GXA

GXA

GXA is an award-winning IT consulting and managed services provider based in Richardson, Texas. With a focus on empowering businesses in Texas, GXA offers a range of IT solutions including managed IT services, business IT consulting, disaster recovery ...

Internet Software & Services
11-50
Founded 2008

Description

  • Serve as a Tier 3 escalation point for security incidents, outages, and complex technical issues.
  • Lead incident analysis through log review, IOC hunting, attacker-activity analysis, and lateral-movement tracing.
  • Execute containment, eradication, and remediation actions, including endpoint isolation, session revocation, credential resets, and access restrictions.
  • Operate and tune the gShield security stack, including Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and related tools.
  • Investigate alerts, vulnerabilities, suspicious activity, configuration weaknesses, and security control failures across client environments.
  • Troubleshoot security and infrastructure issues across identity, endpoints, servers, networks, firewalls, VPNs, virtualization, and cloud services.
  • Execute and validate client remediation, hardening, vulnerability management, and security improvement activities.
  • Support internal security initiatives involving MFA, passkeys, Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Create and maintain incident timelines, evidence packages, SOPs, runbooks, detection playbooks, and technical documentation.
  • Collaborate with SOC, infrastructure, onboarding, Centralized Services, security leadership, vendors, and client stakeholders.

Requirements

  • 5–7+ years of experience in cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong practical understanding of networking, servers, identity, endpoints, cloud services, and their interactions.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Experience with security engineering, threat detection, incident investigation, or incident response workflows.
  • Experience with Microsoft Defender, Huntress, DNSFilter, SIEM, vulnerability management, and endpoint security platforms.
  • Ability to investigate alerts, analyze logs, determine scope, trace attacker activity, and support containment and remediation.
  • Familiarity with phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Strong communication, documentation, collaboration, root-cause analysis, and independent troubleshooting skills.
  • Preferred: MSP/MSSP experience; Intune, Sentinel, AppLocker, ThreatLocker, Azure, PowerShell, APIs, CIS benchmarks, Zero Trust, or relevant security and infrastructure certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

IAM Architect - Saviynt

IDMWORKS 51-250 Professional Services

IDMWORKS is hiring an IAM Architect - Saviynt to design and deliver identity and access management solutions that strengthen security and support access control across enterprise environments.

Active Directory Cybersecurity OAuth SAML
2 days, 1 hour ago

IT Administrator (Google Workspace & Rippling)

Concierge Auctions 51-200 real estate

Concierge Auctions is hiring a remote IT Administrator to manage core internal systems and help build a unified company-wide access control layer for its cloud-based, luxury real estate business.

DHCP DNS macOS Notion Python Salesforce
3 days, 2 hours ago

Cloud Engineer I/II - (W2PE) - Remote

Trace3 1K-5K Internet Software & Services

Trace3 is hiring a Cloud Engineer I/II to support government cloud migration and modernization work from a remote, clearance-required environment.

Active Directory AWS Docker EC2
3 weeks, 4 days ago

Network Security Engineer (Cyber Focus)

Red Canyon Engineering & Software 51-250 Aerospace & Defense

Red Canyon is seeking a Network Engineer with a cyber security focus to support technical operations, network hardening, and compliance work for space-related and government programs.

Ansible AWS Cisco Cybersecurity Terraform
3 weeks, 4 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers