SR INFRASTRUCTURE SECURITY ENGINEER

ESSENTIAL DUTIES AND RESPONSIBILITIES include but are not limited to the following.

  • Security & Hardening (Primary Focus)
  • Implement and maintain secure configurations across Windows Server, Active Directory, and Microsoft 365 using CIS benchmarks and industry best practices.
  • Perform regular security posture assessments and remediate gaps.

Lead initiatives such as, but not limited to:

  • Tiered administration model (Tier 0/1/2)
  • Removal of insecure protocols
  • LAPS implementation and privileged credential protection

Identity & Active Directory SecuritConduct ongoing AD hygiene and security reviews, including:

  • Privileged group membership audits
  • AD ACL and delegation reviews
  • Service account inventory
  • Cleanup of stale objects
  • Help implement Privileged Access Management (PAM) and least privilege models.
  • Microsoft 365 / Entra ID Security
  • Design and maintain Conditional Access policies and MFA enforcement.

Improve tenant posture through:

  • Secure Score optimization
  • Identity protection and sign-in risk policies.

Manage and audit:

  • App registrations, enterprise apps, and OAuth permissions.
  • Guest access and external collaboration settings.
  • Support configuration and tuning of Microsoft Purview DLP, sensitivity labels, and information protection controls in partnership with IT Security and compliance stakeholders.
  • Patching, Vulnerability, & Lifecycle Management

Lead infrastructure patching strategy in partnership with system owners, IT Security, and Operations teams, including:

  • Windows Server updates (including emergency CVE patching)
  • Hypervisor and firmware updates
  • Third-party application patching
  • Track and remediate vulnerability scan findings.
  • Coordinate end-of-life remediation (OS, hardware, platforms).
  • Backup, Recovery, & Resilience
  • Ensure backups are not only successful, but recoverable.
  • Lead restore/recovery testing and DR exercises.
  • Validate immutable and air-gapped backup strategies.
  • Maintain and improve DR runbooks aligned to RPO/RTO goals.
  • Monitoring, Detection & Response
  • Review and respond to infrastructure and identity-related security alerts, escalating to IT Security as appropriate.
  • Tune alerts to reduce noise and increase actionable signals.
  • Partner with IT Security team to investigate infrastructure and identity-related security. events, support containment/remediation actions, and perform root cause analysis.
  • Endpoint & Network Security
  • Partner with Network Engineering and IT Security to review firewall rules, identify overly permissive access, and support remediation based on least privilege and segmentation principles.

Reduce endpoint risk:

  • Removal of local admin rights
  • Hardening endpoint configurations
  • Documentation & Process Improvement
  • Define remediation plans with risk-based prioritization.
  • Create and maintain security-focused runbooks and procedures.
  • Conduct quarterly access reviews and participate in tabletop incident response exercises.
  • Help establish repeatable security operational processes, developing automation where possible.
  • Establishes and maintains operational procedures and practices.
  • Collaboration with System Admin Team
  • Act as the security subject matter expert for the infrastructure team.

Provide guidance and hands-on support for:

  • Secure system builds
  • Patch cycles
  • Incident remediation
  • Step in to assist with core sysadmin tasks during high-demand periods.
  • Change Management
  • Support change control processes, perform risk assessment of changes before deploying to production, define deployment plans, and coordinate deployments with cross-functional teams.
  • Complies with safety and cGMP requirements.

SAFETY RESPONSIBILITY STATEMENT

Supports a culture of safety; follows all workplace health and safety procedures. Responsible for safety performance in respective area. Ensures the implementation of, adherence to, and enforcement of workplace health and safety requirements. Ensures activities are completed to promote and enforce safe behaviors by supervisors and employees. Ensures injury prevention efforts are effectively implemented. Fulfills responsibilities as outlined in the company safety management plan.

QUALIFICATIONS

To perform this job successfully, an individual must be able to perform each essential duty satisfactorily. The requirements listed below are representative of the knowledge, skill, and/or ability required. Reasonable accommodations will be made to enable individuals with disabilities to perform the essential functions.

· 5+ years in Systems Administration, Infrastructure Engineering, or Security Engineering.

· Relevant certifications such as Security+, CISSP, SSCP, GSEC, AZ-500, SC-300, SC-200, MS-102, or equivalent are preferred but not required.

· Working knowledge of security frameworks and hardening standards such as NIST Cybersecurity Framework, CIS Controls, CIS Benchmarks, Microsoft Security Baselines, and ISO/IEC 27001/27002, with the ability to translate control requirements into practical infrastructure and identity security improvements.

· Experience reviewing and remediating security findings from vulnerability scans, audits, or assessments

· Strong problem determination skills are required.

· Good organizational skills are required.

· Ability to work as an effective team member is a must.

Strong hands-on experience with:

o Active Directory (security & architecture)

o Microsoft 365 / Entra ID security

o Windows Server administration

o Windows Operating Systems

· Ability to translate security requirements into practical infrastructure changes.

Experience implementing:

o Conditional Access, MFA, identity security controls

o System hardening standards (CIS Benchmarks, DISA STIGs)

Familiarity with:

o SIEM/logging platforms

o Vulnerability management tools

o Backup/DR solutions

Experience with:

o Defender suite (Endpoint, Identity, Office)

o Intune and endpoint security controls

o PAM/PIM/JIT access models

o Linux/UNIX Operating Systems

o PowerShell or other scripting/automation tools

Knowledge of:

o Networking fundamentals and segmentation strategies

o Hypervisors (VMware, Hyper-V)

Ability to work effectively across IT Security, Infrastructure, Networking, Enterprise Applications, and business teams.

EDUCATION and/or EXPERIENCE

Bachelor’s degree (B.A.) in Information Technology, Computer Science, Cybersecurity, or related field preferred; or equivalent combination of education, certifications, and experience. Minimum of 5–7 years of related experience in systems administration, infrastructure engineering, cybersecurity, or similar role. Strong hands-on experience with Windows Server, Active Directory, Microsoft 365, Entra ID, patching, vulnerability remediation, and infrastructure security is required. Relevant security or Microsoft certifications are preferred.

LANGUAGE SKILLS

Must possess strong verbal and written communication skills, with the ability to clearly communicate technical information, security risks, and remediation recommendations to technical and non-technical audiences. Must be able to read, interpret, apply, and improve technical documentation, procedures, standards, vendor documentation, and system architecture materials.

REASONING ABILITY

Must be able to work independently, prioritize competing demands, analyze complex technical and security issues, and recommend practical solutions. Must demonstrate sound judgment, strong troubleshooting skills, and the ability to proactively identify risks, process gaps, and improvement opportunities. Must be able to assist in guiding junior systems administrators and support timely response to security incidents and critical vulnerabilities.

PHYSICAL DEMANDS

The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

The employee is regularly required to remain at stationary work location and occasionally to move from place to place within work facility. Employee is regularly required to use the telephone and computer. Employee will be required to travel to different work sites.

WORK ENVIRONMENT

Non-standard hours and/or extended work hours can be expected due to user/project requirements and/or deadlines, system or user issues as well as workload backlog. The work environment characteristics described here are representative of those an employee encounters while performing the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

See also

要針對這個職缺調整履歷嗎?

目前無法檢查您與這個職缺的符合程度;請先將履歷加入個人檔案,下次即可查看。

A new version of freehire is available