Skip to content

Open nowPosted 7 days ago

Security Engineer

AGS LLC35 open roles

Where
Duluth, GA, United States
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSecurity EngineerAGS LLC · Duluth, GA, United States
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on AGS LLC's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

8.0% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.5%3 days
  3. 8.0%7 days
  4. 15.0%14 days
  5. 34.1%30 days
This job: posted 7 days ago

The posting

Job Overview

The Security Engineer is responsible for the secure configuration, hardening, and ongoing operation of the AGS security control set and the systems those controls protect. The role ensures that documented security policy and technical standards match what is actually configured in the environment, identifies and remediates configuration drift and misconfiguration, and keeps the technical estate aligned to current industry baselines as they evolve. This is a hands-on engineering role focused on sustained operational quality, taking ownership of the platforms and standards the security team implements and keeping them healthy, current, and effective over time. The role receives technical direction from the Senior Security Engineer and partners closely with Infrastructure, Network, Enterprise Apps, and Business Systems teams.

Responsibilities

  • Lead system and platform hardening across servers, endpoints, network devices, and cloud services using recognized configuration baselines such as CIS Benchmarks and vendor security baselines.
  • Validate that logical configuration across the environment aligns to documented security policy and technical standards, and remediate deviations.
  • Identify, document, and remediate misconfigurations across infrastructure, identity, and security tooling.
  • Implement and monitor configuration drift detection and drive corrective action where baselines have decayed.
  • Enforce endpoint baseline hardening and device compliance policies through enterprise endpoint management tooling.
  • Operationalize device control, application control, and disk encryption policies.
  • Administer day-to-day operation, tuning, and lifecycle maintenance of enterprise security platforms, including endpoint protection, email security, and access control tooling.
  • Maintain security tooling coverage and health, and resolve gaps in agent deployment or policy application.
  • Support vulnerability remediation by implementing patches, configuration changes, and compensating controls in coordination with IT operations.
  • Implement changes required to keep the environment aligned with evolving industry standards, vendor guidance, and control framework updates.
  • Implement and maintain security controls for hybrid environments combining on-premises infrastructure and cloud-based systems.
  • Use scripting and automation (PowerShell, KQL, Graph API) to reduce manual configuration work and enforce consistency.
  • Maintain accurate technical documentation for configuration standards, operational procedures, and control implementation.
  • Partner with systems, network, database, and application teams to implement security requirements without unnecessary disruption to operations.
  • Provide technical evidence supporting internal and external audit, certification, and regulatory assessment activities.
  • Participate in the incident response lifecycle as assigned, including containment, eradication, and recovery support.
  • Balance security requirements with user experience needs to maintain productivity alongside a strong security posture.
  • Occasional travel throughout the United States.

Qualifications

  • Secure configuration and hardening: CIS Benchmarks, DISA STIGs, or vendor security baselines across Windows and Linux systems.
  • Endpoint management and compliance: MDM/MAM tooling, compliance policies, security baselines, device and application control.
  • Enterprise security platform administration: endpoint protection (EDR/XDR), email security, access control tooling.
  • Configuration drift detection and remediation, and reconciling documented policy against live configuration.
  • Patch and vulnerability remediation execution, including compensating control design.
  • Hybrid infrastructure fundamentals: virtualization, enterprise directory services, and cloud service configuration.
  • Scripting and automation (PowerShell, KQL, Graph API); configuration management or infrastructure-as-code preferred.
  • Working understanding of network segmentation and access control concepts.
  • Strong documentation discipline and attention to detail.

Skills/Requirements

  • Bachelor's Degree in Computer Science, Information Security, Information Technology, or equivalent work experience.
  • At least 3 years of experience in security engineering, systems engineering, or infrastructure operations with meaningful security responsibility.
  • Demonstrated hands-on experience hardening Windows and Linux systems against recognized configuration baselines.
  • Practical experience administering enterprise security tooling such as endpoint protection, email security, or access control platforms.
  • Experience reconciling documented policy against live system configuration and closing the resulting differences.
  • Experience working in hybrid environments with a mix of on-premises and cloud-based systems.
  • Familiarity with industry frameworks (NIST, CIS, ISO 27001) and how framework requirements translate into technical configuration.
  • Demonstrated ability to balance robust security controls with positive user experience and business enablement.
  • Relevant technical certifications required or strongly preferred: CompTIA Security+, CySA+, SSCP, GSEC, or equivalent.

Preferred Certification

  • Professional technical certifications such as CompTIA Security+, CySA+, CEH, SSCP, or GSEC, with demonstrated progression toward a senior-level technical certification. Platform-specific certifications are considered supplemental to demonstrated hands-on capability.

Note: All offers are contingent upon successful completion of a background check

*Posted positions are not open to third party recruiters and unsolicited resume submissions will be considered free referrals.

AGS is an equal opportunity employer

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against AGS LLC's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on AGS LLC's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    AGS LLC's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.