About the role
The Cybersecurity Engineer II (L2) is a hands-on technical contributor responsible for implementing, operating, and improving client’s cybersecurity capabilities across a rapidly growing enterprise.
This role focuses on protecting enterprise systems, data, and users, while helping scale security controls across newly acquired agencies and modern cloud-based platforms. You will work closely with infrastructure, cloud, and application teams to ensure security is embedded into everything we build and operate.
Required Qualifications
* 3–5+ years of experience in cybersecurity, IT security, or related engineering roles
* Strong hands-on experience with: * Microsoft 365 / Entra ID / Active Directory * Endpoint management and security tools * Vulnerability management practices
* Experience working in complex or distributed enterprise environments
* Strong troubleshooting, problem-solving, and analytical skills
* Ability to balance security rigor with business agility
Key Responsibilities
Security Engineering & Operations
* Implement and manage security controls across: * Identity & access management (IAM / Entra ID / Active Directory) * Endpoint security and device management (e.g., Intune) * Cloud security for SaaS and emerging platforms
* Support day-to-day security operations, including alert triage, investigation, and response
* Assist in improving detection and response capabilities (EDR/XDR, SIEM use cases)
Vulnerability & Risk Management
* Identify, assess, and remediate vulnerabilities across infrastructure and applications
* Support vulnerability management programs aligned with enterprise risk priorities
* Partner with engineering teams to drive remediation tracking and accountability
M&A Integration Security
* Help onboard newly acquired agencies into client’s security standards
* Participate in: * Identity consolidation and cleanup * Endpoint onboarding and hardening * Security baseline enforcement
* Ensure consistent security posture across a highly distributed organization
Security Enablement (Not “Security Says No”)
* Collaborate with business and technical teams to deliver secure-by-design solutions
* Provide actionable, pragmatic guidance that enables the business while reducing risk
* Contribute to a culture of security as a business enabler, not a blocker
Compliance & Governance Support
* Assist with implementation of controls aligned to regulatory and industry frameworks
* Support audit readiness and evidence collection activities
* Help align security practices with evolving cyber risk and regulatory requirements relevant to insurance and data protection
Automation & Continuous Improvement
* Improve operational efficiency through automation and tooling
* Contribute to standardization of security processes across the enterprise
* Support adoption of scalable, repeatable security patterns
Originally posted on Himalayas