Dragonfli Group logo
Dragonfli Group

CyberSecurity as a Solution: Enabling Secure Business.

Junior Information System Security Officer

Security EngineerSecurity EngineerFull TimeRemoteJuniorTeam 11-50H1B No SponsorCompany SiteLinkedIn

Location

United States

Posted

3 days ago

Salary

0

Seniority

Junior

Bachelor DegreeEnglishCyber Security

Job Description

Junior Information System Security Officer

Dragonfli Group

• Support RMF lifecycle activities for assigned federal information systems, including categorization, control implementation, assessment, and continuous monitoring, under the guidance of senior team members • Assist in developing and updating system security documentation, including SSPs, Security Assessment Reports (SARs), and POA&Ms • Help track and document security control deviations and vulnerabilities through to closure • Support continuous monitoring activities, including log review and vulnerability scan analysis, alongside senior ISSOs • Assist in maintaining system inventory, hardware/software baselines, and interconnection agreements • Support incident response documentation, escalation tracking, and remediation follow-up • Participate in security reviews, audits, and inspections as part of the broader team • Coordinate with Information System Owners (ISOs) and other stakeholders on routine compliance tasks • Build working knowledge of federal directives including FISMA and OMB A-130 through applied, on-the-job training

Job Requirements

  • 0–2 years of experience in IT, cybersecurity, information assurance, or a related military/government role (direct ISSO experience is not required)
  • Working knowledge of the NIST Risk Management Framework (RMF) and NIST SP 800-53 security controls, gained through training, coursework, or certification study
  • U.S. Citizenship required; must be able to pass a background investigation for a Public Trust position
  • Ability to work remotely and collaborate during core business hours (9am–5pm ET)
  • Strong written communication skills
  • Background in IT, communications, electronics, or a security-adjacent role (Preferred / Nice-to-Have)
  • Exposure to GRC/compliance tools such as eMASS or Xacta (Preferred / Nice-to-Have)
  • Bachelor's degree in IT, cybersecurity, or a related field (or equivalent experience) (Preferred / Nice-to-Have)
  • Prior experience in identity and access management (IAM), credentialing, or access control (Preferred / Nice-to-Have)
  • Familiarity with FISMA and OMB A-130 requirements (Preferred / Nice-to-Have)
  • Active CompTIA Security+ or (ISC)² Certified in Cybersecurity (CC) certification (Preferred / Nice-to-Have)

Benefits

  • Medical — Multiple POS health plan options including an HSA-compatible plan
  • Dental — PPO coverage for preventive, basic, and major services
  • Vision — Annual exam, frames, lenses, and contact lens allowance
  • 401(k) — Employer match up to 5% of eligible compensation
  • Long-Term Disability — 100% employer-paid coverage at 50% of pre-disability earnings
  • Life Insurance & AD&D — 100% employer-paid coverage valued at $10,000 each
  • PTO 11 Paid Federal Holidays

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200H1B No Sponsor

• Own the Region • Build and execute the Nordics go-to-market strategy that drives new business and establishes Upwind as the security platform of choice. • Sell to the Top • Build trusted relationships with CISOs, CTOs, and Heads of Cloud - connecting Upwind's platform to real business outcomes. • Run Full-Cycle Enterprise Deals • Own complex sales cycles start to finish: qualify, evaluate, align stakeholders, close. • Win as a Team • Partner closely with Sales Engineering, Product, and Customer Success to deliver a seamless buying experience. • Expand the Ecosystem • Build relationships with channel partners and cloud providers to extend Upwind's reach across the region. • Forecast with Precision • Run a disciplined pipeline with accurate, data-driven forecasting.

Sweden
Full TimeRemoteTeam 10,001+Since 1903H1B Sponsor

• Driving the organization's certification expansion roadmap, maintaining continuous evidence readiness, and ensuring ongoing internal and external audit preparedness • Directing the end-to-end lifecycle of internal cybersecurity audits and compliance certifications • Developing and executing a multi-year certification roadmap while driving continuous readiness through proactive gap analyses, mock audits, and a centralized evidence repository • Leading enterprise risk assessments, maintaining a continuous risk register with clear mitigation timelines • Partnering cross-functionally with engineering, legal, IT, cybersecurity, and business leadership to embed audit readiness into daily operations • Optimizing GRC tooling to automate compliance processes and streamline evidence collection • Delivering executive-level compliance metrics and risk dashboards that track certification roadmap progress

Michigan
$115.5K - $218.1K / year
Eaton Corporation logo

IT - Incident Response Engineer

Eaton Corporation

Eaton announced, on January 26, 2026, the intent to separate its Mobility Group (including both the Vehicle and eMobility segments) into an independent, publicly traded company. We expect to complete the separation by the end of the first quarter of 2027. The application window for this position is anticipated to close on 2/10/2026. The compensation range for this full-time position includes base pay and target sales performance incentive. This position has a target total compensation range of $120,000.00-$176,000.00. Base salaries are based upon candidate skills, experience, and qualifications, as well as market and business considerations. We are committed to ensuring equal employment opportunities for all job applicants and employees. Employment decisions are based upon job-related reasons regardless of an applicant's race, color, religion, sex, sexual orientation, gender identity, age, national origin, disability, marital status, genetic information, protected veteran status, or any other status protected by law. Eaton believes in second chance employment. Qualified applicants with arrest or conviction history will be considered regardless of their arrest or conviction history, consistent with the Los Angeles County Fair Chance Ordinance, the California Fair Chance Act and other local laws. To request a disability-related reasonable accommodation to assist you in your job search, application, or interview process, please call us at 1-800-836-6345 to discuss your specific need. Only accommodation requests will be accepted by this phone number.

