Cyber Security Engineer
Listed on 2025-12-27
-
IT/Tech
Cybersecurity, Systems Engineer, Network Security
ABOUT THE JOB
The ACLU seeks applicants for the full-time position of Cybersecurity Engineer in the Information Security Department of the ACLU’s National office in New York, NY
. This is a hybrid role that has in-office requirements of two (2) days per week or eight (8) days per month.
Director of Security Architecture & Engineering, this hands‑on technical role is responsible for securing the ACLU’s infrastructure, endpoints, and cloud services by reducing vulnerability risk, improving control enforcement, and operationalizing core data protection strategies.
This role is ideal for a security engineer who thrives at the intersection of infrastructure, identity, and data — someone ready to roll up their sleeves to turn policy into technical enforcement. The engineer will drive progress across cloud posture, endpoint compliance, DLP, and insider risk detection, ensuring controls are not just defined but deployed, measurable, and resilient in production environments.
This position is part of a collective bargaining unit. It is represented by ACLU Staff United (ASU).
WHAT YOU'LL DOReporting to the Director of Security Architecture & Engineering
, the Cybersecurity Engineer will be accountable for executing core infrastructure and endpoint security priorities across cloud, network, and device environments.
- Implement and manage cloud security posture tooling and alerts, ensuring visibility into configuration drift, overexposure, and high‑risk services.
- Lead the vulnerability management lifecycle — including scanning, prioritization, stakeholder coordination, remediation tracking, and reporting.
- Deploy and enforce secure configuration baselines across managed devices (Windows, macOS, mobile), including disk encryption, patch compliance, and privileged access.
- Identify exposed services and reduce attack surface across infrastructure and endpoint environments using automation and policy‑based enforcement.
- Develop and maintain secure configuration management practices across IAM, network segmentation, endpoint posture, and SaaS platforms.
- Engineer and support enterprise Data Loss Prevention (DLP) tooling, including policy definition, control enforcement, and incident response workflows across email, endpoint, and cloud.
- Implement and tune insider threat detection signals using endpoint telemetry, behavior analytics, and identity context, in coordination with Security Operations.
- Serve as a technical escalation point for endpoint, cloud, and identity security issues impacting control integrity or coverage.
- Be committed to advancing the mission of the ACLU
- Center and embed the principles of equity, inclusion and belonging in their work by demonstrating commitment to diversity with an approach that respects and values multiple perspectives
- Be committed to work collaboratively and respectfully toward resolving obstacles and conflicts
- Demonstrated experience in security engineering, cloud/infrastructure security, or endpoint protection.
- Strong working knowledge of DLP, data classification, and endpoint telemetry tooling (e.g., Microsoft Purview, Intune, Defender for Endpoint, Jamf, etc.).
- Hands‑on experience with vulnerability management platforms and remediation coordination.
- Experience designing and deploying secure configurations across Windows, macOS, and mobile environments.
- Familiarity with insider risk detection tooling or behavioral analytics platforms is a strong plus.
- Proficiency with scripting or infrastructure‑as‑code (e.g., Power Shell, Python, Terraform).
- Excellent communication and cross‑functional collaboration skills, particularly across IT, Legal, and Privacy stakeholders.
- Commitment to securing digital systems in a mission‑driven and rights‑centered environment.
The ACLU is committed to equity, transparency, and clarity in pay. Consistent with our compensation philosophy, there is a set salary for each role based on geographic work location. The annual salary for this position is $137,206 (Level‑F), reflecting the salary of a position based in New York, NY. Salaries are subject to a regional pay adjustment if authorization is granted to work…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).