Point your AI agent at freehire and let it find you a job.

Get the CLI →

VSE AVIATION

NewBe an early applicant

Sr. Cybersecurity Integration Engineer (USI9) (2697)

Posted Updated
Discussion

Summary

Field-based senior security engineer at an aviation parts/MRO company who travels ~75-80% to newly acquired sites to bring them up to VSE security standards: assesses security posture, leads perimeter firewall and network segmentation buildouts, deploys Zero Trust identity controls, EDR, email security, and SIEM onboarding, then hands off to steady-state operations.

SUMMARY:

VSE Aviation is building a dedicated IT Integration Team, and this role, the Senior Cybersecurity Integration Engineer, brings every acquired site up to VSE security standards, from post-closure activities through architecture buildout and handoff to steady-state operations. This is a senior individual contributor role, and the engineer is trusted to move without waiting for direction. Working alongside the IT Technology Services Integration Specialists, the engineer is the security lead for firewall and network architecture, identity and Zero Trust, endpoint, email protection, and SIEM onboarding. The primary focus is network security: perimeter design, firewall buildout, and segmentation at sites VSE has just acquired and does not yet fully understand. This scope covers the full security scope at a newly acquired site. The engineer designs within VSE's standards and tooling, brings proposed changes back to the cybersecurity team, and partners with security operations through implementation so each site reaches steady-state monitoring without disrupting the business. The position is field-based: travel to acquisitions at both domestic and international sites is required approximately 80% of the time, including overnight, weekend, and on-call coverage during go-live and hyper care periods.

DUTIES & RESPONSIBILITIES:

Responsibilities include, but are not limited to:

Assessment and Containment

  • Execute the day-one security onboarding checklist for acquired site personnel and systems.
  • Assess and document the acquired entity's existing security posture, including known vulnerabilities, unmanaged assets, privileged accounts, and control gaps; produce a written risk summary for IT and business leadership.
  • Conduct initial network reconnaissance and perimeter review, including inbound exposure, remote access paths, and third-party connections.
  • Escalate to cybersecurity leadership on indicators of active or historical compromise, proposed risk acceptances, deviations from VSE security standards, and unplanned spending.

Firewall and Perimeter Buildout

  • Lead the physical and logical deployment of perimeter firewalls at integration sites.
  • Configure firewall rule sets, site-to-site and remote-access VPN, and inspection policy per VSE standards.
  • Validate firewall posture through policy review, traffic analysis, and post-deployment testing.
  • Coordinate with the Infrastructure team on network segmentation design and firewall placement relative to LAN, wireless, and OT/warehouse systems.
  • Decommission or isolate legacy perimeter devices and third-party remote access after cutover.

Identity and Zero Trust

  • Implement Zero Trust Network Access controls, enforcing least privilege across user roles, systems, and applications.
  • Configure Conditional Access policies, device compliance requirements, and application access controls in Microsoft Entra ID.
  • Enforce User Assignment Required on all enterprise applications and remediate legacy authentication.
  • Configure and validate MFA and identity protection for all user accounts, including service and privileged accounts.
  • Validate Zero Trust posture through access review, policy testing, and monitoring dashboards.

Security Tooling and Telemetry

  • Work with the IT point of contact at the acquired company to deploy and configure endpoint detection and response (EDR) across all acquired-site devices and servers; confirm full coverage against the asset inventory.
  • Integrate the acquired site into VSE's SIEM platform, ensuring log source onboarding, ingestion health, and alerting coverage.
  • Implement email security tooling aligned to VSE standards, including anti-phishing, secure email gateway, and DLP policy.
  • Validate that security telemetry is being monitored and that alerting is routed correctly before declaring the site integration complete.

Equipment, Vendor, and Licensing Management

  • Coordinate with vendors to order security hardware, including firewalls and endpoint sensors.
  • Manage vendor relationships for security tooling, including licensing, and support escalations.
  • Manage security application license allocations and ensure compliance with vendor agreements.
  • Track hardware delivery, inventory, and deployment readiness against the integration schedule.

