IT Systems Engineer
Position Title: IT Systems Engineer
Reports to: Director of Finance with line into Compliance
Direct reports: 1 (IT Specialist)
Location: Cincinnati, OH (Hybrid option after introductory period)
We’re hiring a Systems Engineer to lead and execute our NIST 800-171 and CMMC Level 2 compliance initiatives. This role bridges hands-on IT engineering, security control implementation, and program management. You’ll own the technical roadmap, stand up and harden the environment (e.g., GCC High/M365, Entra ID/Intune/Defender), implement and validate controls, maintain documentation (SSP, POA&M, policies), as well support day-to-day IT operations. Key Responsibilities:
Compliance & Security Engineering (40%)
- Lead technical implementation of NIST 800-171 and CMMC L2 controls across endpoints, identity, network, and SaaS.
- Stand up and administer compliant enclaves (e.g., Microsoft 365 GCC High), including Entra ID/Conditional Access, MFA, RBAC/least privilege, Intune device compliance, BitLocker, Defender for Endpoint/Office/Identity, and logging/retention.
- Engineer FIPS-validated encryption at rest/in transit; implement secure configuration baselines (CIS/NIST); enforce vulnerability management SLAs (scan, prioritize, remediate, verify).
- Build/maintain centralized logging and alerting (e.g., Microsoft Sentinel or equivalent SIEM), including detections for CUI handling and incident response playbooks.
- Implement secure backup & recovery (3-2-1, immutable/air-gapped copies, tested restores, RPO/RTO targets).
- Own the network compliance program plan with milestones, dependencies, and budget; drive cross-functional execution with IT, Security, Compliance, Operations, Legal and other key stakeholders.
- Maintain the SSP, POA&M, SPRS score, system boundary diagrams, data flows, and control evidence.
- Coordinate external partners (MSP/MSSP, auditors, assessors) and manage Statements of Work.
- Prepare for assessments (readiness reviews, objective evidence, control owner coaching).
- Draft, update, and enforce policies/standards/SOPs (access control, media protection, incident response, change mgmt, asset mgmt, BYOD, data retention, secure development, etc.).
- Establish configuration management and change control processes with complete audit trails.
- Train users on CUI handling, phishing, secure collaboration, and incident reporting.
- Oversee identity lifecycle, privileged access management, SSO, and conditional access.
- Administer Windows endpoints/servers, patching, GPO/Intune baselines, application packaging, and certificate management.
- Support network security (VLANs, firewalls, VPN/Zero Trust, DNS security) and SaaS governance (DLP, eDiscovery, sensitivity labels, data classification).
- Manage corporate hardware assets including PCs, laptops, tablets (iOS/Android), Zebra/industrial handhelds, scanners, and production-floor business hardware.
- Oversee configuration, deployment, inventory accuracy, preventative maintenance, and support for cameras and security camera systems (direct oversight and contractor coordination).
- Maintain lifecycle and warranty management processes for all IT hardware (procurement, imaging, deployment, repairs, replacements, and decommissioning).
- Manage and coach one direct report; set goals, delegate work, review performance, and develop necessary skills aligned to the future network system roadmap.
- Establish runbooks, escalation paths, and coverage plans.
- Perform other duties as assigned to support the IT, security, and compliance mission of the organization.
- 3–5+ years in systems engineering or security engineering within corporate IT, including hands-on M365/Entra ID/Intune administration.
- Demonstrated experience implementing NIST 800-171 or CMMC controls end-to-end (policy → tech control → evidence).
- Strong knowledge of DFARS 252.204-7012, incident reporting, CUI handling, and audit readiness.
- Proficiency with Windows client/server, Group Policy/Intune, Defender suite, SIEM (Sentinel preferred), vulnerability scanners (Defender TVM, Tenable, or Qualys), backup platforms, and PowerShell automation.
- Solid networking fundamentals: TCP/IP, DNS/DHCP, VLANs, VPN/Zero Trust, firewall rules, TLS/PKI.
- Hands-on experience supporting standard corporate endpoint hardware, including Windows PCs, laptops, and iOS/Android mobile devices, along with responsibility for routine hardware lifecycle processes (procurement, imaging, deployment, warranty coordination, and decommissioning).
- Proven project management ability (timelines, risks, budgets, vendors) and proficient documentation skills.
- Experience with GCC-High tenant builds/migrations and FedRAMP services.
- Prior work in defense/regulated manufacturing (ITAR/EAR awareness).
- Certifications: Security+ or CySA+, Microsoft (SC-200/SC-300/MD-102/AZ-500), CISSP, CCSP, or PMP.
- Exposure to—or direct experience with—industrial tablets, Zebra handheld scanners, and other ruggedized production-floor devices commonly used in manufacturing environments.
- Exposure to EDR/XDR tuning, DLP/sensitivity labels, eDiscovery, and data classification.
Benefits:
- Medical, Vision, Dental *Start on the 1st day of the following month after being hired*
- 401k with Company match of up to 6%!
- 12 Company Paid Holidays
- Additional PTO
- Luxfer Group (NYSE: LXFR)
Recommended Jobs
JPMA Client Operations Account Maintenance Associate
Job Description Join JPMorganChase and discover a career where your skills and ideas truly make a difference. You’ll help shape the future of data management by supporting client onboarding and co…
BIM Modeler
Job Title: BIM Modeler Job Description We are currently seeking a skilled BIM Modeler to join our team. This role is a direct hire position within a leading general contractor in the Great…
Pharmacy Technician II - Toledo Hospital
Location: Toledo Hospital Department: Pharmacy Weekly Hours: 40 Status: Full time Shift: Variable (United States of America) Job Summary: As the Pharmacy Technician II, you ass…
CDL-A Truck Drivers Local
CDL-A Truck Drivers Local Home Daily New Pay Increase & Safety Bonus Avg $1300 per wk $3k Sign-on Pay Full Benefits Must Live 60 mile Radius of Columbus Immediate Hiring 1 Year Tractor Traile…
Industrial Maintenance Technician | All Shifts
Industrial Maintenance Technician - All Shifts - Pay up to $34/hr Job Description: As an Industrial Maintenance Technician, you will be responsible for providing emergency and unscheduled repai…
Assistant Cottage Supervisor - Residential
Benefits and Salary: The salary for this is $21.30 per hour At Applewood, we prioritize our employees and their wellbeing. We provide competitive benefit options to our employees and their fami…
Assistant Supervisor
We are a growing company, currently seeking hard-working, dependable leaders to join our team. Position plays a critical role in ensuring the customers facilities are serviced to standards. Maintain …
Boxing Assembler
Now hiring Boxing Assemblers for a manufacturing company in Eastlake. 1 st shift: 8am – 4pm. 2 nd shift: 4pm – 12am. 3 rd shift: 12am – 8am. Weekly pay at $17 per hour. Job Duties: …
Direct Support Professional (DSP)
Direct Support Professional (DSP) / N ewark, OH / $17.75-$18.75 per hour At ViaQuest Residential Services our DSPs provide support to individuals with developmental disabilities In their homes.…
Process Technician
Job Responsibilities: Demonstrates a commitment to safety in every aspect of work Works safely in laboratory and manufacturing environments Identifies and corrects hazards; ensures rigorous …