Haystack
← Back to Jobs
Technology
QU

Cyber Security Engineer

QualibarAtlanta, GA🇺🇸United StatesPosted Sep 17, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Atlanta, GA, United States
Posted
22 hours ago
ShellPCI DSSSOC 2TCP/IPActive DirectoryAzureDNSPenetration TestingVault

Job Description

Position :Cyber Security Engineer

Client: Mansfield Energy

Location: Gainesville, Georgia

Position Summary

Mansfield Energy is seeking a Cyber Security Engineer to join the Infrastructure organization and work alongside the Network and Security team. The technical work is primary: this is a hands-on engineering seat, not a policy desk. The person in this position will help harden a distributed enterprise environment that spans corporate offices, remote sites, and cloud workloads, and will spend most of their time configuring, tuning, and defending the controls that protect it.

Around that engineering core the role carries three further responsibilities. It owns the technical side of our audit and certification readiness, so the person who configures a control is also the one who can produce the evidence for it. It partners with development and platform teams on secure delivery pipelines and modern application practices. And it brings an offensive mindset to the environment, validating our defenses through testing rather than assuming they hold.

The role reports to the Manager of Network and Security and works closely with systems engineering, network engineering, and application teams. We are looking for an engineer who is comfortable owning a problem end to end, communicating clearly with non-security colleagues, and improving the environment steadily rather than waiting for a project to be handed over.

Key Responsibilities

Security Operations and Incident Response

·        Monitor, triage, and investigate security alerts from endpoint, email, identity, and network telemetry, escalating and driving containment when an event is confirmed.

·        Lead or support incident response activities including scoping, containment, eradication, recovery, and written post-incident review.

·        Build and tune detection rules, dashboards, and alerting in the SIEM to reduce false positives and shorten time to detection.

·        Investigate reported phishing and social engineering attempts and coordinate user notification and remediation.

Infrastructure and Network Security

·        Configure and maintain perimeter and internal security controls, including next-generation firewalls, VPN and remote access, IDS and IPS, web and DNS filtering, and network segmentation.

·        Administer endpoint detection and response tooling across servers and workstations, including policy design, exclusions, and response actions.

·        Secure cloud and hybrid workloads, with emphasis on Microsoft 365 and Azure configuration baselines, conditional access, logging, and tenant hardening.

·        Harden and maintain Linux servers alongside Windows systems, covering baseline configuration, access control, patching, and host-level logging across both platforms.

·        Support identity and access management practices including privileged access controls, multifactor authentication, and periodic access reviews.

·        Partner with network and systems engineers on architecture reviews so that security requirements are designed into new infrastructure rather than retrofitted.

Vulnerability Management and Penetration Testing

·        Run recurring vulnerability scans, interpret results, prioritize by real-world risk rather than raw severity, and drive remediation to closure with the owning teams.

·        Perform internal penetration testing and adversary-style validation against networks, applications, and identity paths, and reproduce findings well enough to prove impact.

·        Scope, coordinate, and act on third-party penetration tests and red team engagements, translating each report into tracked remediation work with owners and dates.

·        Track patch and configuration compliance across the estate and report on trends, exceptions, and residual risk.

Secure Development and Pipeline Security

·        Work with development and platform teams to embed security controls into CI/CD pipelines, including dependency and container scanning, static and dynamic analysis, and build integrity checks.

·        Establish and enforce secrets management practices so that credentials, keys, and tokens are stored in a vault rather than in code, configuration files, or pipeline variables.

·        Review infrastructure as code and cloud deployment templates against hardening baselines, and help teams remediate insecure defaults before they reach production.

·        Advise on application and API security, including authentication patterns, authorization boundaries, and common web vulnerability classes, and support secure design review for new services.

Audit, Compliance, and Certification Readiness

·        Own the technical side of internal and external security audits: gather and validate evidence, produce configuration and log extracts, and answer assessor questions directly rather than routing them elsewhere.

