Senior Cybersecurity Engineer
Senior
Application Security
Cloud Platforms
Cyber Security
Cybersecurity Tools
Data Platform
Data Security
Digital Marketing
Endpoint Security
Engineer
Facilities Management
Firewall
Identity and Access Management
Information Security
Information Technology (IT)
InfoSec
Network Security
Product Security
Risk Governance
Risk Management
Security
Security Compliance
Security Engineering
Security Information And Event Management
Security Monitoring
Security Operations
Security Posture Management
Security Standards
Security Testing
Software Security
Splunk Siem
Vulnerability Management
Web Application Firewall
Job Description
The BISO Engineer is an embedded cybersecurity practitioner aligned to an assigned business unit, responsible for translating enterprise security direction into practical controls and programs across enterprise and operational technology environments.
Role Summary
In this position, you act as a bridge between overall enterprise security strategy and operational execution. The work focuses on identifying risk, driving remediation, and converting security requirements into actionable unit-level initiatives. You will coordinate with multiple security platforms and stakeholders to maintain an effective security posture across applications, infrastructure, and OT.
Responsibilities
- Serve as the primary cybersecurity liaison for assigned business unit(s), converting enterprise security policies into unit-specific controls and procedures
- Conduct and support risk assessments, vulnerability management reviews, and security posture evaluations across applications, infrastructure, and OT environments
- Lead or support security initiatives covering WAF/firewall configurations, identity and access management reviews, endpoint protection, and cloud security posture
- Represent the business unit in change management and security governance forums
- Coordinate with enterprise SIEM, network security, and application security platforms to ensure appropriate monitoring and enforcement
- Support M&A integration activities, including network segmentation, firewall onboarding, and security baseline validation
- Develop and maintain security documentation such as policies, runbooks, risk acceptance memos, and remediation plans
- Engage stakeholders across technical and leadership groups, and present risk posture and program status to senior management
Required Qualifications
- 5+ years of experience in cybersecurity engineering, architecture, or risk management
- Hands-on experience with WAF, NGFW, SIEM, or vulnerability management platforms
- Strong understanding of NIST CSF, CMMC, or equivalent frameworks
- Proven ability to manage cross-functional security programs with minimal oversight
Preferred Skills
- Experience in energy, utilities, or OT/ICS environments
- Familiarity with relevant cloud WAF, segmentation, SIEM, or firewall management tools
- CISSP, CISM, or equivalent certification
- Experience supporting M&A cybersecurity integration
Technology and Framework Focus
- WAF, NGFW, SIEM, vulnerability management platforms
- NIST CSF, CMMC
- Security posture evaluations, identity and access management
- Endpoint protection, cloud security posture
- Network segmentation, firewall onboarding
- Enterprise SIEM, network security, application security platforms
Location and Work Setting
United States, onsite. The position requires physical office presence.
Engagement Dates and Compensation
- Start and end date: 05 Oct 2026 – 05 Oct 2027
- Indicative hourly rate: $50 – $55 per hour
- Respond by: 01 Oct 2026
Additional Information
- Languages: English (professional working proficiency)
- Skill areas (intermediate): security engineering, security requirements, security information and event management, vulnerability management, network security, network segmentation, merger and acquisitions, and software security