Security Engineer
Job Description
Design, implement, and operate security controls across hybrid infrastructure and AI-enabled systems while partnering with infrastructure and business teams to reduce cyber risk.
Responsibilities
- Design and improve preventive, detective, and recovery controls across hybrid infrastructure, SaaS, cloud platforms, endpoints, networks, and business applications.
- Implement MFA, Conditional Access, least privilege, privileged-access management, lifecycle governance, service-identity controls, and periodic access reviews.
- Assess cloud configurations, APIs, containers, serverless services, infrastructure as code, CI/CD pipelines, secrets, and software supply-chain dependencies.
- Identify and prioritize vulnerabilities, attack paths, misconfigurations, unsupported assets, and internet-facing risk, coordinating with owners through verified remediation.
- Lead architecture reviews and threat modeling for new systems, integrations, vendors, and major changes; define proportionate control requirements before production.
- Maintain visibility into approved and unapproved AI services, models, agents, copilots, plugins, data connections, and business use cases; guide teams toward secure, sanctioned paths.
- Review data flows across the AI lifecycle, including model and API access, retrieval pipelines, vector stores, prompts, tools, memory, outputs, and human-approval points.
- Evaluate prompt injection, sensitive-data disclosure, insecure output handling, model or data poisoning, excessive agency, identity abuse, supply-chain compromise, denial of service, and unsafe tool execution.
- Apply authentication and authorization safeguards, data classification and DLP, secrets management, content filtering, tool isolation, rate limits, audit logging, monitoring, and human-in-the-loop controls.
- Coordinate security testing for AI applications, including adversarial evaluation, red teaming, misuse-case testing, and ongoing monitoring for material changes to model, prompt, tool, or data.
- Translate AI policy into usable engineering standards and employee guidance; investigate shadow-AI and risky data-handling patterns without defaulting to indiscriminate blocking.
- Use automation and AI-assisted analysis to accelerate triage, investigation, detection development, and reporting while preserving evidence, access controls, validation, and accountable human decisions.
- Engineer telemetry and detections across identity, endpoint, network, cloud, email, applications, data, and AI services; tune alerting to improve signal quality.
- Support triage, containment, eradication, recovery, evidence preservation, communications, and post-incident improvements, including identity and token compromise.
- Build scripts, queries, playbooks, and integrations to improve investigation speed, control consistency, and operational visibility.
- Validate hardening, patching, backup security, recovery procedures, and disaster-recovery assumptions through exercises and technical testing.
- Produce decision-ready metrics and concise reporting on exposure, incidents, control health, AI risk, remediation performance, and residual risk.
- Maintain security standards, diagrams, procedures, playbooks, risk decisions, and operational records that are usable by other engineers.
- Support audits and controls related to Japanese Sarbanes-Oxley (J-SOX), change management, privacy, third-party risk, and applicable company requirements.
- Evaluate security and AI vendors, permission requests, data usage, architectural fit, contractual security commitments, and operational ownership.
- Communicate risk in business terms, collaborate across technical and nontechnical teams, and provide targeted security guidance and awareness.
- Participate in security projects, an on-call rotation, and related responsibilities as business and threat conditions evolve.
Requirements
- Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
- Five or more years of progressive IT or cybersecurity experience with substantial hands-on responsibility for security engineering, architecture, operations, or incident response.
- Demonstrated experience securing at least three domains: cloud platforms, enterprise identity, endpoints, networks, applications/APIs, SaaS, data platforms, or AI-enabled systems.
- Strong knowledge of identity and access management, modern authentication, network and web protocols, operating-system security, logging, vulnerability management, and secure configuration practices.
- Experience with SIEM, endpoint detection and response, cloud-security or posture-management tooling, and investigation using structured queries and multiple telemetry sources.
- Ability to automate tasks and analyze data using PowerShell, Python, APIs, infrastructure as code, or comparable tools.
- Working knowledge of AI and generative-AI architecture, including model APIs, retrieval-augmented generation, agents and tool use, enterprise copilots, and common AI security failure modes.
- Experience applying threat modeling, security testing, risk assessment, and secure-development practices to new technology or business applications.
- Clear written and verbal communication, sound judgment, and ability to coordinate effectively during ambiguous or high-pressure events.
Technologies
- MFA, Conditional Access, privileged-access management, service-identity controls
- CI/CD pipelines, infrastructure as code
- PowerShell, Python, APIs
- SIEM, endpoint detection and response
- retrieval-augmented generation, vector stores
- DLP, audit logging
- Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint, Azure
- AWS
- NIST Cybersecurity Framework, NIST AI Risk Management Framework
- CIS Controls, ISO 27001
- CISSP, CCSP, GIAC, Security+
Benefits
- Full benefits package (Medical, Dental, Vision, Flexible Spending Accounts and Life Insurance)
- 401(k) with company match
- Annual Incentive
- Paid Time Off
- Tuition Reimbursement
- Professional Certification Reimbursement Program
- Community Service Day
Preferred Qualifications
- Experience with Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint, Azure, AWS, or comparable enterprise platforms.
- Hands-on experience assessing or operating generative-AI applications, enterprise copilots, AI agents, model gateways, or AI security-posture and monitoring capabilities.
- Experience in a manufacturing, industrial, distributed-site, OT/IoT, or regulated environment.
- Familiarity with NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, ISO 27001, secure software-development practices, and recognized AI/LLM security guidance.
- Relevant certification such as CISSP, CCSP, GIAC, Security+, a cloud-security certification, or equivalent demonstrated capability.
What Success Looks Like
- Critical identity, cloud, endpoint, network, application, data, and AI risks have clear owners, realistic priorities, and verified remediation.
- New AI use cases reach production through a repeatable security-review process with documented data boundaries, permissions, abuse cases, guardrails, logging, and accountable approval.
- Detection and incident-response workflows produce faster, more reliable decisions with less avoidable alert noise and stronger evidence preservation.
- Security controls are measurable, documented, supportable, and resilient to personnel, platform, and threat changes.
- Leaders receive concise reporting connecting engineering activity to business resilience, compliance, responsible AI adoption, and residual risk.
Work Environment
- Regular work in an office environment; hybrid schedule available upon approval.
- May join an on-call rotation and require occasional travel or work in data-center, manufacturing, or network environments.
- Reasonable accommodation may be provided to enable qualified individuals to perform essential functions.
Location: West Chester, OH (onsite)
Compensation: USD 94,100 - 168,200 per yearly
Minimum experience: 5 years
Education: Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field (or equivalent relevant experience)