Skip to content

Open nowPosted 3 days ago

Sr Cyber Security Engineer

OnTrac395 open roles

Where
Virginia, USA
Get the CV for this job

From $25 per CV, paid once. No subscription.

Your applicationOpen nowSr Cyber Security EngineerOnTrac · Virginia, USA
  1. YouYes, apply to this one.

  2. CV RocketCV written for this posting.

  3. 25 readersRecruiter, hiring manager, skeptic. Round after round.

  4. CV RocketApplied on OnTrac's own form.

The reply lands in your private mailbox

3×more interviews than doing it yourself with ChatGPT.

The clock on this job

Early applications get read.

7.8% of postings close within 7 days. Measured by our own scanner across the market.

Share of postings closed within
  1. 1.6%1 day
  2. 3.4%3 days
  3. 7.8%7 days
  4. 14.3%14 days
  5. 33.7%30 days
This job: posted 3 days ago

The posting

  OnTrac is hiring a Sr Cyber Security Engineer (PAM / IAM)!   Are you eager to join a dynamic and expanding company where you can both learn and make a meaningful impact? If you possess a strong sense of empathy, enjoy assisting others, thrive in a fast-paced environment, and excel at problem-solving, we encourage you to apply today to connect with a recruiter!   Founded in 1986, OnTrac has evolved into the leading provider of same-day and next-day delivery services in the U.S. for premier e-commerce and product-supply businesses, including five of the largest retailers in the U.S.    Location: Remote - This position may be performed remotely in states where the company is authorized to employ individuals. Compensation: The expected starting base pay range for this position is $156,000 - $195,000, with full potential base salary range over a successful candidate’s tenure in the position of $156,000 - $234,000. Actual compensation will be determined based on experience, skills, internal equity, and other job-related factors. This position may also be eligible for bonus, commission, or other incentive compensation in accordance with the terms of the applicable plan of up to a 20% Bonus Target. Employment Logistics:  The Sr. Cyber Security Engineer is a senior-level individual contributor and hands-on technical owner for Identity and Access Management (IAM), Privileged Access Management (PAM), Entra ID, Microsoft 365, vulnerability management, and mobile device management. This broad security engineering role requires deep identity expertise alongside the ability to support endpoint, cloud, and SaaS security. The Engineer partners daily with IT to secure infrastructure and end-user services, enables the Cyber Security Incident Response Team (CSIRT) as a Tier 3 escalation point, and supports Governance, Risk, and Compliance (GRC) by translating control requirements into technical configurations and automated evidence collection.   Unpacking the Benefits:    Employees are eligible for a comprehensive benefits package which may include:  

Medical, dental, and vision insurance Life and short- and long-term disability coverage 401(k) retirement savings plan with company match  Flex vacation in states other than CA, CO, IL, MA, MT, and NE, with accruals up to 96 hours for first year of employment with tenure-based increases up to 160 hours Two (2) floating holidays per year Paid sick leave* Six (6) paid company holidays Two (2) weeks paid pregnancy disability leave, four (4) weeks paid parental bonding leave   Additional wellness and employee assistance programs

  Benefits eligibility and offerings are subject to the terms and conditions of the applicable plans and company policies.   The Must-Haves: 

Bachelor’s degree in Computer Science, Cybersecurity, Information Technology, or a related field, or equivalent practical experience 7+ years of progressive experience in IT and Security, including at least 3 years dedicated to IAM or security engineering in an enterprise environment Demonstrated hands-on ownership of at least two of the following: Entra ID / Microsoft 365 A PAM platform Qualys or equivalent vulnerability management platform Intune / JAMF device management Hands-on expertise with identity lifecycle, RBAC design, entitlement and access certification, federation and SSO integrations, and privileged-access tooling and workflows Strong working knowledge of Entra ID, including Conditional Access, Identity Protection, PIM, and entitlement management, plus the Microsoft 365 security and compliance stack Working knowledge of Intune, JAMF, and Google device management, including compliance policies, configuration profiles, and application deployment across mixed operating-system environments Strong scripting and automation skills using PowerShell, Microsoft Graph, Python, or Bash Ability to interpret NIST CSF, ISO 27001, or SOC 2 and implement the technical controls and evidence required to meet them Certifications such as SC-300, SC-200, AZ-500, CISSP, CISM, GIAC GCIA, GIAC GDSA, or relevant PAM, JAMF, or Qualys vendor certifications Ability to travel up to 10% ​​It is the responsibility of every position to understand and adhere to the security guidelines outlined in OnTrac’s Acceptable Use policy and to conduct their activities accordingly.​

  Your Mission in Motion:  A summary of key responsibilities for the role is outlined below. Additional duties may be assigned as needed to support business objectives.

