{"id":1322927,"url":"https://alion.io/job/erock-cybersecurity-engineer","title":"Cybersecurity Engineer","company":{"id":2137844,"name":"ERock","domain":"erock.com","url":"https://alion.io/company/erock","size_band":"51-200","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Paylocity","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":"full_time","work_mode":"hybrid","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Houston, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":81000,"max_usd":168000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":194},"experience_years_min":4,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Defense in Depth","optional":false},{"name":"SIEM","optional":false},{"name":"TCP/IP","optional":false}],"status":"live","first_seen_at":"2026-08-24T23:33:40Z","employer_posted_date":"2026-09-26","last_verified_at":"2026-09-27T12:41:29Z","board_verified":true,"closed_at":null,"days_open":34,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":34},"description":"Description\nWe are ERock!\nERock is a leader and innovator in distributed energy. ERock has responded to long-term trends in electricity by becoming the first smart-grid supplier to US energy consumers. The company installs, operates, and integrates its highly flexible, low-cost, and quick-response distributed generation to increase reliability and stability, reduce costs and decrease carbon footprint.\nAt ERock, our backup generators ensure that customers will never be without power, allowing their business to operate normally when there is an outage in the area. Our innovative approach provides customers with highly reliable, ultra-clean backup generation at a fraction of the cost of traditional backup solutions. We seek those who share our commitment to customer service, innovation, and ingenuity.\nRole Overview:\nWe are seeking a Cybersecurity Engineer to help secure our organization’s systems and data through a combination of hands-on engineering and governance, risk, and compliance (GRC) practices. In this role, you will apply cybersecurity best practices, risk management, and vulnerability management to protect the organization’s confidentiality, integrity, and availability. You will identify threats and risks, implement effective security controls, and support monitoring and incident response activities.\nYou will operate with a high degree of independence, designing and executing enterprise-grade security solutions aligned with regulatory requirements and industry frameworks. The ideal candidate is both technical and analytical, capable of translating compliance requirements into practical solutions while driving continuous improvement across security operations. This role reports to the Sr. Cybersecurity Manager and follows a hybrid work model.\n Key Responsibilities:\nDesign, implement, and maintain enterprise-grade security solutions aligned with regulatory requirements and frameworks (e.g., NIST, NERC CIP)\nOperate with a high degree of independence, driving security initiatives end-to-end from design through implementation\nMonitor, detect, and respond to cyber threats and vulnerabilities across IT and OT environments\nLead or support incident response activities, ensuring timely containment, remediation, and documentation\nMaintain and improve incident response playbooks, runbooks, and tabletop exercises\nConduct risk assessments, vulnerability scans, and remediation tracking, focusing on measurable risk reduction\nTrack emerging threats and translate threat intelligence into improved detections and controls\nPerform and support security validation activities, including penetration testing and control testing\nTranslate GRC requirements into practical technical controls and sustainable processes\nSupport and enforce security policies, standards, and procedures, ensuring audit readiness\nContribute to and evolve security architecture across identity, network, cloud, and OT environments\nCollaborate with IT and business teams to embed security into systems and operations\nImplement, tune, and optimize security technologies (SIEM, EDR, IDS/IPS, etc.)\nAnalyze logs and alerts to identify and investigate suspicious activity\nSupport implementation of data protection and encryption controls\nPrepare and maintain security documentation and audit artifacts\nSupport third-party risk management and vendor security reviews\nProvide technical guidance and mentor team members, acting as a deputy when needed\nPromote a culture of security awareness and continuous improvement\nSupport security of OT/ICS environments, including SCADA systems and NERC CIP-aligned controls\nRequirements\n Basic (Required) Qualifications:\nBachelor’s degree in computer science, Information Systems, or equivalent education or work experience\n4+ years of prior relevant experience\nHold Cybersecurity certifications (Security+, SSCP, GSEC, CRISC) and/or specific training and certification in security risk management and IT controls frameworks, such as NIST 800-39, 800-30, 800-53, or CSF.\nCompetency in:\nStrong written and verbal communication (technical + non-technical audiences)\nProject and initiative ownership\nAttention to detail with an audit and risk mindset\nCritical thinking and problem-solving\nAbility to mentor and uplift team members\nComfortable operating both independently and as part of a team\nRequired Skills, Knowledge, and Abilities:\nAdvanced understanding of TCP/IP, common networking ports and protocols, traffic flow, system administration, OSI model, defense-in-depth, and common security elements.