SonicJobs Logo
Left arrow iconBack to search

IT Security and Systems Engineer

SilencerCo
Posted 2 days ago, valid for 2 days
Location

Kearns, UT, US

Salary

Competitive

Contract type

Full Time

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.

Location: West Valley City, UT.

Work Model: Onsite, Full-Time

Reports To: Senior IT Manager

Works Closely With: Chief Technology Officer

Scope: Shared services across multiple companies

Position Overview

SicoSyndicate is the shared services company behind SilencerCo, Zev Technologies, Unity Tactical, and other companies. We have a shared IT function that serves all businesses, and we are looking for the person who will drive security across all of them. You will be the subject matter expert for security and compliance company-wide, working under our Senior IT Manager and directly with our CTO.

This is a hands-on role on a small team. Security and compliance are your center of gravity, and this will be your primary responsibility. The systems engineering half of the title is real as well: you will work alongside our core IT team on infrastructure, systems, and technology initiatives that extend beyond security. If you want a role where you spend all your time writing policy and never touch the systems it governs, this is not it. If you want to own a compliance program and stay technically sharp across the whole environment, keep reading.

 

Key Responsibilities

• Lead readiness and ongoing compliance for CMMC Level 2 and NIST SP 800-171 across our defense-adjacent business units

• Support SOC 2 and PCI DSS efforts, including evidence collection, control design, gap remediation, and audit coordination

• Own security and infrastructure projects end to end: scope them, build the plan, coordinate vendors and internal stakeholders, drive them to agreed timelines, and keep leadership informed on status and risk

• Administer and improve security tooling: endpoint protection, identity and access management, SIEM, MFA, email security, vulnerability management, and logging

• Run access reviews, security awareness training, phishing simulations, and incident response tabletop exercises

• Write and maintain the policies, procedures, and system security plans that our frameworks require, and make sure they reflect what we actually do

• Partner with business unit leaders on risk decisions, vendor reviews, and security questions from customers and partners

• Work alongside the core IT team on systems and infrastructure initiatives beyond security, including Microsoft 365/Entra ID and identity administration, server and network projects, endpoint management, and other technology work that supports all business units

 

How We Work

First, we are lean. Everyone here contributes outside a narrow job description, and the people who do well see that as a chance to understand the whole environment rather than as a distraction.

Second, you will own outcomes, not task lists. Projects here come with real timelines, defined deliverables, and regular check-ins with your manager and business unit leadership. What they do not come with is someone standing over your shoulder deciding how you get there. We will agree on the what and the when. We expect you to surface risks early, keep stakeholders informed, and tell us when a date is going to move before it moves.

Third, you will report to our Senior IT Manager and work directly with our CTO on security strategy, framework roadmaps, and risk decisions. This is a small enough organization that your work is visible at the executive level and your recommendations get heard. That access comes with the expectation that you can communicate clearly with a non-technical audience and defend a position.

If you want a role where the path is handed to you, this is not a fit. If you want ownership with clear expectations and a manager who backs you up rather than second-guesses you, this is that role.

 

Required Qualifications

• 8 to 12 years in IT with meaningful depth in security and compliance

• Direct experience with at least one government contracting framework, ideally NIST SP 800-171 or CMMC

• Working knowledge of at least one commercial framework such as SOC 2, PCI DSS, or ISO 27001

• A track record of running projects from kickoff through completion on committed timelines, including ones you identified and proposed yourself

• Strong general IT fundamentals: Windows and Linux Servers, Microsoft 365 administration, identity and access management, networking, and Windows and Mac endpoint management

• CompTIA Security+ or equivalent certification

• The judgment to know when a control needs to be enforced and when it needs to be adapted to how the business actually operates

• Clear written communication. You will be producing documentation that both auditors and executives read.

 

Preferred Qualifications

• CISA, CCSP, CySA+, or CMMC CCP

• Experience supporting a company through a CMMC assessment

• Manufacturing or regulated industry background

• Familiarity with ITAR or EAR export control requirements

• ERP exposure, particularly Odoo

• Cloud security experience in AWS and Azure

 

Measures of Success

We evaluate this role on outcomes, not activity. In your first year, success means:

• Our CMMC Level 2 gap assessment is complete, the System Security Plan is written, and we are executing against a plan with dates we can defend to an assessor

• Security and compliance projects land on their committed timelines, and when a date has to move, leadership hears it from you in advance rather than after the fact

• Critical and high vulnerabilities are remediated within defined windows, and we can show the trend

• Our security policies reflect how the business actually operates, so people follow them instead of working around them

• Business unit leaders come to you early on decisions with security implications, because you have made yourself useful rather than obstructive




Learn more about this Employer on their Career Site

Apply now in a few quick clicks

By applying, a Sonicjobs account will be created for you. Sonicjobs's Privacy Policy and Terms & Conditions will apply.

SonicJobs' Terms & Conditions and Privacy Policy also apply.