About this role
It's fun to work in a company where people truly BELIEVE in what they're doing!
We're committed to bringing passion and customer focus to the business.
JOB SUMMARY
The Senior Cybersecurity Specialist is responsible for safeguarding NextDecade’s information assets, systems, cloud environments, and sensitive business data through the administration and continuous improvement of cybersecurity technologies, processes, and controls. This role serves as a subject matter expert for Microsoft security and compliance technologies, with particular emphasis on Microsoft Purview, Microsoft Defender, Microsoft Entra ID, data protection, and information governance.
The role combines cybersecurity operations, incident response, vulnerability management, data governance, compliance support, and employee awareness initiatives. The Senior Cybersecurity Specialist collaborates with Information Technology, Legal, Human Resources, Compliance, and business stakeholders to protect company information while supporting effective business operations.
KEY RESPONSIBILITIES
Cybersecurity Operations and Incident Response
- Monitor, investigate, and respond to cybersecurity incidents, alerts, and threats.
- Lead incident response activities, including detection, containment, eradication, recovery, post-incident analysis, and reporting.
- Perform threat hunting, root cause analysis, and forensic data collection for security events.
- Coordinate vulnerability assessments, remediation tracking, and patch-management follow-up.
- Monitor SIEM, EDR/XDR, and threat intelligence platforms to identify and respond to emerging risks.
- Support cybersecurity aspects of business continuity, disaster recovery, and tabletop exercises.
Microsoft Purview and Data Protection
- Administer and optimize Microsoft Purview solutions across the enterprise.
- Develop and maintain data classification, sensitivity labeling, retention, and data lifecycle policies.
- Configure and manage Data Loss Prevention policies across Microsoft 365, SharePoint, OneDrive, Teams, email, and endpoints.
- Administer Information Protection, Records Management, eDiscovery, Audit, Insider Risk Management, and Communication Compliance capabilities, as assigned.
- Support investigations involving sensitive data, insider risk, policy violations, litigation holds, and eDiscovery requests in coordination with Legal and Human Resources.
- Develop, document, and promote secure data-handling and information-governance standards.
Identity, Cloud, and Security Platform Administration
- Administer Microsoft Entra ID security controls, Conditional Access, multifactor authentication, access reviews, and privileged access capabilities.
- Administer Microsoft Defender technologies, including Defender for Endpoint, Defender for Office 365, and Defender for Cloud Apps.
- Support endpoint security, email security, cloud application security, and identity protection technologies.
- Evaluate and recommend improvements to cybersecurity tools, configurations, integrations, and processes.
Governance, Risk, and Compliance
- Support cybersecurity risk assessments, compliance reviews, internal audits, and external audits.
- Maintain cybersecurity policies, standards, procedures, technical documentation, and control evidence.
- Assist with the alignment and monitoring of security controls against applicable frameworks and requirements, including NIST Cybersecurity Framework, CIS Controls, ISO 27001, SOX, GDPR, and other applicable privacy or regulatory obligations.
- Track identified risks, findings, corrective actions, and remediation commitments through closure.
Security Awareness and Collaboration
- Develop and deliver cybersecurity awareness, phishing simulation, and secure data-handling initiatives.
- Provide practical cybersecurity guidance to employees, leadership, and project teams.
- Partner with infrastructure, applications, cloud, operational technology, and business teams to implement secure solutions.
- Participate in technology projects and digital transformation initiatives to embed security and privacy requirements.
- Mentor junior team members and support knowledge sharing across Information Technology.
- Maintain current knowledge of emerging threats, Microsoft security capabilities, industry trends, and regulatory developments.
MINIMUM REQUIREMENTS
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field; an equivalent combination of education and relevant experience may be considered.
- Minimum of five years of progressively responsible cybersecurity or information-security experience.
- Hands-on experience administering Microsoft 365 security and compliance technologies, including Microsoft Purview.
- Experience with Data Loss Prevention, data classification, sensitivity labels, information protection, records management, or eDiscovery.
- Experience with incident response, security investigations, identity and access management, and vulnerability management.
- Working knowledge of SIEM, EDR/XDR, cloud security, and security monitoring technologies.
- Experience supporting risk assessments, compliance programs, audits, and security control documentation.
- Strong analytical, investigative, problem-solving, documentation, and communication skills.
- Ability to appropriately handle confidential and sensitive information and exercise sound judgment.
PREFERRED REQUIREMENTS
- Microsoft Certified: Information Protection and Compliance Administrator Associate (SC-400).
- Microsoft Certified: Security Operations Analyst Associate (SC-200) or Identity and Access Administrator Associate (SC-300).
- CISSP, CISM, CompTIA Security+, CompTIA CySA+, or a comparable security certification.
- Experience with Microsoft Sentinel, Defender XDR, Azure security, security automation, and SOAR capabilities.
- Experience in an energy, critical infrastructure, engineering, construction, or other regulated environment.
OFFICE WORKING CONDITIONS AND PHYSICAL EXPECTATIONS
Work Environment
This position operates in a professional office environment with occasional work within or outside of a complex construction environment. This role routinely uses standard office equipment such as computers, phones, photocopiers/fax, filing cabinets, and related technology equipment. This is primarily a sedentary role; however, the incumbent must be able to stand and/or sit continuously to perform all essential job functions for a full shift.
The physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to support individuals with ADA-recognized disabilities to perform the essential functions of the job.
- Ability to lift up to 20 lbs. as required to lift files, boxes, and office equipment.
- Ability to open filing cabinets and bend, stand on a stool, or climb as necessary to perform these functions.
- While performing the duties of this role, the incumbent may be required to talk or listen.
- Vision abilities include close vision, distance vision, color vision, and the ability to adjust focus.
- The incumbent is required to stand, walk, use hands to handle or feel, and reach with hands and arms.
- Ability to move throughout all areas of each office, site location, and facility.
- Ability to wear all necessary personal protective equipment to perform job functions during site visits.
Other Duties
Please note this job description is not designed to cover or contain a comprehensive listing of activities, duties, or responsibilities required of the employee for this job. Duties, responsibilities, and activities may change at any time with or without notice.
In compliance with federal law, all persons hired will be required to verify identity and eligibility to work in the United States and to complete the required employment eligibility verification documentation upon hire.
NextDecade provides equal employment opportunities to all applicants without regard to race, color, religion, gender, sexual orientation, gender identity, national origin, age, disability, genetic information, marital status, amnesty, or status as a covered veteran, in accordance with applicable federal, state, and local laws. NextDecade complies with applicable state and local laws governing nondiscrimination in employment in every location in which the company has facilities.