{"schemaVersion":"jobsearcher.job.v1","id":"7de4cd5074f359f2678c7050","url":"https://jobsearcher.com/jobs/7de4cd5074f359f2678c7050","canonicalUrl":"https://jobsearcher.com/jobs/7de4cd5074f359f2678c7050","title":"Lead Cybersecurity Engineer - Microsoft Security Stack/Automation","description":"Job Summary\nWe are seeking a highly skilled Lead Cybersecurity Engineer specializing in Microsoft Security Stack and Automation to join our client's dynamic cybersecurity team.\nTitle: Lead Cybersecurity Engineer\nJobDiva #: 26-00397\nCompany: MEP Construction Industry Client\nSalary: $150000 - $180000+/Year based on skills and experience\nPosition Type: Direct Placement (Full Time role)\nLocation: United States\n100% Remote Job\nDepartment: Information Technology — Cybersecurity\nReports To: Director, Infrastructure (in partnership with the vCISO)\nDirect Reports: None; Technical lead for security engineering work across IT and the operating companies\nPosition Summary\nClient is scaling its technology estate faster than its security controls were built to carry — ERP consolidation in flight, a new Microsoft Fabric data platform, enterprise AI assistants rolling out, and a growing set of field-service and OT systems across multiple operating companies. Security today is delivered through a mix of Microsoft-native tooling, a managed detection provider, and vCISO oversight. What does not exist yet is a deep, hands-on engineering bench that owns the controls end to end.\nThe Lead Cybersecurity Engineer is the senior technical practitioner in that function. The role designs, builds, and operates Client's preventive and detective controls — identity, endpoint, email, cloud, network, and data protection — hardens the environments the business is standing up, leads incident response on the technical side, and turns audit and insurance requirements into implemented configuration rather than documented intent.\nThis is a builder's role in an environment with real acquisition velocity: new operating companies arrive with their own tenants, their own tooling, and their own gaps. Success is measured in controls that are deployed, monitored, and evidenced — not in policy documents or dashboards nobody acts on.\nRequired Qualifications\nBachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.\n7 or more years in information security with at least three in a hands-on security engineering role owning production controls.\nDeep, current expertise with the Microsoft security stack — Entra ID, Defender XDR, Sentinel, and Purview — including configuration, tuning, and troubleshooting at enterprise scale.\nDemonstrated incident response experience as a technical lead, from detection through containment, eradication, and post-incident review.\nStrong foundation in identity and access engineering, including conditional access design, privileged access management, and least-privilege enforcement.\nPractical experience running a vulnerability management program with measured remediation against defined service levels.\nWorking knowledge of a recognized control framework such as NIST CSF or CIS Controls, and experience producing audit-grade evidence.\nScripting and automation capability — PowerShell, Python, or equivalent — applied to security operations and configuration at scale.\nAbility to explain technical risk and remediation trade-offs clearly to IT leadership, business stakeholders, and non-technical executives.\nPreferred Qualifications\nIndustry certification such as CISSP, GCIH, GCIA, GPEN, OSCP, or Microsoft security certifications.\nExperience securing multi-tenant or multi-operating-company environments and integrating acquisitions onto a common security standard.\nExperience in construction, specialty contracting, manufacturing, distribution, or field services, including OT or ICS exposure.\nExperience securing enterprise AI deployments — assistant governance, data exposure controls, and model or prompt risk.\nCloud security depth in Azure, including posture management, workload protection, and infrastructure-as-code review.\nExperience managing a managed detection and response or SOC provider relationship to measurable outcomes.\nFamiliarity with cyber insurance underwriting requirements and customer security questionnaire processes.\nKey Responsibilities\nSecurity Architecture & Engineering\nDesign and implement the technical security architecture across identity, endpoint, email, network, cloud, and data — translating the security strategy set with the vCISO into deployed, tested configuration.\nServe as security engineering's design authority on major programs: ERP consolidation, the Microsoft Fabric data platform, enterprise AI assistant deployment, CRM selection, and integration platform work.\nBuild and maintain hardening standards and secure baselines for Windows, Linux, mobile, and cloud workloads, and enforce them through configuration management rather than manual review.\nDefine and operate the secure-by-default patterns other IT teams build against — reference designs for network segmentation, secrets management, logging, and third-party connectivity.\nLead the security engineering workstream for acquisition integrations: assess the acquired estate, prioritize remediation, and bring tenants and endpoints onto Client standards.\nThreat Detection & Response\nOwn the technical relationship with the managed detection and response provider — tuning detections, closing coverage gaps, validating alert quality, and holding the provider to response commitments.\nEngineer detection content and log pipelines in Microsoft Sentinel and Defender XDR, including data source onboarding, analytics rules, and automated response playbooks.\nAct as technical incident commander during security incidents: containment, forensics, eradication, recovery, and the written post-incident review with tracked corrective actions.\nRun purple-team and tabletop exercises against realistic scenarios — ransomware, business email compromise, vendor compromise, and OT disruption — and convert findings into engineering work.\nMaintain and continuously improve the incident response runbooks, escalation paths, and evidence-handling procedures used across the operating companies.\nIdentity & Access\nEngineer and operate the identity security stack — Entra ID conditional access, MFA and phishing-resistant authentication, privileged identity management, and lifecycle joiner-mover-leaver automation.\nDrive least-privilege across cloud and on-premises: privileged access workstations, just-in-time elevation, service account governance, and periodic access recertification.