About the roleCBRE runs one of the largest and most varied technology estates in commercial real estate: corporate networks across more than 100 countries, cloud platforms on AWS, Azure and Google Cloud, client-facing applications, and building systems in the properties we manage. Protecting that estate takes a team of engineers who understand how the pieces fit together and where attackers look for gaps.
As a Cybersecurity Engineer, you deploy, operate and tune the security controls and detection pipelines that defend that estate. You work across identity, endpoint, network, cloud and email security under the guidance of senior engineers and architects. You make sure security telemetry reaches the security operations center (SOC) in usable form, you investigate what the tools surface, and you fix problems at the source.
This is a hands-on role for someone who has solid security fundamentals and wants to build depth across multiple technologies in a large, global environment.
What you will do- Deploy, configure and maintain security controls across endpoint detection and response (EDR), email security, web proxy, firewall, identity and cloud platforms.
- Monitor log-source health for the security data pipeline. Onboard new sources, troubleshoot ingestion and parsing failures, and escalate schema issues that need architectural changes.
- Support detection-coverage assessments against the MITRE ATT&CK framework by gathering evidence of what each log source captures and documenting gaps.
- Build and tune detections in the security information and event management (SIEM) and data pipeline platforms, working from requirements set by senior engineers.
- Conduct technical investigations into suspicious activity: unusual sign-ins, credential attacks, malware delivery, and suspicious network traffic. Document findings clearly and escalate confirmed incidents.
- Run indicator-of-compromise searches across network, identity, cloud and email logs when threat intelligence or an incident calls for it.
- Write and maintain scripts and integrations that automate repetitive security tasks.
- Work with network, identity, cloud and infrastructure teams to implement hardening changes and validate that fixes hold.
- Track vulnerability and threat intelligence relevant to the CBRE technology stack and help translate it into patch and detection priorities.
- Maintain technical documentation: runbooks, configuration records and investigation notes.
- Participate in an on-call rotation for security tooling and pipeline issues. [Confirm on-call expectations with hiring manager.]
What you bring:Required- Three or more years in information security, IT infrastructure or a related technical role, with at least one year of hands-on security engineering or SOC experience.
- Working experience with at least two of: EDR platforms (for example, CrowdStrike Falcon or Microsoft Defender), email security gateways, next-generation firewalls (for example, Palo Alto Networks), web proxies, web application firewalls, or cloud-native logging (AWS CloudTrail, VPC Flow Logs, Azure Monitor).
- Familiarity with Microsoft Entra ID (Azure AD) and common identity-based attack patterns such as password spraying and impossible-travel sign-ins.
- Exposure to a SIEM or security data pipeline platform, including reading and searching logs and understanding how parsing and normalization work.
- Basic familiarity with the MITRE ATT&CK framework and how techniques map to log sources.
- Proficiency in SQL and at least one scripting language (Python preferred) for log analysis and basic automation.
- Sound troubleshooting instincts and the ability to work through an investigation methodically from indicator to conclusion.
- Clear written communication. You can explain a technical finding to a colleague who was not in the room.
Preferred- Experience with security data pipeline platforms (for example, Databahn, Cribl) or SOAR and automation tooling (for example, Torq).
- Cloud security exposure on AWS, Azure or Google Cloud.
- One or more of: Security+, CySA+, GCIH, GSEC, or an entry-level vendor certification (CrowdStrike, Palo Alto Networks PCNSA, Microsoft SC-200 or SC-900).
- Experience working in a multi-entity or multi-tenant environment.
How we workWe value engineers who are direct about what is broken and specific about how to fix it. You will get real access, real ownership of defined workstreams, and senior engineers who expect you to ask questions and challenge assumptions. We invest in people who want to grow; this role is a clear path to senior engineering.
CBRE's RISE values, Respect, Integrity, Service and Excellence, define how we treat each other and our clients. They apply to how we run security, too: we protect people first, we tell the truth about risk, and we hold ourselves to the standard we ask of others.