Sperry Rail, Inc.

Security Engineer

About Sperry:

Sperry Rail is on a mission-critical journey to revolutionize the Rail Flaw Detection industry. Through the continuous development of cutting-edge diagnostic technologies and AI-assisted analysis, we are transforming railway safety worldwide. Our global engineering teams work collaboratively to develop step-change technologies that define Sperry as the unparalleled market leader.

For nearly a century, we have repeatedly modernized and improved rail diagnostics through our relentless pursuit of improvement. Determined is an understatement. We are obsessed with advancing science and raising the bar on what’s possible with our ever-improving suite of products and service offerings.

Emboldened through the shared values of honesty, accountability, passion, integrity, and teamwork, we are driven by the challenge and bridging concepts with fruition. Each technologist entering Sperry imprints themselves into our brand and further galvanizes a culture of innovation and advancement. Allow us to be clear, Thought Leaders are welcome!

We are agile and hungry and invite those with similar passions to join us in challenging the status quo and bringing new ideas to the market. Fast-paced, high-touch with a distinct sense of purpose. We offer more than a job; we offer an opportunity to be part of something different.

Role Summary

Security at Sperry is run today by our Global IT team, alongside everything else that team carries. The tooling is in place and the practice around it is real. What it has not had is someone whose primary job it is, and that is the seat we are hiring. You will work across our security stack day to day: endpoint detection and response, vulnerability management, and the identity and access configuration across Microsoft 365 and Entra ID. You will also help mature the practice around those tools, including the runbooks, the asset inventory, the incident handling, and the measures that tell us whether any of it is working. This is a hybrid role by design, and worth being straightforward about. We run a lean Global IT team where everyone wears several hats. You will be our specialized hand on security, and you will also work side by side with the team on general infrastructure and endpoint administration. That breadth is part of the appeal: you will see the whole environment rather than one slice of it, and you will keep building your cloud and infrastructure skills while you are here. We are hiring experience deliberately. This seat carries real responsibility for the security posture of a company that inspects track for most of the major railroads in North America, and what we are looking for is someone who arrives with a view of how this should be done and is willing to challenge how we do it today.


What We Expect From You

We expect an exceptional level of drive and ambition. You think beyond today's work to what the team and organization need next, champion bold ideas, and see them through. Your hunger is infectious - it inspires those around you to aim higher. We are looking for someone with a genuine no-task-is-too-small attitude. On a small team, the person who investigates the alert is often the person who images the laptop, and we need someone equally willing to do both. This role requires a high degree of self-direction. You will manage complex work with minimal oversight, identify problems and solutions proactively, and may lead workstreams. You make well-reasoned technical decisions and escalate when there is genuine business impact. You should be able to question, challenge, and improve existing practice. You will find things here that were set up for a smaller and simpler company, and part of your value is saying so and then fixing them in a sensible order. Strong communication matters more in this seat than the job title suggests. You will be asking people across the business to work differently, and answering security questions from customers whose own standards we are measured against.

 

Key Responsibilities

Security engineering and operations

• Own the deployment, configuration, and daily monitoring of our vulnerability management platform, and drive patching and remediation to closure across a predominantly Windows environment

• Monitor, tune, and report on endpoint detection and response coverage, and lead the response when something is found

• Perform root cause analysis on security incidents and see corrective actions through

• Scope and coordinate penetration testing and remediation with external partners

• Maintain security runbooks, asset inventories, and incident logs

Identity and access

• Administer and harden Microsoft 365 and Entra ID, with a focus on secure configuration, conditional access, and mail security

• Build the access model for third-party SaaS used across enterprise systems and engineering, so that permissions match roles rather than accumulate

• Support device management and compliance across the fleet

Governance, compliance, and measurement

• Align IT processes, documentation, and controls with ISO 27001 and other relevant frameworks

• Support customer security assessments and questionnaires, and own the technical answers in them

• Establish and maintain security posture KPIs that show whether the program is improving, and report them to IT and digital leadership

• Contribute to security policy, including acceptable use of AI tools and SaaS

Infrastructure and IT operations

• Own the configuration and maintenance of security appliances including firewalls and routers

• Use our central IT management platform for software deployment, patching, scripting, and remote troubleshooting

• Support provisioning, imaging, and deployment of Windows laptops and workstations

 • Assist with troubleshooting and user access provisioning for core business systems

• Automate routine work rather than repeating it

 

Your First Year

The early work is already identified, so you will not spend a quarter looking for a place to start:

• Take on the vulnerability queue and establish a working remediation cycle with the infrastructure team

• Stand up device management and compliance reporting across the fleet

• Scope and run the external penetration testing program, and turn the findings into a prioritized plan

• Take ownership of the technical response to customer security assessments

• Establish security posture KPIs, put them in front of leadership, and define what good looks like for the year after

• Move us toward ISO 27001 alignment, starting with the controls that matter most


Required Skills & Qualifications

• Five or more years in systems administration or IT infrastructure with a substantial security focus, or a cybersecurity degree with equivalent hands-on experience

• Solid foundational knowledge of Windows Server and desktop environments

• Hands-on experience with cloud infrastructure in Azure or AWS, and comfort working across both

• Experience managing and supporting users in Microsoft 365, including identity and access configuration

• Experience with enterprise-grade security appliances such as firewalls and routers

• Practical vulnerability management experience: scanning, prioritization, and driving remediation with teams who do not report to you

• Scripting for automation of routine tasks (PowerShell, Python, or similar)

• Sound judgment about risk, and the ability to explain a security decision to a non-technical audience

• A collaborative, team-first mindset aligned with our values of being Humble, Hungry, and Smart Qualifications and years of experience are indicative guidelines, not mandatory requirements. These criteria may be met through demonstrated competency or equivalent experience.


Desirable Skills

• Direct experience with Rapid7, SentinelOne, or comparable vulnerability management and XDR platforms

• Experience with central IT management platforms such as ConnectWise Automate

• Working experience with ISO 27001; exposure to NIST, SOC 2, or ITIL is an asset

• Security certifications (CISSP, CISM, Security+, AZ-500, AWS Security Specialty, or similar)

• Device management tooling (Intune or equivalent)

• Experience as the dedicated security specialist on a small IT team

• Experience in an operational or industrial environment where availability and safety carry weight

• Experience in rail testing, NDT, or sensor-based inspection industries (ultrasound, eddy current, electromagnetic, etc.)

064 - I.T.

Shelton, CT

Partilhar em:

Termos de serviço.PrivacidadeCookiesDesenvolvido pela Rippling