CybersecurityJobs.io
← Back to all jobs

Job Description

This role focuses on designing secure architectures and developing security approaches to protect ICW Group’s cloud, data, and AI-driven environments. You will partner with engineering teams to embed security from design through production while supporting vulnerability management, threat detection, and incident response.

Role Overview

As a senior technical contributor in information security engineering, you will monitor environments for threats, investigate incidents, produce risk-focused findings, and guide security design reviews for systems involving data, analytics, and AI. The position is based in San Diego, CA and is onsite.

Responsibilities

  • Monitor cloud, on-prem, and SaaS environments for security threats using SIEM, EDR, cloud-native logging, and network telemetry.
  • Support security incident response activities, including investigation, containment, remediation, and post-incident analysis.
  • Research and implement methods to remediate network and application security vulnerabilities.
  • Lead and participate in security architecture controls reporting, compliance audits, and risk-focused reporting, including internal and third-party risk assessments.
  • Produce risk-focused security findings and communicate them clearly to technical and non-technical stakeholders.
  • Conduct threat hunting and root-cause analysis to identify anomalous behavior, exploitation attempts, and indicators of compromise.
  • Investigate potential data misuse, data exfiltration, and anomalous access patterns using logs, DLP, and monitoring tools.
  • Prepare and analyze system security reports by collecting, analyzing, and summarizing data and trends, and provide recommendations to improve security.
  • Serve as a senior technical contributor across cloud security, including IAM, logging, monitoring, detection, and secure deployment patterns.
  • Lead or contribute to vulnerability management across cloud infrastructure, applications, containers, and data platforms.
  • Participate in offensive and defensive security activities, including threat modeling, red team exercises, blue team detection improvements, and threat hunting.
  • Support incident response investigations involving cloud misconfigurations, data exposure, and/or AI-related security events.
  • Perform security architecture reviews and provide guidance to engineering teams to reduce risk while enabling business objectives.
  • Implement and improve security controls that strengthen ICW’s overall security posture while supporting modern cloud and data initiatives.
  • Partner with Engineering, Infrastructure, Cloud, Data, and Operations teams to embed security into system design and delivery.
  • Lead security reviews for new data, analytics, and/or AI initiatives, including architecture reviews and risk assessments prior to production deployment.
  • Create and maintain technical security standards and guardrails for data protection, cloud usage, and/or AI security.
  • Partner with internal teams to remediate security findings and track remediation through closure.
  • Provide security guidance that balances risk reduction with delivery speed and business priorities.
  • Execute technical and process changes required to adopt, maintain, and adjust InfoSec controls aligned with industry best practices.
  • Act as a trusted security advisor to project teams regarding risk, controls, and secure design patterns.
  • Coach and mentor engineers on secure development, data handling, and cloud security best practices.
  • Work with project management and internal stakeholders to define and implement secure, scalable solutions.
  • Design and implement security controls to protect sensitive insurance data across AWS data platforms, analytics pipelines, and AI/ML workloads.
  • Provide security oversight for AI and LLM use cases, including model access controls, training data protection, inference security, data leakage prevention, and misuse/abuse risk.
  • Assess and mitigate risks related to AI systems, LLM usage, prompt injection, data poisoning, third-party data sources, and emerging AI threats.
  • Partner with Compliance and Governance teams to ensure data and AI controls align with NIST, NYDFS, PCI DSS, and California privacy regulations (CPRA/CCPA).
  • Contribute to the development of ICW’s AI security standards, guardrails, and internal guidance as AI adoption expands.
  • Support Third-Party Risk (TPR) evaluations for AI vendors, SaaS platforms, data providers, and analytics tools that process or access ICW data.
  • Evaluate and onboard security tools and vendors related to data protection, cloud security posture, AI governance, and detection.
  • Assist with strategic initiatives to identify and reduce attack surface across applications and systems.
  • Ensure security is embedded into systems from design through production.

Requirements

  • Bachelor’s Degree required in Engineering, Cybersecurity, Networking, or Computer Science (or related discipline).
  • Minimum 8 years of experience in a security engineering role designing secure networks, systems, and application architectures, or an equivalent combination of education and experience.
  • Minimum 3-5 years of experience in AWS Cloud Security services preferred.
  • Direct experience using advanced technologies including IDS/IPS, firewalls, SIEM, antivirus software, network packet analyzers, content filtering, and malware analysis and forensics tools to detect intrusions.
  • Experience in a cybersecurity role requiring knowledge of data analysis, risk assessment, risk mitigation, investigation methods, incident management concepts and practices, and policy and procedure development.
  • Experience with AWS services including AWS Identity & Access Management, AWS Organizations, AWS Security Hub, Guard Duty, CloudTrail, and AWS CloudTrail.

Technologies

  • SIEM, EDR, cloud-native logging, network telemetry
  • DLP
  • IAM
  • Intrusion detection & prevention systems (IDS/IPS), firewalls
  • Antivirus software, network packet analyzers, content filtering, malware analysis, forensics tools
  • AWS Identity & Access Management, AWS Organizations, AWS Security Hub, Guard Duty, CloudTrail
  • NIST, NYDFS, PCI DSS, CPRA, CCPA

Compensation and Job Details

Salary range: USD 121,624 - 217,710 per year (current range: $121,624.81 - $217,710.99). This range is exclusive of fringe benefits and potential bonuses.

Final base salary will be determined based on factors including experience, education, and location of the role, considering employees performing substantially similar work.

Job category: IT
Job type: Full time
REQ ID: JR101654

Education requirement: Bachelor’s Degree in a related discipline

Work arrangement: Onsite (San Diego, CA)

Benefits

  • Competitive benefits package, including medical, dental, and vision plans
  • 401K retirement plans and company match
  • Bonus potential for all positions
  • Paid Time Off
  • Paid holidays throughout the calendar year
  • Support for continued learning (100% support)

Knowledge and Skills

  • Knowledge of risk assessment tools, technologies, and methodologies
  • Knowledge of disaster recovery and computer forensic tools, technologies, and methods
  • Knowledge of enterprise security platforms
  • Ability to communicate network security issues to peers and management
  • Ability to read and use results from mobile code, malicious code, and anti-virus software
  • Strong understanding of endpoint security solutions, including File Integrity Monitoring and Data Loss Prevention
  • Demonstrated experience as a lead engineer in the design, implementation, and support in an enterprise IT environment
  • Ability to combine skills to craft solutions and solve complex operational problems, including hypothesize on root cause of inefficiencies and test solutions
  • Must be able to read, write, and speak English effectively
  • Ability to present technical information to a non-technical audience
  • Ability to cross train and share information with team members

Work Environment

This position operates in an office environment and requires frequent use of a computer, telephone, copier, and other standard office equipment.

Physical Requirements

  • Office environment: no specific or unusual physical or environmental demands; employees regularly sit, walk, stand, talk, and hear
  • Ability to reach with hands and arms; stoop, kneel, crouch, or crawl
  • Occasionally lift and/or move up to 30 pounds
  • Visual acuity required; able to operate and view computers and other electronic devices for extended periods of time

Similar Jobs