{"id":1532301,"url":"https://alion.io/job/nextdecade-sr-specialist-cybersecurity","title":"Sr. Specialist, Cybersecurity","company":{"id":1871236,"name":"NextDecade","domain":"next-decade.com","url":"https://alion.io/company/next-decade","size_band":"501-1000","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Workday","truth_index":null},"role":"Security","role_family":"Security","seniority":"senior","employment_type":"full_time","work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Houston, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":104000,"max_usd":205000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":775},"experience_years_min":5,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"Azure","optional":false},{"name":"GDPR","optional":false},{"name":"ISO 27001","optional":false},{"name":"Microsoft Defender","optional":false},{"name":"Microsoft Defender for Cloud","optional":false},{"name":"Microsoft Entra ID","optional":false},{"name":"Microsoft Sentinel","optional":false},{"name":"OneDrive","optional":false},{"name":"SharePoint","optional":false},{"name":"SIEM","optional":false}],"status":"live","first_seen_at":"2026-09-30T16:50:14Z","employer_posted_date":"2026-09-30","last_verified_at":"2026-10-01T03:40:12Z","board_verified":true,"closed_at":null,"days_open":1,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":1},"description":"It's fun to work in a company where people truly BELIEVE in what they're doing!\nWe're committed to bringing passion and customer focus to the business.\nJOB SUMMARY\nThe Senior Cybersecurity Specialist is responsible for safeguarding NextDecade’s information assets, systems, cloud environments, and sensitive business data through the administration and continuous improvement of cybersecurity technologies, processes, and controls. This role serves as a subject matter expert for Microsoft security and compliance technologies, with particular emphasis on Microsoft Purview, Microsoft Defender, Microsoft Entra ID, data protection, and information governance.\nThe role combines cybersecurity operations, incident response, vulnerability management, data governance, compliance support, and employee awareness initiatives. The Senior Cybersecurity Specialist collaborates with Information Technology, Legal, Human Resources, Compliance, and business stakeholders to protect company information while supporting effective business operations.\nKEY RESPONSIBILITIES\nCybersecurity Operations and Incident Response\nMonitor, investigate, and respond to cybersecurity incidents, alerts, and threats.\nLead incident response activities, including detection, containment, eradication, recovery, post-incident analysis, and reporting.\nPerform threat hunting, root cause analysis, and forensic data collection for security events.\nCoordinate vulnerability assessments, remediation tracking, and patch-management follow-up.\nMonitor SIEM, EDR/XDR, and threat intelligence platforms to identify and respond to emerging risks.\nSupport cybersecurity aspects of business continuity, disaster recovery, and tabletop exercises.\nMicrosoft Purview and Data Protection\nAdminister and optimize Microsoft Purview solutions across the enterprise.\nDevelop and maintain data classification, sensitivity labeling, retention, and data lifecycle policies.\nConfigure and manage Data Loss Prevention policies across Microsoft 365, SharePoint, OneDrive, Teams, email, and endpoints.\nAdminister Information Protection, Records Management, eDiscovery, Audit, Insider Risk Management, and Communication Compliance capabilities, as assigned.\nSupport investigations involving sensitive data, insider risk, policy violations, litigation holds, and eDiscovery requests in coordination with Legal and Human Resources.\nDevelop, document, and promote secure data-handling and information-governance standards.\nIdentity, Cloud, and Security Platform Administration\nAdminister Microsoft Entra ID security controls, Conditional Access, multifactor authentication, access reviews, and privileged access capabilities.\nAdminister Microsoft Defender technologies, including Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps.\nSupport endpoint security, email security, cloud application security, and identity protection technologies.\nEvaluate and recommend improvements to cybersecurity tools, configurations, integrations, and processes.\nGovernance, Risk, and Compliance\nSupport cybersecurity risk assessments, compliance reviews, internal audits, and external audits.\nMaintain cybersecurity policies, standards, procedures, technical documentation, and control evidence.\nAssist with the alignment and monitoring of security controls against applicable frameworks and requirements, including NIST Cybersecurity Framework, CIS Controls, ISO 27001, SOX, GDPR, and other applicable privacy or regulatory obligations.\nTrack identified risks, findings, corrective actions, and remediation commitments through closure.