Sobre este puesto de Senior Cybersecurity Engineer (Azure and GRC heavy) en Hyliion
Hyliion is committed to creating innovative solutions that enable clean, flexible and affordable electricity production. The Company’s primary focus is to develop distributed power generators that can operate on various fuel sources to future-proof against an ever-changing energy economy.
Job Purpose
The Senior Cybersecurity Engineer owns Hyliion’s overall day-to-day cybersecurity operations — endpoint security, identity and Conditional Access, cloud/SaaS security posture, and AI governance — across a cloud-native, Microsoft-centric technology environment. This includes maintaining the System Security Plan (SSP) and control set for Hyliion’s CMMC Level 2 certified enclave, sustaining NIST 800-171 compliance . Beyond the enclave, the role administers Microsoft Entra ID Conditional Access, the Microsoft Defender suite, endpoint management (patching, EDR, and device compliance), our Red Canary Managed Detection and Response (MDR) partnership, and the security and governance of our growing SaaS and enterprise AI footprint across the broader organization.
AI at Hyliion
At Hyliion, AI is core to how we work. We equip every team member with leading AI tools and count on you to use them — to move faster, solve harder problems, and help us realize the full potential of KARNO technology for the world.
Duties and Responsibilities
- Own and maintain Hyliion’s overall day-to-day cybersecurity posture across the enterprise, spanning identity, endpoint, cloud/SaaS, and AI governance.
- Maintain the System Security Plan (SSP) and control implementation for Hyliion’s CMMC Level 2 (C3PAO)-certified enclave, sustaining NIST 800-171 compliance and annual affirmation in SPRS for that defined scope.
- Administer and continuously optimize Microsoft Entra ID (Azure AD) Conditional Access policies, identity protection, and Privileged Identity Management (PIM) to enforce least-privilege and zero-trust principles.
- Own endpoint security end-to-end — patch management, vulnerability remediation, EDR fleet health, and compliance baselines across Windows, macOS, and mobile endpoints — using Microsoft Defender for Endpoint and Intune.
- Manage the broader Microsoft Defender suite (Defender for Office 365, Defender for Cloud Apps, Defender for Identity), including policy tuning, alert triage, and threat response.
- Serve as the primary point of contact for the Red Canary Managed Detection and Response (MDR) partnership, coordinating incident escalations, tuning detections, and reviewing threat intelligence reports.
- Administer Mobile Device Management (MDM)/Intune enrollment, compliance policies, and configuration across corporate and BYOD devices.
- Own security posture and governance across Hyliion’s growing SaaS application footprint (SaaS Security Posture Management), including OAuth/app permission reviews, shadow IT discovery, and third-party app risk assessment.
- Govern the secure and compliant use of enterprise AI platforms — monitoring usage, enforcing acceptable-use and data-handling policies, assessing AI vendor risk, and identifying unsanctioned (“shadow AI”) tool adoption.
- Monitor, triage, and respond to day-to-day cybersecurity incidents and alerts, ensuring timely containment, remediation, and documentation.
- Maintain and update security policies, procedures, and control documentation supporting NIST 800-171, CMMC, SOX IT general controls, and other applicable frameworks.
- Support recurring internal and third-party audits, evidence collection, and control testing, including SOX ITGC, CMMC annual affirmation, and cyber insurance renewal questionnaires.
- Partner with business leaders across departments to assess and mitigate information security risk in new projects, vendor relationships, SaaS adoption, and AI tool deployments.
- Maintain and enhance the executive-level cybersecurity dashboard and reporting cadence, translating technical risk into business-relevant metrics for leadership and the Board Audit Committee.
- Contribute to and maintain the company’s incident response, business continuity, and disaster recovery plans, participating in periodic tabletop exercises.
- Stay current on emerging threats and regulatory changes — including AI/LLM-specific risks (e.g., OWASP Top 10 for LLM applications, data leakage, prompt injection) and DFARS/CMMC/NIST developments — and recommend proactive improvements.
- Additional duties and responsibilities as assigned, needed, or required for the business.
Qualifications
Reasonable accommodation may be made to enable individuals with disabilities to perform the essential functions.
Qualifications include:
- Education, Experience and Certifications
- Bachelor’s degree in Computer Science, Information Systems, or related field.
- 5+ years of IT experience with a focus on cybersecurity operations and compliance.
- CISSP, CISM, Security+, Azure Security Engineer Associate (AZ-500), Microsoft SC-200, or other relevant security certification preferred.
- Skills and Abilities
- Hands-on administration experience with Microsoft Azure/Entra ID, including Conditional Access, Identity Protection, and Privileged Identity Management (PIM).
- Experience with endpoint security operations — patch management, vulnerability remediation, and EDR administration (Microsoft Defender for Endpoint or equivalent).
- Experience managing the Microsoft Defender suite and Microsoft Purview/Compliance Center.
- Experience working with a Managed Detection and Response (MDR) provider (e.g., Red Canary, CrowdStrike), including alert triage and incident response coordination.
- Experience administering MDM/Intune for endpoint compliance and device management.
- Familiarity with SaaS Security Posture Management (SSPM) or CASB concepts and experience securing a cloud-native, SaaS-first technology environment.
- Familiarity with AI/LLM security considerations (e.g., OWASP Top 10 for LLM Applications, data leakage prevention, shadow AI risk) and experience governing enterprise AI tool usage (e.g., Copilot, Claude, ChatGPT Enterprise).
- Working knowledge of NIST 800-171, CMMC 2.0, DFARS, SOX IT general controls, or similar regulatory/compliance frameworks.
- Ability to handle multiple competing priorities in a fast-paced environment.
- Ability to work well under minimal supervision.
- Manufacturing industry experience (preferred).
- Additional duties and responsibilities as assigned, needed, or required for the business.
Role Classification and Working Conditions
This is a salaried, exempt-level position. This position typically works in an office environment; and given the nature of our business is also exposed to operations/warehouses/production environments.
****Sponsorship is not available for this role****
Benefits:
- Medical Plans, with PPO or HDHP options
- Dental Plans, with buy-up option
- Vision Plan
- Life Insurance and Accidental Death & Dismemberment Plans, with buy-up options
- Short Term Disability, paid for by the company
- Long Term Disability, paid for by the company
- Flexible Spending Accounts (FSA)
- Health Savings Account (HSA)
- 401k/Roth 401k
- Voluntary Accident Plans
- Voluntary Critical Illness Plans
- Hospital Indemnity Plan
Hyliion is proud to be an equal opportunity/affirmative action employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, age, disability, veteran status. If a reasonable accommodation is needed to participate in the job application or interview process, to perform essential job functions, and/or to otherwise participate in the employment selection process, please direct your inquires to Hyliion’s human resources department at [email protected].