CBIZ Logo

CBIZ

Lead Security Engineer

Posted Yesterday
Be an Early Applicant
In-Office or Remote
Hiring Remotely in United States
Senior level
In-Office or Remote
Hiring Remotely in United States
Senior level
Lead hands-on security engineer responsible for designing, implementing, hardening, automating, and optimizing enterprise security controls across cloud, identity, endpoint, network, email, and data protection. Builds and maintains security platforms (SIEM, SOAR, XDR/EDR), develops detection logic, automates workflows, supports incident response, and partners with cross-functional teams to raise security engineering maturity and reduce risk.
The summary above was generated by AI

#LI-CR2 #LI-Remote

Responsibilities

The Lead Security Engineer (Cloud & Enterprise Security Engineering) is a deeply technical, hands-on engineering role responsible for designing, implementing, hardening, integrating, and continuously improving CBIZ’s enterprise security technologies and controls across cloud, identity, endpoint, network, email, and data protection domains. This position requires strong engineering fundamentals, broad systems knowledge, and the ability to solve complex technical problems across hybrid and multi-cloud environments.

 

The ideal candidate is an experienced builder and troubleshooter who can translate security requirements into scalable, reliable, and measurable technical solutions. Success in this role depends on advanced expertise in security architecture, platform engineering, automation, systems integration, detection logic, and control validation. The engineer must be able to work across diverse technologies, analyze intricate dependencies, and develop durable solutions that strengthen security posture, reduce risk, and improve operational resilience.

 

This is not a passive monitoring or ticket-routing role. It is a senior technical position focused on engineering secure-by-default solutions, improving platform capabilities, automating security functions, and driving long-term technical maturity across the environment. While incident support and investigation remain part of the role, the primary emphasis is on building, optimizing, and sustaining the security technologies, integrations, and guardrails that prevent, detect, and contain threats at scale.

 

 

Essential Functions and Primary Duties

Cloud & Enterprise Security Engineering

  • Design, implement, harden, and maintain enterprise security controls and reference architectures across:

    • Microsoft Azure and Azure Virtual Desktop (AVD)

    • Amazon Web Services (AWS)

    • Microsoft 365 security and compliance platforms

    • Hybrid identity, endpoint, email, and data protection environments

  • Engineer secure-by-default configurations and technical guardrails that reduce attack surface, improve resilience, and support scalable enterprise operations.

  • Translate business, compliance, and security requirements into practical engineering designs and sustainable technical solutions.

  • Evaluate current-state architectures, identify control gaps, and implement improvements that strengthen security posture while maintaining operational usability.

  • Partner with infrastructure, cloud, networking, systems, and endpoint teams to embed security into enterprise platforms, workflows, and lifecycle processes.

Identity, Data Protection & Platform Security

  • Engineer and operationalize controls for identity protection, phishing defense, DLP, conditional access, privileged access, tenant security baselines, and cloud workload protection.

  • Secure workloads, identities, and data across hybrid and multi-cloud environments through design standards, configuration baselines, and measurable technical guardrails.

  • Support and troubleshoot certificate-based authentication, encryption, and PKI-related services, including lifecycle considerations such as issuance, renewal, revocation, and dependency management.

  • Improve authentication security, access control design, and privileged access protections across enterprise systems and cloud platforms.

  • Design and validate visibility and monitoring coverage for cloud, identity, endpoint, email, and platform security events to ensure reliable telemetry and actionable data.

Security Platforms, Automation & Tooling

  • Build, administer, and continuously improve core security platforms and integrations, including:

    • SIEM and log ingestion pipelines

    • SOAR and workflow automation platforms

    • XDR/EDR and endpoint security tooling

    • Network and zero trust security controls

    • CASB, DLP, and data security platforms

    • Identity and access management controls

    • Email and collaboration security technologies

  • Develop and maintain automation using PowerShell, Python, Bash, APIs, and workflow tooling to support enrichment, orchestration, reporting, evidence collection, system validation, and control enforcement.

