Security Engineer
CBIZ
Job Description #LI-CR2 #LI-Hybrid Responsibilities The Security Detection Engineer is a senior, hands-on technical role responsible for building, tuning, validating, and operating security detections across CBIZ environments. Detection engineering is the core of the role: translating threat intelligence, adversary behavior, incident findings, and business risk into dependable analytics that identify suspicious activity with useful context. The engineer also investigates incidents, improves supporting controls, and uses automation to increase speed, consistency, and coverage. This is not a passive monitoring or ticket-routing role; the engineer owns detection problems from use-case design and telemetry validation through deployment, triage support, measurement, and continuous improvement. Essential Functions and Primary Duties Detection Engineering and Threat Analytics
- Design, test, deploy, document, and maintain detection content across SIEM, XDR, NDR, identity, email, endpoint, network, cloud, and application security platforms.
- Turn threat intelligence, adversary tactics and techniques, incident findings, and business risk into prioritized detection use cases; develop behavioral, correlation, threshold, anomaly, and indicator-based analytics.
- Map detection coverage to recognized adversary behaviors and maintain clear traceability among threats, telemetry, analytics, response actions, and control owners.
- Validate detections through structured testing, historical-log review, attack simulation, purple-team exercises, and post-incident analysis; tune for meaningful signal while reducing false positives and duplicates.
- Own the detection lifecycle, including intake, prioritization, peer review, testing, release, version control, performance review, exception handling, and retirement.
- Monitor detection health, data freshness, rule execution, alert quality, and coverage gaps; drive corrective action when controls or telemetry degrade.
- Partner with cloud, identity, endpoint, network, infrastructure, and application teams to onboard, normalize, and retain security-relevant telemetry.
- Assess log quality and availability, including timestamps, identity context, event fidelity, field mapping, parsing, retention, and ingestion health required for reliable investigations and detections.
- Document data dependencies and recovery procedures for critical detections, and contribute to detection architecture, data-source strategy, and use-case roadmaps across hybrid and multi-cloud environments
- Investigate and respond to alerts and incidents across SIEM, XDR, NDR, identity, email, endpoint, network, and cloud platforms; lead work from triage and scoping through containment, eradication, recovery, validation, and lessons learned.
- Perform root-cause analysis, reconstruct activity across data sources, preserve relevant evidence, validate remediation, and convert incidents, near misses, and control failures into improved detections, playbooks, and preventive controls.
- Configure, harden, maintain, and troubleshoot security controls across Microsoft Azure, Azure Virtual Desktop, AWS, and Microsoft 365 security and compliance platforms, including identity protection, Conditional Access, email defense, endpoint security, DLP, cloud workload protection, and tenant baselines.
- Support certificate-based authentication, encryption, and PKI dependencies; coordinate remediation and control changes with technology owners and confirm intended security outcomes.
- Participate in an on-call rotation and after-hours response as needed.
- Use PowerShell, Python, Bash, APIs, SOAR workflows, and other automation methods to enrich alerts, test controls, improve data quality, orchestrate response, and reduce repetitive work.
- Build reusable queries, scripts, integrations, dashboards, investigation guidance, runbooks, playbooks, SOPs, and knowledge articles that improve operational consistency.
- Evaluate AI-enabled security capabilities responsibly to improve detection development and investigation efficiency while retaining appropriate human review and control.
- Partner with Security Operations, GRC, IT, Cloud, Networking, Systems, Endpoint, application owners, threat intelligence, vulnerability management, and red/purple teams; provide technical guidance and peer review when appropriate.
- 3-5 years of experience in information security, security operations, detection engineering, incident response, threat hunting, or security engineering.
- Proven hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform.
- Strong ability to analyze authentication, endpoint, network, email, cloud, and application telemetry and translate findings into durable detection logic.
- Hands-on experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation.
- Working knowledge of adversary behavior, common attack techniques, detection lifecycle practices, and methods for validating detection coverage.
- Experience securing Azure and/or AWS environments and operating Microsoft 365 security capabilities; experience supporting or securing Azure Virtual Desktop is required.
- Working knowledge of PKI, certificate-based authentication, encryption, enterprise logging architectures, networking, identity and access, endpoint security, and malware fundamentals.
- Strong PowerShell skills and experience with Linux command-line administration, logs, and services; ability to work independently, exercise sound judgment, and drive complex work to completion.
- Advanced skill with SIEM query languages, detection-as-code, source control, testing frameworks, SOAR, APIs, and automated response.