·        Prepare the environment for security certification and attestation work, mapping existing controls to the applicable framework, identifying the gaps, and driving the remediation needed to close them.

·        Complete customer and partner security questionnaires and support insurance and regulatory reviews with accurate, current technical detail.

·        Maintain a continuous state of audit readiness through recurring control testing and self-assessment, so that a scheduled audit is a confirmation rather than a scramble.

Governance, Documentation, and Awareness

·        Maintain runbooks, standards, network and data-flow documentation, and evidence needed for internal and customer security reviews.

·        Contribute to security awareness efforts, including simulated phishing campaigns and practical guidance for end users.

·        Support business continuity and disaster recovery planning and participate in tabletop and recovery exercises.

Required Qualifications

·        Four or more years of hands-on experience in information security, network engineering, or systems engineering with substantial security responsibility.

·        Demonstrated production experience with enterprise firewalls and VPN, endpoint detection and response, and email security controls.

·        Working knowledge of TCP/IP, routing and switching, DNS, VLANs, and network segmentation, with the ability to read a packet capture and reason about traffic.

·        Practical experience securing Microsoft environments: Active Directory, Entra ID, Microsoft 365, and Windows Server.

·        Hands-on Linux and UNIX administration and hardening, including shell fluency, SSH and key management, service and file permissions, system logging, and patching.

·        Experience with vulnerability management tooling and with driving remediation across teams that do not report to you.

·        Understanding of penetration testing methodology and common offensive tooling, sufficient to validate a finding and reproduce it rather than only read the report.

·        Working familiarity with CI/CD pipelines and modern delivery practices, including source control workflow, build automation, containers, and secrets handling.

·        Direct experience supporting security audits or a certification effort, including evidence collection, control mapping, and working with external assessors.

·        Familiarity with a recognized security framework such as NIST CSF, CIS Controls, or ISO 27001, and the ability to translate a control into a concrete configuration change.

·        Clear written and verbal communication, including the ability to explain risk and remediation to business stakeholders and to write an audit-quality narrative.

·        Willingness to participate in an on-call rotation and to respond outside business hours during a security incident.

Preferred Qualifications

·        Bachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.

·        Additional certifications such as OSCP, CySA+, GCIH, GCIA, GWAPT, CISSP, CISA, or a vendor certification in the firewall or endpoint platform they have used.

·        Experience carrying an organization through a formal certification such as ISO 27001, SOC 2, or a comparable attestation from readiness assessment to audit.

·        Hands-on Azure security experience, including conditional access, Defender for Cloud, and log analytics.

·        Experience securing a mixed estate where Linux and Windows systems share authentication and logging, or with Linux-based network and security appliances.

·        Scripting or automation skill for reporting, log parsing, pipeline integration, and repetitive response tasks.

·        Experience with DevSecOps tooling in a real pipeline, such as dependency scanning, container image scanning, or policy as code.

·        Experience in energy, fuel distribution, logistics, or another operationally distributed industry.

·        Exposure to OT or industrial control environments, or to card and payment data requirements such as PCI DSS.

What Success Looks Like in the First Year

Within the first ninety days the engineer should understand our environment well enough to own alert triage end to end and to close the highest-risk items already on the vulnerability backlog. By the end of the first year we expect measurable improvement in four areas: faster and better documented incident handling, a smaller and steadily shrinking backlog of critical and high findings, audit and certification evidence that can be produced on request rather than assembled under pressure, and security checks running inside our delivery pipelines instead of being applied after release.

Candidate Screening Notes

We would rather see depth than a long list of tool names. Strong candidates should be able to walk through an incident or a penetration test they personally worked, describe what the telemetry or the exploit path showed, and explain what they changed afterward to prevent a repeat. Audit, compliance, and offensive security exposure are all genuinely valued here, but they have to sit on top of engineering depth. Please screen out candidates whose experience is limited to policy authorship, questionnaire completion, or ticket routing without direct configuration ownership.

Similar jobs