Jobs Companies Nash Plumbing & Mechanical Cybersecurity Engineer

Über diese Cybersecurity Engineer Stelle bei Nash Plumbing & Mechanical

Nash Plumbing & Mechanical · Remote · Remote - Pennsylvania
This position will report to HB Mechanical Group, LLC, a subsidiary of HB Global.

We empower our employee owners to make this a great place to work and create value.

SUMMARY: The Cybersecurity Engineer is HB Global's dedicated, hands-on owner of cybersecurity operations and engineering across the enterprise. Reporting to the Director of IT, who owns the enterprise security strategy, and partnering with third-party solution architects where specialized design is required, this role translates strategy into working, well-managed security controls. It is a true generalist position: on any given week the engineer performs day-to-day threat hunting, monitoring, and incident response, then implements, configures, and manages the tools that protect the organization. This position operates in a multi-division enterprise environment in which divisions maintain autonomy in business decisions; the Cybersecurity Engineer maintains consistent enterprise security standards while adapting to each division's needs and supporting the integration of newly added business units.

To be successful you must possess these core value characteristics:

Trust: Clear Communication. Be committed. Accountable. Open. Honest.

Team: No "I". Do what's best. Assume the best. Be a leader. Celebrate wins.

Grit: Goal-focused. Be positive. Persevere. Show passion. Take ownership.

Growth: Lifelong learner. Forward-thinker. Self-aware. Curious. Open-minded.

WORK SCHEDULE & TRAVEL:

This is a full-time position with benefits. The role is a hybrid Remote–On Site position; we prefer candidates within driving distance of the HB Mechanical Group office in Camp Hill, PA or the Tamarac, FL office, and will consider strong candidates residing anywhere in the U.S. Eastern time zone. Hours may vary according to business needs. Occasional travel between HB Global offices and divisional worksites may be required. On-call availability for security incidents and urgent requests is required.

ESSENTIAL DUTIES and RESPONSIBILITIES:

Threat Detection, Hunting & Response

  • Perform day-to-day threat hunting, monitoring, and alert triage across the CrowdStrike Falcon platform (EDR, NG-SIEM, and Identity Threat Protection).
  • Investigate, contain, and remediate security incidents end to end; perform root-cause analysis and document findings and lessons learned.
  • Tune detections, correlation rules, and alerting to reduce noise and improve fidelity.
  • Monitor and respond to email-borne threats and user-reported phishing through Mimecast, managing quarantine and policy tuning.

Security Engineering, Implementation & Configuration

  • Implement, configure, and maintain security controls across Microsoft Azure and on-premises systems, coordinating with third-party architects on solution design where required.
  • Administer identity and access security across Microsoft Entra ID / Active Directory, Okta, Microsoft 365, and Google Workspace, enforcing least privilege, MFA, and conditional access.
  • Manage endpoint protection and DNS-layer security (Cisco Umbrella), and support network security policy on Cisco Meraki in partnership with the Senior Network Administrator.
  • Own vulnerability management, including scanning, prioritization, and coordinating remediation within the IT team.
  • Partner with the Senior Systems Administrator — who administers our data protection and recovery tools (Druva, Veeam) — to validate and test backup integrity and to participate in disaster-recovery testing.
  • Manage the secrets and password platform (1Password) and champion strong credential hygiene across the organization.

Security Operations & Management

  • Maintain security configuration standards and hardening baselines aligned to the strategy set by leadership.
  • Plan, track, and report on security initiatives using Zoho Projects.
  • Manage day-to-day relationships with security vendors and managed-service providers, holding third parties accountable to their commitments.
  • Own the Mimecast security-awareness program, including scheduling and managing quarterly awareness trainings and quarterly phishing simulations, and reporting on progress and completion rates.

Reporting, Metrics & Executive Communication

  • Produce clear, regular reporting on the organization's overall cybersecurity posture, translating technical detail into concise summaries for leadership and executive audiences.
  • Pull and correlate data from across the security stack — CrowdStrike (EDR, NG-SIEM, Identity Threat Protection), Mimecast, Cisco Umbrella and Meraki, identity, and vulnerability tools — into clear, easy-to-understand reports and dashboards.
  • Define and track key security metrics and KPIs (such as detection and response times, vulnerability remediation, patch status, and phishing-test results) and report on trends over time.
  • Provide on-demand snapshots of the current security state and clearly communicate risks, priorities, and recommendations to non-technical stakeholders.

Business Partnership & Business-Unit Integration

  • Partner with multiple semi-autonomous divisions to deliver consistent security protections, adapting engagement and communication to each division's operational needs while maintaining enterprise standards and governance.
  • As HB Global grows and brings new business units into the organization, onboard and standardize their security controls to HB Global's baseline.
  • Assess the security posture of incoming environments and build practical plans to consolidate identity, endpoint, email, network, and backup protections.

Governance & Collaboration

  • Support compliance, audit, and cyber-insurance requirements with clear evidence and documentation.
  • Partner with leadership to turn security strategy into hands-on execution, and flag risks and priorities as they emerge.
  • Partner closely with the Senior Network Administrator — who is responsible for network security — to validate network security controls and to provide backup and cross-coverage for the network security function.

