{"id":1303343,"url":"https://alion.io/job/sourceability-cybersecurity-engineer","title":"Cybersecurity Engineer","company":{"id":1880443,"name":"Sourceability","domain":"sourceability.com","url":"https://alion.io/company/sourceability","size_band":"201-500","is_staffing_agency":false,"employer_type":"direct","is_intermediary":false,"listed_via":null,"ats_vendor":"Greenhouse","truth_index":null},"role":"Security","role_family":"Security","seniority":"middle","employment_type":null,"work_mode":"on_site","remote_scope":null,"remote_scope_basis":null,"remote_working_hours":null,"hiring_geo_confidence":"structured","locations":["Austin, United States"],"countries":["US"],"hiring_countries":[],"hiring_countries_total":0,"salary":null,"salary_estimate":{"min_usd":83000,"max_usd":172000,"period":"year","method":"role_seniority_country_remote_cell","sample_n":194},"experience_years_min":3,"visa_sponsorship":false,"relocation_package":false,"has_equity":false,"technologies":[{"name":"CI/CD","optional":false},{"name":"DNS","optional":false},{"name":"Least Privilege","optional":false},{"name":"Linux","optional":false},{"name":"SIEM","optional":false},{"name":"VPN","optional":false},{"name":"Windows","optional":false},{"name":"Zero Trust","optional":false},{"name":"AWS","optional":true},{"name":"Azure","optional":true},{"name":"CIS Benchmarks","optional":true},{"name":"GCP","optional":true},{"name":"GDPR","optional":true},{"name":"IAM","optional":true},{"name":"ISO 27001","optional":true},{"name":"Microsoft Defender","optional":true},{"name":"Microsoft Entra ID","optional":true},{"name":"Microsoft Sentinel","optional":true},{"name":"SOC 2","optional":true}],"status":"live","first_seen_at":"2026-09-09T18:36:59Z","employer_posted_date":"2026-09-09","last_verified_at":"2026-09-26T12:39:37Z","board_verified":true,"closed_at":null,"days_open":17,"trust":{"level":"ok","repost_count":null,"flags":[],"days_open":17},"description":"Sourceability® is a global digital distributor of electronic components transforming how modern businesses bring products to market. With innovation, qualityandlogisticsas the backbone of the company, Sourceability’scutting-edgeproducts and services expeditethe procurement process across a wide range of industries, including communications/cellular, consumer electronics, and auto manufacturing. \nSourceability is building a new Global Engineering Organization (GEO) to strengthen internal software delivery, production reliability, infrastructure operations, and practical security ownership across business-critical systems.\nWe are looking for a Cybersecurity Engineer to help implement, monitor, and improve security controls across Sourceability’s systems, infrastructure, endpoints, identity platforms, and engineering delivery processes. This role will work closely with the Infrastructure & Security Manager, SysOps, DevOps, Software Engineering, DBA, and business technology teams to reduce security risk in a practical and operationally effective way.\nThis is a hands-on security engineering role. The Cybersecurity Engineer will support vulnerability management, access control, endpoint and server security, network security, security monitoring, incident response, DevSecOps practices, and compliance evidence collection. This role is not expected to own all corporate security governance independently, but it will be a key execution role for improving Sourceability’s security posture.\nThe right candidate should be comfortable working in a hybrid environment with on-premise infrastructure, cloud services, distributed teams, business-critical applications, and security practices that are still being formalized as part of the GEO operating model.\nThis role is hybrid from our Austin, TX office. \nInsight on Your Impact:\nImplement, maintain, and improve practical security controls across servers, endpoints, cloud services, network infrastructure, identity systems, and engineering platforms.\nSupport vulnerability management, including scanning, validation, prioritization, remediation tracking, and reporting of security risks.\nMonitor security alerts and events from endpoint protection, SIEM / logging tools, vulnerability scanners, identity systems, firewalls, VPNs, and other security platforms.\nTriage security alerts, investigate suspicious activity, document findings, and escalate incidents through the agreed incident response process.\nSupport security incident response activities, including evidence collection, containment support, remediation tracking, and post-incident improvement actions.\nPartner with Infrastructure / SysOps teams on server hardening, patching, configuration baselines, backup security, firewall rules, VPN access, and network segmentation.\nPartner with DevOps and Software Engineering teams to embed security into CI/CD, code repositories, dependency management, secrets handling, release readiness, and application security checks.\nSupport identity and access management controls, including least privilege, role-based access, privileged account review, MFA, access reviews, and joiner / mover / leaver process improvements.\nAssist with endpoint, server, and cloud security tooling, including policy configuration, alert tuning, remediation follow-up, and operational documentation.\nSupport security reviews for new systems, integrations, infrastructure changes, vendor tools, and production-impacting technology decisions.\nHelp maintain security policies, standards, procedures, runbooks, and technical documentation in a practical and usable format.\nSupport compliance and audit activities by collecting evidence, documenting controls, and tracking remediation items, without becoming the sole owner of compliance programs.\nCommunicate security risks clearly to technical and non-technical stakeholders, including impact, priority, recommended actions, and remediation status.\nContribute to security awareness by helping teams understand practical security expectations and common risk areas.\nYour Qualifications, Your Influence:\n3+ years of experience in cybersecurity, information security, security engineering, infrastructure security, or similar hands-on security roles.\nPractical understanding of cybersecurity principles, vulnerability management, incident response, access control, endpoint security, network security, and secure system configuration.\nHands-on experience with security tooling such as EDR / endpoint protection, SIEM or log management, vulnerability scanners, identity platforms, firewall / VPN tools, or cloud security tools.