×
Register Here to Apply for Jobs or Post Jobs. X
More jobs:

Lead Cybersecurity Engineer

Job in Cincinnati, Hamilton County, Ohio, 45208, USA
Listing for: First Student
Full Time position
Listed on 2026-09-04
Job specializations:
  • IT/Tech
    Cybersecurity
  • Engineering
    Cybersecurity
Salary/Wage Range or Industry Benchmark: 130000 - 155000 USD Yearly USD 130000.00 155000.00 YEAR
Job Description & How to Apply Below

The Lead Cybersecurity Engineer is a senior individual contributor on First Student's Cybersecurity team, responsible for the day-to-day design, engineering, oversight, and operation of the controls that protect First Student's cloud, endpoint, application, and identity environments. The role leads cybersecurity engineering projects, drives detection and response engineering, and serves as a senior technical resource for cybersecurity investigations and cross-functional partnership with I&O, Data, and Application teams.

This is a hands-on practitioner role. The individual is expected to lead engineering execution, mentor junior team members, and provide technical oversight and peer review of the team's work product within cybersecurity.

Responsibilities

Identify and assess

  • Perform cybersecurity assessments and technical reviews for new platforms, cloud services, identity/authN/authZ changes, and externally-facing systems.
  • Lead offensive-informed technical assessments and translate findings into remediation plans.
  • Perform threat modeling for cloud and SDLC initiatives.

Securely build and protect

  • Engineer and lead operations of cybersecurity controls and cloud security posture management.
  • Author and code-review IaC for cloud governance components, including cloud policy management.
  • Provide SDLC cybersecurity engineering, including SAST and DAST program operation and secure code guidance for custom applications.
  • Provide oversight for identity and endpoint tooling and support enterprise secrets management.

Monitor, hunt, and detect

  • Own the technical integration of First Student systems and log sources into the managed MDR platform, and coordinate with the MDR provider on detection use cases, scenario-based workshops, and joint investigations.
  • Tune telemetry and sensor platforms to reduce false positives and improve detection fidelity.
  • Maintain existing and build new cybersecurity dashboards and telemetry that feed operational and leadership-facing reporting.

Respond, recover, and sustain

  • Serve as a senior technical lead for cybersecurity incidents, directing investigation, evidence collection, and containment across identity, endpoint, cloud, and email in coordination with I&O and MDR partners.
  • Maintain incident investigation templates, IR runbooks, and technical playbooks; drive lessons-learned and control improvements post-incident.
  • Support the incident management technical workflow and tabletop exercise execution.

Govern and manage risk

  • Contribute technical content to policies and standards (e.g., Vulnerability Management, cloud security, SDLC).
  • Interpret control requirements and translate them into enforceable technical controls.
  • Support leadership-facing reporting with technical evidence and narrative for internal reviews and external assessment cycles.
  • Contribute technical evidence to cyber risk acceptance packages.

Lead and coordinate

  • Provide technical oversight and peer review of the cybersecurity team's work product.
  • Mentor cybersecurity analysts and junior engineers on cloud cybersecurity, investigations, and secure design; support individual growth plans in coordination with the Senior Director.
  • Lead cybersecurity engineering projects end to end, including planning, effort estimation, resource coordination, and delivery.
  • Liaise with cybersecurity vendors and managed service providers for issue resolution and operational escalation.
Desired qualifications

Education and certifications
  • BS/BA in IT, Computer Science, Engineering, or related field, or equivalent experience.
  • Industry certifications preferred: one or more of AWS Certified Security
    - Specialty, AWS Certified Solutions Architect
    - Associate/Professional, SANS/GIAC (GSEC, GCIH, GCSA, GCPN, GCIA), CISSP, CCSP, CRISC.
Knowledge and experience
  • 10+ years total experience in IT, with 5+ years of hands‑on, demonstrated experience in one or more of cybersecurity engineering, cloud engineering, or Dev Ops.
  • Deep, hands‑on AWS cybersecurity engineering:
    Organizations/Control Tower, SCPs and tag policies, IAM Identity Center, KMS key policy design, S3 hardening, Lambda runtime lifecycle, VPC segmentation and flow logging, Cloud Trail/Guard Duty/Security Hub, Systems…
To View & Apply for jobs on this site that accept applications from your location or country, tap the button below to make a Search.
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).
 
 
 
Search for further Jobs Here:
(Try combinations for better Results! Or enter less keywords for broader Results)
Location
Increase/decrease your Search Radius (miles)
0
200
Filters
Education Level
Experience Level (years)
Posted in last:
Salary