Snap-on Inc logo

Senior Security & Infrastructure Engineer

Snap-on Inc
  • Tustin, California
  • $145,000–$165,000 Per Year
  • Full-time
3 days ago

Job Description

Overview:

AutoCrib is the leader in industrial vending technology. We design and create all the software and hardware in-house to help manage inventory for our customers. Our industry is vast; customers range from manufacturing to government to retail to data centers. We are a growing company that is looking for candidates who are looking for a challenge and like to wear a lot of hats. AutoCrib is big enough to provide the resources you need, but small enough to still feel like a family. We believe in giving employees autonomy to make their own decisions and actively help them with their career path. Our benefits include healthcare, 401k, life insurance, and PTO.

 

Job location:  This position is located in Tustin, California, on-site (full-time)

 

We are seeking a hands-on Senior Security & Infrastructure Engineer to own and mature the organization's cybersecurity program while supporting the security, reliability, and compliance of our mission-critical SaaS platform and corporate infrastructure.

 

This role serves as the primary technical security resource for the organization and is responsible for security operations, vulnerability management, incident response, infrastructure hardening, identity security, compliance initiatives, and cloud security governance. The ideal candidate combines strong cybersecurity expertise with practical infrastructure experience and can effectively partner with Engineering, DevOps, and IT teams to reduce risk while enabling business growth.

 

This position is ideal for an experienced security professional who enjoys working across multiple technology domains and wants to have a direct impact on the organization's overall security posture.

Responsibilities:

Security Operations & Monitoring

  • Own and administer enterprise security tools, including SIEM, EDR, vulnerability management, email security, and security monitoring platforms.
  • Monitor, investigate, and respond to security alerts and incidents.
  • Develop and maintain detection rules, dashboards, and alerting strategies.
  • Conduct proactive threat hunting and security investigations.
  • Coordinate third-party penetration testing and security assessments.
  • Maintain security metrics, reporting, and executive-level visibility into organizational risk.

Vulnerability & Risk Management

  • Own and manage the enterprise vulnerability management program.
  • Perform vulnerability scanning across infrastructure, operating systems, cloud services, applications, and endpoints.
  • Prioritize remediation efforts based on business impact and risk.
  • Track remediation activities and communicate status to leadership.
  • Validate remediation efforts and drive continuous improvement.
  • Maintain risk registers and support organizational risk assessments.

Incident Response & Security Engineering

  • Lead security incident response activities including containment, eradication, recovery, and lessons learned.
  • Develop and maintain incident response procedures and playbooks.
  • Perform root cause analysis and coordinate post-incident reviews.
  • Support forensic investigations and evidence collection.
  • Partner with internal and external stakeholders during security events.
  • Improve detection, response, and recovery capabilities across the organization.

Infrastructure & Platform Security

  • Secure and harden Windows Server, Linux, virtualization platforms, databases, storage systems, and enterprise applications.
  • Review and maintain firewall configurations, VPNs, remote access solutions, and network security controls.
  • Support network segmentation and Zero Trust initiatives.
  • Implement security baselines aligned with CIS Benchmarks and industry best practices.
  • Participate in infrastructure architecture reviews and technology evaluations.
  • Validate backup, disaster recovery, and ransomware recovery readiness.

Cloud Security

  • Administer and secure Microsoft Azure and Microsoft 365 environments.
  • Implement cloud security controls, monitoring, and governance standards.
  • Review cloud architecture for security and compliance requirements.
  • Manage security configurations for cloud-hosted SaaS infrastructure.
  • Support continuous monitoring and cloud security posture management initiatives.

Identity & Access Management

 

  • Administer and secure Active Directory and Microsoft Entra ID.
  • Implement least-privilege access controls and role-based access management.
  • Manage privileged access, service accounts, and identity governance processes.
  • Conduct periodic access reviews and entitlement audits.
  • Support MFA, Conditional Access, and identity security initiatives.

Compliance & Governance

  • Support and lead security initiatives aligned with NIST, FedRAMP, CMMC, FISMA, and other applicable frameworks.
  • Develop and maintain policies, standards, procedures, SSPs, POA&Ms, and security documentation.
  • Coordinate technical evidence collection for auditys and assessments.
  • Participate in risk assessments and security reviews.
  • Drive continuous monitoring and compliance activities.
  • Serve as the primary technical security resource during audits and customer security reviews.

 

Customer & Vendor Security

  • Support customer security questionnaires, audits, and due diligence reviews.
  • Participate in customer-facing security discussions as needed.
  • Perform security reviews of third-party vendors, suppliers, and service providers.
  • Assist with security-related contractual and compliance requirements.

Automation & Continuous Improvement

  • Develop scripts and automation to improve security operations and reporting.
  • Support integration of security controls into CI/CD and operational workflows.
  • Evaluate new technologies and recommend security improvements.
  • Promote secure engineering and operational best practices across the organization.

 

 

Qualifications:

Qualifications and Education Requirements

  • Bachelor's degree in Cybersecurity, Information Technology, Computer Science, Engineering, or equivalent
  • experience.
  • 5+ years of experience in Security Engineering, Infrastructure Security, Cybersecurity Operations, or a related
  • Experience administering SIEM, EDR, and vulnerability management platforms.
  • Experience leading or participating in incident response investigations.
  • Strong understanding of networking, firewalls, VPNs, and security architecture.
  • Experience securing Windows Server, Linux, Active Directory, Microsoft Entra ID, and virtualized environments.
  • Experience managing cloud environments, preferably Microsoft Azure.
  • Strong understanding of vulnerability management and risk mitigation practices.
  • Experience with NIST Cybersecurity Framework and related security controls.
  • Experience with PowerShell, Python, Bash, or other scripting languages.
  • Strong written, verbal, and executive communication skills.