Full TimeRemoteTeam 10,001

Role Description Eaton’s Corporate Sector division is currently seeking an IT - Incident Response Engineer. The expected annual salary range for this role is $113,000 - $165,000 a year. This role can sit out of any US Eaton site; however, remote candidates will be considered. Identify, analyze, and respond to advanced cyber threats and incidents — across on-premises, hybrid, and multi-cloud environments — as a senior member of Eaton's Cyber Security Incident Response Team (CSIRT). Serve as a force-multiplier within the Prevent–Detect–Respond strategy, applying deep incident response and cloud security expertise while advancing the team's next-generation capabilities in agentic AI, automation, detection engineering, and insider threat program. Protect Eaton's intellectual property, operational technology, cloud workloads, and brand across a highly complex, global, multi-technology, regulated, and diversified business environment. This role requires hands-on response capabilities and the aptitude to elevate the broader team's technical maturity. Responsibilities - Responsible for the engineering, health, and continuous improvement of detection and response capabilities across cloud and on-premises estates. - Investigating, analyzing, containing, and remediating cyber threats and security incidents. - Building the automation and AI-enabled tooling that scales the Security Operations Center (SOC). What you'll do: - Provide 24/7/365 (on-call rotation) cyber security incident response. - Respond to, investigate, and resolve information security issues in accordance with compliance, regulatory, and investigative standards. - Manage and coordinate response to malicious cyber activity inside or targeting Eaton's assets. - Perform proactive threat hunting based on emerging indicators of compromise, vulnerabilities, and threat intelligence. - Lead detection, investigation, and response for cloud security incidents across major platforms (Microsoft Azure, AWS, and/or Google Cloud). - Develop and tune cloud-native detections using cloud logging and telemetry. - Apply knowledge of cloud identity and access management, misconfigurations, and cloud attack paths. - Partner with cloud platform and engineering teams to embed security into cloud architecture. - Track threat actors and campaigns relevant to Eaton's industry and geography. - Design, build, and enable agentic AI and automation workflows (SOAR, scripting, AI agents). - Develop and maintain automated playbooks that reduce mean time to detect and respond. - Contribute to securing Eaton's adoption of AI. - Conduct digital forensic analysis and eDiscovery in support of incident response. - Provide security engineering services, including deployment, configuration, management, and updating of the security tool stack. - Develop advanced queries, correlation rules, and detections to enhance the organization's detection coverage. - Contribute to SIEM architecture. Qualifications - Bachelor’s Degree from an accredited institution. - Minimum seven (7) years in security operations, incident response, cloud security, e-Discovery, insider threat, security engineering or related field. - This position requires use of information or access to hardware which may be subject to the International Traffic in Arms Regulations (ITAR). - Must be legally authorized to work in the United States without company sponsorship both now and in the future. Preferred Qualifications - Demonstrated hands-on experience leading or performing cyber security incident response. - Hands-on cloud security experience with one or more major platforms. - Experience correlating events from multiple sources. - Detection engineering experience and SIEM content development and architecture. - Experience building automation and/or agentic AI workflows. - Working knowledge of AI/LLM security concepts. - Emphasis on experience with digital forensics and eDiscovery tools. - Solid understanding of adversary TTPs and the MITRE ATT&CK framework. - Strong analytical and problem-solving skills. Skills - Exceptional communication skills. - Ability to translate complex technical findings into clear, business-relevant language. - Communicate incident status, risk, and impact with accuracy and transparency. - Produce clear, concise written deliverables. - Present confidently and credibly to senior leadership. - Strong project management, multitasking, and organizational skills. Benefits - Various Health and Welfare benefits. - Retirement benefits. - Programs that provide for paid and unpaid time away from work.

United States
$113K - $165K / year
Full TimeRemoteTeam 5,001-10,000H1B No Sponsor

• Partner with engineering teams building Black Duck SCA, Coverity, and adjacent products on architecture reviews, threat models, and security design feedback. • Contribute to a measurable secure development lifecycle covering SCA, SAST, secret scanning (GitGuardian), dependency hygiene, and build pipeline security. • Recommend systematic improvements when patterns emerge across the portfolio rather than relying on one-off fixes. • Triage internally discovered and externally reported product vulnerabilities and help drive resolution with engineering teams. • Coordinate vulnerability fixes with engineering and support customer-facing communications when needed. • Help triage customer security questionnaires, audit requests, and ad hoc product security questions in close partnership with the Director of Security Operations. • Draft technically accurate answers to customer security inquiries; gather evidence from engineering when needed. • Join customer security calls as a subject matter expert when called upon and contribute to a growing knowledge base of reusable responses. • Support detection engineering and incident response activities across the corporate environment, with a focus on issues that intersect with our products. • Maintain and tune detection content in CrowdStrike NG-SIEM and Sumo Logic related to product security risks; help work escalations from our MDR provider (ReliaQuest). • Contribute to SOAR automations and runbooks that reduce manual toil. • Lead discrete workstreams within larger security initiatives or coordinate small project teams where appropriate. • Track projects through Jira with clear milestones and concise status updates; provide technical input into vendor evaluations and POCs across the SecOps and AppSec stack. • Act as an informal resource and mentor for less experienced team members on product security, secure development, and threat modeling. • Explain difficult or sensitive technical information clearly to engineers, security peers, and non-technical stakeholders. • Document tribal knowledge into runbooks, SOPs, and onboarding materials. • Other tasks and activities as assigned.

Canada
$100K - $150K / year