Title : Cyber Security Engineer
Location : Houston, TX - Onsite
Type : Contract to Hire
Sector : Energy
About the Role
We are seeking a skilled and proactive Cyber Security Engineer to join our growing security team. You will design, implement, and maintain security controls that protect our organizations networks, systems, cloud environments, and sensitive data from evolving cyber threats.
Key Responsibilities
- Design, deploy, and manage security tools and technologies (firewalls, IDS / IPS, SIEM, EDR / XDR, WAF, vulnerability scanners, etc.)
- Perform security architecture reviews and provide actionable recommendations for new systems and applications
- Conduct threat modeling, risk assessments, and security hardening of infrastructure (on-prem and cloud : AWS, Azure, GCP)
- Respond to and investigate security incidents; perform digital forensics when needed
- Lead or contribute to penetration testing, red / blue / purple team exercises
- Develop and automate security processes using scripting (Python, PowerShell, Bash) and infrastructure-as-code (Terraform, Ansible, etc.)
- Monitor, analyze, and respond to security alerts from SIEM and other detection systems
- Implement and maintain identity & access management controls (MFA, RBAC, Zero Trust principles)
- Create and update security policies, standards, and procedures
- Collaborate with DevOps, engineering, and IT teams to integrate security into the SDLC (DevSecOps)
- Stay current with emerging threats, vulnerabilities (CVEs), and industry best practices
- Participate in compliance efforts (SOC 2, ISO 27001, NIST, GDPR, HIPAA, PCI-DSS, etc., as applicable)
Required Qualifications
Bachelors degree in Computer Science, Information Security, or equivalent experience25+ years of hands-on experienceStrong knowledge of network security, operating systems (Windows, Linux), and cloud securityProficiency with security tools such as Splunk, CrowdStrike, Palo Alto, Tenable / Nessus, Qualys, Burp Suite, Metasploit, etc.Experience with scripting / automation (Python strongly preferred)Solid understanding of security frameworks (NIST CSF, MITRE ATT&CK, CIS Controls, Zero Trust)Relevant certifications (at least one required; more are a plus) : CISSP, CCSP, CEH, OSCP, CompTIA Security+, GSEC, GIAC (GCIH, GCIA, GNFA, etc.), AWS / Azure / GCP security certifications