Cyber Security Engineer
About this role
Job Title: Security Engineer
Location
Hybrid
About Classic Collision
Classic Collision is a private‑equity‑backed, high‑growth leader in the automotive repair industry, providing best‑in‑class collision repair, auto glass services, and ADAS calibrations across a broad range of vehicle brands. Fueled by rapid expansion and commitment to operational excellence, Classic Collision recently surpassed $1B in annual revenue and continues to scale nationwide. As the company grows its geographically distributed footprint, it is also investing heavily in modern, scalable security capabilities to protect its people, customers, and operations, staying ahead of an increasingly complex and evolving threat landscape.
About the Role
Classic Collision is seeking a skilled IT Security Engineer to join our security team with a primary focus on incident response, vulnerability management, and data protection. This role is well-suited for IT professionals with hands-on security experience who are comfortable working incidents, coordinating remediation efforts, and partnering across teams to improve security posture.
These engineers will play an active role in day-to-day security operations while collaborating closely with IT, networking, and implementation teams. While team members may concentrate on specific areas at different times, they are expected to maintain a broad working knowledge across all areas outlined below.
Key Responsibilities
Incident Response & Security Operations
- Investigate and respond to security incidents, including analysis, containment, remediation, and recovery activities
- Review alerts, logs, and telemetry from security tools to identify threats and anomalous behavior
- Perform root cause analysis and contribute to post-incident documentation and improvement efforts
- Help maintain and improve incident response runbooks and operational procedures
Vulnerability Management
- Perform vulnerability identification and management using platforms such as Tenable Nessus or similar tools (Qualys, Rapid7, etc.)
- Analyze and prioritize vulnerability findings based on risk and business impact
- Partner with system owners to coordinate remediation efforts across infrastructure, endpoints, and applications
- Validate remediation and track vulnerabilities through closure
- Assist in reporting risk trends and remediation metrics
Data Protection & Security Controls
- Support controls to protect sensitive, confidential, and regulated data
- Assist with investigations related to potential data exposure or misuse
- Contribute to data protection initiatives such as encryption, access controls, and DLP efforts
- Provide security input on system changes that may impact data risk
Collaboration & Communication
- Work closely with other security engineers, IT teams, and system owners
- Clearly communicate risks, findings, and remediation guidance to technical and non-technical stakeholders
- Participate in cross-team discussions to balance security controls with operational needs
- Contribute to technical documentation, procedures, and security standards
Help Desk Collaboration & User Support
- Partner closely with the Help Desk and IT support teams to assist with escalated security-related tickets
- Investigate and respond to phishing reports, malicious emails, and suspicious user activity
- Provide guidance and recommendations for handling user-reported security concerns
- Assist with troubleshooting endpoint or access-related security issues escalated from Tier 1/Tier 2/Tier 3 support
- Communicate clearly and professionally with end users to explain security findings, risks, and next steps
- Help improve security ticket handling workflows and documentation to streamline escalation processes
Required Qualifications
- Experience in security, security engineering, or security operations role
- Practical experience with incident response and security investigations
- Experience working with vulnerability management processes and remediation tracking
- Familiarity with common attack techniques and defensive controls
- Ability to communicate clearly, document findings, and collaborate effectively across teams
- Strong organizational and prioritization skills
Certifications (Nice to Have, Not Required)
- Security+ or equivalent foundational security certification
- Microsoft or Azure-related certifications (e.g., Azure fundamentals or security-focused certs)
- Networking certifications such as CCNA
Certifications are valued but not required—equivalent hands-on experience is acceptable.
Nice-to-Have / Preferred Skills
Experience in one or more of the following areas is a plus but not mandatory:
- Vulnerability platforms such as Tenable Nessus, Qualys, or Rapid7
- SOC experience or participating in on-call/incident response rotations
- Networking fundamentals (firewalls, routing, DNS, TCP/IP)
- Endpoint and policy management using Intune and Group Policy (GPO)
- Microsoft Azure administration or cloud security concepts
- Identity and access management, including PIM/PAM
- Privileged access management solutions such as CyberArk