Full Job Description
Under the direction of the SOC Manager, the Sr. Cybersecurity Engineer is a senior technical role focused primarily on the engineering, operation, and optimization of Clayco's Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) solutions, while also supporting the broader security control stack. The role is responsible for engineering effective, supportable, and sustainable control configurations to meet the design requirements and objectives of our security control solutions, including initial implementations, life-cycle management changes, and necessary integrations. Operation, oversight, gap remediation, and change management of the security control stack as a member of the SOC team will be included in the day-to-day responsibilities.
This role will oversee the Data Loss Prevention (DLP) & Cloud Access Security Broker (CASB) solutions for Clayco's environment to include configuration and administration of applicable policies, alerts, data sources, and remediation of any misconfigurations. This role will also identify and remediate gaps across Clayco's cybersecurity control set to include agent deployments, configuration changes, and tuning activities.
The Specifics of the Role
3As a member of the Cybersecurity Team, contributes however and whenever necessary to Incident Response efforts as circumstances dictate.
3Assists with management of access controls, policies, and rules configurations for firewalls, DNS Layer Security, Email Security & Fraud Defense, Web App Firewalls (WAF), as well as responds to operational issues for each.
3Operates the Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) solutions to include their administration, maintenance, support, troubleshooting, and optimization of the solutions such as:
3Endpoint, Network, and Cloud/SaaS DLP Platforms
3Host-based DLP Agents and CASB Connectors
3Required Integrations (CASB, SaaS APIs, Identity Provider, SIEM/SOAR)
3Data Classification & Sensitive Data Discovery Inputs
3Conducts regularly scheduled and ad-hoc data discovery and policy scans across endpoints, network, and cloud/SaaS applications, ensuring that high-fidelity DLP and CASB detection data is successfully and reliably ingested into the Incident Management & Workflow Platform in coordination with GRC.
3Partners with GRC and business units to map data flows, classify sensitive data, and address data-protection gaps by aligning DLP and CASB policies with regulatory and contractual requirements (e.g., GDPR, CCPA, HIPAA, PCI-DSS) and deploying specialized controls (encryption, tokenization, blocking, or quarantine) as needed.
3Develops DLP and CASB incident reports, data-risk ratings, and compliance scorecards that define the current state of data exposure for Clayco's environment.
3Designs, tests, and tunes DLP detection rules and data classification policies (e.g., PII, PCI, PHI, source code, financials, and confidential business data) to balance data protection with business productivity while minimizing false positives.
3Administers CASB controls for sanctioned and unsanctioned cloud applications, including Shadow IT discovery, application risk scoring, and enforcement of access, sharing, and data-residency policies.
3Triages, investigates, and resolves DLP and CASB alerts, coordinating with Incident Response, HR, and Legal on potential data exfiltration and insider-risk events.
3Maintains DLP and CASB policy, exception, and runbook documentation, and produces KRI/KPI metrics on data-loss events, policy violations, and remediation timelines.
3Understands and complies with Clayco's Change Management process to ensure that change is justified, tested, approved, and communicated effectively.
3Serves as a senior technical resource and mentor on DLP and CASB matters, providing guidance to SOC analysts and junior engineers and representing the data-protection program in cross-functional initiatives.
3Interfaces with vendor support teams to keep abreast of developments in product lines.
3Performs other duties as assigned.
Requirements
3Bachelor's Degree (Cybersecurity, Computer Science, or Information Technology) preferred, or equivalent work experience.
3Certified Cloud Security Professional (CCSP, (ISC) 2), Cloud Security Alliance Certificate of Cloud Security Knowledge (CSA CCSK), or equivalent (current status or obtained within 6 months of assuming role).
36-8 years of technical work experience in Information Security.
33-5 years of direct work-related Cybersecurity Operations experience, including hands-on experience administering and engineering Data Loss Prevention (DLP) and Cloud Access Security Broker (CASB) solutions, as well as Security Control Engineering (firewalls, email security gateways, WAFs, etc.).
3Experience with scripting languages (Python, PowerShell, BASH, etc.).
3Understanding of malware, emerging threats, attacks, and vulnerability exploitation with a personal drive to continue learning.
3Experience in Enterprise Client-Server, Cloud (Azure, AWS, GCP), & IoT Hybrid environments and knowledge of how various technologies and processes interact and behave.
3Knowledge of secure network/systems configuration management as well as an understanding of networking protocols, concepts, and devices.
3Excellent oral and written communication skills, including the ability to document functional requirements, test and validation criteria, communication plans, KRI/KPI reports, and other relevant operational communications.
3Ability to respond to incidents or outages 24/7, including holidays and weekends.
3Ability to thrive in a fast-paced environment.
3Minimal travel required.
Some Things You Should Know
3This position will service our clients regionally.
3Our clients and projects are nationwide - Travel will be required.
3No other builder can offer the collaborative design-build approach that Clayco does.
3We work on creative, complex, award-winning, high-profile jobs.
3The pace is fast!
3This position is classified as a safety-sensitive role in accordance with applicable state and federal laws. Candidates selected for this position will be subject to a comprehensive background check, which includes mandatory drug testing.
Benefits
3Discretionary Annual Bonus: Subject to company and individual performance.
3Comprehensive Benefits Package Including: Medical, dental and vision plans, 401k, generous PTO and paid company holidays, employee assistance program, flexible spending accounts, life insurance, disability coverage, learning & development programs and more!
Compensation
3The salary range for this position considers a wide range of factors in making compensation decisions including but not limited to: Education, qualifications, skills, training, experience, certifications, internal equity, and location. Compensation decisions are dependent on the facts and circumstances of each case.