\nSecurity Awareness and Collaboration\nDevelop and deliver cybersecurity awareness, phishing simulation, and secure data-handling initiatives.\nProvide practical cybersecurity guidance to employees, leadership, and project teams.\nPartner with infrastructure, applications, cloud, operational technology, and business teams to implement secure solutions.\nParticipate in technology projects and digital transformation initiatives to embed security and privacy requirements.\nMentor junior team members and support knowledge sharing across Information Technology.\nMaintain current knowledge of emerging threats, Microsoft security capabilities, industry trends, and regulatory developments.\nMINIMUM REQUIREMENTS\nBachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; an equivalent combination of education and relevant experience may be considered.\nMinimum of five years of progressively responsible cybersecurity or information-security experience.\nHands-on experience administering Microsoft 365 security and compliance technologies, including Microsoft Purview.\nExperience with Data Loss Prevention, data classification, sensitivity labels, information protection, records management, or eDiscovery.\nExperience with incident response, security investigations, identity and access management, and vulnerability management.\nWorking knowledge of SIEM, EDR/XDR, cloud security, and security monitoring technologies.\nExperience supporting risk assessments, compliance programs, audits, and security control documentation.\nStrong analytical, investigative, problem-solving, documentation, and communication skills.\nAbility to appropriately handle confidential and sensitive information and exercise sound judgment.\nPREFERRED REQUIREMENTS\nMicrosoft Certified: Information Protection and Compliance Administrator Associate (SC-400).\nMicrosoft Certified: Security Operations Analyst Associate (SC-200) or Identity and Access Administrator Associate (SC-300).\nCISSP, CISM, CompTIA Security+, CompTIA CySA+, or a comparable security certification.\nExperience with Microsoft Sentinel, Defender XDR, Azure security, security automation, and SOAR capabilities.\nExperience in an energy, critical infrastructure, engineering, construction, or other regulated environment.\nOFFICE WORKING CONDITIONS AND PHYSICAL EXPECTATIONS\nWork Environment\nThis position operates in a professional office environment with occasional work within or outside of a complex construction environment. This role routinely uses standard office equipment such as computers, phones, photocopiers/fax, filing cabinets, and related technology equipment. This is primarily a sedentary role; however, the incumbent must be able to stand and/or sit continuously to perform all essential job functions for a full shift.\nThe physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to support individuals with ADA-recognized disabilities to perform the essential functions of the job.\nAbility to lift up to 20 lbs. as required to lift files, boxes, and office equipment.\nAbility to open filing cabinets and bend, stand on a stool, or climb as necessary to perform these functions.\nWhile performing the duties of this role, the incumbent may be required to talk or listen.\nVision abilities include close vision, distance vision, color vision, and the ability to adjust focus.\nThe incumbent is required to stand, walk, use hands to handle or feel, and reach with hands and arms.\nAbility to move throughout all areas of each office, site location, and facility.\nAbility to wear all necessary personal protective equipment to perform job functions during site visits.\nOther Duties\nPlease note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.\nIn compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification documentation upon hire.\nNextDecade provides equal employment opportunities to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, in accordance with applicable federal, state, and local laws. NextDecade complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities.","description_format":"text","description_chars":8376,"description_truncated":false,"requirements":{"experience_years_min":5,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":{"level":"bachelor","optional":false},"security_clearance":false,"languages":[]},"benefits":[],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security"],"lifecycle":[{"event":"open","at":"2026-09-30T16:50:14Z"}],"liveness":{"score":86,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.86,"p_room":1,"age_days":0,"expected_fill_days":35,"reasons":["conf:2","win:early"],"computed_at":"2026-10-01T05:45:00Z"},"pay":null,"html_url":"https://alion.io/job/nextdecade-sr-specialist-cybersecurity","json_url":"https://alion.io/job/nextdecade-sr-specialist-cybersecurity.json","meta":{"generated_at":"2026-10-01T17:56:44Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":185,"day_limit":5000,"remaining_today":4815,"minute_limit":60,"resets_at":"2026-10-02T00:00:00Z"}}}