Description
Location: Fully remote
Shift: 8 AM – 5 PM EST (1 hr lunch)
Hours: 40 Hours a week, no OT, no weekend work
Duration: 1 year initial contract, medium possibility of extension.
Conversion depending on business condition at the time.
JOB DESCRIPTION:
• Extensive M&A cybersecurity due diligence experience, including conducting security assessments of acquisition targets, identifying technical risks, validating security control implementations, and translating findings into actionable integration plans.
• Deep security engineering expertise across endpoint, identity, network, cloud, and infrastructure domains, with the ability to independently validate security configurations rather than relying solely on interviews or documented responses.
• Advanced endpoint security knowledge, including deployment and administration of EDR, antivirus, disk encryption, device control, MDM, Group Policy, and endpoint hardening technologies across Windows, macOS, and Linux environments.
• Hands-on compromise assessment and threat hunting experience, including forensic data collection, telemetry analysis, identification of Indicators of Compromise (IoCs), endpoint triage, and validation of containment or remediation activities.
• Strong network and edge security engineering capabilities, including architecture reviews and configuration analysis of firewalls, IDS/IPS, web proxies, SSL/TLS inspection platforms, WAFs, VPNs, ZTNA solutions, Citrix environments, and network segmentation controls.
• Expert-level identity and access management knowledge, including SAML, OAuth, federation services, MFA implementation, privileged access controls, conditional access policies, and Zero Trust security architectures.
• Practical PKI and certificate management experience, including certificate lifecycle management, internal and external certificate authorities, secrets management, TLS hardening, and identification of legacy protocol risks.
• Advanced email security expertise, including secure email gateway technologies, anti-phishing controls, domain authentication standards (SPF, DKIM, DMARC), and cloud email security platforms.
• Strong SIEM and security telemetry experience, including log source validation, ingestion sizing, use case assessment, logging coverage review, and forecasting licensing requirements for enterprise security platforms.
• Experience gathering and validating infrastructure metrics from enterprise systems, such as Active Directory, cloud environments, CMDBs, endpoint management platforms, vulnerability scanners, and SIEM solutions to support integration planning and budget forecasting.
• Working knowledge of leading enterprise security platforms, including CrowdStrike, Zscaler, Splunk, Wiz, Microsoft security technologies, and other modern cybersecurity tooling commonly used during post-acquisition integration efforts.
• Demonstrated experience developing Day 1 and Day 100 integration plans, with an understanding of security control rationalization, tooling consolidation, migration sequencing, and risk-based remediation prioritization.
• Hands-on remediation experience, including deployment of security agents, implementation of MFA controls, API security improvements, protocol hardening, endpoint policy enforcement, and validation of completed corrective actions.
• Strong technical leadership and stakeholder engagement skills, enabling effective collaboration with target-company administrators, infrastructure teams, security personnel, consultants, and acquisition stakeholders while driving technical outcomes.
• Ability to translate complex technical findings into executive-level risk and integration recommendations, producing assessment reports, remediation roadmaps, integration runbooks, and budgetary forecasts suitable for both engineering teams and leadership audiences.
• A minimum of 8 years of progressively responsible experience in cybersecurity engineering, security architecture, incident response, infrastructure security, and enterprise technology integrations, with prior participation in M&A due diligence or post-acquisition integration activities strongly preferred.