4+ years in cybersecurity operations or security-focused systems administration, primarily in cloud environments
Experience with security monitoring and SIEM platforms, including alert investigation
Practical knowledge of endpoint detection and cloud-native security tools
Familiarity with cloud identity security concepts like multifactor authentication
Experience managing a vulnerability program and driving remediation
Participation in recognized audit programs like SOC 2 or ISO 27001
Strong written communication skills for policies and executive summaries
Ability to lead incidents calmly and document outcomes clearly
Responsibilities
Own detection and response for cloud identity, endpoint, and infrastructure security
Serve as primary incident responder, coordinating with internal and external stakeholders
Maintain and exercise the incident response plan, including post-incident reviews
Develop detection rules and automated response playbooks to enhance response times
Administer the SIEM platform, ensuring data source onboarding and log health
Produce security reports for IT leadership, translating technical findings into business risks
Run the vulnerability management lifecycle, partnering with system owners for remediation
Benefits
Opportunity to work in a fully cloud-based environment
High visibility role with direct impact on organizational security decisions
Independence in setting operational security agendas
Access to managed security service providers for enhanced support
Potential for professional development and training opportunities
Full Job Description
Cybersecurity Engineer
The Cybersecurity Engineer owns the day-to-day security operations of the organization's fully cloud-based technology environment. This is the company's dedicated security role, and it operates with a high degree of independence: the incumbent drafts and sets the approved operational security agenda, oversees external MDR, drives vulnerability and access remediation with system owners, and carries the organization through external audit. Because the scope is broad by design, the role is structured to scale through leverage - directing managed security service providers and specialist vendors for around-the-clock monitoring and surge capacity, while retaining ownership of strategy, configuration, escalation, and outcomes in-house.
The successful candidate is equally comfortable investigating an alert at the console and explaining residual risk to business leadership. This is a high-visibility role with a direct line to decisions about how the organization protects its data, its residents' information, and its capital.
Key Responsibilities:
Threat Detection & Incident Response
Own detection and response across cloud identity, endpoint, email, and cloud infrastructure, including triage, containment, eradication, and recovery
Serve as primary incident responder and incident commander for security events, coordinating internal stakeholders, managed service providers, and outside counsel or forensics as required
Maintain and exercise the incident response plan, including tabletop exercises and post-incident reviews that produce tracked corrective actions
Develop and tune detection rules, alert logic, and automated response playbooks to reduce mean time to detect and mean time to respond
Build and maintain runbooks for recurring incident types so that response is repeatable and not dependent on a single individual
Security Monitoring, SIEM & Reporting
Administer the security information and event management (SIEM) platform, including data source onboarding, log ingestion health, normalization, and retention configuration
Manage ingestion cost and data tiering to keep monitoring coverage aligned with budget
Build and maintain dashboards, analytics rules, and workbooks that provide operational visibility into the security posture of the cloud environment
Produce recurring security reporting for IT leadership and executive stakeholders, translating technical findings into business risk and clear recommendations
Define and track security metrics - detection coverage, alert volume and disposition, patch and remediation timeliness, phishing susceptibility, and audit readiness
Vulnerability & Configuration Management
Run the vulnerability management lifecycle across endpoints, servers, cloud workloads, and third-party platforms: discovery, assessment, risk-based prioritization, remediation tracking, and verification
Partner with system and application owners to drive remediation to closure, escalating where service-level targets are at risk
Assess and harden security configuration baselines against recognized benchmarks, and monitor for configuration drift
Coordinate external penetration testing and vulnerability assessments, and manage the resulting findings through to resolution
Maintain the risk register and formal exception process for accepted risks, with documented compensating controls and review dates
Identity & Privileged Access Governance
Administer privileged identity and privileged access management, including just-in-time elevation, approval workflows, activation justification, and time-bound role assignment
Conduct recurring privileged access reviews and audits, validating that standing administrative access is eliminated or justified and that every elevation is attributable
Own access review and recertification cycles across the cloud tenant and integrated business platforms, coordinating with business owners as reviewers
Review and strengthen conditional access, multifactor authentication, and device compliance policies, including break-glass account controls and their periodic testing
Monitor for identity-based threats - token theft, consent phishing, risky sign-ins, legacy authentication, and over-permissioned service principals and application registrations