\nDeep understanding of networking (TCP/IP, ports, protocols, OSI model, traffic flows)\nHands-on experience with log analysis, threat investigation, and incident response\nExperience with vulnerability management platforms and remediation workflows\nProficiency with security tools such as:\no EDR / MDR\no SIEM (engineering, tuning, and use cases)\no IDS/IPS\no Endpoint and network forensics tools\nStrong understanding of modern security architecture (identity, cloud, endpoint, network)\nExperience supporting or operating security monitoring and detection capabilities at scale\nPhysical requirements and working conditions:\nMust possess mobility to work in a standard office setting.\nMust be able to use standard office equipment, including a computer.\nStamina to maintain attention to detail despite interruptions.\nStrength to lift and carry [computer equipment weighing up to 20lbs].\nVision to read printed materials and a computer screen.\nHearing and speech to communicate in person and over the telephone.\nPreferred Qualifications:\nBring a strong GRC foundation but can translate governance requirements into real technical controls\nHave hands-on experience with NERC CIP or regulated environments\nCan independently drive risk, compliance, and security improvement initiatives end-to-end\nNaturally operate as a technical leader and mentor, even without formal direct reports\nBalance strategic thinking with hands-on execution\n What Success Looks Like:\nSecurity controls are effectively implemented, monitored, and continuously improved, reducing overall organizational risk.\nCybersecurity initiatives are delivered end-to-end with minimal oversight, demonstrating strong ownership and accountability.\nThreats and vulnerabilities are identified early and addressed proactively, with measurable improvements in detection and response times.\nIncident response is well-coordinated, documented, and repeatable, with clear lessons learned driving ongoing improvements.\nCompliance requirements (e.g., NERC CIP, NIST) are translated into sustainable, auditable technical controls with minimal operational friction.\nSecurity tools (SIEM, EDR, etc.) are well-tuned and producing high-quality, actionable alerts rather than noise.\nRisk assessments and remediation efforts result in clear, measurable risk reduction across IT and OT environments.\nSecurity documentation, runbooks, and audit artifacts are accurate, up-to-date, and audit-ready at all times.\nCross-functional teams actively engage with and trust cybersecurity, reflecting strong collaboration and practical security integration.\nThe individual is recognized as a go-to technical leader and mentor, capable of stepping in to lead initiatives or guide the team when needed.\n Benefits:\nMedical, Dental, Vision, and Prescription Drug Insurance\nCompany-Paid Life Insurance\nFlexible Spending Account (FSA)\nWellness Programs and Incentives\n401(k) Retirement Plan & Company Match\nPaid Time Off - Sick & Vacation Time\nPaid Holidays\nHybrid Work Schedule!\nCool Open-Office Concept\nDo you have what it takes to join the ERock team? Send us your cover letter and resume today.\nThe physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.\nERock is committed to creating a diverse environment and is proud to be an equal opportunity employer. All qualified applicants will receive consideration for employment without regard to race, color, religion, gender, gender identity or expression, sexual orientation, national origin, genetics, disability, age, or veteran status.\nAt ERock, we embrace diversity, including all the unique characteristics that make us human: race, age, sexual orientation, gender identity, religion, disability, and education - to name a few. We understand and recognize that diverse backgrounds and perspectives strengthen our teams and our business. The foundation of our diversity efforts is closely tied to our core values specifically our value of “The Team” which includes “Mutual Respect, Openness, and Honesty.”","description_format":"text","description_chars":8730,"description_truncated":false,"requirements":{"experience_years_min":4,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":true},"security_clearance":false,"languages":[]},"benefits":["Hybrid work","Life insurance","Retirement plans","Wellness"],"hiring_locations":[{"name":"United States","iso":"US","kind":"country"}],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Data & Analytics","Financial Services"],"lifecycle":[{"event":"open","at":"2026-09-26T23:27:03Z"}],"liveness":{"score":51,"band":"ok","label":"Likely open","p_open":1,"p_active":0.682,"p_room":0.75,"age_days":33,"expected_fill_days":39,"reasons":["conf:3","velocity","win:late"],"computed_at":"2026-09-27T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/erock-cybersecurity-engineer","json_url":"https://alion.io/job/erock-cybersecurity-engineer.json","meta":{"generated_at":"2026-09-28T04:21:28Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2625,"day_limit":5000,"remaining_today":2375,"minute_limit":60,"resets_at":"2026-09-29T00:00:00Z"}}}