Remote Senior Cybersecurity Engineer - Build & Own Controls
Columbus, Franklin County, Ohio, 43224, USA
Listed on 2026-09-16
-
IT/Tech
Cybersecurity
100% Remote:
Preferred locations:
Columbus, OH, Cincinnati, OH, Richmond, VA or Dallas, TX.
EST OR CST required.
Think Consulting is a national technology and operations consulting firm partnering with organizations to build the people, process, and technical capability behind their growth. We've been engaged by Our Client - a fast-scaling, multi-operating-company enterprise - to identify a Senior Cyber Security Engineer who can build a real engineering bench around a maturing security program.
Why This Role Exists
Our Client is scaling its technology estate faster than its security controls were originally built to carry - ERP consolidation in flight, a new enterprise data platform, AI assistants rolling out, and a growing footprint of field-service and operational technology (OT) systems across multiple business units. Security today is delivered through a mix of cloud-native tooling, a managed detection provider, and fractional/vCISO oversight.
What's missing is a deep, hands-on engineering bench that owns the controls end to end.
The Senior Cyber Security Engineer is the senior technical practitioner in that function - the person who designs, builds, and operates Our Client's preventive and detective controls across identity, endpoint, email, cloud, network, and data protection; hardens new environments as the business stands them up; leads incident response on the technical side; and turns audit and insurance requirements into implemented configuration rather than documented intent.
This is a builder's role in a high-velocity environment. New business units and acquisitions arrive with their own tenants, tooling, and gaps. Success here is measured in controls that are deployed, monitored, and evidenced - not in policy binders or dashboards nobody acts on.
What You'll Own
Security Architecture & Engineering
- Design and implement technical security architecture across identity, endpoint, email, network, cloud, and data - translating strategy into deployed, tested configuration.
- Serve as security engineering's design authority on major programs: ERP consolidation, enterprise data platform buildout, AI assistant deployment, CRM selection, and integration platform work.
- Build and maintain hardening standards and secure baselines for Windows, Linux, mobile, and cloud workloads - enforced through configuration management, not manual review.
- Define the secure-by-default reference patterns other IT teams build against: network segmentation, secrets management, logging, and third-party connectivity.
- Lead security engineering for acquisition integrations: assess the acquired estate, prioritize remediation, and bring new tenants and endpoints onto company standards.
- Own the technical relationship with the managed detection and response (MDR) provider - tuning detections, closing coverage gaps, validating alert quality, and holding the provider to response SLAs.
- Engineer detection content and log pipelines across a modern SIEM/XDR stack, including data source onboarding, analytics rules, and automated response playbooks.
- Act as technical incident commander during security incidents: containment, forensics, eradication, recovery, and post-incident review with tracked corrective actions.
- Run purple-team and tabletop exercises against realistic scenarios - ransomware, business email compromise, vendor compromise, OT disruption - and convert findings into engineering work.
- Own and continuously improve incident response runbooks, escalation paths, and evidence-handling procedures.
- Engineer and operate the identity security stack - conditional access, MFA and phishing-resistant authentication, privileged identity management, and joiner-mover-leaver lifecycle automation.
- Drive least-privilege across cloud and on-prem: privileged access workstations, just-in-time elevation, service account governance, and periodic access recertification.
- Secure machine and workload identity for integrations, APIs, and automation, including secrets management and credential rotation.
- Partner with application teams so role design in ERP, CRM, and field-service platforms is enforceable and segregation-of-duties conflicts are caught before go-live.
- Own the vulnerability management program end to end - discovery, prioritization by exploitability and business exposure, remediation tracking, and SLA reporting.
- Run internal and third-party penetration testing and red-team engagements, driving findings to…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).