- Design, deploy, and manage endpoint security solutions (EDR/XDR) across macOS and Windows fleets
- Own network security architecture including firewall rule management, IDS/IPS tuning, and VPN infrastructure
- Lead vulnerability management program, including scanning, prioritization, and coordination of remediation
- Administer and harden IAM systems including Okta and AWS IAM
- Develop and maintain security monitoring and alerting using SIEM platforms
- Conduct security assessments of new tools, vendors, and architectural changes
- Drive cloud security posture management across AWS environments
- Support CMMC Level 2 and NIST SP 800-171 compliance efforts
- Lead or support incident response, containment, and forensic analysis