Join a team that is STRONGER THAN STEEL℠, by applying to become a Security Engineer at our West Chester, OH location.
POSITION SUMMARYThe Security Engineer designs, implements, and operates security controls across identity, endpoints, networks, cloud services, applications, data, and AI-enabled systems. This hands-on role reduces cyber risk while enabling the responsible use of modern technology. The engineer partners with infrastructure, application, data, legal, privacy, and business teams to build resilient services, detect and respond to threats, and translate technical findings into practical action.
KEY RESPONSIBILITIESSecurity architecture and engineering- Engineer secure platforms. Design and improve preventive, detective, and recovery controls across hybrid infrastructure, SaaS, cloud platforms, endpoints, networks, and business applications.
- Strengthen identity. Implement MFA, Conditional Access, least privilege, privileged-access management, lifecycle governance, service-identity controls, and periodic access reviews.
- Secure cloud-native workloads. Assess cloud configurations, APIs, containers, serverless services, infrastructure as code, CI/CD pipelines, secrets, and software supply-chain dependencies.
- Manage exposure. Identify and prioritize vulnerabilities, attack paths, misconfigurations, unsupported assets, and internet-facing risk; partner with owners through verified remediation.
- Embed security by design. Perform architecture reviews and threat modeling for new systems, integrations, vendors, and major changes; define proportionate control requirements before production.
AI and emerging-technology security- Govern enterprise AI use. Maintain visibility into approved and unapproved AI services, models, agents, copilots, plugins, data connections, and business use cases; help teams choose secure, sanctioned paths.
- Secure AI systems end to end. Review data flows, model and API access, retrieval pipelines, vector stores, prompts, tools, memory, outputs, and human-approval points across the AI lifecycle.
- Threat-model AI-specific abuse. Evaluate prompt injection, sensitive-data disclosure, insecure output handling, model or data poisoning, excessive agency, identity abuse, supply-chain compromise, denial of service, and unsafe tool execution.
- Implement AI guardrails. Apply strong authentication, scoped authorization, data classification and DLP, secrets management, content filtering, tool isolation, rate limits, audit logging, monitoring, and human-in-the-loop controls.
- Validate before and after launch. Coordinate security testing, adversarial evaluation, red teaming, misuse-case testing, and ongoing monitoring for AI applications and material model, prompt, tool, or data changes.
- Enable safe adoption. Translate AI policy into usable engineering standards and employee guidance; investigate shadow-AI and risky data-handling patterns without defaulting to indiscriminate blocking.
- Use AI responsibly in security operations. Apply automation and AI-assisted analysis to accelerate triage, investigation, detection development, and reporting while preserving evidence, access controls, validation, and accountable human decisions.
Detection, incident response, and resilience- Improve detection. Engineer useful telemetry and detections across identity, endpoint, network, cloud, email, applications, data, and AI services; tune alerting to improve signal quality.
- Respond to incidents. Lead or support triage, containment, eradication, recovery, evidence preservation, communications, and post-incident improvement, including identity and token compromise.
- Automate repeatable work. Build scripts, queries, playbooks, and integrations that improve investigation speed, control consistency, and operational visibility.
- Protect recovery paths. Validate hardening, patching, backup security, recovery procedures, and disaster-recovery assumptions through exercises and technical testing.
- Share actionable intelligence. Produce decision-ready metrics and concise reporting on exposure, incidents, control health, AI risk, remediation performance, and residual risk.
Governance and collaboration- Maintain security standards, diagrams, procedures, playbooks, risk decisions, and operational records that are clear enough for another engineer to use.
- Support audits and controls related to Japanese Sarbanes-Oxley (J-SOX), change management, privacy, third-party risk, and applicable company requirements.
- Evaluate security and AI vendors, permission requests, data usage, architectural fit, contractual security commitments, and operational ownership.
- Communicate risk in business terms, collaborate across technical and nontechnical teams, and provide targeted security guidance and awareness.
- Participate in security projects, an on-call rotation, and related responsibilities as business and threat conditions evolve.
REQUIRED QUALIFICATIONS- Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
- Five or more years of progressive IT or cybersecurity experience, including substantial hands-on responsibility for security engineering, architecture, operations, or incident response.
- Demonstrated experience securing at least three of the following domains: cloud platforms, enterprise identity, endpoints, networks, applications/APIs, SaaS, data platforms, or AI-enabled systems.
- Strong knowledge of identity and access management, modern authentication, network and web protocols, operating-system security, logging, vulnerability management, and secure configuration practices.
- Experience with SIEM, endpoint detection and response, cloud-security or posture-management tooling, and investigation using structured queries and multiple telemetry sources.
- Ability to automate tasks and analyze data using PowerShell, Python, APIs, infrastructure as code, or comparable tools.
- Working knowledge of AI and generative-AI architecture, including model APIs, retrieval-augmented generation, agents and tool use, enterprise copilots, and common AI security failure modes.
- Experience applying threat modeling, security testing, risk assessment, and secure-development practices to new technology or business applications.
- Clear written and verbal communication, sound judgment, and the ability to coordinate effectively during ambiguous or high-pressure events.
PREFERRED QUALIFICATIONS- Experience with Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint, Azure, AWS, or comparable enterprise platforms.
- Hands-on experience assessing or operating generative-AI applications, enterprise copilots, AI agents, model gateways, or AI security-posture and monitoring capabilities.
- Experience in a manufacturing, industrial, distributed-site, OT/IoT, or regulated environment.
- Familiarity with NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, ISO 27001, secure software-development practices, and recognized AI/LLM security guidance.
- Relevant certification such as CISSP, CCSP, GIAC, Security+, a cloud-security certification, or equivalent demonstrated capability.
WHAT SUCCESS LOOKS LIKE- Critical identity, cloud, endpoint, network, application, data, and AI risks have clear owners, realistic priorities, and verified remediation.
- New AI use cases reach production through a repeatable security-review process with documented data boundaries, permissions, abuse cases, guardrails, logging, and accountable approval.
- Detection and incident-response workflows produce faster, more reliable decisions with less avoidable alert noise and stronger evidence preservation.
- Security controls are measurable, documented, supportable, and resilient to personnel, platform, and threat changes.
- Leaders receive concise reporting that connects engineering activity to business resilience, compliance, responsible AI adoption, and residual risk.
WORK ENVIRONMENTThis position may require regular work in an office environment, with a hybrid schedule available upon approval. The role may also join an on-call rotation and require occasional travel or work in data-center, manufacturing, or network environments. Reasonable accommodation may be provided to enable qualified individuals to perform the essential functions.
CLARKDIETRICH BENEFITS INCLUDE- Full benefits package (Medical, Dental, Vision, Flexible Spending Accounts and Life Insurance)
- 401(k) with company match
- Annual Incentive
- Paid Time Off
- Tuition Reimbursement
- Professional Certification Reimbursement Program
- Community Service Day