  • Design and optimize log collection, parsing, normalization, retention, and access models to improve searchability, detection quality, auditability, and investigative efficiency.

  • Improve platform reliability, scalability, and maintainability through lifecycle upgrades, engineering standards, technical documentation, and structured change control.

  • Evaluate and responsibly implement AI-enabled security capabilities where they provide measurable improvements in efficiency, visibility, or control effectiveness.

Detection Engineering & Technical Response Support

  • Engineer and refine analytic rules, correlation logic, alerting thresholds, and detection content across cloud, identity, endpoint, email, and network security technologies.

  • Validate detections and controls through testing, simulation, tuning, and gap analysis to improve fidelity and reduce noise.

  • Translate lessons learned from incidents, platform issues, and control failures into durable engineering improvements such as new detections, automation, hardening standards, and preventive safeguards.

  • Contribute to complex investigations and incident response activities as a senior technical resource, including root cause analysis, containment support, and remediation validation.

  • Participate in on-call or escalation support as needed for significant incidents or high-priority technical issues.

Technical Ownership, Documentation & Continuous Improvement

  • Own complex technical initiatives from design through implementation, support, optimization, and documentation.

  • Balance project-based engineering work with platform maintenance, technical debt remediation, backlog reduction, and continuous control improvement.

  • Create and maintain actionable documentation including architecture diagrams, standards, SOPs, runbooks, playbooks, and knowledge base content aligned to production reality.

  • Define and track measurable improvements in platform health, control coverage, alert quality, automation effectiveness, and engineering maturity.

  • Serve as a senior technical contributor who establishes patterns, improves standards, and advances overall enterprise security engineering maturity.

Collaboration & Communication

  • Partner closely with GRC, IT, Cloud, Networking, Systems, Endpoint, and business teams to develop secure designs and pragmatic technical solutions.

  • Clearly communicate architecture decisions, technical findings, control gaps, implementation plans, and remediation priorities to both technical and non-technical stakeholders.

  • Provide technical guidance and mentorship to analysts and engineers, helping elevate engineering practices, platform understanding, and troubleshooting capability across the team.

  • Influence cross-functional stakeholders and help remove blockers to drive timely technical outcomes.

 

 

 

Preferred Qualifications

  • 10+ years of experience in Information Security, Security Engineering, Infrastructure Security, or closely related technical roles, including senior or lead ownership of complex security initiatives.

  • Demonstrated hands-on expertise designing, implementing, and supporting enterprise security technologies across cloud, identity, endpoint, network, email, and data protection domains.

  • Deep experience securing cloud environments such as Azure and/or AWS, and operationalizing Microsoft 365 security capabilities including Defender, email protection, DLP, conditional access, and identity protections.

  • Strong experience securing and supporting Azure Virtual Desktop (AVD) environments, including identity controls, endpoint protections, logging, monitoring, and configuration hardening.

  • Working knowledge of PKI, certificate-based authentication, and encryption, with the ability to troubleshoot production issues and understand operational and security impacts.

  • Strong scripting and systems skills, including PowerShell as a core requirement, with Python and/or Bash strongly preferred.

  • Hands-on experience building and maintaining security platforms such as SIEM, SOAR, XDR/EDR, log pipelines, and platform integrations, including data onboarding, content tuning, and workflow development.

  • Strong understanding of security engineering fundamentals including networking, identity and access management, operating systems, endpoint behavior, logging and telemetry, and common attack techniques.

  • Demonstrated ability to work independently, exercise strong technical judgment, and drive complex engineering efforts through completion.

  • Security certifications such as CISSP, GIAC (GCIA, GCIH, GCED), Azure/AWS security certifications, or other relevant technical credentials.

  • Strong command of enterprise networking concepts including TCP/IP, VLANs, routing, packet analysis, DNS, and application protocols such as HTTP/S, SMTP, and LDAP.

