Lead Security Engineer
Posted 12hrs ago
Employment Information
Report this job
Job expired or something wrong with this job?
Job Description
Lead Security Engineer designing and automating CBIZ’s enterprise security controls across cloud, identity, endpoint, network, email, and data protection. Strengthening security posture through platform engineering, detection, and response support.
Responsibilities:
- Design, implement, harden, integrate, and continuously improve CBIZ’s enterprise security technologies and controls across cloud, identity, endpoint, network, email, and data protection domains
- Engineer secure-by-default configurations, technical guardrails, scalable security solutions, and platform capabilities across hybrid and multi-cloud environments
- Translate business, compliance, and security requirements into practical engineering designs and sustainable technical solutions
- Evaluate architectures, identify control gaps, and implement improvements that strengthen security posture and operational resilience
- Partner with infrastructure, cloud, networking, systems, endpoint, GRC, IT, and business teams to embed security into platforms and workflows
- Engineer controls for identity protection, phishing defense, DLP, conditional access, privileged access, tenant security baselines, and cloud workload protection
- Support and troubleshoot certificate-based authentication, encryption, and PKI-related services
- Build, administer, and improve SIEM, SOAR, XDR/EDR, network, zero trust, CASB, DLP, identity, email, and collaboration security platforms
- Develop automation using PowerShell, Python, Bash, APIs, and workflow tooling
- Design and optimize log collection, parsing, normalization, retention, access models, detections, correlation logic, alerting thresholds, and detection content
- Validate detections and controls through testing, simulation, tuning, and gap analysis
- Contribute to complex investigations and incident response, including root cause analysis, containment support, and remediation validation
- Participate in on-call or escalation support for significant incidents or high-priority technical issues
- Own technical initiatives from design through implementation, support, optimization, and documentation
- Create architecture diagrams, standards, SOPs, runbooks, playbooks, and knowledge base content
- Define and track improvements in platform health, control coverage, alert quality, automation effectiveness, and engineering maturity
- Provide technical guidance and mentorship to analysts and engineers and communicate technical decisions and remediation priorities to stakeholders
Requirements:
- College Degree or equivalent required
- 8 years related experience
- Expert technical knowledge
- Knowledge of industry regulations
- Ability to lead and coordinate team activities
- Ability to formulate, document, and recommend policies and procedures
- Ability to work in and lead a team
- Demonstrated verbal and written communication across all organizational levels
- Ability to travel as required by business and provide on-call availability
- 10+ years of experience in information security, security engineering, infrastructure security, or closely related technical roles is preferred
- Hands-on expertise designing, implementing, and supporting enterprise security technologies across cloud, identity, endpoint, network, email, and data protection domains
- Experience securing Azure and/or AWS environments and operationalizing Microsoft 365 security capabilities
- Experience securing and supporting Azure Virtual Desktop environments
- Working knowledge of PKI, certificate-based authentication, and encryption
- PowerShell proficiency required; Python and/or Bash preferred
- Experience with SIEM, SOAR, XDR/EDR, log pipelines, and platform integrations
- Understanding of networking, identity and access management, operating systems, endpoint behavior, logging and telemetry, and common attack techniques
- Security certifications such as CISSP, GIAC, Azure/AWS security certifications, or other relevant credentials are preferred
- Knowledge of TCP/IP, VLANs, routing, packet analysis, DNS, HTTP/S, SMTP, and LDAP
- Experience supporting Windows and Linux systems, Active Directory, NTLM, Kerberos, domain services, and systems hardening
- Advanced SIEM content engineering experience with correlation logic, custom parsers, rule tuning, dashboards, KQL, SPL, or equivalent tools
- Advanced automation experience using PowerShell and Python, including API integrations, orchestration, data transformation, workflow design, and scalable operational automation



















