GXA

GXA

GXA is an award-winning IT consulting and managed services provider based in Richardson, Texas. With a focus on empowering businesses in Texas, GXA offers a range of IT solutions including managed IT services, business IT consulting, disaster recovery ...

Internet Software & Services
11-50
Founded 2008

Description

  • Serve as a Tier 3 escalation point for security incidents, outages, and complex technical issues.
  • Lead incident analysis through log review, IOC hunting, attacker-activity analysis, and lateral-movement tracing.
  • Execute containment, eradication, and remediation actions, including endpoint isolation, session revocation, credential resets, and access restrictions.
  • Operate and tune the gShield security stack, including Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and related tools.
  • Investigate alerts, vulnerabilities, suspicious activity, configuration weaknesses, and security control failures across client environments.
  • Troubleshoot security and infrastructure issues across identity, endpoints, servers, networks, firewalls, VPNs, virtualization, and cloud services.
  • Execute and validate client remediation, hardening, vulnerability management, and security improvement activities.
  • Support internal security initiatives involving MFA, passkeys, Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Create and maintain incident timelines, evidence packages, SOPs, runbooks, detection playbooks, and technical documentation.
  • Collaborate with SOC, infrastructure, onboarding, Centralized Services, security leadership, vendors, and client stakeholders.

Requirements

  • 5–7+ years of experience in cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong practical understanding of networking, servers, identity, endpoints, cloud services, and their interactions.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Experience with security engineering, threat detection, incident investigation, or incident response workflows.
  • Experience with Microsoft Defender, Huntress, DNSFilter, SIEM, vulnerability management, and endpoint security platforms.
  • Ability to investigate alerts, analyze logs, determine scope, trace attacker activity, and support containment and remediation.
  • Familiarity with phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Strong communication, documentation, collaboration, root-cause analysis, and independent troubleshooting skills.
  • Preferred: MSP/MSSP experience; Intune, Sentinel, AppLocker, ThreatLocker, Azure, PowerShell, APIs, CIS benchmarks, Zero Trust, or relevant security and infrastructure certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

MEDR Threat Engineer US work hours

Proficio 51-250 Professional Services

Proficio is seeking a Managed EDR Threat Engineer to guide the evolution of its managed endpoint detection, response, visibility, and prevention services while collaborating with engineering, SOC, MDR, sales, and customer teams.

Carbon Black Cybersecurity Linux macOS Network Security PowerShell Python
1 day, 21 hours ago

DevSecOps and Security Compliance Engineer

K.L. Scott & Associates 11-50 Professional Services

K.L. Scott & Associates, LLC is hiring a DevSecOps and Security Compliance Engineer to integrate security into SAP delivery and operations for federal clients while improving deployment controls, addressing vulnerabilities, and maintaining authorization evidence.

CI/CD DevSecOps SAP Secrets Management
1 day, 21 hours ago

Senior Defensive Content Engineer

Hack The Box 51-250 Internet Software & Services

Hack The Box is seeking a Senior Defensive Content Engineer to create and validate cyber ranges, threat-hunting labs, and defensive learning experiences that strengthen enterprise cybersecurity capabilities.

Ansible Linux SIEM Terraform Wireshark
1 day, 21 hours ago

Senior Security Engineer, Customer Transparency

Tanium 1K-5K Internet Software & Services

Tanium is hiring a Senior Security Engineer for its Customer Transparency team to improve visibility into Tanium’s security posture, manage vulnerability disclosure, and address customer security needs.

CI/CD Encryption Git
2 days, 21 hours ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers