GXA

GXA

GXA is an award-winning IT consulting and managed services provider based in Richardson, Texas. With a focus on empowering businesses in Texas, GXA offers a range of IT solutions including managed IT services, business IT consulting, disaster recovery ...

Internet Software & Services
11-50
Founded 2008

Description

  • Serve as a Tier 3 escalation point for security incidents, outages, and complex technical issues.
  • Lead incident analysis through log review, IOC hunting, attacker-activity analysis, and lateral-movement tracing.
  • Execute containment, eradication, and remediation actions, including endpoint isolation, session revocation, credential resets, and access restrictions.
  • Operate and tune the gShield security stack, including Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and related tools.
  • Investigate alerts, vulnerabilities, suspicious activity, configuration weaknesses, and security control failures across client environments.
  • Troubleshoot security and infrastructure issues across identity, endpoints, servers, networks, firewalls, VPNs, virtualization, and cloud services.
  • Execute and validate client remediation, hardening, vulnerability management, and security improvement activities.
  • Support internal security initiatives involving MFA, passkeys, Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Create and maintain incident timelines, evidence packages, SOPs, runbooks, detection playbooks, and technical documentation.
  • Collaborate with SOC, infrastructure, onboarding, Centralized Services, security leadership, vendors, and client stakeholders.

Requirements

  • 5–7+ years of experience in cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong practical understanding of networking, servers, identity, endpoints, cloud services, and their interactions.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Experience with security engineering, threat detection, incident investigation, or incident response workflows.
  • Experience with Microsoft Defender, Huntress, DNSFilter, SIEM, vulnerability management, and endpoint security platforms.
  • Ability to investigate alerts, analyze logs, determine scope, trace attacker activity, and support containment and remediation.
  • Familiarity with phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Strong communication, documentation, collaboration, root-cause analysis, and independent troubleshooting skills.
  • Preferred: MSP/MSSP experience; Intune, Sentinel, AppLocker, ThreatLocker, Azure, PowerShell, APIs, CIS benchmarks, Zero Trust, or relevant security and infrastructure certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Cybersecurity & Software Engineering Specialist (AI Projects)

Gramian Consultancy Group Professional Services

Gramian Consultancy is seeking remote Cybersecurity and Software Engineering Specialists to debug code, identify vulnerabilities, improve backend systems, and provide technical insights for an AI training project.

C++ Cybersecurity Go Java Penetration Testing Python Rust TypeScript
1 day, 18 hours ago

Security Operations Engineer - PCI DSS

teamified.com Hotels, Restaurants & Leisure

A three-month contract Security Engineer will own the PCI DSS v4.0.1 compliance cycle for a cloud-hosted payments platform, implementing controls, preparing evidence, and completing executive sign-off alongside engineering and operations teams.

AWS Encryption JIRA Penetration Testing Secrets Management SIEM
1 day, 18 hours ago

Senior Cloud Security Engineer - AI Resilience & Security Enhancements (Fixed-term contract)

Form3 251-1K Diversified Financial Services

Form3 is hiring a Senior Cloud Security Engineer on a 12-month fixed-term contract to deliver cloud security, resilience, and governance improvements across its cloud-native payments platform.

AWS CI/CD Kubernetes Terraform
2 weeks, 1 day ago

Senior Identity Security Engineer (Remote - LATAM)

Atmosera 51-250 IT Services

Atmosera is seeking a Senior Identity Security Engineer to modernize and secure hybrid Active Directory and Microsoft Entra ID environments while advancing identity governance and Zero Trust initiatives for clients.

Active Directory Azure OAuth PowerShell SAML
3 weeks, 4 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers