Neumo Logo

Neumo

Cybersecurity Engineer (Remote)

Posted 16 Days Ago
Remote
Hiring Remotely in USA
Senior level
Remote
Hiring Remotely in USA
Senior level
Owns perimeter, cloud, email, identity, endpoint, and detection defenses across AWS and Azure. Responsibilities include managing WAF and bot controls, writing Terraform, operating SIEM and EDR/MDR tooling, developing detections, responding to incidents, administering email security and MDM, advancing Zero Trust, supporting penetration testing, and using AI-assisted tools for security automation. The role requires strong compliance experience, on-call incident response participation, and hands-on security engineering skills.
The summary above was generated by AI

Job Summary:

Neumo is a PE-backed govtech company formed from the merger of Avenu, ITI, and GovOS, delivering payments, DMV, justice, revenue compliance, and public administration solutions to state and local government clients nationwide. Our InfoSec program operates under SOC 1, SOC 2, and PCI DSS, and active pursuit of FedRamp High and GovRamp.

We're growing our InfoSec team and looking for a hands-on Security Engineer who blends deep technical depth across the security stack with fluency in AI-assisted tooling. You'll own and harden our perimeter and cloud defenses, build detection and automation as code, and be a first responder when incidents happen..

Duties and Responsibilities:

Perimeter, Cloud & Application Security

  • Own perimeter security controls: WAF, firewall, and CDN policy — including authoring and tuning bot management rules to block automated abuse without harming legitimate traffic.
  • Write and maintain Terraform to manage security infrastructure as code across cloud and edge environments (version-controlled, peer-reviewed, repeatable).
  • Secure our AWS/Azure environments: harden configurations, close CSPM findings, and partner with engineering on secure-by-design reviews.
  • Own email security end-to-end: configure and tune the secure email gateway, enforce DMARC/SPF/DKIM (including moving DMARC toward quarantine/reject), and manage attachment sandboxing and URL rewriting/detonation.
  • Run phishing simulation and awareness campaigns, report on click/report rates, and use results to tighten filtering rules and target training.
  • Detect and respond to business email compromise and account takeover, mailbox forensics, inbox-rule abuse, OAuth/app-consent abuse, and coordinating with IT on containment.

SIEM, Logging & Detection Engineering

  • Own log source onboarding across cloud (AWS/Azure), identity, endpoint, network/perimeter, and email systems, ensuring coverage gaps are identified and closed.
  • Build, tune, and maintain correlation rules and detection content in the SIEM, continuously reducing false positives/negatives and improving signal-to-noise for the team.
  • Define and maintain log retention, normalization, and parsing standards to support investigations, audits, and PCI DSS / SOC 2 / FedRAMP logging requirements.
  • Build dashboards and alerting for key telemetry (identity, servers, endpoint, cloud, perimeter, email, critical systems) and report on SIEM health, coverage, and detection efficacy to the CISO.
  • Map detection content to a framework such as MITRE ATT&CK and close identified coverage gaps.

Detection, Response & Endpoint

  • Operate and tune EDR and MDR tooling; triage alerts across the security stack and drive them to resolution.
  • Participate in incident management as needed, including after-hours response: investigation, containment, remediation, and clear post-incident write-ups.
  • Support annual incident response tabletop exercises and help mature our IR runbooks.
  • Contribute to red team / adversarial simulation exercises and support annual third-party penetration testing, translating findings into fixes.

Identity, Endpoint & Zero Trust

  • Advance our Zero Trust architecture across identity, network segmentation, and access policy.
  • Administer MDM and BYOD programs, balancing usability with device compliance and data protection standards.

AI-Augmented Security Engineering

  • Use AI coding assistants and agentic tooling to accelerate detection engineering, automation, and Terraform development, while applying sound judgment about what AI-generated output ships to production.
  • Evaluate and pilot AI-driven security tooling (e.g., AI-assisted triage, threat detection, or bot/traffic classification) and help set guardrails for safe internal use of AI.


 Education and Experience:

  • 5+ years in a security engineering or security operations role, with direct, hands-on experience across most of: perimeter/WAF and bot management, EDR/MDR, SIEM, MDM/BYOD, Zero Trust, cloud security, and email security.
  • Hands-on SIEM experience: onboarding log sources, writing/tuning correlation and detection rules, and managing retention and parsing.
  • Hands-on email security experience: secure email gateway administration, DMARC/SPF/DKIM enforcement, and BEC/phishing investigation (e.g., Proofpoint, Abnormal Security, Mimecast, or Microsoft Defender for Office 365).
  • Experience participating in incident response, including on-call or after-hours response to active incidents.
  • Experience in a regulated or compliance-heavy environment (PCI DSS, SOC 2, FedRAMP/GovRAMP, or similar).
  • Relevant certifications: OSCP, GPEN, GCIH, Security+, or CISSP.
  • Experience with tools such as Cloudflare, SentinelOne, Tenable, Wiz, or Delinea (or direct equivalents).


