Remotery

Lead Security Engineer

Posted 2 days ago

This is a fully remote position, open to applicants in New York.

📋 Description

• Design, implement, secure, integrate, and continuously enhance CBIZ’s enterprise security technologies and controls across various domains including cloud, identity, endpoint, network, email, and data protection.

• Engineer configurations that prioritize security by default, establish technical guardrails, and develop scalable security solutions and platform capabilities within hybrid and multi-cloud environments.

• Convert business, compliance, and security needs into effective engineering designs and sustainable technical solutions.

• Assess architectures, identify control deficiencies, and implement enhancements that bolster security posture and operational resilience.

• Collaborate with infrastructure, cloud, networking, systems, endpoint, GRC, IT, and business teams to integrate security into platforms and workflows.

• Develop controls for identity protection, phishing defense, DLP, conditional access, privileged access, tenant security baselines, and cloud workload protection.

• Provide support and troubleshooting for certificate-based authentication, encryption, and PKI-related services.

• Build, manage, and enhance SIEM, SOAR, XDR/EDR, network, zero trust, CASB, DLP, identity, email, and collaboration security platforms.

• Create automation using PowerShell, Python, Bash, APIs, and workflow tools.

• Design and optimize processes for log collection, parsing, normalization, retention, access models, detections, correlation logic, alerting thresholds, and detection content.

• Validate detections and controls through testing, simulation, tuning, and gap analysis.

• Contribute to complex investigations and incident responses, including root cause analysis, containment support, and remediation validation.

• Participate in on-call or escalation support for significant incidents or high-priority technical challenges.

• Manage technical initiatives from design through implementation, support, optimization, and documentation.

• Create architecture diagrams, standards, SOPs, runbooks, playbooks, and knowledge base materials.

• Define and monitor enhancements in platform health, control coverage, alert quality, automation effectiveness, and engineering maturity.

• Provide technical guidance and mentorship to analysts and engineers while communicating technical decisions and remediation priorities to stakeholders.


⛳️ Requirements

• A college degree or equivalent is required.

• A minimum of 8 years of relevant experience.

• Expert-level technical knowledge.

• Familiarity with industry regulations.

• Proven ability to lead and coordinate team activities.

• Capability to formulate, document, and recommend policies and procedures.

• Ability to work collaboratively and lead a team.

• Demonstrated verbal and written communication skills across all organizational levels.

• Willingness to travel as required by business needs and provide on-call availability.

• Preferred: 10+ years of experience in information security, security engineering, infrastructure security, or closely related technical roles.

• Hands-on experience in designing, implementing, and supporting enterprise security technologies across various domains including cloud, identity, endpoint, network, email, and data protection.

• Experience securing Azure and/or AWS environments and operationalizing Microsoft 365 security capabilities.

• Experience with securing and supporting Azure Virtual Desktop environments.

• Working knowledge of PKI, certificate-based authentication, and encryption.

• Proficiency in PowerShell is required; Python and/or Bash proficiency is preferred.

• Experience with SIEM, SOAR, XDR/EDR, log pipelines, and platform integrations.

• Understanding of networking, identity and access management, operating systems, endpoint behavior, logging and telemetry, and common attack techniques.

• Preferred: Security certifications such as CISSP, GIAC, Azure/AWS security certifications, or other relevant credentials.

• Knowledge of TCP/IP, VLANs, routing, packet analysis, DNS, HTTP/S, SMTP, and LDAP.

• Experience supporting Windows and Linux systems, Active Directory, NTLM, Kerberos, domain services, and systems hardening.

• Advanced experience in SIEM content engineering, including correlation logic, custom parsers, rule tuning, dashboards, KQL, SPL, or equivalent tools.

• Advanced automation experience utilizing PowerShell and Python, including API integrations, orchestration, data transformation, workflow design, and scalable operational automation.


🏝️ Benefits

• Comprehensive health coverage.

• Retirement savings plan with company match.

• Opportunities for professional development and continuing education.

• Flexible work arrangements.

• Generous paid time off and holidays.

People also viewed

GuidePoint Security2 days ago

Senior Security Entra Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
Redpanda Data2 days ago

Staff Security Engineer

US flagUnited States, +1 more stateFull-timeCybersecurity / Security Engineer$210k – $247k/year
ApplyView job
CyberSheath2 days ago

Cloud Security Engineer

US flagUnited States OnlyFull-timeCybersecurity / Security Engineer$85k – $100k/year
ApplyView job
Akamai Technologies2 days ago

Senior Security Sales Specialist

US flagCalifornia OnlyFull-timeCybersecurity / Security Engineer
ApplyView job
CloudLinux2 days ago

AI Pipeline Engineer – Security Automation Platform

PL flagPoland, +4 more statesFull-timeCybersecurity / Security Engineer
ApplyView job
Oxfam America2 days ago

Manager, Cybersecurity and Infrastructure

US flagMassachusetts OnlyFull-timeCybersecurity / Security Engineer$105k – $115k/year
ApplyView job

Never miss a great job!

Get handpicked remote jobs straight to your inbox weekly.

Trusted by 7,400+ designers