M&A Security Engineer
Job Description
Hybrid (San Jose, CA) role where you’ll help integrate security into newly acquired organizations. You’ll lead information security initiatives through the M&A Security Insertion and Integration Team, strengthening endpoint and identity protections while supporting incident and vulnerability response using Microsoft security tooling.
What you’ll do
As part of the M&A Security Insertion and Integration Team, you’ll support security insertion and integration activities to strengthen the security posture of acquired entities. Your work focuses on practical security operations across endpoint and identity controls, along with continuous monitoring and remediation.
- Manage endpoint and identity security, including access reviews, authentication support, multifactor authentication enrollment, workstation compliance, security updates, and vulnerability remediation
- Monitor and remediate security incidents and workstation vulnerabilities using Microsoft 365 Defender, Microsoft Defender for Endpoint, and Microsoft Sentinel
- Administer endpoint security and management technologies, including Microsoft Intune, Mosyle, JAMF, and related tools
- Review user and administrative access periodically and remove permissions that are no longer necessary
- Examine simulated and realistic phishing emails and implement protections against malicious domains
- Assist with the implementation of system security configurations
- Monitor software currency across operating systems, browsers, and other workstation applications
- Assess security controls and configurations, recommend infrastructure improvements, develop progress reports, and communicate security concerns and events to the M&A Security Insertion and Integration Team lead and acquired entity security leadership
What you bring
- 3 to 5 years of progressive information security experience across areas such as application security, infrastructure security, identity and access management, vulnerability management, cyber threat management, security architecture, or information technology risk management
- A bachelor’s degree in Computer Science, Engineering, or a related field, or equivalent professional experience
- Experience implementing and maintaining information technology and security controls across complex networks, systems, applications, and infrastructure
- Proficiency in endpoint security and management, identity management, multifactor authentication, and security information and event management technologies
- Experience monitoring, managing, and tuning core security controls
- Knowledge of information risk management frameworks, regulations, data-protection guidelines, security standards, and industry best practices
- Ability to understand, build, and document complex information security designs and apply confidentiality, integrity, and availability principles
- Ability to incorporate security designs and technologies into new and legacy environments, including environments undergoing technology transitions or upgrades
- Broad knowledge of IT systems, networking and security components, applications, operating systems, and risk-mitigation controls
- Technical aptitude and critical-thinking skills to identify security risks, resolve complex problems, and recommend appropriate controls
- Ability to communicate technical risks clearly to IT business leaders and senior management
- Strong written and verbal communication, organization, time-management, and multitasking skills
- Experience working with global teams across time zones, cultures, and languages
- Proficiency with word-processing, spreadsheet, and presentation software
- A strong sense of ownership aligned with Cognizant values: Work as One, Dare to Innovate, Raise the Bar, Do the Right Thing, Own It
- Preferred/Required credentials: CISSP, CISM, or another relevant industry-recognized information security certification
- Graduate degree in Computer Science, Engineering, information security, or a related field
- Experience with Microsoft Intune, Mosyle, JAMF, Microsoft Defender for Endpoint, Microsoft 365 Defender, or Microsoft Sentinel
- Knowledge of controls such as web application firewalls, intrusion detection and prevention systems, and application allowlisting
- Work model: East Coast preferred
Tools and technologies
- Microsoft 365 Defender
- Microsoft Defender for Endpoint
- Microsoft Sentinel
- Microsoft Intune
- Mosyle
- JAMF
Compensation and schedule
- Salary: USD 105,000 to 115,000 per year (depending on experience and qualifications)
- Incentive: eligible for Cognizant’s discretionary annual incentive program, based on performance and subject to plan terms
- Application deadline: Applications accepted until October 21, 2026
- Hybrid requirement: 3 days per week in the Cognizant office
Benefits
- Medical/Dental/Vision/Life Insurance
- Paid holidays plus Paid Time Off
- 401(k) plan and contributions
- Long-term/Short-term Disability
- Paid Parental Leave
- Employee Stock Purchase Plan