\nWorking knowledge of Windows and Linux server security, patching, hardening, logging, and operational troubleshooting.\nUnderstanding of network security concepts including firewalls, VPN, DNS, IDS / IPS, segmentation, remote access, and zero trust principles.\nExperience supporting identity and access management practices, including MFA, least privilege, privileged access, role-based access control, and access reviews.\nAbility to investigate security alerts, analyze logs, validate vulnerabilities, document findings, and follow issues through remediation.\nUnderstanding of application security concepts, secure SDLC, dependency scanning, secrets management, SAST / DAST concepts, and DevSecOps practices.\nAbility to work with infrastructure, DevOps, software engineering, DBA, and business teams to implement security controls without unnecessarily blocking delivery.\nStrong written communication skills and ability to create clear documentation, runbooks, remediation notes, and risk summaries.\nHigh ownership mindset, structured troubleshooting approach, and ability to operate in a distributed, multi-timezone environment.\nPreferred Skills and Technical Familiarity:\nExperience with Microsoft security ecosystem, including Microsoft Defender, Microsoft Entra ID / Azure AD, Intune, Microsoft Sentinel, or related tools.\nExperience with security controls in hybrid environments that include on-premise infrastructure, cloud services, VPN, data centers, and distributed offices.\nFamiliarity with Azure, AWS, or GCP security services and cloud security best practices.\nExperience supporting vulnerability remediation for Windows servers, Linux servers, network devices, endpoints, databases, and web applications.\nFamiliarity with compliance frameworks or control libraries such as SOC 2, ISO 27001, NIST, CIS Controls, GDPR, or similar.\nExperience with secure configuration baselines, CIS benchmarks, patch management, endpoint management, and configuration drift detection.\nExperience with application security testing tools, dependency scanning, container scanning, or CI/CD security integrations.\nRelevant certifications such as Security+, CySA+, SSCP, CISSP Associate, CEH, Azure Security Engineer, or similar are helpful but not required.\nBackground in electronic components, B2B technology, supply chain, distribution, manufacturing, logistics, e-commerce, or similar business environments.\nSuccess in the First 90 Days:\nUnderstand Sourceability’s infrastructure, identity systems, endpoint environment, security tooling, production platforms, and key operational risks.\nBuild working relationships with the Infrastructure & Security Manager, SysOps, DevOps, Software Engineering, DBA, Product / Delivery, and business technology stakeholders.\nReview existing vulnerability management, patching, endpoint protection, IAM, logging, alerting, and incident response practices.\nIdentify the highest-priority security risks and create a practical remediation tracking approach with clear owners and due dates.\nImprove visibility into active vulnerabilities, access risks, alert trends, and security remediation status.\nHelp document or improve core security runbooks, including vulnerability response, security alert triage, access review, incident escalation, and remediation tracking.\nSupport at least one meaningful security improvement in endpoint security, server hardening, identity controls, vulnerability management, logging, or DevSecOps integration.\nHelp establish a practical security operating cadence with reporting that is useful to GEO leadership and technical owners.\nWhat This Role Does Not Own:\nThis role does not independently own all corporate security strategy, legal compliance, or executive-level security governance. The Cybersecurity Engineer supports security execution, control implementation, monitoring, investigation, documentation, and remediation tracking under the direction of Infrastructure & Security leadership.\nThis role does not replace Infrastructure / SysOps, DevOps, DBA, or Software Engineering ownership. Instead, it partners with those teams to improve security controls, reduce risk, and ensure remediation is completed by the appropriate technical owners.\nThis role does not independently approve business access decisions or security exceptions. It provides risk assessment, technical validation, and recommendations for review by the appropriate business and technology leaders.\nBenefits:\nCompetitive salary\nOngoing training and professional development opportunities\nCollaborative global work environment\nPTO\nEQUAL OPPORTUNITY EMPLOYER. \nIt is our policy to abide by all federal, state and local laws prohibiting employment discrimination based on a person’s race, color, religious creed, sex, national origin, ancestry, citizenship status, pregnancy, childbirth, physical disability, mental and/or intellectual disability, age, military status, veteran status (including protected veterans), marital status, registered domestic partner or civil union status, familial status, gender (including sex stereotyping and gender identity or expression), medical condition (including, but not limited to, cancer related or HIV/AIDS related), genetic information, sexual orientation, or any other protected status.","description_format":"text","description_chars":9873,"description_truncated":false,"requirements":{"experience_years_min":3,"management_years_min":null,"team_size_min":null,"manages_managers":false,"education":null,"security_clearance":false,"languages":[]},"benefits":["Professional development"],"hiring_locations":[],"hiring_excludes":[],"relocation_offered":false,"industries":["Cybersecurity","Information Security","Transportation & Logistics","Electronic Components Distribution"],"lifecycle":[{"event":"open","at":"2026-09-26T12:39:37Z"}],"liveness":{"score":73,"band":"hot","label":"Hiring now","p_open":1,"p_active":0.816,"p_room":0.9,"age_days":17,"expected_fill_days":43,"reasons":["conf:13","win:mid"],"computed_at":"2026-09-27T02:26:31Z"},"pay":null,"html_url":"https://alion.io/job/sourceability-cybersecurity-engineer","json_url":"https://alion.io/job/sourceability-cybersecurity-engineer.json","meta":{"generated_at":"2026-09-27T02:26:31Z","cache_seconds":300,"methodology":"https://alion.io/methodology","terms":"https://alion.io/terms","contact":"https://alion.io/contact","api":"https://alion.io/developers","usage":{"tier":"crawler","counted_by":"address","units_charged":1,"used_today":2180,"day_limit":5000,"remaining_today":2820,"minute_limit":60,"resets_at":"2026-09-28T00:00:00Z"}}}