  • Experience supporting Windows and Linux systems in enterprise environments, including Active Directory, authentication protocols such as NTLM and Kerberos, domain services, and systems hardening practices.

  • Advanced experience in SIEM content engineering, including architecting correlation logic, custom parsers, rule tuning, and dashboards using platforms and query languages such as KQL, SPL, or equivalent tools.

  • Advanced automation experience using PowerShell and Python, including API integrations, orchestration, data transformation, workflow design, and scalable operational automation.

     

Qualifications

Minimum Qualifications 

  • College Degree or equivalent required
  • 8 years related experience
  • Expert technical knowledge
  • Knowledge of industry regulations
  • Ability to lead and coordinate the team activities of others
  • Ability to formulate, document and recommend new policies and procedures
  • Able to work in and lead a team
  • Demonstrated ability to communicate verbally and in writing throughout all levels of an organization, both internally and externally
  • Ability to travel as required by business and on-call availability
About Us

CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.

CBIZ strives to be our team members' employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers.

Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.

CBIZ Denver, Colorado, USA Office

Denver, United States

Similar Jobs

5 Days Ago
Remote or Hybrid
US
133K-193K Annually
Senior level
133K-193K Annually
Senior level
Information Technology
Lead technical security strategy and implementation for Managed Services platforms. Design and improve security controls, IAM, PAM, vulnerability management, incident response, and compliance. Embed secure-by-design and DevSecOps practices, mentor engineers, and partner with architecture, engineering, and operations to reduce risk and enable scalable growth.
Top Skills: Azure SecurityCloud SecurityDevsecopsEndpoint ProtectionIamInfrastructure AutomationNetwork SecurityPlatform EngineeringPowershellPrivileged Access ManagementPythonSecure SdlcSecurity AutomationThreat DetectionZero Trust
Yesterday
Remote
United States
170K-210K Annually
Senior level
170K-210K Annually
Senior level
Fintech • HR Tech • Payments • Cryptocurrency
Owner of security, infrastructure ops, and reliability across GCP, application, and on-chain surfaces. Lead incident response, secrets and IAM governance, vulnerability management, detection/alerting, compliance (SOC2), CI/CD and IaC, Cloud Run/BigQuery/MySQL/Cloudflare hardening, disaster recovery, and secure Ethereum wallet/key and smart-contract operations.
Top Skills: BigQueryCi/CdCloud RunCloudflareCloudflare PagesDnsEthereumEvmGoogle Cloud PlatformIamInfrastructure-As-CodeLogging/MonitoringMySQLNode.jsObservabilitySecrets ManagementSecurity Command Center (Scc)Smart ContractsTracingTypescriptWafWallets
Yesterday
In-Office or Remote
North Carolina, USA
152K-308K Annually
Senior level
152K-308K Annually
Senior level
Cloud • Information Technology • Internet of Things • Professional Services • Software
Lead design and implementation of AI-driven automation for cloud security, architect backend services and observability, guide 2-3 engineers, define roadmap and SDLC/CI/CD practices, build reusable tooling, and mentor peers to deliver secure, scalable cloud solutions.
Top Skills: APIsAspmAWSAws Bedrock AgentcoreAzureAzure Ai FoundryCi/CdCspmDockerEcsGCPGoogle Vertex AiKubernetesLanggraphNosql DatabasesOciOpenai Agents SdkPolicy-As-CodePythonRelational DatabasesSdksSemantic KernelStrands AgentsTerraform

What you need to know about the Colorado Tech Scene

With a business-friendly climate and research universities like CU Boulder and Colorado State, Colorado has made a name for itself as a startup ecosystem. The state boasts a skilled workforce and high quality of life thanks to its affordable housing, vibrant cultural scene and unparalleled opportunities for outdoor recreation. Colorado is also home to the National Renewable Energy Laboratory, helping cement its status as a hub for renewable energy innovation.

Key Facts About Colorado Tech

  • Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
  • Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
  • Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
  • Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
  • Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
  • Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account