Knowledge, Skills and Abilities:

  • Working proficiency with Terraform or another IaC tool, plus scripting ability (Python, Bash, or similar) for automation.
  • Exposure to red teaming or offensive security: as a practitioner, or in close partnership with red team / pen test engagements.
  • Comfort using AI tools (Copilot-style coding assistants, LLM-based analysis, agentic workflows) as part of daily engineering work, with a clear-eyed view of their limits.
  • Clear written communication: you can document an incident or a control decision so a non-technical exec or an auditor can follow it.

 
Work Environment:

  • Office setting with a moderate noise level.
  • The employee will work at an individual workstation, using a telephone and computer.


Physical Demands:

  • Must be able to remain seated for extended periods.
  • Regular use of a computer and other office machinery, such as printers and copy machines.
  • Occasional movement around the office.
  • Frequent communication via telephone.


Neumo Summary:

With the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.

Neumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.

Neumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.

Neumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.

Similar Jobs

Yesterday
Remote
Georgia, USA
120K-160K Annually
Senior level
120K-160K Annually
Senior level
Retail
Designs and operates enterprise-scale discovery, governance, and lifecycle automation for non-human identities, including service accounts, API tokens, cloud roles, CI/CD identities, certificates, and AI agents. Partners with IAM, cloud, DevOps, and application teams to modernize authentication, automate credential management, support access reviews, detect misuse, and align controls with Zero Trust principles. Develops threat-hunting and data-analysis capabilities, produces technical documentation, and supports incident response, audits, and compliance.
Top Skills: Ci/CdCloud IamIamInfrastructure As CodeItsmMtlsOauthPamPkiPowershellPythonSecrets ManagementTlsZero Trust
7 Days Ago
In-Office or Remote
83K-138K Annually
Senior level
83K-138K Annually
Senior level
Retail • Sports
Lead the architecture and execution of a large-scale CIAM platform migration and consolidation. Own customer identity operations, authentication flows, integrations, microservices, mobile login experiences, observability, resilience, and identity-related incident response. Partner with product, marketing, business, and customer support teams to optimize security, fraud prevention, customer experience, and conversion. Communicate platform health, migration progress, and fraud metrics to stakeholders.
Top Skills: Api IntegrationsAuth0Aws CognitoCi/CdCiamFido2ForgerockLogging And MonitoringMfaMicroservicesMobile Application UiOauth 2.0OktaOpenid Connect (Oidc)PasskeysPing IdentitySAML
10 Days Ago
In-Office or Remote
48 Locations
90K-100K Annually
Senior level
90K-100K Annually
Senior level
Hardware • Security • Software • Cybersecurity
Lead cybersecurity assessments for government and enterprise clients, focusing on FedRAMP, FISMA, and NIST RMF compliance. Conduct vulnerability scanning, analyze security architectures and controls, validate remediation, author assessment documentation, engage client stakeholders, mentor team members, and support secure cloud architecture and risk mitigation. The role is remote, requires U.S. citizenship and clearance eligibility, and involves up to 25–50% travel.
Top Skills: AcasAcunetixApplication SecurityApplied CryptographyAuthentication ProtocolsCjis Security PolicyCloud ComputingDb ProtectDisa StigsFedrampFismaNessusNist RmfNist Sp 800-SeriesNmapSoftware Development Lifecycle (Sdlc)Stig ViewerWebinspect

What you need to know about the Los Angeles Tech Scene

Los Angeles is a global leader in entertainment, so it’s no surprise that many of the biggest players in streaming, digital media and game development call the city home. But the city boasts plenty of non-entertainment innovation as well, with tech companies spanning verticals like AI, fintech, e-commerce and biotech. With major universities like Caltech, UCLA, USC and the nearby UC Irvine, the city has a steady supply of top-flight tech and engineering talent — not counting the graduates flocking to Los Angeles from across the world to enjoy its beaches, culture and year-round temperate climate.

Key Facts About Los Angeles Tech

  • Number of Tech Workers: 375,800; 5.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Snap, Netflix, SpaceX, Disney, Google
  • Key Industries: Artificial intelligence, adtech, media, software, game development
  • Funding Landscape: $11.6 billion in venture capital funding in 2024 (Pitchbook)
  • Notable Investors: Strong Ventures, Fifth Wall, Upfront Ventures, Mucker Capital, Kittyhawk Ventures
  • Research Centers and Universities: California Institute of Technology, UCLA, University of Southern California, UC Irvine, Pepperdine, California Institute for Immunology and Immunotherapy, Center for Quantum Science and Engineering

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account