Lead Security Engineer
Listed on 2026-08-13
-
IT/Tech
Cybersecurity, Systems Engineer
- Locations 730 3rd Ave, 11th Floor, New York, NY, 10017, US (Remote)
- Base Range Info Compensation for this role will be based on the background of the individual selected for this position. For more details see the “About Us” section.
- Base Range $111,000 - $180,000
The Lead Security Engineer (Cloud & Enterprise Security Engineering) is a deeply technical, hands‑on engineering role responsible for designing, implementing, hardening, integrating, and continuously improving CBIZ’s enterprise security technologies and controls across cloud, identity, endpoint, network, email, and data protection domains. This position requires strong engineering fundamentals, broad systems knowledge, and the ability to solve complex technical problems across hybrid and multi‑cloud environments.
The ideal candidate is an experienced builder and troubleshooter who can translate security requirements into scalable, reliable, and measurable technical solutions. Success in this role depends on advanced expertise in security architecture, platform engineering, automation, systems integration, detection logic, and control validation. The engineer must be able to work across diverse technologies, analyze intricate dependencies, and develop durable solutions that strengthen security posture, reduce risk, and improve operational resilience.
This is not a passive monitoring or ticket‑routing role. It is a senior technical position focused on engineering secure‑by‑default solutions, improving platform capabilities, automating security functions, and driving long‑term technical maturity across the environment. While incident support and investigation remain part of the role, the primary emphasis is on building, optimizing, and sustaining the security technologies, integrations, and guardrails that prevent, detect, and contain threats at scale.
EssentialFunctions and Primary Duties Cloud & Enterprise Security Engineering
Design, implement, harden, and maintain enterprise security controls and reference architectures across:
Amazon Web Services (AWS)
Microsoft 365 security and compliance platforms
Hybrid identity, endpoint, email, and data protection environments
Engineer secure‑by‑default configurations and technical guardrails that reduce attack surface, improve resilience, and support scalable enterprise operations.
Translate business, compliance, and security requirements into practical engineering designs and sustainable technical solutions.
Evaluate current‑state architectures, identify control gaps, and implement improvements that strengthen security posture while maintaining operational usability.
Partner with infrastructure, cloud, networking, systems, and endpoint teams to embed security into enterprise platforms, workflows, and lifecycle processes.
Identity, Data Protection & Platform SecurityEngineer and operationalize controls for identity protection, phishing defense, DLP, conditional access, privileged access, tenant security baselines, and cloud workload protection.
Secure workloads, identities, and data across hybrid and multi‑cloud environments through design standards, configuration baselines, and measurable technical guardrails.
Support and troubleshoot certificate‑based authentication, encryption, and PKI‑related services, including lifecycle considerations such as issuance, renewal, revocation, and dependency management.
Improve authentication security, access control design, and privileged access protections across enterprise systems and cloud platforms.
Design and validate visibility and monitoring coverage for cloud, identity, endpoint, email, and platform security events to ensure reliable telemetry and actionable data.
Security Platforms, Automation & ToolingBuild, administer, and continuously improve core security platforms and integrations, including:
SIEM and log ingestion pipelines
SOAR and workflow automation platforms
XDR/EDR and endpoint security tooling
Network and zero trust security controls
CASB, DLP, and data security platforms
Identity and access management controls
Email and collaboration security technologies
Develop and maintain automation using Power Shell, Python, Bash, APIs, and workflow tooling to support…
(If this job is in fact in your jurisdiction, then you may be using a Proxy or VPN to access this site, and to progress further, you should change your connectivity to another mobile device or PC).