- Experience with threat hunting, attack simulation, purple teaming, adversary emulation, breach-and-attack simulation, or measuring detection coverage and quality.
- Experience with AI-assisted security analytics and responsible use of AI in detection and response workflows.
- Relevant certifications such as Security+, GIAC, Microsoft security certifications, ISC2 CC or CISSP, or comparable credentials.
- Experience in a large enterprise SOC, hybrid or multi-cloud environment, or large-scale security transformation.
- College Degree or equivalent required
- 1 year related experience
- Proficient use of applicable technology
- Ability to follow technical instructions and guidelines
- Ability to document daily activities and system functions
- Able to work in team environment
- Demonstrated ability to communicate verbally and in writing throughout all levels of organization both internally and externally
- Ability to travel as required by business and on-call availability
- Able to lift up to 50 lbs
Vacancy posted 5 days ago
Similar jobs that could be interesting for youBased on the Security Engineer in Independence, OH vacancy
- ...office-based teams coming together four days a week to collaborate and thrive, together! Position Description The Senior Security Engineer is responsible for strengthening Flynn Group’s cyber defense posture across infrastructure, endpoint, cloud, identity, and network...SuggestedTemporary workCasual workWork at officeWork from homeFlexible hours
- ...organization, both internally and externallyAbility to travel as required by business and on-call availabilityThe Senior Product Security Engineer is a deeply technical, hands-on engineering and architect-level role responsible for establishing and leading the Product...Suggested
- OverviewWe are seeking a highly skilled Security Engineer II to join our Information Security team. This role will play a key part in managing, administrating, reporting and identifying enhancements for our security solutions and assisting with implementation across cloud...SuggestedFull timeFlexible hours
- ...Summary: This is a role responsible for the design and execution of our application security program as well as the maintenance and enforcement of information security policy and strategy for the Digital organization. This role will be working closely with the...SuggestedHourly pay
$116k - $216k
...Location: 4910 Tiedeman Road, Brooklyn Ohio API Security Engineer Role Overview We are seeking an experienced API & Application Security Engineer with expertise in API security, Web Application Firewall (WAF/WAAP), application security, API gateway integrations...SuggestedFull timeWork at officeRemote workFlexible hours- OverviewWe are seeking a highly skilled Senior Security Engineer to join our Information Security team. This role will play a key part in shaping security strategy, designing enterprise-class security solutions, and assisting with implementation across cloud and on-premises...Full timeFlexible hours
$91k - $185.9k
...have an opportunity to contribute to the company’s success. As a Security Specialist within PNC's Technology organization, you will be... ...Dallas, TX, Birmingham, AL, Denver, CO, Phoenix, AZ.As a Security Engineer on PNC's Cloud Security team, you will build and deploy...Full timeTemporary workPart timeWork experience placementWork at officeShift work- ...A typical day of a Security Engineer revolves around system changes, lifecycle of firewalls, and the user VPN environment. It is the responsibility of this individual for device monitoring and response, proactive fault management, vendor engagement, vulnerabilities, and...Long term contractContract workLocal areaRemote workNight shiftWeekend work
- ...Interacts with business users and vendors to identify, define requirements, and expectations of new and existing network systems security needs. Participates in design, implementation, and troubleshooting process for complex firewall solutions. Assists in the development...Casual workNight shift
$95k - $115k
...re looking for driven individuals to join our team. That’s where you come in!Base Pay Range:$95,000-$115,000As an Information Security Engineer, your essential job functions will include the following:Key Responsibilities: Vendor Risk Assessment Management (25%) - Performing...Full timeWork experience placementRemote work- About Keyfactor Our mission is to securely connect the world: humans, machines, and AI. Keyfactor is the leader in trust infrastructure... ...the position We are seeking an experienced Information Security Engineer with a strong background in implementing and managing general...Remote work
$91k - $185.9k
...culture where all of our employees feel respected, valued and have an opportunity to contribute to the company’s success. As a Security Engineer within PNC’s Technology organization, you will be based in Pittsburgh, PA; Cleveland, OH; Birmingham, AL; Dallas, TX or Denver...Full timeTemporary workPart timeWork experience placementWork at officeRemote workWork from home$82.6k - $162.8k
...our clients to operate with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Work you'll doAs a Security Engineer on the Deloitte Cyber team, you will be responsible for:Supporting the design and...Local areaVisa sponsorship$105.4k - $207.8k
Position Summary Zscaler Network Security Engineer / Senior Consultant, Strategy, Growth, and TransformationDeloitte’s Cyber business is passionate about making an impact with lasting change. Delivering our industry leading services requires fresh thinking and a...Work experience placementLocal area- ...Job Description We are looking for a Lead Security Engineer to work for our client. The ideal candidate aligns with the responsibilities and qualifications outlined below. This is a great opportunity for an experienced security professional to lead technical...
