Cybersecurity Engineer (Troy, MI)
Job Summary
The Cybersecurity Engineer is responsible for implementing, maintaining, and continuously improving the organization's cybersecurity technologies, processes, and controls. This role investigates and remediates security threats, supports incident response activities, strengthens security posture across on-premises and cloud environments, and collaborates closely with IT Infrastructure and Compliance teams to protect BeneSys systems and data.
The Cybersecurity Department is a growing team focused on continuously maturing the organization's security program. As security standards and technologies evolve, the Cybersecurity Engineer must be adaptable, self-motivated, and capable of delivering results in a fast-paced environment while maintaining a collaborative approach. This position is expected to demonstrate professionalism, technical excellence, and sound judgment in representing both the department and BeneSys.
BeneSys maintains a substantial hybrid infrastructure consisting of on-premises and cloud-based systems that support the organization's Cybersecurity and IT Compliance programs. This position primarily requires onsite work, with occasional travel to company locations as business needs require.
Applicant must live in the Metro Detroit area of Michigan.
Essential Functions
- Monitor, investigate, triage, and respond to alerts generated by enterprise security platforms, including:
- Endpoint Detection and Response (EDR)
- Extended Detection and Response (XDR)
- Security Information and Event Management (SIEM)
- Vulnerability management platforms
- Email security systems (malware, phishing, spam, blacklisting, and relay protection)
- External breach notifications and threat intelligence
- Deploy, configure, maintain, upgrade, and decommission cybersecurity software, hardware, and security appliances in collaboration with the IT Infrastructure team.
- Continuously optimize existing security tools and configurations to improve detection capabilities, align with industry best practices, and support business requirements.
- Assist with secure integration of third-party applications and services, including Single Sign-On (SSO), OAuth, and Microsoft Entra ID identity services.
- Design, implement, and continuously improve security controls across Microsoft Entra ID, Conditional Access, Microsoft Defender XDR, Microsoft Defender for Endpoint, Microsoft Defender for Identity, Microsoft Defender for Cloud, and Microsoft Defender for Cloud Apps.
- Administer and continuously enhance the organization's SIEM platform by developing analytics rules, dashboards, workbooks, data connectors, and monitoring content to improve visibility and detection fidelity.
- Develop and maintain Kusto Query Language (KQL) detection libraries, threat hunting queries, automation workflows, Logic Apps, playbooks, and other SOAR capabilities.
- Deploy and maintain endpoint security technologies, including Managed Detection and Response (MDR) solutions.
- Perform vulnerability assessments, prioritize remediation efforts, and coordinate corrective actions with the IT Infrastructure team.
- Support internal and external compliance initiatives, including security audits, penetration testing, risk assessments, and regulatory reviews.
- Investigate, document, and report cybersecurity incidents, including root cause analysis, impact assessments, and remediation activities.
- Assist in developing, maintaining, and improving cybersecurity policies, standards, procedures, and technical documentation.
- Research emerging cybersecurity threats, vulnerabilities, technologies, and industry trends, providing recommendations for improving the organization's security posture.
- Participate in security awareness training and provide technical guidance to IT staff and end users as needed.
- Maintain accurate operational documentation, security metrics, support logs, and incident records.
- Communicate project status, security incidents, operational metrics, and remediation progress to the Manager of Cybersecurity in a timely and professional manner.
- Demonstrate regular attendance, professionalism, accountability, and compliance with all company policies, procedures, and security standards.
- Regular and predictable attendance is an essential function of this job.
Qualifications
- Required Experience
- Bachelor's degree in Information Technology, Cybersecurity, Computer Science, or a related field, or equivalent professional experience.
- Minimum of four (4) years of progressively responsible experience in cybersecurity, including Security Operations Center (SOC), Incident Response, Threat Hunting, Security Engineering, or similar roles.
- Minimum of one (1) year of experience supporting enterprise IT infrastructure, such as Service Desk, Systems Administration, or Infrastructure Engineering.
- Minimum of two (2) years of hands-on experience administering Microsoft Defender XDR and Microsoft Sentinel.
- Technical Knowledge
- Strong understanding of cybersecurity threats, attacker tactics, techniques, and procedures (TTPs).
- Experience with incident response methodologies and security operations.
- Experience securing hybrid cloud, cloud-native, and on-premises enterprise environments.
- Working knowledge of cybersecurity frameworks and regulatory standards, including NIST, ISO 27001, CIS Controls, HIPAA, HITRUST, and COBIT.
- Strong PowerShell scripting skills and experience using Python (preferred) or another general-purpose programming language for automation, threat detection, and response.
- Experience with Kusto Query Language (KQL) for Microsoft Sentinel and Microsoft Defender.
- Experience with Microsoft Active Directory, Microsoft Entra ID, Windows Server, Group Policy, and enterprise identity management.
- Familiarity with endpoint management technologies, including MDM, MAM, and Microsoft Intune.
- Working knowledge of firewalls, IDS/IPS technologies, encryption, authentication, and identity security.
- Excellent troubleshooting, analytical, and problem-solving skills.
- Professional Competencies
- Self-motivated with the ability to work independently while contributing effectively within a collaborative team.
- Strong verbal and written communication skills with the ability to explain technical concepts clearly to both technical and non-technical audiences.
- Demonstrated ability to manage multiple priorities and adapt quickly to changing business needs.
- Strong organizational skills and attention to detail.
- Ability to summarize incidents, projects, risks, and technical findings in a concise and meaningful manner.
- Commitment to continuous learning and professional development.
- Demonstrates professionalism, accountability, reliability, punctuality, and proactive communication.
Work Schedule - Full time. Monday - Friday, 7:30am - 4:30 pm. Requires in-office days but also offers at-home flexibility after 90 days.
Competitive Benefits and Compensation Package
- 12 paid holidays
- Paid Time Off (PTO)
- Pro-rated during first year of employment
- 15 days of PTO provided in the next calendar year!
- 3 days paid bereavement
- Up to 20 days paid jury leave
- Medical, dental, and vision insurance, with option for dependent coverage
- Company-paid basic life, short-term disability, long-term disability, and AD&D insurance
- 401k with employer match
- Tuition reimbursement program
- Career development opportunities
- Referral bonus for all successful full-time referrals
- Annual opportunities for increases
Pay - The salary range for this position is $90,000 - $100,000 per year. Actual salary is dependent on skills, experience, education, and other business factors.
Our Culture
BeneSys wants to be a great service provider to the members we serve, and we recognize we can only do that if we are also a great employer with successful employees. In short, our success is driven by our employees' successes. We want to be a place where people want to work, feel proud of what they do and feel fulfilled both professionally and personally. We want to create a place where employees can find long-term growth and potential.
Our culture focuses on three core values:
- Collaboration: working together across 31 locations to achieve the best for the company and our clients
- Dedication: striving to create an environment where all employees work toward a common goal while committing to providing the best customer service to our members and our colleagues
- Integrity: doing what we say we will do. Upholding strong ethical and moral principles
ADA & EEO
Reasonable accommodations will be made so that qualified individuals with disabilities are able to complete the application process and, if hired, fulfill the essential functions of their job.