Haystack
← Back to Jobs
Technology
EM

Senior Information Security Engineer

EmployVisionGarland, TX🇺🇸United StatesPosted Oct 5, 2026

Quick Overview

Seniority
Mid Senior
Work mode
Hybrid
Location
Garland, TX, United States
Posted
3 days ago
EncryptionMFAPCI DSSSOC 2Active DirectoryAzure

Job Description

Security Engineer, Information Security

Position Overview

Location: Garland, TX 75041

We are seeking an experienced Security Engineer with 10+ years of information security experience to strengthen and protect the organization’s corporate security environment. Reporting to the Head of IT and CISO, this is a highly hands-on role responsible for designing, implementing, monitoring, and operating security controls across endpoints, networks, identity, Microsoft 365, Azure, cloud, and data environments.

The ideal candidate will be able to translate security strategy into practical day-to-day protection by hardening systems, detecting and responding to threats, managing vulnerabilities, strengthening access controls, and supporting compliance across a multi-location environment with 75+ branches.

Key Responsibilities

<>Security Engineering & Architecture

  • Design, implement, and maintain security controls across network, endpoint, identity, email, and cloud environments.

  • Secure and manage Microsoft 365, Azure, Active Directory, and Exchange environments.

  • Manage firewalls, VPNs, network segmentation, and secure remote-access solutions.

  • Establish security standards, configuration baselines, and system-hardening guidelines.

  • Assess new technologies, vendors, systems, and infrastructure changes for security risks.

<>Threat Detection & Incident Response

  • Monitor and investigate security alerts using SIEM, EDR, log-monitoring, and other security tools.

  • Triage security events and lead or support incident response activities from containment through root-cause analysis.

  • Develop, maintain, and test incident-response playbooks and escalation procedures.

  • Monitor emerging threats and apply relevant threat intelligence to improve security defenses.

<>Vulnerability & Patch Management

  • Conduct regular vulnerability assessments and prioritize findings based on risk.

  • Partner with infrastructure, desktop, and application teams to drive timely remediation.

  • Monitor patching and configuration compliance across the environment.

  • Coordinate penetration tests and security assessments and ensure findings are tracked through resolution.

<>Identity, Access & Data Protection

  • Strengthen IAM, MFA, privileged access, conditional access, and RBAC controls.

  • Support encryption, data-loss prevention, and secure email/file-sharing solutions.

  • Improve security across Office 365 and SharePoint environments.

  • Conduct periodic access reviews and maintain appropriate account lifecycle controls within Active Directory.

<>Governance, Risk & Compliance

  • Develop and maintain information security policies, standards, procedures, and documentation.

  • Support audits, customer security questionnaires, and regulatory/compliance requirements.

  • Maintain security evidence and ensure documentation remains audit-ready.

  • Partner with the Head of IT and CISO to maintain a security risk register and drive remediation of identified gaps.

  • Apply security frameworks and best practices such as NIST CSF, CIS Controls, and ISO 27001.

<>Security Awareness & Business Partnership

  • Support security awareness training and phishing simulation programs.

  • Partner with IT, HR, Finance, Legal, and business leadership on security initiatives.

  • Communicate technical risks and recommendations clearly to both technical and non-technical stakeholders.

  • Evaluate and manage security technologies and vendors as directed by IT leadership.

Key Success Measures

  • Reduction in time required to remediate critical vulnerabilities.

  • Improved patch and security-configuration compliance.

  • Reduction in outstanding security risks and audit findings.

  • Faster detection, investigation, and response to security incidents.

  • Consistent security controls across endpoints, network, identity, and cloud.

  • Successful completion of incident-response exercises and security assessments.

  • Strong audit and compliance results.

  • Increased MFA and access-control coverage.

  • Improved security-awareness and phishing-simulation results.

Required Qualifications

  • 10+ years of information security experience, including hands-on security engineering.

  • Strong knowledge of cybersecurity, infrastructure security, and information security principles.

  • Experience with NIST CSF, CIS Controls, ISO 27001, or comparable security frameworks.

  • Hands-on experience with:

    • Firewalls and network security

    • Endpoint security/EDR

    • Microsoft 365 and Azure

    • Active Directory and Exchange

    • SIEM and security log monitoring

    • Vulnerability management

    • Incident response

    • Identity and access management

    • MFA and RBAC

  • Strong analytical, communication, and stakeholder-management skills.

  • Bachelor’s degree in Information Technology, Cybersecurity, or related field, or equivalent experience.

  • Relevant certifications such as CISSP, CISM, Security+, or GIAC are preferred.

Preferred Qualifications

  • Experience supporting multi-branch or multi-location organizations.

  • Experience with SOC 2, PCI DSS, ISO 27001, or similar compliance programs.

  • Background in distribution, technology, telecommunications, or related industries.

  • Microsoft security certifications or other relevant cybersecurity certifications.

Ideal Candidate

  • Hands-on security engineer who can design, implement, and operate security controls.

  • Practical and risk-focused, balancing security requirements with business needs.

  • Calm and decisive during security incidents.

  • Strong communicator who can translate technical security risks into clear business terms.

  • Takes ownership, drives remediation, and collaborates effectively across IT and business teams.

Similar jobs