assigned engagements, and contribute to internal practice and knowledge-sharing efforts between projects. Roles and Responsibilities - Identity & Access (Entra ID / AD): - Design and implement identity architecture, hybrid sync (Entra Connect), Conditional Access, MFA/passwordless, and identity governance (PIM, RBAC, access reviews, entitlement management). - Integrate applications via SSO (SAML/OIDC), enterprise app registrations, and SCIM provisioning. - Investigate and remediate identity risks using Entra ID Protection, sign-in and audit logs; drive hybrid identity hygiene (stale object cleanup, privileged account reduction, tiered admin models). - Data Security & Compliance (Purview): - Design and implement sensitivity labels, DLP, and retention policies across M365; support data classification, information protection rollouts, and data security posture assessments. - Support eDiscovery, Insider Risk Management, communication compliance, and AI data security readiness (DSPM for AI) as engagements require. - Intune & Defender XDR: - Configure device compliance, configuration profiles, and app deployments across platforms; support Defender for Endpoint, Office 365, Identity, and Cloud Apps in cloud and hybrid environments. - Other duties as assigned. - Adhere to GuidePoint Security Core Values. Qualifications - Bachelor’s degree preferred. - 2–5 years in IT administration, identity management, or security operations. - Hands-on production experience with Microsoft Entra ID and on-premises Active Directory, including Conditional Access, MFA, RBAC, and hybrid identity (Entra Connect). - Knowledge of core authentication protocols: SAML, OAuth 2.0/OIDC, Kerberos, LDAP. - Experience implementing Microsoft Purview (sensitivity labels, DLP, retention, or eDiscovery) and comfort supporting Intune and Defender XDR. - Basic PowerShell scripting for automation and reporting (e.g., Microsoft Graph PowerShell). - Strong troubleshooting skills, attention to detail, and clear written and verbal communication. - Embraces emerging technologies, including AI tools, to work smarter, solve problems, and drive better business outcomes. Preferred Experience - Advanced AD work: multi-domain/forest design, migrations, tiered administration, legacy auth cleanup. - Microsoft Sentinel: log onboarding, detection development, or broader SIEM/SOAR experience. - Azure infrastructure and security (Azure Policy, network security, landing zones, RBAC). - SharePoint Online governance, Teams Voice, Power BI/Fabric, or Copilot Studio/Azure AI Foundry experience. Travel Requirements - This role is 100% remote requiring less than 10% travel for corporate events. Physical Requirements - Sedentary work. - Substantial movement of the wrists, hands, and/or fingers for a minimum of 8 hours a day. - Required to have close visual acuity to view computer terminal and/or extensive reading for a minimum of 8 hours a day. Benefits - Remote workforce primarily (U.S. based only, some travel may be required for certain positions, working on-site may be required for Federal positions). - Group Medical Insurance options: Zero Deductible PPO Plan (GuidePoint pays 90% of the premium for employees and 70% for family plans) or High Deductible Health Plan with HSA (GuidePoint pays 100% of the employees premiums and 75% for family plans). - Group Dental Insurance: GuidePoint pays 100% of the premium for employees and 75% of family plans. - 12 corporate holidays and a Flexible Time Off (FTO) program. - Healthy mobile phone and home internet allowance. - Eligibility for retirement plan after 2 months at open enrollment. - Pet Benefit Option.



