Confidential Jobs · 3 weeks ago
Senior Cybersecurity Engineer
Confidential Jobs is seeking a Senior Cybersecurity Engineer to act as the primary architect of the organization’s digital defense. This role is responsible for operationalizing the security strategy, advising on the software development pipeline, and ensuring resilience against modern threats.
Computer Software
Responsibilities
Secure Microsoft Azure environments by managing Entra ID (Identity), Defender for Cloud, and Sentinel. Configure and audit conditional access policies and resource grouping
Own the roadmap to CMMC Level 2 assessment readiness. Manage the System Security Plan (SSP) and Plan of Action and Milestones (POAMs) specifically for Defense Industrial Base (DIB) requirements
Conduct continuous security risk assessments, bridging the gap between technical vulnerabilities (CVSS scores) and business impact
Oversee the lifecycle of vulnerability management, from scanning to patch verification, working closely with infrastructure teams to minimize downtime
Develop and enforce policies regarding the use of Generative AI tools (LLMs) within the enterprise to prevent data leakage and IP loss
Collaborate with development teams to integrate security scanners (SAST/DAST) into the CI/CD pipeline, ensuring Security by Design
Translate complex cyber metrics into a "Risk Scorecard" for leadership, highlighting ROI on security investments and current threat levels
Champion security awareness training, running phishing simulations and tabletop exercises to build organizational resilience
Engage with key stakeholders in the development of contingency plans, business continuity strategies, and disaster recovery efforts, ensuring our organization's resilience
Qualification
Required
Bachelor's degree in computer science, information systems, or related degree
Minimum 6 years of technical security experience
Minimum 2 years specifically managing cloud security (Azure preferred)
Proven experience preparing an organization for CMMC, NIST 800-171, or ISO 27001 audits
Expert knowledge of NIST 800-171, CMMC 2.0, and SOC 2 standards
Direct experience securing Microsoft Azure infrastructure
Ability to manage risk assessments and threat modeling
Skilled in writing technical policies, procedures, and SSPs
Experience coordinating third-party audits and external assessments
Knowledge of DevSecOps pipelines and OT/Industrial security
Ability to work both independently and collaboratively, and handle ambiguity
Excellent communication skills and ability to succinctly present recommendations
Strong ability to prioritize competing deadlines in a fast-paced environment
Adaptability to perform additional duties as business needs evolve
Benefits
Competitive compensation and benefits.