KPA is seeking a Senior Security Engineer to serve as the senior technical counterpart to the Director of Security & Technology. This role owns KPA's security platforms, cloud security, identity, automation, and technical security initiatives. The ideal candidate is a hands-on security engineer with strong cloud and infrastructure experience who can independently lead complex security projects, partner effectively with IT Operations and DevOps, and continuously improve KPA's security posture.
Responsibilities:
- Own KPA's enterprise security platforms, including CrowdStrike, Rapid7 (InsightIDR, InsightVM, InsightAppSec, MDR), Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies.
- Lead vulnerability management and remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives.
- Lead security incident response, investigations, containment, remediation, and post-incident reviews.
- Own the ongoing operation of SOC 2 controls, security audit requirements, and technical compliance initiatives.
- Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity.
- Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud-native workloads using modern security best practices.
- Administer and improve identity governance across Microsoft Entra ID, Cisco Duo, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture.
- Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security technologies.
- Own and continually improve KPA's cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes.
- Own email security across Microsoft 365, SendGrid, Amazon SES, SPF, DKIM, DMARC, and phishing protection.
- Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI-assisted development.
- Lead security assessments for new vendors, SaaS platforms, cloud services, and third-party integrations; administer third party vendor management (TPVM) and support ongoing vendor risk management.
- Administer and improve KPA's security awareness program, security policies, standards, and technical procedures.
- Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies.
- Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives.
- Proactively identify security gaps, technical debt, and opportunities to improve KPA's security posture through automation, AI, and modern engineering practices.
Qualifications:
- 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role.
- Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles.
- Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux.
- Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices.
- Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies.
- Experience supporting SOC 2 & NIST CSF or comparable security and compliance frameworks.
- Relevant certifications such as CompTIA Security+, CISSP, CCSP, AWS Certified Security, or equivalent certifications are preferred.
- Excellent communication, documentation, project leadership, and problem-solving skills.
- Bachelor's degree in Computer Science, Information Technology or Cybersecurity or equivalent experience.
Success Criteria:
- Work ethic that aligns with KPA's core values:
- Trust: earning trust through integrity, expertise, and acting in the client's best interest.
- Innovation: continuously seeking out ways to better serve clients.
- Excellence: holding ourselves to high standards in everything we do.
- Results: moving with purpose to deliver meaningful outcomes.
- Owns and continually improves KPA's enterprise security platforms and technical security controls.
- Improves KPA's security posture across endpoints, identity, networking, cloud, and DevOps environments.
- Delivers complex security initiatives with strong planning, communication, documentation, testing, and post-implementation validation.
- Reduces manual security work through automation and modern engineering practices.
- Serves as the senior escalation point for complex security incidents and technical security issues.
- Partners effectively with IT Operations and DevOps to embed security into operational and development workflows.
Physical Requirements:
- Working at a computer typing and view a screen - Constantly
- Stationary sitting or standing - Constantly
- Visual Recognition - Constantly
- Hearing/Listening - Occasionally
- Communicating verbally and/or in writing - Occasionally
- Travel - Seldom
Compensation:
- Annual base salary range between $110-130k commensurate with experience.
- Bonus potential of 10% annually
KPA Westminster, Colorado, USA Office
Our headquarters is located in the CirclePoint Corporate Center in Westminster, right off US 36 between 104th and 112th. Minutes from the Westminster Promenade, a major entertainment and food hub.
Similar Jobs at KPA
What you need to know about the Colorado Tech Scene
Key Facts About Colorado Tech
- Number of Tech Workers: 260,000; 8.5% of overall workforce (2024 CompTIA survey)
- Major Tech Employers: Lockheed Martin, Century Link, Comcast, BAE Systems, Level 3
- Key Industries: Software, artificial intelligence, aerospace, e-commerce, fintech, healthtech
- Funding Landscape: $4.9 billion in VC funding in 2024 (Pitchbook)
- Notable Investors: Access Venture Partners, Ridgeline Ventures, Techstars, Blackhorn Ventures
- Research Centers and Universities: Colorado School of Mines, University of Colorado Boulder, University of Denver, Colorado State University, Mesa Laboratory, Space Science Institute, National Center for Atmospheric Research, National Renewable Energy Laboratory, Gottlieb Institute
