{"id":2000889,"url":"https://alion.io/job/neumo-cybersecurity-engineer-remote","title":"Cybersecurity Engineer (Remote)","company":{"id":2482496,"name":"Neumo","domain":"neumo.com","url":"https://alion.io/company/neumo","size_band":"1001-5000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"ADP","truth_index":{"grade":"B","score":75,"open_postings":10,"ghost_share":0,"stale_share":1,"repost_share":0,"time_to_fill_p50_days":null,"computed_at":"2026-10-09T06:01:00Z"}},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":[],"countries":[],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":null,"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Agentic Workflows","optional":false},{"name":"AI Agents","optional":false},{"name":"AWS","optional":false},{"name":"Azure","optional":false},{"name":"Cloudflare","optional":false},{"name":"Copilot","optional":false},{"name":"Delinea","optional":false},{"name":"FedRAMP","optional":false},{"name":"Incident Management","optional":false},{"name":"LLM","optional":false},{"name":"LLM Guardrails","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"MITRE ATT&CK","optional":false},{"name":"PCI DSS","optional":false},{"name":"Python","optional":false},{"name":"Red Teaming","optional":false},{"name":"SentinelOne","optional":false},{"name":"SIEM","optional":false},{"name":"SOC 2","optional":false},{"name":"Terraform","optional":false},{"name":"Wiz","optional":false},{"name":"Zero Trust","optional":false}],"status":"live","first_seen_at":"2026-09-09T20:09:00Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-10-09T23:28:41Z","board_verified":true,"closed_at":null,"days_open":30,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":30},"description":"Job Summary:\nNeumo is a PE-backed govtech company formed from the merger of Avenu, ITI, and GovOS, delivering payments, DMV, justice, revenue compliance, and public administration solutions to state and local government clients nationwide. Our InfoSec program operates under SOC 1, SOC 2, and PCI DSS, and active pursuit of FedRamp High and GovRamp.\nWe're growing our InfoSec team and looking for a hands-on Security Engineer who blends deep technical depth across the security stack with fluency in AI-assisted tooling. You'll own and harden our perimeter and cloud defenses, build detection and automation as code, and be a first responder when incidents happen..\nDuties and Responsibilities:\nPerimeter, Cloud & Application Security\nOwn perimeter security controls: WAF, firewall, and CDN policy - including authoring and tuning bot management rules to block automated abuse without harming legitimate traffic.\nWrite and maintain Terraform to manage security infrastructure as code across cloud and edge environments (version-controlled, peer-reviewed, repeatable).\nSecure our AWS/Azure environments: harden configurations, close CSPM findings, and partner with engineering on secure-by-design reviews.\nOwn email security end-to-end: configure and tune the secure email gateway, enforce DMARC/SPF/DKIM (including moving DMARC toward quarantine/reject), and manage attachment sandboxing and URL rewriting/detonation.\nRun phishing simulation and awareness campaigns, report on click/report rates, and use results to tighten filtering rules and target training.\nDetect and respond to business email compromise and account takeover, mailbox forensics, inbox-rule abuse, OAuth/app-consent abuse, and coordinating with IT on containment.\nSIEM, Logging & Detection Engineering\nOwn log source onboarding across cloud (AWS/Azure), identity, endpoint, network/perimeter, and email systems, ensuring coverage gaps are identified and closed.\nBuild, tune, and maintain correlation rules and detection content in the SIEM, continuously reducing false positives/negatives and improving signal-to-noise for the team.\nDefine and maintain log retention, normalization, and parsing standards to support investigations, audits, and PCI DSS / SOC 2 / FedRAMP logging requirements.\nBuild dashboards and alerting for key telemetry (identity, servers, endpoint, cloud, perimeter, email, critical systems) and report on SIEM health, coverage, and detection efficacy to the CISO.\nMap detection content to a framework such as MITRE ATT&CK and close identified coverage gaps.\nDetection, Response & Endpoint\nOperate and tune EDR and MDR tooling; triage alerts across the security stack and drive them to resolution.\nParticipate in incident management as needed, including after-hours response: investigation, containment, remediation, and clear post-incident write-ups.\nSupport annual incident response tabletop exercises and help mature our IR runbooks.\nContribute to red team / adversarial simulation exercises and support annual third-party penetration testing, translating findings into fixes.\nIdentity, Endpoint & Zero Trust\nAdvance our Zero Trust architecture across identity, network segmentation, and access policy.\nAdminister MDM and BYOD programs, balancing usability with device compliance and data protection standards.\nAI-Augmented Security Engineering\nUse AI coding assistants and agentic tooling to accelerate detection engineering, automation, and Terraform development, while applying sound judgment about what AI-generated output ships to production.\nEvaluate and pilot AI-driven security tooling (e.g., AI-assisted triage, threat detection, or bot/traffic classification) and help set guardrails for safe internal use of AI.\n\nEducation and Experience:\n5+ years in a security engineering or security operations role, with direct, hands-on experience across most of: perimeter/WAF and bot management, EDR/MDR, SIEM, MDM/BYOD, Zero Trust, cloud security, and email security.