Design, deploy, and operate security controls for classified corporate-style IT networks, including authentication and identity services (hardware tokens, certificate-based authentication, privileged access), on-premises SIEM for logging and detection, endpoint/host protection, and vulnerability management. Harden and secure traditional IT services used by engineering staff (email, file servers/shares, directory services, collaboration tools, and internal applications); review and improve permissions, group membership, and access models to reduce standing privilege.