Hermeus Logo

Hermeus

Cybersecurity Engineer

Posted 4 Days Ago
Be an Early Applicant
In-Office
Los Angeles, CA, USA
138K-227K Annually
Senior level
In-Office
Los Angeles, CA, USA
138K-227K Annually
Senior level
The Cybersecurity Engineer will design and manage security controls in Microsoft environments, oversee vulnerability management, conduct risk assessments, ensure compliance with defense regulations, and respond to security incidents, focusing on protecting classified information systems.
The summary above was generated by AI
Hermeus is a high-speed aircraft manufacturer focused on the rapid design, build, and test of high-Mach and hypersonic aircraft for the national interest. Working directly with the Department of Defense, Hermeus delivers capabilities that will ensure that our nation, and our allies, maintain an asymmetric advantage over any and all potential adversaries.

We are seeking a highly skilled and experienced Cybersecurity Engineer to join our team. The ideal candidate will have a strong background working within a defense contractor environment, bringing specialized knowledge of security best practices, regulatory compliance (e.g., CMMC, NIST 800-171), and robust system hardening. This role is critical in protecting our sensitive and classified information systems. A deep understanding of Microsoft security ecosystem, including Microsoft Entra ID (formerly Azure AD) and Microsoft Purview, is essential. The engineer will play a key role in our vulnerability management program, encompassing detection, analysis, and remediation, and will be central to performing in-depth risk analysis across our IT infrastructure. 

Responsibilities:

    Technical Implementation & Management 

    • Design, implement, and manage security controls and configurations within the Microsoft ecosystem, with a focus on Entra ID and Purview. 

    • Manage identity and access governance (IAG) using Entra ID, including conditional access policies, privileged identity management (PIM), and multi-factor authentication (MFA). 

    • Utilize Microsoft Purview for data governance, data loss prevention (DLP), eDiscovery, and compliance management to meet defense contractor requirements. 

    • Configure and maintain security solutions across cloud (Azure/Microsoft 365) and on-premises environments. 

    Vulnerability & Risk Management 

    • Lead the organization's vulnerability detection and remediation efforts, utilizing industry-standard tools to identify, prioritize, and track security flaws. 

    • Conduct comprehensive risk analysis and assessments (RAAs) on new and existing systems, providing actionable recommendations to mitigate identified threats. 

    • Develop and implement patching and configuration management strategies to reduce the attack surface. 

    • Respond to and investigate security incidents, performing root cause analysis and implementing preventative measures. 

    Compliance & Defense Sector Expertise 

    • Ensure all security measures and procedures comply with mandatory defense industry regulations and frameworks (e.g., NIST SP 800-171, CMMC). 

    • Participate in internal and external audits related to security compliance. 

    • Develop and maintain security documentation, including System Security Plans (SSPs), Plan of Action and Milestones (POA&Ms), and standard operating procedures (SOPs). 

Minimum Requirements:

  • Bachelor's degree in Computer Science, Information Technology, Cyber Security, or a related field (or equivalent work experience).  
  • Minimum of 5 years of experience in a dedicated Cyber Security or Information Assurance role. 

    • Proven experience working directly for or extensively with a U.S. defense contractor, including familiarity with controlled unclassified information (CUI) handling and protection. 

    • Demonstrable expertise in Microsoft Entra ID (formerly Azure AD) administration, including tenant configuration, governance, and security feature deployment. 

    • Hands-on experience with Microsoft Purview, particularly in managing data governance, compliance, and DLP policies. 

    • Specialized experience in vulnerability management lifecycle (scanning, analysis, prioritization, remediation tracking) and using associated tools. 

    • Strong background in security risk analysis, threat modeling, and formulating mitigation strategies. 

Preferred Skills & Experience:

    • Excellent written and verbal communication skills, with the ability to articulate complex security risks to both technical and non-technical stakeholders. 

    • Proficiency with scripting languages (e.g., PowerShell, Python) for automation of security tasks. 

    • Familiarity with Security Information and Event Management (SIEM) platforms. 

    • Relevant security certifications such as: GIAC, CASP+, CEH, or Microsoft certifications (e.g., SC-300, SC-400, AZ-500) are highly desirable. 

U.S. EXPORT CONTROL COMPLIANCE STATUS 
The person hired will have access to information and items subject to U.S. export controls, and therefore, must either be a “U.S. person” as defined by 22 C.F.R. § 120.62 or otherwise eligible for deemed export licensing. US persons include U.S. citizens, U.S. nationals, lawful permanent residents (green card holders), and asylees and refugees with such status granted, not pending. 

EQUAL OPPORTUNITY
Hermeus is an Equal Opportunity Employer. Employment decisions at Hermeus are based solely on merit, competence, and qualifications, without regard to race, color, religion, gender, national origin/ethnicity, veteran status, disability status, age, sexual orientation, gender identity, marital status, mental or physical disability, or any other legally protected status.

Top Skills

Azure
Microsoft 365
Microsoft Entra Id
Microsoft Purview

Hermeus Los Angeles, California, USA Office

Los Angeles, CA, United States

Similar Jobs

6 Days Ago
In-Office
El Segundo, CA, USA
130K-180K Annually
Junior
130K-180K Annually
Junior
Information Technology
The Cybersecurity Engineer will implement security controls for internal systems and cloud services, ensure compliance with federal requirements, and support product deployment.
Top Skills: Cis BenchmarksCmmcDisa StigsFedrampIso 27001KubernetesNessusNist Sp 800-171Nist Sp 800-53ScapStig Viewer
12 Days Ago
Remote or Hybrid
United States
125K-159K Annually
Senior level
125K-159K Annually
Senior level
Automotive • Big Data • Information Technology • Robotics • Software • Transportation • Manufacturing
Design, build, and maintain secure, scalable SecOps platforms using C++, Rust, and scripting. Implement CI/CD and DevOps practices, integrate systems via APIs/webhooks and AI-driven tools, architect cloud (AWS/Azure/GCP) environments, optimize Linux/kernel configurations, automate infrastructure, and collaborate with SecOps on monitoring, detection, and response to protect enterprise assets.
Top Skills: Ai-Driven ToolsAPIsAWSAzureC++Ci/CdDevOpsGCPLinuxLinux KernelRustScripting LanguagesWebhooks
12 Days Ago
In-Office
161K-259K Annually
Senior level
161K-259K Annually
Senior level
Fintech • Information Technology • Payments
The role involves designing and operating security platforms, implementing cloud security controls, and establishing GenAI workflows to enhance security posture and automation across Visa’s cloud environments.
Top Skills: AWSAzureGCPGitopsOpaPythonRegoSentinelTerraform

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account