Cloud & DevOps Security
Provide security oversight of the organization's cloud productivity tenant and cloud infrastructure platform, including tenant-level security configuration and posture management
Embed security into development and automation pipelines: secrets management, dependency and container scanning, infrastructure-as-code review, and pipeline identity and permission hygiene
Review and advise on cloud architecture changes, network segmentation, and secure-by-default configuration before deployment rather than after
Administer cloud-delivered secure access and secure web gateway capabilities for private application access, internet egress filtering, and conditional network controls
Govern third-party application consent, API permissions, and integration security across the cloud tenant
Data Protection, Compliance & eDiscovery
Serve as the primary owner for the annual SOC 2 audit: control mapping, evidence collection, gap remediation, auditor liaison, and management of the readiness timeline
Maintain the security control framework and supporting policy set, keeping documentation current and demonstrably operating
Administer the data governance and compliance platform, including data loss prevention policies, sensitivity labeling, retention, and insider risk controls
Conduct eDiscovery searches, legal holds, exports, and collection activities in support of legal, human resources, and compliance requests, maintaining defensible chain of custody
Support security questionnaires, investor and lender due-diligence requests, and cyber insurance renewals with accurate control attestations
Track applicable regulatory and contractual obligations relating to personal information and advise the business on required controls
Security Awareness & Human Risk
Own the security awareness program end to end: content selection, campaign calendar, assignment, completion tracking, and effectiveness measurement
Design and administer simulated phishing campaigns, including scenario selection, difficulty progression, targeting, and results analysis
Deliver targeted follow-up training and coaching for repeat-susceptible users, favoring constructive reinforcement over punitive measures
Provide role-specific training for higher-risk functions such as finance, accounting, and executive support, with emphasis on payment fraud and business email compromise
Contribute security content to new-hire onboarding in partnership with Human Resources and Training
Vendor & Managed Service Oversight
Manage outsourced security functions and managed security service providers, including scope definition, service-level expectations, escalation paths, and performance review
Validate provider work rather than accepting it at face value: review alert dispositions, challenge false-negative and false-positive patterns, and audit coverage gaps
Evaluate, pilot, and recommend security tooling, with attention to consolidation and total cost of ownership rather than point-solution accumulation
Own security vendor relationships, contract renewals, and license true-ups in coordination with IT leadership
Conduct third-party and vendor security risk assessments for new platforms prior to adoption
Qualifications:
Required:
4+ years of hands-on experience in cybersecurity operations, security engineering, or a security-focused systems administration role, in a predominantly cloud environment
Demonstrated experience with security monitoring and SIEM platforms, including detection tuning and investigation of real alerts through to disposition
Practical experience with endpoint detection and response and cloud-native security tooling across identity, endpoint, email, and cloud workloads
Working knowledge of cloud identity security, including conditional access, multifactor authentication, and privileged access management concepts
Experience running a vulnerability management program, including prioritization and driving remediation through other teams
Direct participation in a recognized audit or compliance program such as SOC 2, ISO 27001, or NIST Cybersecurity Framework, including evidence collection
Ability to lead an incident calmly under pressure and to document what happened clearly afterward
Strong written communication: policies, runbooks, findings, and executive-level summaries
Sound judgment about what to escalate and what to handle independently, with the discretion the role requires
Preferred:
Experience administering a cloud data governance and compliance platform, including data loss prevention and eDiscovery
Experience integrating security controls into CI/CD pipelines and infrastructure-as-code workflows
Experience managing or holding a managed security service provider accountable to service levels
Scripting or automation capability for reporting, evidence collection, and repetitive response tasks
Experience administering a security awareness and simulated phishing platform
Familiarity with secure access service edge or zero-trust network access technologies
Exposure to real estate, construction, property management, or another multi-site operating environment
Relevant certifications such as CISSP, CISM, GIAC, CCSP, or vendor-specific cloud security certifications; certification is valued but does not substitute for demonstrated hands-on capability
Work Environment:
This is a fully cloud-based environment. Incumbents primarily work in an office setting with occasional travel between office locations required. The role requires availability outside standard business hours for security incidents, and as the primary on-call escalation. Occasional extended hours may be needed to support audit deadlines, remediation windows, or critical incidents.