Cyber Security Engineer
Direct Energy Business · Houston
Job description
About the role
The Cyber Security Engineer will protect NRG’s systems, cloud workloads and data by identifying vulnerabilities, operating security tools, and supporting incident response across on‑premises and cloud environments. The role works closely with cloud, infrastructure and development teams to ensure secure configurations and compliance with standards such as NIST CSF, PCI DSS and SOX.
Key responsibilities
- Assess and improve cloud posture across AWS (and optionally Azure/GCP), identify misconfigurations and drive remediation with owners.
- Provide security guidance on secure configuration, IAM, encryption, network segmentation and logging to cloud, infrastructure and development teams.
- Conduct secure cloud architecture reviews aligned with the Security Pillar, CIS Benchmarks and internal cloud security standards.
- Administer IAM platforms and integrations (SSO, MFA, directory services, conditional access) in hybrid environments.
- Perform vulnerability assessments on on‑premises, cloud and container workloads and assist in remediation.
- Deploy, configure and maintain security tools such as IDS/IPS, endpoint protection, SIEM and WAF.
- Develop, implement and enforce security policies, procedures and cloud guardrails.
- Execute routine audits to verify compliance with organizational policies and regulatory frameworks.
- Stay current on emerging threats, cloud attack techniques and best practices, and advise technical teams.
Required profile
- Hands‑on experience with a CSPM/CNAPP platform (Orca preferred; Wiz, Prisma Cloud or Defender for Cloud acceptable).
- Working knowledge of at least one major cloud provider, preferably AWS, including native security services.
- Strong understanding of cloud security concepts: IAM, key management, network security, logging/monitoring and shared responsibility.
- Ability to collaborate with IT, cloud engineering and development teams to remediate findings.
- Familiarity with security frameworks and regulations such as NIST CSF, PCI DSS and SOX.
- Experience conducting vulnerability assessments and security audits in hybrid environments.
Required skills
- AWS (GuardDuty, Security Hub, IAM Identity Center, KMS, CloudTrail, WAF/Shield)
- Orca (CSPM/CNAPP) – also Wiz, Prisma Cloud, Defender for Cloud
- IAM, SSO, MFA, directory services, conditional access
- IDS/IPS, endpoint protection, SIEM, WAF
- Network protocols, NAC, VPC, transit gateway, private endpoints
- CIS Benchmarks, NIST CSF, PCI DSS, SOX compliance
Questions fréquentes
Why are you reporting this job?
Explore further
Salaries, guides and searches in the United States.
Salaries by job title
Apply in 30 seconds
Enter your email to apply. An account will be created automatically.
By continuing, you accept our terms of use.
Already have an account? Login
Published 1 month ago
Expires 2 days from now
35 views · 0 interested
Boost your chances
Upload your CV — we will match you with relevant openings.
Analyzing your CV...
Direct Energy Business
Houston
Related job offers
-
Senior Product Manager, Platform Experience & Insights
HungerRush Houston -
Senior Product Manager, POS
HungerRush Houston -
Senior Project Manager – Virtual or Houston
Kelly Houston -
Support Technique & Application – B2B SaaS (H/F)
epension GmbH - -
AI & Full-Stack Developer
Exclusively Remote Gibor Group Chicago