Cybersecurity Sr Engineer
Job Description
CBRE is seeking a Cybersecurity Sr Engineer to help reduce enterprise cyber security risk by embedding security processes, tools, and people into the business culture. In this role, you will support and maintain secure solutions for GenAI and LLM-based systems, and help shape AI security governance, threat modeling, incident response, and reporting across the organization.
Key Responsibilities
- Support and maintain secure solutions for GenAI, LLMs, agents, and MLOps platforms.
- Develop and implement guardrails, access controls, and prompt protection.
- Lead AI-focused threat modeling and help reduce model and system attack surface.
- Align security controls with NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, and MITRE ATLAS.
- Collaborate with red teams and support adversarial testing.
- Guide incident response playbooks for AI security events.
- Integrate with secrets managers and cloud-native security platforms.
- Deploy security tooling and observability to monitor AI behavior.
- Mentor teams and serve as an SME for AI risks and controls.
- Contribute to policy and governance for responsible AI use.
- Develop reporting that demonstrates operational excellence and product performance metrics.
- Participate in an on-call rotation to help ensure uptime and functionality of critical internal customer services.
- Maintain well-founded opinions and be prepared to challenge approaches that do not pass the “smell test.”
- Mentor and coach team members to build competencies, modeling behaviors consistent with company values.
- Perform other duties as assigned.
Required Education and Experience
- Bachelor’s degree (BA/BS) in a related field of work.
- Minimum of 3 years related work experience, or an equivalent combination of education and experience (equivalent work experience equals 2 years of related experience for every 1 year of higher level education).
Requirements
- Advanced experience administering security-based tools related to CSPM/CNAPP, CIEM, and Vulnerability Scanners (OSA, SAST, DAST).
- Intermediate experience solutioning with cloud provider services such as OpenSearch, Azure OpenAI, and AWS Bedrock.
- Intermediate experience solutioning and working with one or more other cloud providers besides AWS, such as GCP, Alibaba, or Azure.
- Intermediate experience writing and running Terraform.
- Intermediate Linux systems administrator experience or equivalent skills.
- Intermediate experience or equivalent skills with DevOps or CI/CD pipelines (e.g., GitHub Actions, GitLab, Jenkins).
- Intermediate experience automating multiple systems using functional and object-oriented programming languages.
- Intermediate experience with RDBMS and Vector storage solutions.
- Intermediate understanding of source control management using Git and GitHub.
- Advanced experience onboarding and integrating to third-party PaaS & SaaS.
- Experience with the Microsoft ecosystem, including directory services such as AD and LDAP.
- Understanding and experience with backend software application development, including API development and integrating with third-party sources.
- Understanding of system integration design patterns at scale, with experience in microservice design or development.
- Strong written and verbal communication skills, including the ability to explain complex cybersecurity concepts across technical and business stakeholders and to document standards and author technical reports.
- Strong analytical and decision-making skills for solving complex cybersecurity problems, including risk-based reasoning and delivering strategies that improve enterprise security posture and operational resilience.
Technologies
- GenAI, LLMs, agents, MLOps, guardrails, prompt protection
- NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS
- CSPM/CNAPP, CIEM, OSA, SAST, DAST
- OpenSearch, Azure OpenAI, AWS Bedrock, GCP, Alibaba, Azure
- Terraform, Linux, DevOps, CI/CD pipelines, GitHub Actions, GitLab, Jenkins
- Functional and object-oriented programming languages, RDBMS, Vector storage solutions
- Git, GitHub, PaaS, SaaS
- Microsoft ecosystem, AD, LDAP
- API development, microservice design
Applicant AI Use Disclosure: CBRE does not use artificial intelligence (AI) tools to make hiring decisions, and requests that candidates disclose any use of AI in the application and interview process.
Authorization to Work: Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
Candidate Accommodations: CBRE provides reasonable accommodations in job application procedures for individuals with disabilities. To request assistance, email [email protected] or call +1 866 225 3099 (U.S.) and +1 866 388 4346 (Canada).
Location: Richardson, TX (onsite)