Cybersecurity Engineer
Indexed description
About the Company
Nordis Technologies helps businesses modernize how they communicate and get paid. Through our innovative customer communications management and payment solutions, we enable organizations to deliver critical communications across print, digital, email, SMS, and payment channels with greater efficiency, compliance, and customer engagement. Headquartered in Coral Springs, Florida, Nordis has been a trusted technology and communications partner since 1990.
About the Role
The Cybersecurity Engineer is responsible for the design, implementation, administration, and continuous improvement of cybersecurity controls across a hybrid technology environment that includes private cloud infrastructure, Microsoft Azure, enterprise endpoints, and multiple operating locations. The role safeguards organizational systems, data, and technology assets through proactive risk management, security operations, incident response, vulnerability management, and regulatory compliance activities. This position serves as a subject matter expert for cybersecurity technologies and practices and provides technical leadership in maintaining a secure, compliant, and resilient operating environment. The role directly supports security and compliance obligations associated with frameworks such as SOC 2, PCI DSS, HIPAA, NIST, and other applicable regulatory or contractual requirements.
Responsibilities
Security Operations & Incident Response
- Monitor, analyze, investigate, and respond to cybersecurity threats, alerts, and incidents across cloud, endpoint, network, email, and application environments.
- Lead technical incident response activities, including containment, remediation, recovery, and post-incident analysis.
- Administer and optimize security monitoring, detection, and response capabilities to improve threat visibility and reduce organizational risk.
- Serve as a senior technical escalation resource for security incidents and managed security service providers.
- Maintain incident response procedures, playbooks, and testing exercises to support organizational preparedness.
Security Architecture, Infrastructure & Cloud Protection
- Implement and maintain security controls across Microsoft Azure, private cloud environments, and enterprise infrastructure.
- Administer identity and access management controls, including Multifactor Authentication (MFA), Conditional Access, privileged access management, and access review processes.
- Support network security architecture, including firewalls, VPNs, segmentation, secure remote access, and related security technologies.
- Evaluate new technologies, architectural changes, and third-party integrations to ensure alignment with cybersecurity requirements and risk management objectives.
Vulnerability Management & Security Engineering
- Manage enterprise vulnerability management programs, including assessment, prioritization, remediation tracking, validation, and reporting.
- Oversee endpoint and server patch management processes across operating environments.
- Develop automation, workflows, and technical solutions that improve operational efficiency and security effectiveness.
- Enhance logging, monitoring, telemetry, and security visibility through integration and optimization of security platforms and tools.
Compliance, Audit & Risk Management
- Implement and operate technical controls supporting compliance with applicable regulatory, customer, and security framework requirements.
- Develop and maintain security documentation, standards, procedures, control evidence, and technical diagrams.
- Support internal audits, external audits, client assessments, and remediation initiatives.
- Participate in enterprise risk assessments, vendor security reviews, and customer security due diligence activities.
- Develop and communicate security metrics, risk indicators, and compliance reporting to leadership.
Stakeholder Partnership & Security Awareness
- Provide cybersecurity guidance and consultation to technical and business stakeholders.
- Promote security best practices through awareness initiatives, training, and ongoing collaboration.
- Partner with infrastructure, application, operations, compliance, and leadership teams to support secure business operations and technology initiatives.
Technology Environment
The role supports and administers security controls within environments that may include:
- Microsoft Azure
- Private cloud infrastructure
- CrowdStrike
- Rapid7 SIEM/MDR
- Abnormal AI
- Automox
- Microsoft Entra ID / Active Directory
- Microsoft Defender Suite
- Microsoft Intune
- Microsoft Purview
- Enterprise networking and remote access technologies
- Additional security platforms and monitoring tools as assigned
Qualifications
Required Qualifications
- Minimum five (5) years of progressive experience in cybersecurity, security engineering, or security operations.
- Current Certified Information Systems Security Professional (CISSP) certification.
- Experience administering enterprise security technologies, including EDR, SIEM, vulnerability management, and identity security platforms.
- Working knowledge of Microsoft security technologies, cloud security principles, and enterprise infrastructure security.
- Experience supporting security and compliance frameworks such as SOC 2, PCI DSS, HIPAA, NIST CSF, ISO 27001, or similar standards.
- Knowledge of networking and information security principles, including TCP/IP, DNS, firewalls, VPNs, segmentation, and access controls.
- Experience with scripting, automation, or security process optimization using PowerShell, Python, or similar technologies.
- Strong analytical, problem-solving, communication, and documentation skills.
- Ability to participate in an on-call rotation and satisfy applicable background screening requirements.
Preferred Qualifications
- Bachelor's degree in Information Security, Computer Science, Information Technology, or a related discipline; equivalent experience may be considered.
- Experience supporting SaaS, healthcare, financial services, payments, or other regulated industries.
- Experience working with managed detection and response (MDR) providers.
- Experience supporting geographically distributed or multi-site environments.
- Exposure to security automation, SOAR technologies, cloud-native security controls, and infrastructure-as-code security practices.
Create a free Caio profile to unlock more results and save your role and location preferences.
Unlock free search