Closeout, Documentation, and Continuous Improvement

  • Maintain per-site integration documentation: architecture diagrams, rule sets, exceptions, and residual risk.
  • Produce a formal security handoff package transitioning the site to steady-state IT and security operations.
  • Track and drive closure of open security findings and accepted-risk items after cutover.
  • Surface integration milestones, blockers, and cross-team dependencies in integration stand-ups and the shared IT Integration project workspace.
  • Serve as the cybersecurity contributor in PMO-led integration project closeouts, presenting security outcomes, residual risk, and unresolved findings for each completed site.
  • Maintain and improve VSE's cybersecurity integration playbook and supporting documentation, translating lessons learned from each closeout into updated standards, checklists, and effort estimates that inform security requirements and risk assumptions on future integrations.
  • Other duties as assigned.

MINIMUM REQUIREMENTS:

Demonstrated firsthand experience is the primary screening criterion for this role. Certifications are treated as supporting evidence and are not a substitute for a verifiable record of building and defending enterprise networks.

  • Bachelor’s degree in information technology, cybersecurity, or a related field
    • Or an additional 3 years of specific work experience in lieu of degree.
  • 7 years of firsthand network security engineering in a multi-site enterprise environment, including at least three years at a senior or lead level.
  • Demonstrated ability to own a security architecture end to end: assess, design, build, validate, document, while following defined standards, and hand off with no senior engineer above them.
  • Deep, demonstrable enterprise firewall experience: physical deployment, rule set design and cleanup, NAT, site-to-site and remote-access VPN, and inspection policy on a major next-generation firewall (NGFW) platform. Candidates should be able to walk through firewall deployments they personally designed and built.
  • Proven network segmentation design experience, including the ability to segment a network the candidate did not build and does not have complete documentation for.
  • Strong routing and switching fundamentals: VLANs, dynamic routing protocols, and ACLs.
  • Practical experience migrating production firewalls and VPN appliances off legacy platforms without causing a business outage.
  • Demonstrated ability to assess an unfamiliar environment and build a migration plan that brings it to standard, including compensating controls for business-critical systems that must remain in place and accessible to the business.
  • Working expertise in Microsoft 365 and Entra ID security, including Conditional Access, MFA, and identity protection.
  • Practical experience deploying and operating an EDR platform at scale.
  • Track record of building to an established enterprise security standard and improving it within a team.
  • Comfortable operating independently in the field while staying closely connected to an in-house security team.
  • Willingness and ability to travel up to 75% to acquisition sites, including occasional short-notice travel.

PREFERRED REQUIREMENTS:

  • Prior experience as technical lead on M&A technology integration, carve-outs, or divestitures.
  • Experience presenting security risk findings to executives or acquiring company leadership.
  • Vendor firewall certification (Palo Alto, Fortinet, Cisco) or an industry certification such as CISSP or GIAC (GSEC, GCIH, GCIA).
  • Experience in aviation, aerospace, defense, or another regulated manufacturing or MRO environment.
  • Familiarity with NIST CSF, NIST SP 800-171, or CMMC control expectations.
  • Experience securing warehouses, shop floor, or OT-adjacent environments where downtime tolerance is low.
  • Scripting, automation, or AI-assisted tooling (PowerShell, Python) to speed up onboarding and validation at scale.

OTHER:

  • Remote-based role with sustained periods on-site at acquisition locations; travel may reach 75% during active integration cycles.
  • Occasional after-hours and weekend work required to support cutover windows.
  • Must be able to lift and rack network and security hardware (up to 40 lbs.) and work in data closets, MDF/IDF spaces, and warehouse environments.
  • Must be able to meet any customer- or contract-driven background screening requirements.
  • The selected applicant will be subject to a background check and drug testing.

Skills

What Senior Security jobs ask for — and how much of it you have →

See also

Security jobs by country — openings, pay and top skills →

Tailor your CV for this role?

We couldn't check your fit for this role — add a CV to your profile to see it next time.

A new version of freehire is available