Information Security EngineerCorporate Office - Charlotte, NCOverviewPosition Type: Full Time Job Shift: Day Education Level: Bachelor Degree Travel Percentage: Up to 10% Category: Information TechnologyDescriptionAt Midrex, you will do work that matters alongside people who believe you matter. The work won't be easy, but it will be worth it. You'll be part of a great team—with plenty of autonomy—to bring out your best. And you'll be well compensated and have a best-in-class benefits package. Take a look:Competitive benefits effective from Day 1 - Dollar-for-dollar 401(k) matching (up to 6%)Profit sharing with 401(k) kicker - Generous overtime for qualified positions4 weeks of paid vacation - Tuition reimbursementRaffles for professional sports tickets - Half-day FridaysFlexible home/office work practices - Paid time to volunteerEmployee recognition awardsSince 1987, Midrex has been the world leader in direct reduction technology, offering the best proven method for decarbonization in the iron and steel industry available today. Our rapid growth is transforming the steel industry and our planet. And none of it would be possible without our people, who bring vision, compassion, and extraordinary expertise to this work every day. So, if you're looking to do big work in a small-team environment, Midrex is just the place for you.QualificationsThe Information Security Engineer is responsible for monitoring, detecting, investigating, and responding to cybersecurity threats across the organization's global technology environment. This role supports the protection of company systems, networks, cloud services, applications, and data through continuous security monitoring, vulnerability management, security awareness initiatives, compliance activities, and implementation of security controls. The role increasingly leverages AI-enabled security tooling to accelerate threat detection, triage, and response, and supports the secure adoption of AI technologies across the organization.The Information Security Engineer serves as a key member of the cybersecurity team and works closely with IT infrastructure, cloud, networking, application, and business teams to improve the organization's security posture. This position requires strong analytical abilities, attention to detail, problem-solving skills, and a commitment to continuous improvement.The Information Security Engineer should demonstrate broad, hands-on security experience encompassing security investigations, endpoint and cloud security, vulnerability management, Data Loss Prevention (DLP), networking, security compliance, security tooling, and partnership with IT Operations.The Information Security Engineer should be capable of independently handling security responsibilities while also serving as a security resource to infrastructure, networking, cloud, endpoint, and other IT teams.This is NOT a SOC ticket-triage-only position.Essential Duties and ResponsibilitiesSecurity OperationsMonitor security alerts, events, and incidents generated by security platforms including SIEM, endpoint protection, email security, cloud security, and network security systems.Investigate suspicious activity and coordinate incident response activities through resolution.Perform threat hunting and security investigations to identify potential risks and unauthorized activities.Document security incidents, findings, lessons learned, and remediation activities.Participate in on-call rotation and security incident escalations as required.Vulnerability and Risk ManagementConduct vulnerability assessments and coordinate remediation efforts with system owners.Track and report remediation progress and risk reduction metrics.Support annual penetration testing activities and validation of remediation actions.Assist in risk assessments and implementation of corrective actions.Identify opportunities to reduce organizational cyber risk through technology, process, and control improvements.Security Engineering and AdministrationAssist with implementation, administration, and optimization of security technologies.Manage security policies and configurations across Microsoft 365, Azure, endpoint management, email security, and network security platforms.Support identity and access management controls including role-based access control, least privilege, and privileged account management.Assist with implementation and maintenance of Zero Trust security architecture initiatives.Manage SSL/TLS certificate lifecycle processes including acquisition, renewal, deployment, and documentation.Security Awareness and TrainingCoordinate and administer the corporate Security Awareness Program.Develop and deliver security awareness communications, training campaigns, and phishing simulations.Analyze user participation metrics and identify improvement opportunities.Conduct coaching sessions with employees requiring additional phishing awareness training.Compliance and GovernanceAssist with maintaining compliance with ISO 27001, NIST Cybersecurity Framework, and corporate security policies.Support internal and external audits by collecting evidence and documenting security controls.Participate in policy development, standards creation, and security procedure improvements.Maintain accurate security documentation, inventories, and records.Business Continuity and Disaster RecoverySupport backup, recovery, and disaster recovery processes.Participate in periodic testing of business continuity and disaster recovery plans.Assist in maintaining resilience and recoverability of critical technology services.AI SecurityLeverage AI-assisted security tools (e.g., Microsoft Security Copilot, CrowdStrike Charlotte AI) to accelerate alert triage, incident summarization, and threat investigations.Support monitoring and governance of enterprise AI usage, including detection of unauthorized ("shadow AI") applications and enforcement of AI acceptable use policies.Assist with securing generative AI deployments, including Microsoft 365 Copilot data protection and Purview-based data governance and DLP controls for AI services.Help identify and analyze AI-enabled threats such as AI-generated phishing, deepfake, and social engineering campaigns, and incorporate these risks into security awareness content.Support AI risk assessments and contribute to AI governance activities aligned with emerging frameworks and standards.Required QualificationsEducationBachelor's degree in Information Technology, Cybersecurity, Computer Science, or related field; or equivalent professional experience.ExperienceThree to five years of cybersecurity, information security, or IT infrastructure experience.Experience supporting enterprise security technologies in a Microsoft-centric environment.Experience investigating security events and coordinating remediation activities.Required Technical KnowledgeCrowdStrike Falcon / Next-Gen SIEMMicrosoft Defender Security SuiteSecurity Operations Center (SOC) processes and methodologiesIncident response and breach investigationVulnerability management and remediationMicrosoft 365 and Azure security fundamentalsEndpoint Detection and Response (EDR/XDR) platformsSecurity Information and Event Management (SIEM)Email security technologies and phishing protectionImplementation and / or Administration of security compliance frameworks including ISO 27001 and NISTNetworking fundamentals including TCP/IP, DNS, DHCP, HTTP/S, TLS, VPN, and wireless securityArtificial Intelligence (AI) security fundamentals, including generative AI and large language model (LLM) risk conceptsCommon AI threat vectors such as prompt injection, data leakage, model manipulation, and AI-generated phishing (e.g., OWASP Top 10 for LLM Applications)Familiarity with AI-assisted security operations tools for alert triage, investigation, and reportingAwareness of AI governance and risk frameworks such as the NIST AI Risk Management Framework (AI RMF)Identity and Access Management (IAM)Encryption, certificate management, and key management principlesWindows security administration and endpoint hardeningPreferred QualificationsTechnical ExperienceMicrosoft IntuneCisco Umbrella / Secure AccessPalo Alto, Cisco, and Meraki security platformsKnowBe4 Security Awareness platformAbnormal
Apply Now