    Nice to Have

  • Experience supporting FedRAMP, CMMC, FISMA, SOC 2, or similar compliance frameworks.
  • Experience with Microsoft Sentinel, Microsoft Defender, CrowdStrike, Splunk, Tenable, Nessus, Qualys, or equivalent platforms.
  • Experience implementing CIS Benchmarks or DISA
  • Experience supporting SaaS environments and cloud-hosted
  • Experience with Infrastructure-as-Code solutions such as Terraform or
  • Professional certifications such as CISSP, Security+, GSEC, GCIA, Azure Security Engineer, or equivalent.

Pay range: $145,000-$165,000

 

#IND-SOAC-TUS

 

 

 

 

 

 

 

 

Numbers & Facts

LocationTustin, California
Job TypeFull-time
IndustryManufacturing - Other
Salary$145,000–$165,000 Per Year
Company Size10,000 employees or more
Websitehttp://www.snapon.com

About Company

Snap-on Incorporated is a leading global innovator, manufacturer and marketer of tools, equipment, diagnostics, repair information and systems solutions for professional users performing critical tasks. Products and services include hand and power tools, tool storage, diagnostics software, information and management systems, shop equipment and other solutions for vehicle dealerships and repair centers, as well as for customers in industries, including aviation and aerospace, agriculture, construction, government and military, mining, natural resources, power generation and technical education. Snap-on also derives income from various financing programs to facilitate the sales of its products and support its franchise business. Products and services are sold through the company’s franchisee, company-direct, distributor and internet channels. Founded in 1920, Snap-on is a $3.7 billion, S&P 500 company headquartered in Kenosha, Wisconsin.

Skills

  • Access Controlunmatched
  • Automationunmatched
  • Bash Scriptingunmatched
  • Benchmarkingunmatched
  • Best Practicesunmatched
  • Business Growthunmatched
  • Business Operationsunmatched
  • CISSP - Certified Information Systems Security Professionalunmatched
  • Cloud Applicationsunmatched
  • Cloud Architectureunmatched
  • Cloud Computingunmatched
  • Communication Skillsunmatched
  • CompTIA Security+unmatched
  • Computer Scienceunmatched
  • Computer Securityunmatched
  • Configuration Managementunmatched
  • Continuous Deployment/Deliveryunmatched
  • Continuous Improvementunmatched
  • Continuous Integrationunmatched
  • Contract Requirementsunmatched
  • Cross-Functionalunmatched
  • Customer Relationsunmatched
  • Data Recoveryunmatched
  • Defense Information Systems Agency (DISA)unmatched
  • DevOpsunmatched
  • Disaster Recoveryunmatched
  • Documentationunmatched
  • Email Securityunmatched
  • Enterprise Protectionunmatched
  • FISMA - Federal Information Security Management Actunmatched
  • Firewall Administrationunmatched
  • Firewallsunmatched
  • GCIA - GIAC Certified Intrusion Analystunmatched
  • GSEC - GIAC Security Essentials Certificationunmatched
  • Governmentunmatched
  • Healthcareunmatched
  • Huntingunmatched
  • Identity Data Managementunmatched
  • Incident Managementunmatched
  • Incident Responseunmatched
  • Information Technology & Information Systemsunmatched
  • Internet Securityunmatched
  • Inventory Managementunmatched
  • Leadershipunmatched
  • Linux Operating Systemunmatched
  • Maintain Complianceunmatched
  • Manufacturingunmatched
  • Metricsunmatched
  • Microsoft Active Directoryunmatched
  • Microsoft Product Familyunmatched
  • Microsoft Windows Azureunmatched
  • Microsoft Windows Serverunmatched
  • Nessusunmatched
  • Network Operations Centerunmatched
  • Network Securityunmatched
  • Network Supportunmatched
  • Operating Systemsunmatched
  • Operational Improvementunmatched
  • Operations Managementunmatched
  • Operations Security (OPSEC)unmatched
  • Penetration Testingunmatched
  • Policy Developmentunmatched
  • Presentation/Verbal Skillsunmatched
  • Process Improvementunmatched
  • Python Programming/Scripting Languageunmatched
  • Ransomwareunmatched
  • Regulatory Complianceunmatched
  • Remote Accessunmatched
  • Reporting Dashboardsunmatched
  • Retailunmatched
  • Riskunmatched
  • Risk Analysisunmatched
  • Risk Managementunmatched
  • Root Cause Analysisunmatched
  • Scripting (Scripting Languages)unmatched
  • Security Analysisunmatched
  • Security Architectureunmatched
  • Security Attacksunmatched
  • Security Auditingunmatched
  • Security Complianceunmatched
  • Security Information and Event Management (SIEM)unmatched
  • Security Infrastructureunmatched
  • Security Monitoringunmatched
  • Software as a Service (SaaS)unmatched
  • Splunkunmatched
  • Systems Administration/Managementunmatched
  • Technical Leadershipunmatched
  • Technology Analysisunmatched
  • U.S. National Institute of Standards and Technology (NIST)unmatched
  • VPN (Virtual Private Network)unmatched
  • Virtualizationunmatched
  • Vulnerability Scannersunmatched
  • Windows PowerShellunmatched
  • Writing Skillsunmatched

Be found by employers

5,500+ employers search our resume database daily. Add yours to get found by recruiters looking for candidates like you.

Level up your application

Professional resume templates

Browse dozens of recruiter approved resume templates, layouts and formats. Choose your favorite and make it your own in minutes.

Free resume templates

Free resume builder

Improve your existing resume or start from scratch and create a standout, ATS-friendly resume. Add job-specific content, download and apply.

Free resume builder