\nHands-on SIEM experience: onboarding log sources, writing/tuning correlation and detection rules, and managing retention and parsing.\nHands-on email security experience: secure email gateway administration, DMARC/SPF/DKIM enforcement, and BEC/phishing investigation (e.g., Proofpoint, Abnormal Security, Mimecast, or Microsoft Defender for Office 365).\nExperience participating in incident response, including on-call or after-hours response to active incidents.\nExperience in a regulated or compliance-heavy environment (PCI DSS, SOC 2, FedRAMP/GovRAMP, or similar).\nRelevant certifications: OSCP, GPEN, GCIH, Security+, or CISSP.\nExperience with tools such as Cloudflare, SentinelOne, Tenable, Wiz, or Delinea (or direct equivalents).\nKnowledge, Skills and Abilities:\nWorking proficiency with Terraform or another IaC tool, plus scripting ability (Python, Bash, or similar) for automation.\nExposure to red teaming or offensive security: as a practitioner, or in close partnership with red team / pen test engagements.\nComfort using AI tools (Copilot-style coding assistants, LLM-based analysis, agentic workflows) as part of daily engineering work, with a clear-eyed view of their limits.\nClear written communication: you can document an incident or a control decision so a non-technical exec or an auditor can follow it.\nWork Environment:\nOffice setting with a moderate noise level.\nThe employee will work at an individual workstation, using a telephone and computer.\nPhysical Demands:\nMust be able to remain seated for extended periods.\nRegular use of a computer and other office machinery, such as printers and copy machines.\nOccasional movement around the office.\nFrequent communication via telephone.\nNeumo Summary:\nWith the backing of four decades of public sector expertise and corporate capability, Neumo has successfully supported government services. Neumo was honored and recognized for four (4) consecutive years as a GovTech 100 Company representing the top 100 companies focused on making a difference in and selling to state and local government agencies across the United States.\nNeumo is committed to helping communities thrive and brings a wealth of experience combined with innovation. Today, Neumo offers more administrative and financial support to government officials than any other organization. And with a responsive, client-focused approach, we foster partnerships that give our customers the certainty they need to accomplish more.\nNeumo offers a competitive benefits and compensation package and are looking for team members who will thrive in our dynamic environment.\nNeumo is an Equal Opportunity Employer. Selection for a position will be made without regard to race, religion, national origin, sex, political affiliation, marital status, non-disqualifying physical handicap, and age.","description_format":"text","description_chars":6781,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Government","Digital Government"],"lifecycle":[{"event":"open","at":"2026-10-07T11:27:25Z"}],"visa":[],"liveness":{"score":29,"band":"fade","label":"Fading","p_open":1,"p_active":0.525,"p_room":0.55,"age_days":29,"expected_fill_days":29,"reasons":["conf:6","stale_co","velocity","win:tail"],"computed_at":"2026-10-09T06:01:00Z"},"pay":null,"html_url":"https://alion.io/job/neumo-cybersecurity-engineer-remote","json_url":"https://alion.io/job/neumo-cybersecurity-engineer-remote.json","meta":{"generated_at":"2026-10-10T01:55:29Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","about":"Alion is a live layer of people, companies and AI agents: who they are, whether they are real and active right now, what they do and how to work with them, readable by people and by agents and paid per call.","catalog":"https://alion.io/catalog.json","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":3409,"day_limit":5000,"remaining_today":1591,"minute_limit":60,"resets_at":"2026-10-11T00:00:00Z"}},"offers":[{"id":"company.slices","title":"One company in depth, by slice","status":"live","price":{"credits":0.02,"usd":0.002,"plus_per_slice":{"credits":0.05,"usd":0.005}},"unit":"per company, plus each slice with data","note":"the employer in depth","call":{"mcp_tool":"get_company","arguments":{"id":2482496},"rest":"https://alion.io/mcp/rest/get_company?id=2482496"},"human":"https://alion.io/catalog?offer=company.slices&for=job%2Fneumo-cybersecurity-engineer-remote"},{"id":"market.stats","title":"A market slice: pay, demand and time to fill","status":"live","price":{"credits":1,"usd":0.1},"unit":"per slice","note":"pay, demand and time to fill for this role and place","call":{"mcp_tool":"market_stats"},"human":"https://alion.io/catalog?offer=market.stats&for=job%2Fneumo-cybersecurity-engineer-remote"},{"id":"job.search","title":"Open jobs by role, technology, place, pay and visa","status":"live","price":{"credits":0.02,"usd":0.002},"unit":"per posting in a list","note":"similar open postings","call":{"mcp_tool":"search_jobs"},"human":"https://alion.io/catalog?offer=job.search&for=job%2Fneumo-cybersecurity-engineer-remote"},{"id":"company.verify","title":"Is this company real and active right now","status":"pilot","price":null,"unit":"per company","request":{"url":"https://alion.io/catalog/request","method":"POST","body":"{\"offer\": \"company.verify\", \"for\": \"job/neumo-cybersecurity-engineer-remote\", \"note\": \"what you need it for\"}"},"human":"https://alion.io/catalog?offer=company.verify&for=job%2Fneumo-cybersecurity-engineer-remote"}]}