Cybersecurity Engineer
Ai Security
Cloud Identity Security
Cloud Platforms
Cloud Security
Cloud Security Architecture
Cybersecurity Tools
Data Loss Prevention
Data Security
Engineer
Iam Governance
Identity and Access Management
Information Security
InfoSec
Microsoft Azure Security
Privileged Access Management
Risk Governance
Security
Security Engineering
Job Description
Kimley-Horn is seeking a Cybersecurity Engineer to join its Information Security team and strengthen the security of the firm’s cloud environments, identities, data, and AI technologies. This onsite role in Warrenville, IL focuses on cloud security and the security controls that support IAM, PAM, DLP, and AI governance. You will work across technical and business stakeholders to identify risks, design controls, and improve the organization’s overall security posture.
Role Focus
- Secure cloud infrastructure by analyzing architectures to clarify risks, concerns, and decision outcomes
- Drive Identity and Access Management initiatives across authentication, authorization, privileged access management, conditional access, and identity governance
- Develop and maintain Data Loss Prevention controls to protect sensitive data across cloud services, endpoints, collaboration platforms, and AI-enabled applications
- Design, implement, and manage Privileged Access Management solutions, including privileged account lifecycle management, just-in-time access, credential protection, session monitoring, and privileged access governance
- Establish security policies and governance for AI and agentic AI technologies, including authentication, authorization, monitoring, and lifecycle management
Responsibilities
- Track cloud application vulnerabilities using security tools and coordinate with development teams to develop remediation plans
- Perform threat modeling, security assessments, and architecture reviews for cloud services, AI applications, and new technology deployments
- Partner with IT, infrastructure, and application teams to integrate security controls into cloud platforms, identity services, and AI-powered business solutions
- Participate in tabletop exercises and simulations to validate and improve incident response plans
- Support compliance, audit, and risk management by documenting security controls, procedures, and technical standards
Required Qualifications
- Bachelor’s degree in Cybersecurity, Information Technology, Computer Science, Information Systems, or a related field
- 5+ years of experience with Cloud Security, Identity and Access Management, Information Security, or a similar enterprise role
- Professional certifications such as Security+, Cloud+, AZ-300, AZ-500, CCSP, CISSP, or other relevant security certifications
- Experience designing, implementing, and supporting security controls in Microsoft Azure, AWS, or other enterprise cloud environments
- Hands-on experience with IAM technologies, including authentication, authorization, single sign-on (SSO), federation, identity governance, and conditional access
- Experience administering or supporting PAM solutions, including privileged account governance, just-in-time access, credential vaulting, and privileged session management
- Experience implementing and managing Data Loss Prevention and data governance controls across cloud services, endpoints, and collaboration platforms
- Knowledge of AI and agentic AI security concepts, including governance, identity lifecycle management, authorization models, and monitoring of AI agents
- Knowledge of security frameworks and standards such as NIST CSF, CIS Controls, ISO 27001, and Zero Trust Architecture
- Strong analytical, troubleshooting, and problem-solving skills
- Experience with change-management policies and procedures
- Strong written and verbal communication skills, including translating complex technical concepts to non-technical stakeholders
Technologies
- Microsoft Azure, AWS
- Microsoft Entra ID
- PIM, Identity Governance, Conditional Access
- Microsoft Purview DLP and Information Protection
- CyberArk, OneIdentity, Delinea
- Security+, Cloud+, AZ-300, AZ-500, CCSP, CISSP
- NIST CSF, CIS Controls, ISO 27001, Zero Trust Architecture
Benefits
- Exceptional Retirement Plan: 2-to1 company match on up to 4% of eligible compensation (salary + bonus) plus additional profit-sharing contribution
- Comprehensive Health Coverage: low-cost medical, dental, and vision insurance options
- Time Off: personal leave, flexible scheduling, floating holidays, and half-day Fridays
- Financial Wellness: student loan matching in our 401(k) and performance-based bonuses
- Professional Development: tuition reimbursement and extensive internal training programs
- Family-Friendly Benefits: new parent leave, family building benefits, and childcare resources
Preferred Skills
- Microsoft Entra ID, PIM, Identity Governance, and Conditional Access
- Microsoft Purview DLP and Information Protection
- CyberArk, OneIdentity, Delinea, or similar PAM platforms
- Security automation and orchestration experience
- AI and agentic AI security governance
- Experience managing machine identities, service accounts, and workload identities
- Threat modeling and cloud security architecture review experience
Location: Warrenville, IL (onsite)