Senior Cybersecurity Engineer
WSI
2 days ago
Full-time
On-site
Appleton, Wisconsin, United States
Ready to help protect a growing supply chain leader? WSI is looking for a hands-on Senior Cybersecurity Engineer to strengthen vulnerability management, security operations, identity protection, and incident response. In this high-impact role, you’ll partner with IT and business leaders, mentor teams on security best practices, and help build a proactive security culture across the organization.
DUTIES AND ACCOUNTABILITIES:
- Administer and optimize our Rapid7 platform (InsightVM and Managed Detection & Response) to run the enterprise vulnerability management program across on-premises, cloud, and mixed Windows/Linux environments.
- Design and maintain a risk-based vulnerability prioritization framework, incorporating asset criticality, exploitability, and business context rather than age alone.
- Lead the weekly Vulnerability Management review cadence, producing remediation metrics and driving remediation timelines to closure with IT, Infrastructure, and business stakeholders.
- Maintain and mature the organization's CIS Critical Security Controls (CIS 18) program, tracking control implementation, identifying gaps, and prioritizing remediation roadmaps.
- Own and maintain the organization's Security Incident Response Plan, and lead its execution during security incidents identified through Rapid7 MDR (e.g., credential resets, session/MFA revocation, device isolation), including documentation of root cause and resolution.
- Monitor and manage the SSL certificate lifecycle across endpoints, proactively identifying and remediating expired or soon-to-expire certificates.
- Own the Security Awareness Program, including phishing simulation and reporting (PhishAlert) and associated metrics, to build a culture of security awareness across the organization.
- Review, develop, and maintain IT and security policies, standards, and procedures (e.g., the electronic use/acceptable use policy, data protection policy, and emerging areas such as AI usage policy), in partnership with the Director of Cybersecurity & Infrastructure.
- Own Zero Trust and Conditional Access policy design within Microsoft Entra ID, including MFA policy, identity protection alerting, and least-privilege role design.
- Review privileged access requests, applying least-privilege and risk-based decision-making, and conduct periodic access reviews for sensitive systems.
- Coordinate external penetration testing and vulnerability assessment engagements; validate, triage, and integrate findings into the vulnerability management program.
- Conduct proactive threat hunting to identify potential compromises, misconfigurations, and emerging risks ahead of formal alerts.
- Evaluate and select security and business applications/software prior to deployment, including endpoint/EDR tooling, by building vendor scoping documents, leading vendor evaluation sessions, and assessing third-party/vendor security risk.
- Produce and deliver a monthly security metrics and dashboard report to leadership summarizing vulnerability management, incident, and program status.
- Partner with leadership on annual planning to identify and prioritize the coming year's security initiatives.
- Partner with and mentor IT associates on security best practices, helping to elevate the organization's overall security posture.
- Support completion of cyber insurance renewal questionnaires and audit/compliance documentation requests.
- Collaborate with Infrastructure, Legal, HR, and external partners (auditors, MSSP/vendor partners) on security initiatives, incident response, and contractual or compliance requirements.
REQUIRED KNOWLEDGE, SKILLS, AND ABILITIES:
- Hands-on experience administering Rapid7 InsightVM and/or Rapid7 MDR, or a comparable enterprise vulnerability management/MDR platform.
- Working knowledge of security frameworks (such as CIS 18 or NIST CSF) and experience assessing or tracking control maturity.
- Experience designing and administering Zero Trust/Conditional Access policies, MFA, and identity protection within Microsoft Entra ID.
- Experience coordinating penetration tests or vulnerability assessments and translating findings into a prioritized remediation program.
- Solid understanding of infrastructure fundamentals (networking, Windows/Linux server administration, Active Directory/Entra ID) sufficient to assess risk.
- Demonstrated experience developing, reviewing, or maintaining IT and security policies, standards, and procedures.
- Incident response experience, including credential/session remediation, endpoint isolation, and clear written documentation of findings.
- Experience evaluating third-party vendors, applications, or software from a security risk perspective.
- Strong analytical and problem-solving skills, with the ability to communicate technical risk clearly to both technical and non-technical stakeholders, including in monthly leadership reporting.
- Demonstrated ability to mentor or coach colleagues on security best practices.
- Ability to work independently and manage multiple competing priorities in a fast-paced environment.
PREFERRED EDUCATION AND EXPERIENCE:
- 5+ years of experience in a dedicated cybersecurity role, ideally including vulnerability management and MDR/SIEM operations.
- One or more of the following certifications preferred: Security+, CISSP, CISM, or CCSP.
- Experience supporting compliance or regulatory requirements (e.g., cyber insurance questionnaires, data protection/privacy policy).
- Experience evaluating and scoping security tooling or vendor solutions.
PHYSICAL CAPABILITIES AND REQUIREMENTS:
- Sitting at a desk or standing at a workstation for extended periods (often 6 to 8 hours a day).
- Close visual acuity to view computer monitors, analyze data, and review security logs and technical documentation.
- Frequent use of hands, wrists, and fingers for typing, operating a mouse, and handling phone equipment.
- Ability to clearly speak, hear, and exchange information verbally and in writing with team members and stakeholders.
BENEFITS AND TOTAL REWARDS:
- Competitive wages, and opportunities for advancement.
- Medical, Dental, Vision, Critical Illness, Accident, and Flexible Spending Plans available.
- Company-paid Short/Long-term Disability, Life Insurance, and Employee Assistance plans.
- Company-paid Time-Off (PTO), Sick Leave, and Holiday Pay.
- Retirement 401(k) Plan with Discretionary Employer Match, and Profit Sharing.
- Wellness Programs, Clothing Allowance, Safety Shoes, and Safety Glasses Reimbursement.