Senior Cybersecurity Engineer (Azure and GRC heavy)
Hyliion
| Company | Hyliion |
| Category | Engineering |
| Location | Austin |
| Remote | On-site (inferred) |
| Employment | Not stated |
| Level | Senior |
| Salary | Not stated by the employer |
| Posted | 1 Aug 2026 |
| Last verified | 9 Aug 2026 |
| Source | Employer ATS (greenhouse) |
Description
Hyliion is committed to creating innovative solutions that enable clean, flexible and affordable electricity production. The Company’s primary focus is to develop distributed power generators that can operate on various fuel sources to future-proof against an ever-changing energy economy. Job Purpose
The Senior Cybersecurity Engineer owns Hyliion’s overall day-to-day cybersecurity operations — endpoint security, identity and Conditional Access, cloud/SaaS security posture, and AI governance — across a cloud-native, Microsoft-centric technology environment. This includes maintaining the System Security Plan (SSP) and control set for Hyliion’s CMMC Level 2 certified enclave, sustaining NIST 800-171 compliance . Beyond the enclave, the role administers Microsoft Entra ID Conditional Access, the Microsoft Defender suite, endpoint management (patching, EDR, and device compliance), our Red Canary Managed Detection and Response (MDR) partnership, and the security and governance of our growing SaaS and enterprise AI footprint across the broader organization.
AI at Hyliion
At Hyliion, AI is core to how we work. We equip every team member with leading AI tools and count on you to use them — to move faster, solve harder problems, and help us realize the full potential of KARNO technology for the world.
Duties and Responsibilities
Own and maintain Hyliion’s overall day-to-day cybersecurity posture across the enterprise, spanning identity, endpoint, cloud/SaaS, and AI governance.
Maintain the System Security Plan (SSP) and control implementation for Hyliion’s CMMC Level 2 (C3PAO)-certified enclave, sustaining NIST 800-171 compliance and annual affirmation in SPRS for that defined scope.
Administer and continuously optimize Microsoft Entra ID (Azure AD) Conditional Access policies, identity protection, and Privileged Identity Management (PIM) to enforce least-privilege and zero-trust principles.
Own endpoint security end-to-end — patch management, vulnerability remediation, EDR fleet health, and compliance baselines across Windows, macOS, and mobile endpoints — using Microsoft Defender for Endpoint and Intune.
Manage the broader Microsoft Defender suite (Defender for Office 365, Defender for Cloud Apps, Defender for Identity), including policy tuning, alert triage, and threat response.
Serve as the primary point of contact for the Red Canary Managed Detection and Response (MDR) partnership, coordinating incident escalations, tuning detections, and reviewing threat intelligence reports.
Administer Mobile Device Management (MDM)/Intune enrollment, compliance policies, and configuration across corporate and BYOD devices.
Own security posture and governance across Hyliion’s growing SaaS application footprint (SaaS Security Posture Management), including OAuth/app permission reviews, shadow IT discovery, and third-party app risk assessment.
Govern the secure and compliant use of enterprise AI platforms — monitoring usage, enforcing acceptable-use and data-handling policies, assessing AI vendor risk, and identifying unsanctioned (“shadow AI”) tool adoption.
Monitor, triage, and respond to day-to-day cybersecurity incidents and alerts, ensuring timely containment, remediation, and documentation.
Maintain and update security policies, procedures, and control documentation supporting NIST 800-171, CMMC, SOX IT general controls, and other applicable frameworks.
Support recurring internal and third-party audits, evidence collection, and control testing, including SOX ITGC, CMMC annual affirmation, and cyber insurance renewal questionnaires.
Partner with business leaders across departments to assess and mitigate information security risk in new projects, vendor relationships, SaaS adoption, and AI tool deployments.
Maintain and enhance the executive-level cybersecurity dashboard and reporting cadence, translating technical risk into business-relevant me