Junior Cybersecurity Engineer
The Junior Cybersecurity Engineer supports both security operations and assurance functions, including monitoring security systems, managing vulnerabilities, and conducting IT security assessments. This entry-level role offers exposure to engineering and governance, risk, and compliance activities, providing a foundation for career growth in cybersecurity. The position requires collaboration with the security team to protect Confidential Client and ANAB information systems and ensure compliance with security policies and standards.
About Careertakes
👉 Important disclosure: Careertakes is a third-party recruiting platform supporting this hiring process. If selected, you will be employed directly by our client, Standards & Accreditation.
Applicants for this role may also receive access to additional matched opportunities through the Careertakes platform.
Overview
Confidential Client is hiring a Junior Cybersecurity Engineer (entry-level) to join their security team in Manhattan, NY. This role blends hands-on security operations (SIEM/log review, endpoint hardening, patch follow-up) with security assurance (assessments, vendor reviews, compliance and risk reporting). The position reports to the Chief Information Security Officer (CISO) and is designed for candidates starting their cybersecurity careers who want exposure to both engineering and GRC (governance, risk & compliance).
Key Responsibilities
- Monitor security logs and alerts, triage and escalate confirmed issues to senior engineers
- Maintain an accurate inventory of systems, infrastructure and applications; ensure logging coverage to the SIEM/log-management platform
- Validate configurations and access rights on security tooling (firewalls, IPS, WAF, EDR/endpoint protection); report deviations
- Support firewall change management: review requests, document approvals and assist rule recertification
- Assist with network segmentation and secure-architecture tasks
- Help run vulnerability and threat management activities; verify patch deployment and follow up on overdue items
- Operate and maintain security infrastructure and automated controls across servers, endpoints, cloud workloads and network environments
- Support privileged activity monitoring and associated investigations
- Support cryptographic key management tasks under established procedures
- Act as first-line support during incidents: triage alerts, preserve evidence, document timelines and assist recovery
- Create, run and improve incident response playbooks
- Schedule and coordinate vulnerability and penetration testing; consolidate findings and track remediation through closure
- Perform vendor security assessments and maintain assessment records
- Assist with internal/external audit evidence preparation and remediation tracking
- Contribute to security awareness and maintain documentation, runbooks and recurring reporting
Success Metrics (KPIs)
- Timely triage and escalation of alerts and log review queues
- Timely closure of vulnerabilities, patches and audit findings with clear remediation tracking
- Completion of scheduled assessments and recertifications within scope and on time
- High quality, audit-ready documentation and evidence with minimal rework
Qualifications
- Bachelor’s degree in computer science, information security, information systems or a related field — OR an associate degree with relevant hands-on experience or a recognized technical certification
- Approximately 0–5 years of professional exposure to information security; experience spanning both operational security and audit/compliance is a plus
- Entry-level security certification preferred (CompTIA Security+, CySA+, Network+, ISC2 CC) or willingness to obtain within 12 months
- Working knowledge of networking fundamentals (TCP/IP, DNS, routing, segmentation) and Windows/Linux OS
- Familiarity with cloud/SaaS concepts (Microsoft 365, Azure preferred)
- Comfortable with basic scripting (PowerShell, Python) for reporting and automation
- Familiarity with security tooling: SIEM/log management, EDR, firewalls, IPS/WAF, vulnerability scanners, MFA/identity management
- Attention to detail and rigor in evidence and documentation
- Strong communication skills; able to explain risks in plain language to non-technical colleagues
- Ability to handle confidential information with discretion and occasionally be available outside standard hours for incidents or audits
- Curiosity and a drive for continuous learning; interest in progressing toward a security engineering or GRC specialization
Preferred / Nice-to-Have
- Exposure to security frameworks (NIST CSF, NIST SP 800-53, ISO/IEC 27001, CIS Controls)
- Experience with cloud security tools and automation
- Prior work supporting compliance or audit activities
Compensation & Location
- Starting compensation: $82,800 — $91,100 per year (depending on education, experience and qualifications)
- Location: Manhattan, NY — on-site or primarily on-site (specific scheduling and hybrid expectations will be clarified during the interview process)
- Employment type: Full-time
Why Join
- Structured mentorship from senior security staff and the CISO
- Exposure to both security operations and compliance/assurance work — ideal for building a broad cybersecurity foundation
- Support for professional development and certifications
- Work on meaningful security programs that support the client’s mission and accreditation activities
Required Legal & Compliance Notes
- Confidential Client and Careertakes are committed to lawful, non-discriminatory hiring practices in New York and all U.S. jurisdictions where this posting is visible.
- This posting contains a reliable salary range per applicable pay transparency requirements.
Equal Opportunity & Hiring Transparency
Careertakes and our client are Equal Opportunity Employers committed to building a diverse and inclusive workforce. We prohibit discrimination or harassment of any kind. To support a fair and efficient hiring process, AI tools may be used to assist with application review or resume screening. These tools do not replace human decision-making. Final hiring decisions are made by people.
If you have questions about how your data is used, please contact us directly.
Negotiate a higher salary! Check the salary ranges for this job type in your area.
View My Salary Range