Senior Security Engineer

AGS

• $110K — $130K *
Information Technology
5 - 7 years of experience
Job Overview by Ladders

Qualifications

  • Expertise in Identity & Access Management, including enterprise directory, Conditional Access, MFA, and privileged access management.
  • Strong background in security monitoring and detection engineering, with proficiency in SIEM and log management platform engineering.
  • Experience in threat and vulnerability management, including risk-based prioritization and patch orchestration.
  • Demonstrated skill in endpoint and email security platforms, with a focus on EDR/XDR administration and compliance.
  • Knowledge of data protection practices, including classification, encryption, and key management principles.
  • Understanding of Zero Trust Network Access and Secure Service Edge concepts, as well as network segmentation fundamentals.

Responsibilities

  • Execute the enterprise security program roadmap and assist with tactical implementation of security initiatives.
  • Lead technical delivery for security projects, including planning and hands-on execution.
  • Manage enterprise Identity & Access Management capabilities across hybrid environments, ensuring security by design.
  • Implement and advance privileged access management and role-based access control across systems.
  • Engineer and enhance the SIEM and log management platform for better security monitoring.
  • Develop and refine detection content and alerting logic to improve incident response effectiveness.
  • Coordinate the vulnerability management program and ensure compliance with security remediation standards.

Benefits

  • Opportunity for professional growth through mentorship and collaboration with other security professionals.
  • Hands-on involvement with cutting-edge security technologies and frameworks.
  • Exposure to a variety of security programs across the enterprise and business units.
  • Participation in enterprise incident response planning and exercises.
  • Potential for travel across the United States for work-related needs.
Full Job Description
Job Description

Job Overview

The Senior Security Engineer is the senior technical implementer on the AGS security team, responsible for executing and maintaining the enterprise security control set in support of the security program strategy, roadmap, and standards set by the Senior IT Security Manager. The role provides senior engineering capability across Identity & Access Management, security monitoring and detection, and threat and vulnerability management, translating program requirements into working technical controls and documented procedures. This is a hands-on senior individual contributor role that assists in leading technical delivery and provides guidance and mentorship to other security engineers and analysts, without direct people management responsibility. The role partners closely with Infrastructure, Network, Enterprise Apps, Compliance, and Business Units to implement security by design and enable the business.

Responsibilities
  • Execute against the enterprise security program roadmap, control priorities, and risk treatment decisions set by the Senior IT Security Manager.
  • Assist in leading technical delivery of assigned security initiatives, including planning, sequencing, and hands-on implementation.
  • Implement and advance enterprise Identity & Access Management capability across hybrid on-premises and cloud environments, including authentication, authorization, and Conditional Access configuration.
  • Administer identity governance in partnership with Infrastructure: identity lifecycle (joiner/mover/leaver), MFA, self-service password reset, just-in-time administrative access, app registrations, and service principals.
  • Implement privileged access management capability, including privileged session controls and reduction of standing administrative rights.
  • Apply role-based access (RBAC/ABAC) and least privilege models across cloud and SaaS; expand SSO and federation coverage (SAML, OIDC) across enterprise and third-party applications.
  • Engineer, deploy, and expand the enterprise SIEM and log management platform, including log source onboarding, normalization, and retention configuration.
  • Develop and tune detection content, correlation rules, and alerting logic aligned to recognized adversary behavior frameworks; reduce noise while improving catch rate.
  • Build automated triage, enrichment, containment, and notification workflows for recurrent alert types.
  • Assist in leading the vulnerability and patch management program: operate scanning coverage, apply the risk-based prioritization model, and drive remediation to the service levels set by security leadership.
  • Integrate threat intelligence into vulnerability prioritization and asset risk scoring.
  • Coordinate remediation with IT operations and system owners; track SLA performance and report risk reduction.
  • Develop and maintain technical playbooks and runbooks in support of the enterprise incident response plan; participate in tabletop exercises and post-incident reviews.
  • Support crown jewel and critical asset identification, and recommend technical treatment options for review and approval by the Senior IT Security Manager.
  • Implement data classification and data protection controls, including labeling, encryption, and key management practices, in alignment with program standards.
  • Maintain enterprise security asset visibility and security tooling coverage across the estate.
  • Produce technical metrics and reporting in support of the KPIs and KRIs defined by security leadership (e.g., MFA coverage, privileged access reduction, endpoint agent coverage, MTTD/MTTR, patch SLA attainment, automation rate).
  • Use scripting and automation to codify controls and eliminate manual work.
  • Implement technical controls that align to the frameworks adopted by the security program (NIST CSF, NIST SP 800-53, CIS Controls, ISO 27001) and to applicable gaming and privacy requirements; maintain auditable technical evidence.
  • Support internal and external audit, certification, and regulatory assessment activities with technical evidence and remediation execution.
  • Evaluate security products and services and provide technical input to vendor selection, consolidation, and ROI decisions made by security leadership.
  • Provide technical guidance and mentorship to security engineers and analysts; document technical procedures for the team to operate against.
  • Provide technical risk input to the Senior IT Security Manager to support business and executive communication.
  • Occasional travel throughout the United States.


Qualifications
  • Identity & Access Management: enterprise directory and cloud identity administration, Conditional Access, MFA, privileged access management, SSO and application integration, access review execution.
  • Security monitoring and detection engineering: SIEM and log management platform engineering, detection content development, query language proficiency, SOAR and playbook automation.
  • Threat and vulnerability management: enterprise scanning platforms, risk-based prioritization, patch orchestration, and SLA reporting.
  • Endpoint and email security platforms: EDR/XDR administration, policy tuning, baseline hardening, device compliance.
  • Data protection: classification and labeling, DLP concepts, encryption and key management.
  • Zero Trust Network Access patterns and Secure Service Edge (SSE) concepts, network segmentation fundamentals.<

Similar Jobs

More Jobs at AGS

More Information Technology Jobs

Find similar Senior Security Engineer jobs: