SlipstreamJobs tracks this role from the company's public career site. Apply directly on the employer's site.
Vulcan Elements manufactures American rare-earth permanent magnets for defense, aerospace, and automotive industries with a focus on national security and economic resilience. As an IT Cybersecurity Engineer, you will be a hands-on member of the security team responsible for deploying, tuning, and operating security tools and controls that protect the company's IT environment.
You will deploy, configure, and operate core security tooling including SIEM, endpoint detection and response (EDR), vulnerability scanning, and email/web security controls. You will administer and harden identity systems (Active Directory/Entra ID), enforce MFA, least-privilege access, just-in-time access, and Conditional Access policies across IT systems. You will run regular vulnerability scans, prioritize findings, and drive remediation with system owners while tracking exceptions and compensating controls.
You will monitor security alerts, investigate and triage incidents, and lead or support incident response and root cause analysis for IT systems. You will support assessment of IT controls against the NIST SP 800-53 Low-Impact Baseline, help build and maintain the System Security Plan (SSP), and contribute to the Plan of Action and Milestones (POA&M). You will coordinate with external CMMC compliance partners to keep IT security controls consistent across NIST SP 800-171 (CMMC Level 2) and NIST SP 800-53.
Additional responsibilities include owning patch management and secure configuration baselines for servers, endpoints, and network devices; providing security review and input on new IT systems, applications, and vendor tools before production deployment; maintaining security procedures, playbooks, network/data flow diagrams, and audit evidence; supporting delivery of security awareness training to personnel with access to CUI or other sensitive systems; and partnering with Automation, Engineering, and OT teams to build security into new production lines and control system upgrades.
REQUIREMENTS:
- 3+ years of hands-on IT security engineering experience (security operations, security engineering, or systems administration with a strong security focus)
- Strong knowledge of Azure Active Directory/Entra ID and Windows/endpoint security hardening
- Working knowledge of NIST SP 800-53 and/or NIST SP 800-171/CMMC; experience contributing to a System Security Plan (SSP) or POA&M is a strong plus
- Must be a U.S. Person due to required access to U.S. export-controlled information or facilities
DESIRED SKILLS:
- Working knowledge of ISA/IEC 62443, NIST SP 800-82, and NIST SP 800-53; experience contributing to an SSP or POA&M for OT systems is a strong plus
- Prior experience in a defense contractor, federal contractor, or CHIPS/DoD-funded environment
- CompTIA Security+, GSEC, CySA+, or similar; CCP (Certified CMMC Professional) a plus