Identity and privileged-access engineering: Design, deploy, and maintain enterprise identity services across Entra ID and hybrid Active Directory, including SAML/OIDC federation, SSO, Conditional Access, MFA and phishing-resistant authentication, joiner/mover/leaver automation, RBAC, role and group governance, access reviews, credential vaulting, session monitoring, just-in-time elevation, tiered administration, service-account governance, and break-glass procedures. Microsoft 365 and Entra ID security: Harden and administer Exchange Online, SharePoint, OneDrive, Teams, Defender, Purview, and the Entra ID tenant, including configuration baselines, application registration and OAuth consent governance, license-aligned feature enablement, and posture remediation. Vulnerability, endpoint and mobile security: Operate Qualys, including asset coverage, tagging, authenticated scanning, agents, policy compliance, and risk-based reporting; drive remediation within established SLAs; and manage compliance, configuration, enrollment, encryption, patching, application deployment, and device-posture signals across Intune, JAMF, and Google device management for Windows, macOS, iOS, and Android. IT partnership and security by design: Serve as the embedded security engineering partner for directory, endpoint, network, and infrastructure changes, applying security by design to projects, migrations, and new deployments without unnecessarily slowing delivery. CSIRT enablement and Tier 3 escalation: Support complex identity and endpoint incidents through containment actions, including token revocation, account disablement, and device isolation; assist with evidence collection, log-source onboarding, and detection tuning in partnership with CSIRT and the MDR provider. GRC enablement and technical controls: Translate requirements from NIST CSF, ISO 27001, and SOC 2 into technical configurations and automated evidence collection that supports audits, third-party risk reviews, and risk-remediation tracking. Automation, documentation and mentorship: Automate recurring identity, access, integration, and reporting tasks using PowerShell, Microsoft Graph, and Python; maintain runbooks, SOPs, architecture diagrams, and platform standards; and provide technical guidance to analysts and junior engineers.

  Paving your way to your success:   

You explain technical risk clearly to non-technical stakeholders and collaborate effectively across IT, CSIRT, GRC, and business teams. You bring proficiency across identity, endpoint, network security, cloud environments including Azure, GCP, and AWS, and SaaS administration, moving effectively between domains as priorities shift. You analyze complex issues by thoroughly evaluating multiple variables and their technical and business implications. You define appropriate methods and procedures for new assignments, using sound judgment to select, adapt, and evaluate advanced techniques. You build strong stakeholder relationships beyond your area of expertise, adapting your communication style and using persuasive skills to align decisions with broader business objectives.

  Posting Timeline:    This job posting is anticipated to remain open for at least 15 days from the date of posting   Disclosures:    *Washington state employees are eligible for up to 56 hours of paid sick leave annually.   The salary range above represents the national range for this position. The salary range may be inclusive of several career levels at OnTrac, and the actual base salary offered may vary depending on several factors including, but not limited to: Geographic location, candidate experience and qualifications, job-related skills and competencies, market alignment, and financial considerations.    Compensation decisions are made based on the specific circumstances of each hire to ensure fair and competitive pay.   ADA Statement:    We are committed to providing equal employment opportunities to all qualified individuals. If you require reasonable accommodation to participate in the application or interview process, perform essential job functions, or access other employment benefits, please contact Human Resources.   If you are excited to be part of our team and grow with our OnTrac family, we invite you to apply!   

OnTrac is proud to be an Equal Opportunity Employer Lasership, Inc. dba OnTrac Final Mile with its affiliates, including OnTrac Logistics, Inc. (collectively, "OnTrac" or the "Company") is an equal opportunity employer. We value diversity and welcome applications from individuals of all backgrounds, abilities, and experiences. We do not discriminate based on race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or age. Join us in our commitment to creating a diverse and inclusive workplace. If you are excited to be part of our team and contribute to our talent acquisition efforts, we invite you to apply.    

From $25, paid onceGet the CV for this job

What happens when you press

One press. We do the rest.

  1. A CV for this posting

    Written against OnTrac's own wording, from every piece of relevant proof in your profile.

  2. 25 readers review it

    Recruiter, hiring manager, skeptic and more read every draft, round after round. You get the best round.

    The review screen in CV Rocket: how each CV was read, round by round.
  3. We apply on OnTrac's form

    Our application engine gets through the hardest forms there are. Where a question needs you, AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

    An application in CV Rocket: every answer filled in on the employer's form.
  4. Every reply, sorted

    OnTrac's answer lands in your private mailbox, and we classify it on arrival: interview, question, rejection.

    The CV Rocket inbox: each employer reply classified as an interview, an action or a rejection.
  5. Reply with AI

    AI helps you write the email, checks it and sends it. We show you whether the recruiter read it.

  6. The interview in your calendar

    Full integration with your calendar. The invitation goes straight in.

    An interview invitation in the CV Rocket inbox, added to the candidate's calendar.
Get the CV for this job

From $25 per CV, paid once. No subscription.

Why it works

3×

more interviews than doing it yourself with ChatGPT.

ChatGPT writes a CV and never learns what happened to it. We see every reply. For each CV we know:

  • How it was written, and how the review scored it
  • When we applied, and how long after the posting went up
  • Which posting, which company, which city
  • Who got the interview, and who heard nothing

That is how we know which CVs get called.

Get the CV for this job

From $25 per CV, paid once. No subscription.

The numbers game

More applications. More interviews.

Every application goes out with its own CV, written for that posting and paid once. Send enough of them and the law of large numbers finds you the job.

By hand5–10
With CV Rocket100
applications a day

Nearby

Live postings like this one

Same employer first, then the same role elsewhere.

Before you press

Straight answers

Get the CV for this job

From $25 per CV, paid once. No subscription.

What if my background isn't good enough?

We make the most of the background you have. The CV uses every piece of relevant proof your profile holds, and one of the 25 readers reads your whole profile and flags what the CV left out.

Do you really apply for me?

Yes, on the employer's own form, the hardest ones included. Where a question needs you, you answer it right there and AI suggests the best answer. Don't want us applying from our IP addresses? Use our Chrome extension: we apply straight from your own browser.

Is it a subscription?

No. You pay once per CV, from $25. Every application goes out with its own CV, written for that posting.

One job. One CV.
Paid once.

Pick the posting you want. We write for it, apply for you and catch the reply.

Get the CV for this job

From $25 per CV, paid once. No subscription.