
Lead Security Engineer
Posted 2 days ago

Posted 2 days ago
This is a fully remote position, open to applicants in New York.
• Design, implement, secure, integrate, and continuously enhance CBIZ’s enterprise security technologies and controls across various domains including cloud, identity, endpoint, network, email, and data protection.
• Engineer configurations that prioritize security by default, establish technical guardrails, and develop scalable security solutions and platform capabilities within hybrid and multi-cloud environments.
• Convert business, compliance, and security needs into effective engineering designs and sustainable technical solutions.
• Assess architectures, identify control deficiencies, and implement enhancements that bolster security posture and operational resilience.
• Collaborate with infrastructure, cloud, networking, systems, endpoint, GRC, IT, and business teams to integrate security into platforms and workflows.
• Develop controls for identity protection, phishing defense, DLP, conditional access, privileged access, tenant security baselines, and cloud workload protection.
• Provide support and troubleshooting for certificate-based authentication, encryption, and PKI-related services.
• Build, manage, and enhance SIEM, SOAR, XDR/EDR, network, zero trust, CASB, DLP, identity, email, and collaboration security platforms.
• Create automation using PowerShell, Python, Bash, APIs, and workflow tools.
• Design and optimize processes for log collection, parsing, normalization, retention, access models, detections, correlation logic, alerting thresholds, and detection content.
• Validate detections and controls through testing, simulation, tuning, and gap analysis.
• Contribute to complex investigations and incident responses, including root cause analysis, containment support, and remediation validation.
• Participate in on-call or escalation support for significant incidents or high-priority technical challenges.
• Manage technical initiatives from design through implementation, support, optimization, and documentation.
• Create architecture diagrams, standards, SOPs, runbooks, playbooks, and knowledge base materials.
• Define and monitor enhancements in platform health, control coverage, alert quality, automation effectiveness, and engineering maturity.
• Provide technical guidance and mentorship to analysts and engineers while communicating technical decisions and remediation priorities to stakeholders.
• A college degree or equivalent is required.
• A minimum of 8 years of relevant experience.
• Expert-level technical knowledge.
• Familiarity with industry regulations.
• Proven ability to lead and coordinate team activities.
• Capability to formulate, document, and recommend policies and procedures.
• Ability to work collaboratively and lead a team.
• Demonstrated verbal and written communication skills across all organizational levels.
• Willingness to travel as required by business needs and provide on-call availability.
• Preferred: 10+ years of experience in information security, security engineering, infrastructure security, or closely related technical roles.
• Hands-on experience in designing, implementing, and supporting enterprise security technologies across various domains including cloud, identity, endpoint, network, email, and data protection.
• Experience securing Azure and/or AWS environments and operationalizing Microsoft 365 security capabilities.
• Experience with securing and supporting Azure Virtual Desktop environments.
• Working knowledge of PKI, certificate-based authentication, and encryption.
• Proficiency in PowerShell is required; Python and/or Bash proficiency is preferred.
• Experience with SIEM, SOAR, XDR/EDR, log pipelines, and platform integrations.
• Understanding of networking, identity and access management, operating systems, endpoint behavior, logging and telemetry, and common attack techniques.
• Preferred: Security certifications such as CISSP, GIAC, Azure/AWS security certifications, or other relevant credentials.
• Knowledge of TCP/IP, VLANs, routing, packet analysis, DNS, HTTP/S, SMTP, and LDAP.
• Experience supporting Windows and Linux systems, Active Directory, NTLM, Kerberos, domain services, and systems hardening.
• Advanced experience in SIEM content engineering, including correlation logic, custom parsers, rule tuning, dashboards, KQL, SPL, or equivalent tools.
• Advanced automation experience utilizing PowerShell and Python, including API integrations, orchestration, data transformation, workflow design, and scalable operational automation.
• Comprehensive health coverage.
• Retirement savings plan with company match.
• Opportunities for professional development and continuing education.
• Flexible work arrangements.
• Generous paid time off and holidays.
GuidePoint Security
Redpanda Data
CyberSheath
Akamai Technologies
Get handpicked remote jobs straight to your inbox weekly.