Sobre este puesto de IT Cybersecurity Engineer en Vulcan Elements
Vulcan Elements is manufacturing American rare-earth permanent magnets for a secure, resilient future. With a focus on national security and economic resiliency, we serve critical industries such as defense, aerospace, and automotive powering a high-technology future. Vulcan Elements is building a team of ambitious professionals committed to Mission Focus, Technical Excellence and Integrity.
As an IT Cybersecurity Engineer, you will be a hands-on member of our security team, responsible for deploying, tuning, and operating the tools and controls that protect Vulcan Elements’ IT environment. You will also support our NIST SP 800-53 (Low-Impact Baseline) assessment and Plan of Action and Milestones (POA&M, working alongside our external compliance partner and our existing NIST SP 800-171/CMMC program. This role is a strong fit for someone who wants to build and run real security tooling day to day while also gaining exposure to federal compliance frameworks in a regulated manufacturing environment.
Responsibilities
- Deploy, configure, and operate core security tooling including SIEM, endpoint detection and response (EDR), vulnerability scanning, and email/web security controls.
- Administer and harden identity systems (Active Directory/Entra ID), and enforce MFA, least-privilege access, just-in-time access, and Conditional Access policies across IT systems.
- Run regular vulnerability scans, prioritize findings, and drive remediation with system owners; track exceptions and compensating controls.
- Monitor security alerts, investigate and triage incidents, and lead or support incident response and root cause analysis for IT systems.
- Support the assessment of IT controls against the NIST SP 800-53 Low-Impact Baseline, help build and maintain the System Security Plan (SSP), and contribute to the Plan of Action and Milestones (POA&M).
- Coordinate with our external CMMC compliance partner to keep IT security controls consistent across NIST SP 800-171 (CMMC Level 2) and NIST SP 800-53, avoiding duplicate or conflicting work.
- Own patch management and secure configuration baselines for servers, endpoints, and network devices.
- Provide security review and input on new IT systems, applications, and vendor tools before they go into production.
- Maintain security procedures, playbooks, network/data flow diagrams, and audit evidence.
- Support delivery of security awareness training to personnel with access to CUI or other sensitive systems.
- Partner with Automation, Engineering, and OT teams to build security into new production lines and control system upgrades from the start.
Responsibilities and tasks outlined are not exhaustive and may change as determined by the needs of the business.
Qualifications
- 3+ years of hands-on IT security engineering experience (security operations, security engineering, or systems administration with a strong security focus).
- Strong knowledge of Azure Active Directory/Entra ID and Windows/endpoint security hardening.
- Working knowledge of NIST SP 800-53 and/or NIST SP 800-171/CMMC; experience contributing to a System Security Plan (SSP) or POA&M is a strong plus.
Must be a U.S. Person due to required access to U.S. export-controlled information or facilities.
Desired Skills
- Working knowledge of ISA/IEC 62443, NIST SP 800-82, and NIST SP 800-53; experience contributing to an SSP or POA&M for OT systems is a strong plus.
- Prior experience in a defense contractor, federal contractor, or CHIPS/DoD-funded environment.
- CompTIA Security+, GSEC, CySA+, or similar; CCP (Certified CMMC Professional) a plus.