GXA

GXA

GXA is an award-winning IT consulting and managed services provider based in Richardson, Texas. With a focus on empowering businesses in Texas, GXA offers a range of IT solutions including managed IT services, business IT consulting, disaster recovery ...

Internet Software & Services
11-50
Founded 2008

Description

  • Serve as a Tier 3 escalation point for security incidents, outages, and complex technical issues.
  • Lead incident analysis through log review, IOC hunting, attacker-activity analysis, and lateral-movement tracing.
  • Execute containment, eradication, and remediation actions, including endpoint isolation, session revocation, credential resets, and access restrictions.
  • Operate and tune the gShield security stack, including Huntress, Microsoft Defender for Endpoint, Cyrisma, DNSFilter, SIEM, and related tools.
  • Investigate alerts, vulnerabilities, suspicious activity, configuration weaknesses, and security control failures across client environments.
  • Troubleshoot security and infrastructure issues across identity, endpoints, servers, networks, firewalls, VPNs, virtualization, and cloud services.
  • Execute and validate client remediation, hardening, vulnerability management, and security improvement activities.
  • Support internal security initiatives involving MFA, passkeys, Intune, Defender, ThreatLocker, AppLocker, and RMM scripting.
  • Create and maintain incident timelines, evidence packages, SOPs, runbooks, detection playbooks, and technical documentation.
  • Collaborate with SOC, infrastructure, onboarding, Centralized Services, security leadership, vendors, and client stakeholders.

Requirements

  • 5–7+ years of experience in cybersecurity, security engineering, infrastructure engineering, network engineering, security operations, or related technical roles.
  • Strong practical understanding of networking, servers, identity, endpoints, cloud services, and their interactions.
  • Hands-on experience troubleshooting on-premises, cloud, or hybrid environments.
  • Working knowledge of Active Directory, Windows Server, DNS, DHCP, TCP/IP, routing, switching, VLANs, VPNs, firewalls, and virtualization.
  • Experience with security engineering, threat detection, incident investigation, or incident response workflows.
  • Experience with Microsoft Defender, Huntress, DNSFilter, SIEM, vulnerability management, and endpoint security platforms.
  • Ability to investigate alerts, analyze logs, determine scope, trace attacker activity, and support containment and remediation.
  • Familiarity with phishing, BEC, account compromise, ransomware, identity-based attacks, and endpoint compromise.
  • Strong communication, documentation, collaboration, root-cause analysis, and independent troubleshooting skills.
  • Preferred: MSP/MSSP experience; Intune, Sentinel, AppLocker, ThreatLocker, Azure, PowerShell, APIs, CIS benchmarks, Zero Trust, or relevant security and infrastructure certifications.

Interested in this position?

Apply directly on the company website

Apply Now

Similar Roles

Security Engineer

Chainguard 51-250 Internet Software & Services

Chainguard is hiring a Security Engineer for its Cyber Resiliency team to strengthen company-wide information security, support compliance, and enable low-friction protection against cyber threats.

Go Linux macOS Python Shell Scripting
38 minutes ago

Senior Detection Engineer

DoorDash 10K-50K Air Freight & Logistics

DoorDash is hiring a Senior Detection Engineer to help build and operate detection engineering for its global cyber defense function across DoorDash, Deliveroo, and Wolt.

Go Python SIEM Snowflake SQL
1 day, 23 hours ago

Staff Security Engineer

Redox 51-250 Internet Software & Services

Redox is hiring a Staff Security Engineer to own cloud-native and application security for its remote healthcare data exchange platform, with a focus on hardening systems and driving secure-by-default engineering practices.

Argo CD AWS CI/CD CrowdStrike Docker GitHub Actions Go HashiCorp Vault Helm Kafka Kubernetes LLM Node.js PostgreSQL Python Redis Terraform TypeScript
2 days ago

Senior Information Security Engineer

KPA 251-1K Professional Services

KPA is hiring a Senior Information Security Engineer to own and improve its technical security platforms, cloud and identity security, and incident response efforts across a modern enterprise environment.

AWS AWS SES Azure CI/CD CrowdStrike DevSecOps Kubernetes Linux Network Security Penetration Testing PowerShell Python REST API SendGrid
2 days ago

You're on a roll! Sign up now to keep applying.

Sign Up

Already have an account? Log in

Used by 14,729+ remote workers