BEHIND EVERY LEGEND IS A FLAWLESS FOUNDATION.
THE BREACH THAT NEVER HAPPENED.
That's your best work β and nobody will ever know.
DuraServ is looking for a Security Specialist who monitors, analyzes, and protects the enterprise β across Azure environments, endpoints, cloud infrastructure, and regulatory compliance frameworks β with precision that makes the invisible work visible only when it matters most.
The Best Security Work Is the Kind Nobody Notices.
DuraServ operates a national field service organization with hundreds of endpoints, cloud environments, enterprise applications, and team members across nine U.S. and Canadian regions β all of whom depend on a security posture that holds without requiring them to think about it. When the security function works, the business runs. When it doesn't, the consequences reach far beyond IT.
As Security Specialist, you own the continuous monitoring, analysis, and improvement of DuraServ's security posture β vulnerability management, threat detection, attack surface visibility, incident response support, endpoint and cloud security operations, data protection, and compliance alignment across NIST, CMMC, ISO, SOC, CIS, and FedRAMP frameworks. You work within Microsoft Azure, Defender, Sentinel, and Purview ecosystems and serve as the organization's subject matter expert across the security stack.
If you're the kind of security professional who finds the vulnerability before the attacker does β and you document it, remediate it, and prevents the next one β this role was built for you.
What You'll Own
Threat & Vulnerability Management
- Monitor, analyze, and support remediation of security vulnerabilities across enterprise systems, applications, endpoints, cloud environments, and network infrastructure
- Assess and prioritize security findings, threats, and control gaps based on business risk, attack exposure, and operational impact β you know what to fix first and why
- Monitor and evaluate the organization's attack surface to identify exposed assets, misconfigurations, unauthorized access risks, and security weaknesses before they become incidents
- Support incident response activities including alert triage, threat investigation, escalation, documentation, and coordination with technical teams
Cloud & Endpoint Security
- Support security operations within Microsoft Azure environments β monitoring and administration across Microsoft Defender, Microsoft Sentinel, Microsoft Purview, and related security technologies
- Assist with endpoint, OS, and network security initiatives β configuration validation, compliance monitoring, access controls, firewall reviews, and device management
- Support data governance and data security posture management β data classification, labeling, access monitoring, and protection of sensitive information
Compliance & Continuous Improvement
- Assist with implementation, validation, and documentation of security controls aligned with NIST, CMMC, ISO, SOC, CIS, and FedRAMP frameworks β your documentation is audit-ready at all times
- Maintain and update security policies, procedures, standards, audit evidence, and compliance tracking records with the rigor those frameworks demand
- Collaborate with engineering, infrastructure, data, and compliance teams to improve security posture, support secure AI adoption, participate in tabletop exercises, and drive continuous improvement
Who You Are
You don't wait for alerts to tell you something is wrong. You're already looking at the logs, reviewing the surface, and asking the question the alert hasn't asked yet.
- Technically fluent in the Microsoft security stack β Defender, Sentinel, Purview, and Azure security operations are your working environment, not your stretch goals
- A threat hunter by instinct β you analyze logs, investigate anomalies, and prioritize remediation with the judgment that comes from experience, not just tooling
- Compliance-capable β you understand NIST, CMMC, ISO, SOC, CIS, and FedRAMP not as acronyms but as frameworks you've worked within and documented against
- A precise documenter β your audit evidence, policies, and incident records are current, complete, and defensible; you don't treat documentation as an afterthought
- A cross-functional collaborator β you work effectively with engineering, infrastructure, data, and compliance teams and communicate security risk to both technical and non-technical audiences
- Analytically disciplined β you assess risk based on business impact, not just CVSS scores; you know the difference between a critical vulnerability in a production environment and one in an isolated test system
What We're Looking For
Required
- 3β6 years of practical experience in information security operations β SOC, IT security, or infrastructure security team experience required
- Strong working knowledge of cybersecurity principles: threat detection, vulnerability management, incident response, SIEM platforms, EDR/XDR solutions, and enterprise security controls
- Experience with Microsoft Azure security environments and the Microsoft security technology stack (Defender, Sentinel, Purview, or equivalent)
- Working knowledge of networking, OS security, identity and access management, endpoint security, and cloud security concepts
- Ability to investigate security alerts, analyze logs and attack activity, prioritize remediation, and support containment and recovery
Preferred
- Bachelor's degree in Cybersecurity, Information Technology, or related field; equivalent hands-on experience considered
- Relevant industry certifications: CompTIA Security+, Certified Ethical Hacker (CEH), Microsoft Azure security certifications, Microsoft Purview certifications, or comparable credentials
- Experience supporting compliance frameworks including NIST, CMMC, ISO, SOC, CIS, or FedRAMP
- Background supporting AI security adoption or secure integration of emerging technologies in enterprise environments
What's in It for You
- Competitive compensation commensurate with experience
- Full benefits package: medical, dental, vision, and 401K with company match
- Company-provided life insurance, short-term and long-term disability
- A broad and technically substantive security scope β vulnerability management, cloud security, incident response, compliance, and data protection all in one role
- A stable, office-based environment at DuraServ Corporate in Coppell, TX with no travel requirement
- Direct collaboration with engineering, infrastructure, and compliance teams β your work has cross-functional visibility and real organizational impact
- An environment investing in AI adoption and emerging technology β you'll help shape how that happens securely
A Note to the Right Candidate.
If you've been in a security role where the alerts were noise, the documentation was backlogged, and the compliance frameworks were treated as checkboxes rather than guardrails β this is a different environment.
DuraServ is building a security function that operates with rigor β where vulnerabilities get remediated, not deferred; where audit evidence is maintained, not assembled at the last minute; and where the security posture improves continuously because someone owns it.
Behind every legend is a flawless foundation. Come help us build ours.
APPLY NOW β Security Professionals Wanted.
Hit Apply. Tell us what you've monitored, what you've remediated, and what your documentation looks like when an auditor walks in.
Please note: This is NOT a remote or hybrid role. This position is based on-site at DuraServ Corporate in Coppell, TX.
About DuraServ
DuraServ is a national leader in commercial dock and door solutions, operating across the U.S. and Canada since 2001. As we grow through acquisition and expand our technology infrastructure, we are building the security posture that protects everything we've built β and we hire people who understand what that responsibility requires.
DuraServ is an Equal Opportunity Employer.
NOTICE TO EXTERNAL RECRUITING AGENCIES & SEARCH FIRMS |
DuraServ LLC and its affiliate businesses do not accept unsolicited resumes or candidate profiles from external recruiting/staffing agencies or search firms. Any resume or candidate information submitted to any DuraServ employee β without a fully executed, written search agreement in place with DuraServ's Talent Management team β will be deemed the property of DuraServ LLC.Β No placement fee will be owed or paid, now or in the future, regardless of whether the candidate is subsequently hired. Agencies seeking to be considered as an authorized vendor must have a current, countersigned agreement with DuraServ LLC prior to submitting any candidates. Agencies should not contact hiring managers, regional leadership, or any other DuraServ LLC employee directly. |
DuraServ β Building Careers That Move Commerce Forward |
Learn more about this Employer on their Career Site