$134.5k - $265.1k
...operate with resilience, grow with confidence, and proactively manage their security posture.Recruiting for this role ends on 12/31/2026.Work you will do:As a Cyber Forward Deployed Engineer (FDE) Sr Consultant, you will drive delivery of cybersecurity and AI-enabled...Local areaVisa sponsorship- ...Affirm is seeking a Security Risk Management Specialist to evaluate and refine third-party risk and governance across the Security Third... ..., reducing manual work while partnering with business and engineering stakeholders to scale risk management. You will lead third-party...
$198k - $368k
...passionate about your future as we are, join our team.KPMG is currently seeking a Director, Cyber Architecture & Engineering to join our Enterprise Security Services organization.Responsibilities:Serve as a senior security architect and trusted advisor, leading the development...H1bLocal area$95.86k - $208.27k
...hacking certifications not required but preferred; GIAC Web Application Penetration Tester (GWAPT), Council for Registered Ethical Security Testers (CREST), Offensive Security Web Expert (OSWE), Offensive Security Web Assessor (OSWA)Ability to travel as requiredMust be...H1bLocal area$134.5k - $265.1k
...with resilience, grow with confidence, and proactively manage to secure success.Recruiting for this role ends on 12/31/2026.Position... ...PlainID. This role combines deep technical ownership with engineering expertise, governance, and stakeholder management.Work you’ll...Local areaVisa sponsorship$134.5k - $265.1k
Position Summary Join Deloitte’s Cloud Cyber Security practice as a GCP Forward Deployed Engineer, Senior Consultant and help organizations secure Google Cloud Platform (GCP) cloud and artificial intelligence (AI) workloads at scale. In this hands-on role, you will...Local areaVisa sponsorship- ...Bellevue, PA0738 Processing CenterJob DescriptionThe Lead Software Engineer provides technical leadership for the design, development,... ...The Lead Software Engineer partners with business, architecture, security, and product teams to deliver scalable, secure, and...Full timeWork experience placementWork at office
$118.7k - $243.7k
Position Summary As a Manager in AI Security Engineering, you will play a critical role in securing the development and deployment of AI/ML and Generative AI solutions. You will operate hands-on across high-visibility initiatives, embedding security, trust, and...- Job Description \n \n Location: METROHEALTH MEDICAL CENTER \n Biweekly Hours: 60\n Shift: Nights \n Schedule: 5x12hr shifts every 2 weeks \n Start/End Time: 7p - 7a \n Weekends: Every other Sunday \n Call: Yes \n \n \n *** Up to $15,000 Sign...Relocation packageShift workNight shiftWeekend work
- ...A Brief Overview The Cyber Security engineer position will support multiple security initiatives involving design and implementation of different cyber security initiatives. This position will frequently collaborate with Cybersecurity Management and provide guidance...Casual workNight shift
$25 per hour
...4-Day Workweek | Wednesday-Saturday | Noon-10:00 PM ET Looking to launch your cybersecurity career in a real-world Security Operations Center (SOC)? Join Tusker as a Cyber Security Analyst I and gain hands-on experience protecting organizations from today's...Full timeShift work- ...Huntington Ingalls Industries (HII) Mission Technologies seeks a Systems Security Engineering professional to support cybersecurity across DoD programs at Wright-Patterson AFB, OH. You will integrate SSE, RMF/A&A, and DoW/DoA requirements for aircraft, avionics, weapon...
$122k - $240.5k
Position Summary As a Full Stack Engineer Senior Consultant in Deloitte Cyber’s Digital Trust & Privacy practice, you will operate... ...engineering teams, and communicate effectively with business, security, privacy, legal, and compliance stakeholders.Recruiting for...Local areaVisa sponsorship$105.4k - $207.8k
...navigate an evolving threat landscape through scalable, resilient security operations solutions. In this hands-on role, you will support... ...engagements focused on Google SecOps, threat detection engineering, and automation. You will work with cross-functional teams to...Local areaVisa sponsorship- ...around you.Job Type: Full-Time, On-SiteLocation: Brecksville, OH (with a planned move to Wickliffe)How You'll Make an ImpactThe Resin Engineer will provide technical and engineering support for PVC/CPVC resin technology development, raw material qualification, chlorination...Full timeWork at office
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security Engineer. Be the first to apply!



