Security Engineer (Remote)

Remote in Dodgeville, WI, US • Posted 2 days ago • Updated 1 hour ago
Full Time
On-site
Fitment

Dice Job Match Score™

🔢 Crunching numbers...

Job Details

Skills

  • Dependability
  • Service Desk
  • Legal
  • Communication
  • Root Cause Analysis
  • Data Quality
  • Security Controls
  • Design Review
  • Messaging
  • Emerging Technologies
  • Reporting
  • Normalization
  • Data Deduplication
  • Security Management
  • Orchestration
  • Threat Analysis
  • ROOT
  • Recovery
  • Licensing
  • Multi-factor Authentication
  • Authentication
  • Risk Management
  • IT Risk Management
  • IT Risk
  • Testing
  • Due Diligence
  • Collaboration
  • Security Architecture
  • Auditing
  • Leadership
  • Mentorship
  • Analytics
  • Onboarding
  • Network
  • Enterprise Networks
  • Virtual Private Network
  • Dragon NaturallySpeaking
  • DNS
  • TLS
  • Routing
  • Proxies
  • Windows PowerShell
  • Python
  • JSON
  • Change Management
  • Documentation
  • PCI DSS
  • Sarbanes-Oxley
  • Privacy
  • Palo Alto
  • Firewall
  • Microsoft
  • ServiceNow
  • Microsoft Azure
  • Microsoft Office
  • Email Security
  • Cloud Computing
  • Management
  • SIEM
  • Dashboard
  • Vulnerability Management
  • Workflow
  • Retail
  • Electronic Commerce
  • Data Security
  • High Availability
  • Cyber Security
  • Information Technology
  • Computer Science
  • Security Engineering
  • Security Operations
  • Incident Management
  • Cloud Security
  • Network Security
  • Security+
  • GCIH
  • GCIA
  • CISSP

Summary

This role is eligible to be performed remotely, however, if you reside within 60 miles of Lands' End's office in Dodgeville, WI or New York City, you will be expected to collaborate onsite in a hybrid fashion for up to 12 days per month.

The Security Engineer is a hands-on technical role responsible for designing, implementing, operating, and continuously improving security controls across cloud, identity, endpoint, email, network, data, and hybrid infrastructure. The engineer converts security requirements and threat scenarios into dependable configurations, detections, automations, investigations, and documented operating procedures.

This role partners with Infrastructure, Network, Cloud, IAM, Microsoft 365, Application, Service Desk, Legal, Privacy, Audit, and third-party providers. Success requires disciplined ownership, sound judgment, technical curiosity, clear communication, and the ability to move work from initial intake through validation, implementation, evidence collection, and closure.

Primary Outcomes

  • Improved visibility and reduced detection latency for high-impact identity, privilege, endpoint, email, cloud, and network threats.
  • Secure, supportable, and well-documented configurations for enterprise security platforms and integrations.
  • Timely, evidence-based incident triage, investigation, containment coordination, root-cause analysis, and follow-through.
  • Consistent security review of technology changes, firewall requests, cloud deployments, identity changes, and production releases.
  • Automation that reduces manual effort, improves data quality, and strengthens repeatability without compromising control or auditability.
  • Clear technical ownership, current documentation, defensible change records, and measurable operational health.

Security Engineering and Architecture

  • Design, implement, maintain, and improve security controls aligned with Zero Trust, least privilege, defense-in-depth, secure-by-default, and risk-based design principles.
  • Provide security design review and technical consultation for cloud, network, identity, endpoint, messaging, data protection, application, and hybrid infrastructure initiatives.
  • Translate business, regulatory, and architectural requirements into practical security configurations, standards, baselines, and implementation plans.
  • Participate in major technology projects and changes early enough to identify security dependencies, rollback needs, logging requirements, and control gaps before production implementation.
  • Evaluate emerging technologies and recommend improvements based on business value, operational supportability, threat reduction, integration fit, and total cost.

Detection Engineering, SIEM and Security Automation

  • Engineer and optimize Microsoft Sentinel data connectors, analytics rules, incident creation logic, automation rules, workbooks, watchlists, and Logic Apps or SOAR playbooks.
  • Develop and maintain KQL queries for alerting, threat hunting, operational monitoring, troubleshooting, evidence collection, and security reporting.
  • Validate source telemetry, connector health, ingestion gaps, parsing, normalization, rule execution, alert grouping, deduplication, and escalation paths.
  • Tune detections using documented threat scenarios, severity, expected detection latency, false-positive analysis, query performance, and analyst workload.
  • Automate repeatable security administration and response activities with PowerShell, KQL, APIs, and approved orchestration capabilities while preserving approvals and audit trails.

Incident Response and Threat Investigation

  • Triage and investigate alerts from Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Mimecast, Palo Alto Networks, identity platforms, and other enterprise sources.
  • Correlate identity, endpoint, network, cloud, email, application, and threat-intelligence telemetry to determine scope, impact, chronology, and likely root cause.
  • Coordinate containment, eradication, recovery, evidence preservation, and escalation with internal teams, vendors, and managed security partners.
  • Document investigative steps, queries, screenshots, findings, decisions, affected assets, communications, and remediation actions in the designated incident record.
  • Lead or support high-severity incidents and after-action reviews, including lessons learned, detection improvements, procedure updates, and assigned follow-up actions.
  • Participate in an on-call or after-hours rotation as required for significant security events and approved production changes.

