Lead Security Engineer

Security EngineerSecurity EngineerOtherRemoteLeadTeam 51-200

Location

United States

Posted

2 days ago

Salary

Not specified

Seniority

Lead

Job Description

Role Description

The A.C.Coy has an immediate need for a Lead Security Engineer. Qualified candidates will be responsible for supporting the security and compliance of the company-wide infrastructure, including networks, servers, workstations, and telecommunications systems.

  • Manage and maintain the organization’s Public Key Infrastructure (PKI) systems, ensuring secure encryption, certificate management, and cryptographic key lifecycle processes are in place and operating effectively.
  • Implement and oversee encryption solutions to protect data at rest, in transit, and in use across both on-premises and cloud environments, ensuring compliance with industry security standards.
  • Secure cloud environments (including AWS, Azure, and GCP) by ensuring adherence to internal security policies and industry best practices, and assist in the implementation and management of identity management, access control, and data protection within cloud services.
  • Collaborate with third-party vendors to securely integrate external systems.
  • Deploy, manage, and maintain firewalls, including Firewall-as-a-Service (FWaaS), Unified Threat Management (UTM) solutions, and Secure Web Gateways (SWG), to secure network traffic and enforce security policies.
  • Implement and manage advanced security technologies such as Cloud Access Security Brokers (CASB), Zero Trust Network Access (ZTNA), and other solutions to strengthen security posture.
  • Serve as a primary escalation point for security incidents and audits, leading or assisting in the development of mitigation strategies, post-incident reviews, and compliance reviews to ensure ongoing ISO 27001 adherence.
  • Act as an internal consultant to IT teams and departments, providing subject matter expertise on infrastructure security, cloud environments, and endpoint protection.
  • Lead reviews of infrastructure security components, recommend improvements, and develop risk mitigation strategies that align with the security posture and industry requirements.
  • Continuously monitor internal control systems to ensure appropriate access levels and security configurations are maintained across all infrastructure components.
  • Analyze daily security events and alerts in the context of policies, prioritizing and escalating issues as appropriate to support timely and effective incident response.
  • Evaluate security policies and procedures to identify improvement opportunities and ensure alignment with standards, industry requirements, and regulatory expectations.
  • Provide technical support and administration for LAN/WAN, remote access, IDS/IPS, and unified threat management systems, including troubleshooting, analysis, and the testing and deployment of new hardware and security applications.
  • Deploy and manage policies for antivirus and endpoint detection and response agents in collaboration with system owners to ensure effective endpoint security management.
  • Manage the availability and security of public domains and DNS records.

Qualifications

  • Bachelor’s degree in Computer Science, Business, Engineering, or a related field; or equivalent work experience is required.
  • CISSP certification or progress toward CISSP certification is preferred.
  • 7-10+ years in infrastructure or security engineering.
  • Candidate must understand enterprise environments, not just security tools:
    • Windows Server and Active Directory
    • Microsoft 365 and Entra ID (Azure AD)
    • Azure infrastructure and migrations
    • Networking fundamentals (routing, DNS, load balancers, proxies)
    • Working with server and cloud teams during deployments
    • Comfortable supporting production systems and change control
    • Able to troubleshoot across network, identity, and platform layers
    • CyberArk – Privileged Access & Identity Security
    • Certificate lifecycle management via CyberArk / Venafi
    • PKI modernization and certificate lifecycle automation
    • Service to service authentication and machine identity strategy
    • TLS and encryption design across applications and infrastructure
    • Supporting cloud and SaaS integrations requiring certificates

Job Requirements

  • Bachelor’s degree in Computer Science, Business, Engineering, or a related field; or equivalent work experience is required.
  • CISSP certification or progress toward CISSP certification is preferred.
  • 7-10+ years in infrastructure or security engineering.
  • Candidate must understand enterprise environments, not just security tools:
  • Windows Server and Active Directory
  • Microsoft 365 and Entra ID (Azure AD)
  • Azure infrastructure and migrations
  • Networking fundamentals (routing, DNS, load balancers, proxies)
  • Working with server and cloud teams during deployments
  • Comfortable supporting production systems and change control
  • Able to troubleshoot across network, identity, and platform layers
  • CyberArk – Privileged Access & Identity Security
  • Certificate lifecycle management via CyberArk / Venafi
  • PKI modernization and certificate lifecycle automation
  • Service to service authentication and machine identity strategy
  • TLS and encryption design across applications and infrastructure
  • Supporting cloud and SaaS integrations requiring certificates

Related Categories

Related Job Pages

More Security Engineer Jobs

Istari Digital logo

Cybersecurity Solutions Architect

Istari Digital

We may use artificial intelligence (AI) tools to support parts of the hiring process, such as reviewing applications, analyzing resumes, or assessing responses. These tools assist our recruitment team but do not replace human judgment. Final hiring decisions are ultimately made by humans. If you would like more information about how your data is processed, please contact us.

OtherRemoteTeam 51-200

Istari Digital delivers a model-based digital engineering platform used by defense and aerospace organizations to design and operate mission-critical systems. Our platform is deployed into classified and high-security environments, where cybersecurity is foundational—not option...

United States
Tyto Athene logo

Security Engineer, AWS & GCP

Tyto Athene

Tyto Athene is a trusted leader in IT services and solutions, delivering mission-focused digital transformation that drives measurable success. Our expertise spans four core technology domains—Network Modernization, Hybrid Cloud, Cybersecurity, and Enterprise IT—empowering our clients with cutting-edge solutions tailored to their evolving needs. With over 50 years of experience, Tyto Athene proudly supports Defense, Intelligence, Space, National Security, Civilian, Health, and Public Safety clients across the United States and worldwide. At Tyto Athene, we believe that success starts with our people. We foster a collaborative, innovative, and mission-driven environment where every team member plays a critical role in shaping the future of technology. Are you ready to join #TeamTyto?

Tyto Athene is hiring a Security Engineer, AWS & GCP to join our team of cloud, security, and compliance experts. This role is primarily focused on day‑to‑day security engineering, including system hardening, vulnerability remediation, cloud operations, and security tool mana...

United States
$115K - $130K / year
Zoom logo

Senior AI Security Assurance Engineer

Zoom

Zoomies help people stay connected so they can get more done together. We set out to build the best collaboration platform for the enterprise, and today help people communicate better with products like Zoom Contact Center, Zoom Phone, Zoom Events, Zoom Apps, Zoom Rooms, and Zoom Webinars. We’re problem-solvers, working at a fast pace to design solutions with our customers and users in mind. Find room to grow with opportunities to stretch your skills and advance your career in a collaborative, growth-focused environment.

OtherRemoteTeam 11,053Since 2013

The role involves leading adversarial verification of AI systems by designing and executing deep assessments of models and pipelines to uncover security, safety, or privacy control failures across the full AI lifecycle. Responsibilities also include developing AI-powered systems to automate security discovery, scaling offensive operations, and shaping continuous adversarial testing methodologies.

United States
$124K - $271K / year
OtherRemoteTeam 1,001-5,000

The role involves architecting and managing robust access control strategies using AWS IAM, implementing encryption via AWS KMS, and deploying native AWS security services for continuous threat detection and compliance monitoring. Responsibilities also include leading the technical validation of NIST and DoD controls to achieve ATO and serving as a technical SME for RMF documentation.

United States
$90.3K - $155K / year