Job Summary
Enovix seeks a junior-level, hands-on Cyber Security Engineer to strengthen security across enterprise IT, manufacturing, applications, infrastructure, and data. The role covers assessing cyber risk, implementing controls, monitoring threats, investigating incidents, and improving security across IT and OT environments, working closely with IT, engineering, manufacturing, and business teams. The ideal candidate combines technical engineering ability with analytical judgment and understands how to scale security practices in a growing, global organization.
Key Responsibilities
Security Operations & Monitoring
Monitor SIEM, EDR/XDR, IDS/IPS, email, and cloud security platforms for threats. Triage and investigate alerts, escalating as needed. Analyze logs from endpoints, servers, network devices, cloud, and applications. Support incident response, including evidence collection, documentation, and remediation tracking. Assist in tuning detection rules and use cases to reduce false positives and collaborate with IT and engineering on threat detection and response.
Vulnerability Management & Security Assessments
Assist with vulnerability assessments and security reviews of systems, applications, cloud services, and infrastructure. Document and track vulnerabilities through remediation, supporting prioritization by risk, threat intelligence, and business impact. Validate remediation and perform follow-up assessments. Maintain vulnerability management reports and metrics.
Cyber Threat Intelligence
Monitor threat intelligence feeds, vendor advisories, and industry alerts. Validate relevance to the organization's environment and identify emerging threats and attack trends. Support mitigation recommendations and integrate threat intelligence into monitoring and vulnerability management.
Security Projects & Continuous Improvement
Participate in projects that strengthen the security posture, including deployment of security technologies and controls. Support process improvements and research emerging security technologies and best practices.
Security Metrics, Reporting & Dashboards
Assist in developing dashboards and reports covering vulnerabilities, incidents, threat intelligence, compliance, asset inventory, and operations. Track metrics such as remediation status, alert volumes, incident trends, MTTD, and MTTR.
IT Asset & Inventory Management
Maintain accurate inventory of endpoints, servers, applications, cloud resources, security tools, and network devices. Support asset reconciliation, classification, and ownership assignment to keep data aligned with security and compliance requirements.
Operational Technology (OT) & Manufacturing Security
Support cybersecurity for manufacturing and OT environments, including asset inventories for industrial devices, engineering workstations, and production networks. Participate in OT risk assessments, monitoring, and IT/OT segmentation efforts. Support investigations involving OT-related security events.
Third-Party Risk & Compliance
Assist in evaluating vendors and SaaS platforms for compliance with security requirements. Support vendor risk reviews and compliance initiatives (ISO 27001, SOC 2, NIST, SOX), including documentation and evidence for audits.
AI, Automation & Process Optimization
Use AI tools and prompt engineering to improve efficiency and reduce manual effort. Support AI-assisted workflows for reporting, threat analysis, and documentation. Identify opportunities to automate routine processes via scripting, APIs, and workflow tools, ensuring AI is used securely and responsibly.
Information Security Governance
Follow security policies, standards, and procedures. Maintain awareness of threats and best practices, and support security awareness initiatives and documentation of playbooks.
Qualifications
Required
- Bachelor's degree in Computer Science, IT, Cybersecurity, Information Security, or related field, or equivalent practical experience.
- ~2 years of experience in IT, infrastructure, systems administration, networking, cybersecurity, or related fields.
- Understanding of cybersecurity principles, risk management, and best practices.
- Basic networking knowledge (TCP/IP, DNS, routing, switching, firewalls, segmentation).
- Familiarity with Windows and Linux operating systems.
- Strong analytical, troubleshooting, and problem-solving skills.
- Excellent written and verbal communication skills.
- Ability to manage multiple priorities in a collaborative environment.
Preferred
- Exposure to SIEM platforms (Microsoft Sentinel, Splunk, QRadar, Elastic, LogRhythm, or similar).
- Exposure to EDR/XDR (Microsoft Defender, CrowdStrike, SentinelOne, Carbon Black, or similar).
- Familiarity with vulnerability management tools (Tenable, Nessus, Qualys, Rapid7, or similar).
- Understanding of threat intelligence and threat hunting methodologies.
- Exposure to security frameworks (NIST CSF, NIST SP 800-82, CIS Controls, ISO 27001, SOC 2, IEC 62443).
- Familiarity with manufacturing, semiconductor, industrial, or OT environments.
- Scripting/automation experience (PowerShell, Python, Bash, APIs, Power Automate).
- Knowledge of AI tools, prompt engineering, and automation for security operations.
- Experience with reporting/dashboard tools (Power BI, Tableau, Grafana, or similar).
Certifications (Preferred)
- CompTIA Security+
- Microsoft Security Certifications (SC-200, SC-300, AZ-500)
- SSCP
- CEH
- ISC2 Certified in Cybersecurity (CC)
- GIAC Foundational Certifications
- ISO 27001 Foundation or Internal Auditor Certification