Security Platform Operations

  • Administer and improve controls across Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Microsoft Entra ID, Microsoft Purview, Mimecast, Palo Alto Networks firewalls and Panorama, and related security technologies.
  • Monitor platform health, integration status, licensing or capacity constraints, privileged access, configuration drift, policy exceptions, and vendor escalations.
  • Review and validate firewall and connectivity requests, including source, destination, port, protocol, direction, business purpose, data sensitivity, segmentation, logging, ownership, and rollback requirements.
  • Support identity security capabilities such as Conditional Access, MFA, Identity Protection, privileged access, access governance, service-account controls, and investigation of anomalous authentication activity.
  • Partner with platform owners to address endpoint coverage, cloud posture findings, vulnerability exposure, unsupported systems, and telemetry gaps.

Vulnerability, Change and Risk Management

  • Analyze vulnerability and exposure data, validate technical risk, coordinate remediation with system owners, and track material findings through closure or approved risk acceptance.
  • Provide security subject-matter expertise for standard, normal, and emergency changes; verify testing, implementation evidence, and post-change validation.
  • Support third-party security reviews and technical due diligence by identifying integration risks, required controls, logging expectations, access boundaries, and remediation needs.
  • Escalate material control weaknesses, unsupported technology, recurring operational failures, and accepted risks through established governance channels.

Documentation, Audit Support and Collaboration

  • Create and maintain security architecture records, standards, procedures, runbooks, playbooks, diagrams, configuration baselines, control narratives, and knowledge articles.
  • Produce complete and timely ServiceNow records, change documentation, investigation notes, evidence packages, and status updates that can withstand operational and audit review.
  • Support internal and external assessments involving PCI DSS, SOX, NIST, privacy obligations, and other applicable requirements by supplying accurate technical evidence and remediation updates.
  • Communicate technical findings and recommendations clearly to engineers, service owners, leadership, auditors, and business stakeholders.
  • Mentor developing team members, share investigative methods, and contribute to a unified operating model with clear handoffs, ownership, and follow-through.

Skills

  • Hands-on experience with an enterprise SIEM and security analytics, including query development, log-source onboarding, detection tuning, alert investigation, and operational health monitoring.
  • Practical experience investigating security events across two or more domains such as identity, endpoint, email, network, cloud, applications, or data.
  • Working knowledge of Microsoft cloud and security technologies, including Microsoft Sentinel, Defender XDR, Entra ID, Azure, Microsoft 365, or Purview.
  • Working knowledge of enterprise network security concepts, including firewalls, segmentation, VPNs, DNS, TLS, routing, ports and protocols, proxy technologies, and traffic analysis.
  • Ability to script or automate technical work using PowerShell, KQL, Python, APIs, JSON, or comparable tools.
  • Experience with incident, request, problem, and change-management practices, including accurate ticket documentation and validation of completed work.
  • Understanding of NIST security principles and experience supporting regulated or audited environments such as PCI DSS, SOX, privacy, or comparable control frameworks.
  • Ability to communicate risk, investigation findings, and technical recommendations to both technical and non-technical audiences.

Qualifications

  • Hands-on experience with Microsoft Sentinel, Microsoft Defender XDR, CrowdStrike Falcon, Palo Alto Networks firewalls or Panorama, Mimecast, Microsoft Entra ID, Microsoft Purview, and ServiceNow.
  • Experience with Azure security engineering, hybrid identity, Microsoft 365 security, email security, cloud posture management, or data protection capabilities.
  • Experience building SIEM or SOAR content, custom parsers, automation playbooks, threat-hunting queries, operational dashboards, or detection-as-code practices.
  • Experience with vulnerability-management platforms and remediation workflows in a large or complex enterprise.
  • Experience in retail, ecommerce, payment environments, customer-data protection, or high-availability digital services.

Education & Experience Requirements

  • Bachelor's degree in cybersecurity, information technology, computer science, engineering, or a related field, or equivalent practical experience.
  • At least 4 years of progressive experience in security engineering, security operations, incident response, cloud security, network security, or a closely related technical discipline.
  • Relevant certifications such as SC-200, AZ-500, SC-300, SC-400, PCNSE, Security+, GCIH, GCIA, CISSP, or comparable technical credentials.

Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities

This employer is required to notify all applicants of their rights pursuant to federal employment laws.
For further information, please review the Know Your Rights notice from the Department of Labor.
Employers have access to artificial intelligence language tools (“AI”) that help generate and enhance job descriptions and AI may have been used to create this description. The position description has been reviewed for accuracy and Dice believes it to correctly reflect the job opportunity.
  • Dice Id: 10255428
  • Position Id: 51be60a178e61d45a16ca8baa59bebe0
  • Posted 2 days ago
Create job alert
Set job alertNever miss an opportunity! Create an alert based on the job you applied for.

Similar Jobs

Texas

Today

Full-time

Texas

Today

Full-time

USD 110,000.00 - 120,000.00 per year

Remote or Hybrid

Today

Easy Apply

Full-time

$160000 - $200000 per annum

Remote

Today

Full-time

USD 150,000.00 per year

Search all similar jobs