Cybersecurity Engineer
Job Description
This hybrid role supports and secures global, enterprise-scale directory services. You will engineer and maintain Active Directory and Entra ID capabilities, with a focus on authentication, automation, monitoring, vulnerability investigation, and L3 troubleshooting.
Key Responsibilities
- Architect, implement, and maintain secure directory systems, including on-premises and cloud AD and Entra ID environments.
- Act as a subject matter expert for authentication and directory-facilitated authorization.
- Investigate and remediate security vulnerabilities affecting directory service components.
- Lead and contribute to global initiatives that enable and support directory services.
- Develop and maintain automated solutions for monitoring and managing directory service components at scale.
- Provide L3 support for critical directory service components, including troubleshooting complex authentication and directory issues.
- Collaborate with a globally distributed team with members in different regions.
- Manage and guide permissions, group policies, and access controls for AD and Entra ID.
- Partner with IT and security teams to support compliance requirements and security best practices.
- Document processes, configurations, and incident response activities.
- Demonstrate behaviors aligned with CBRE RISE values.
- Contribute to customer, operational, project, and service objectives across multi-discipline teams.
- Work guided by functional policies that influence procedure and policy design.
- Communicate complex ideas and influence outcomes when coordinating across technical and non-technical stakeholders.
Requirements
- Bachelor’s Degree preferred with 5–8 years of relevant experience, including 3+ years supporting enterprise or government-level directory services (AD and Entra ID/Azure AD).
- In-depth understanding of AD and Entra ID architecture, permissions, and security best practices.
- Expertise with Active Directory, Entra ID, Azure, AWS, GCP, and DNS, including Entra Conditional Access, Entra Connect, and Federation.
- Strong scripting and automation skills using PowerShell, Python, or similar tooling.
- Expertise with authentication protocols including Kerberos, SAML, OAuth, and related technologies.
- Experience with monitoring tools and SIEM platforms.
- Excellent troubleshooting, communication, and documentation skills.
- Relevant certifications are preferred (example: Microsoft Certified, CISSP).
- Innovative approach to developing methods that extend beyond existing solutions.
- Ability to address unique problems using standard and innovative solutions with broad business impact.
- Expert organizational skills with an advanced inquisitive mindset.
Technologies
- Active Directory, Entra ID, Azure AD, Entra Conditional Access, Entra Connect, Federation
- Azure, AWS, GCP, DNS
- PowerShell, Python
- Kerberos, SAML, OAuth
- SIEM
Certifications
- Preferred: Microsoft Certified, CISSP, etc.
Location and Work Model
Richardson, TX (hybrid)