Other

  • Perform other duties as assigned

EDUCATION, EXPERIENCE and SKILLS:

Education

  • High School Diploma
  • BA/BS in Information Technology, Computer Science, Cybersecurity, or equivalent experience
  • Relevant security certifications and continuing education preferred

Experience (Required)

  • 5+ years of hands-on experience in cybersecurity engineering, security operations, or a blended security/IT role.
  • Demonstrated ability to both build and operate security controls with minimal supervision as a security generalist.
  • Hands-on experience with EDR/endpoint security and SIEM (CrowdStrike strongly preferred).
  • Strong identity and access management experience (Entra ID / Active Directory, Okta, MFA, conditional access).
  • Experience securing Microsoft 365 and cloud environments (Microsoft Azure).
  • Practical incident-response and threat-hunting experience, with solid networking and firewall fundamentals.
  • Experience working with outside security vendors/managed services and coordinating deliverables to timelines and quality expectations.

Skills & Technical Knowledge

  • Working knowledge of security frameworks and best practices (e.g., NIST Cybersecurity Framework, CIS Controls) and the ability to enforce data/access security policies.
  • Scripting and automation ability (PowerShell and/or Python) for routine tasks and tool integrations.
  • Strong analytical and problem-solving skills; able to communicate clearly with technical and non-technical stakeholders.
  • Ability to pull data from multiple security platforms and present the organization's security posture in clear reports and dashboards for executive, non-technical audiences.
  • Extensive knowledge of Microsoft Entra ID / Active Directory, Microsoft 365, and Azure security.
  • Familiarity with email security, DNS security, and backup/disaster-recovery concepts.
  • Familiarity with confidentiality requirements related to IT operations and network information.

PREFERRED QUALIFICATIONS:

  • Industry certifications such as CISSP, SSCP, CompTIA Security+/CySA+, GIAC (GCIH, GCIA), or CrowdStrike / Microsoft Azure security certifications.
  • Direct experience with our stack: CrowdStrike, Mimecast, Cisco Meraki, Cisco Umbrella, Druva, Veeam, Google Workspace, Okta, and 1Password.
  • Experience standardizing security across multiple sites or business units within a growing, multi-entity organization.
  • Experience integrating or supporting newly added business units.
  • Experience in a multi-division or federated IT/security environment.

PHYSICAL REQUIREMENTS:

  • Prolonged periods sitting at a desk and working on a computer
  • Must be able to lift up to 15 pounds at times
  • Ability to travel to divisions and worksites as needed
Bereit, sich bei Nash Plumbing & Mechanical zu bewerben?
Bei Nash Plumbing & Mechanical bewerben

Über Nash Plumbing & Mechanical

Nash Plumbing & Mechanical, LLC. was founded on humble beginnings in 1974 by George J. Nash and his two sons George and Cliff. The company that was once intended to earn a living for Nash's newly relocated family is now celebrating over 50 years in the industry with three generations of family leadership. What started as a one-truck operation now provides employment for 300 Employee-Owners and is one of the largest and most trusted plumbing and mechanical contractors in the Southeastern United States. Our mission is to make Nash a great place to work and create value for our Employee-Owners. Nash Plumbing & Mechanical is a division of HB Mechanical Group.

Alle Jobs bei Nash Plumbing & Mechanical ansehen →

Ähnliche Jobs

Accela
Cybersecurity Engineer
Accela
⚡ Früh bewerben Remote Based - US · standortgebunden $90,000–$110,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Support Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, United States Vor Ort $94,000–$94,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Support Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, Canada Vor Ort $118,600–$118,600
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Coalition, Inc.
Senior Security Analyst
Coalition, Inc.
⚡ Früh bewerben Any location, Canada Vor Ort $118,600–$118,600
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Virtru
Security Governance Risk & Compliance (GRC) Analyst
Virtru
⚡ Früh bewerben Washington, DC - Remote · standortgebunden $130,000–$170,000
● Neu 👁 Gesehen ✓ Beworben vor 1 Tg.
Pinterest
Security GRC Analyst
Pinterest
⚡ Früh bewerben San Francisco, CA, US; Remote,... · standortgebunden $123,696–$254,667
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
Twilio
Senior Analyst, Security Risk
Twilio
⚡ Früh bewerben Remote - Canada · standortgebunden $99,760–$124,700
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
CACI
Cybersecurity Assessment Data Analyst
CACI
⚡ Früh bewerben Remote (Any State) · standortgebunden $90,300–$189,600
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.
CO
HR Data Security Sr. Analyst (Workday)
Cox
⚡ Früh bewerben REMOTE - USA · standortgebunden $81,400–$122,000
● Neu 👁 Gesehen ✓ Beworben vor 2 Tg.

Registrieren für Vorschläge, die auf die von Ihnen geöffneten Jobs und gespeicherten Suchen zugeschnitten sind.

Mehr Jobs bei Nash Plumbing & Mechanical

Alle Jobs bei Nash Plumbing & Mechanical ansehen →

Jetzt bewerben
🤖

Moment — langsam

JobsRadar wurde für echte Menschen gebaut, die eine schwere Zeit bei der Jobsuche haben — nicht für automatisierte Anfragen. Sie klicken viel zu schnell und sind jetzt vorübergehend blockiert.

Kommen Sie später wieder. Wenn Sie wirklich auf Jobsuche sind, stehen wir hinter Ihnen — verhalten Sie sich einfach wie ein Mensch.

Catch your next role the second it’s posted.

Create a free account and we’ll watch the boards for you — the instant a job matches your search, it lands in your inbox or Telegram. No digging, no refreshing.

Create free account

Free forever · takes 30 seconds · already have one?

Verschaffe dir einen Vorsprung bei der Jobsuche.

Tritt unserem Telegram-Kanal bei für das, was dir hilft, die Stelle zu bekommen — Gehaltsbenchmarks, den wöchentlichen Marktpuls und neue Feature-Drops. Kein Spam, nur Signal.

Dem Kanal beitreten — kostenlos