\nSecure machine and workload identity for integrations, APIs, and automation, including secrets management and credential rotation.\nPartner with the applications team so role design in ERP, CRM, and field-service platforms is enforceable and segregation-of-duties conflicts are caught before go-live.\nVulnerability & Risk Management\nOwn the vulnerability management program end to end — discovery, prioritization by exploitability and business exposure, remediation tracking, and reporting against defined SLAs.\nRun internal and third-party penetration testing and red-team engagements, and drive findings to closure with the accountable technical owners.\nMaintain an accurate asset inventory across endpoints, servers, cloud resources, SaaS, and field devices as the foundation for coverage measurement.\nAssess and monitor third-party and supply chain risk for critical vendors, and set the security requirements built into vendor selection and contracts.\nQuantify and report residual risk to IT leadership and the vCISO in terms of business impact rather than raw finding counts.\nCompliance, OT & Partnership\nTranslate cyber insurance, customer, and contractual security requirements into implemented controls with evidence that survives audit.\nSupport attestation and assessment work against recognized frameworks — NIST CSF, CIS Controls, and customer-driven questionnaires — as the technical subject matter expert.\nExtend appropriate controls into OT and field-service environments — building systems, shop floor, fleet telematics, and connected field devices — with segmentation and monitoring suited to availability-sensitive systems.\nPartner with the AI function on securing assistant and model use: data exposure controls in Microsoft Purview, prompt and output handling, and guardrails against shadow AI.\nDeliver security awareness and phishing simulation content that changes behavior, and coach IT and operating company staff on secure practice.\nTechnical Environment\nThe Lead Cybersecurity Engineer operates and hardens the following stack:\nLayer\nPlatform / Tooling\nIdentity\nMicrosoft Entra ID — conditional access, MFA, PIM, identity protection\nEndpoint & email\nMicrosoft Defender for Endpoint and Defender for Office 365; managed EDR coverage\nDetection & response\nMicrosoft Sentinel; Defender XDR; 24x7 managed detection and response partner\nCloud & infrastructure\nMicrosoft Azure; Microsoft 365; hybrid Windows and Linux estate\nData & AI governance\nMicrosoft Purview — DLP, sensitivity labeling, model and prompt governance\nData platform\nMicrosoft Fabric (F64 today, F128 planned), OneLake, Azure data lake and warehouse\nVulnerability management\nEnterprise vulnerability scanning, attack surface management, penetration testing partners\nNetwork\nFirewall, secure edge and remote access, segmentation across OpCo sites\nBusiness systems\nIFS Cloud, Vista/Viewpoint, Sage Intacct, ComputerEase; Boomi integration platform\nField service & OT\nBuildOps and OpCo field-service systems; fleet telematics and connected field devices\nFirst-Year Success Measures\nSecure baselines defined and enforced for endpoints, servers, and cloud workloads, with measured configuration compliance rather than sampled review.\nConditional access and phishing-resistant MFA fully deployed across the enterprise, with privileged access under just-in-time control.\nDetection coverage mapped to a recognized threat framework, with priority log sources onboarded to Sentinel and alert quality measurably improved.\nVulnerability remediation operating to defined SLAs, with critical and high findings trending down quarter over quarter.\nIncident response plan tested through at least two exercises, with corrective actions tracked to closure.\nSecurity engineering requirements embedded as a standard gate in ERP, data platform, and AI program delivery.\nAcquisition security integration playbook published and applied to at least one operating company onboarding.\nCyber insurance and customer security requirements satisfied with evidence produced from operating systems rather than assembled by hand.\nKey Competencies\nHands-on engineer first — builds and operates controls rather than delegating them to documents.\nRisk-based prioritizer; distinguishes what is exploitable and material from what is merely reportable.\nCalm and decisive under incident pressure, with disciplined communication to leadership.\nEnables the business securely instead of defaulting to no; finds the controlled path to yes.\nAutomates repeat work and measures control effectiveness continuously.\nCollaborative across IT pillars — infrastructure, applications, data, integration, and AI.\nIntellectually current on the threat landscape without chasing tooling for its own sake.\nThis role offers an engaging environment where your expertise will directly impact the organization’s ability to defend against evolving cyber threats while advancing your career in cybersecurity engineering.\nPay: $150,000.00 - $180,000.00 per year\nBenefits:\nDental insurance\nHealth insurance\nVision insurance\nEducation:\nBachelor's (Preferred)\nExperience:\nInformation security: 7 years (Required)\nSecurity engineering: 3 years (Required)\nAzure: 3 years (Required)\nBuild automation: 3 years (Required)\nPowerShell: 1 year (Preferred)\nPython: 1 year (Preferred)\nIdentity & access management: 3 years (Required)\nThreat detection & response: 3 years (Required)\nVulnerability management: 2 years (Required)\nRisk management: 2 years (Required)\nData lake: 2 years (Required)\nWork Location: Remote","company":"Centralpointpartners","rawCompany":"centralpointpartners","city":"Remote","state":"OR","isRemote":false,"isActive":false,"createdAt":"2026-08-09T15:05:07.930Z","occupations":[{"code":"15-1299.05","title":"Information Security Engineers","slug":"information-security-engineers"},{"code":"15-1212.00","title":"Information Security Analysts","slug":"information-security-analysts"},{"code":"15-1299.08","title":"Computer Systems Engineers/Architects","slug":"computer-systems-engineers-architects"}],"industries":[{"code":"541512","title":"Computer Systems Design Services","slug":"computer-systems-design-services"},{"code":"541690","title":"Other Scientific and Technical Consulting Services","slug":"other-scientific-and-technical-consulting-services"},{"code":"541330","title":"Engineering Services","slug":"engineering-services"}],"jobPosting":{"@context":"https://schema.org","@type":"JobPosting","title":"Lead Cybersecurity Engineer - Microsoft Security Stack/Automation","description":"Job Summary\nWe are seeking a highly skilled Lead Cybersecurity Engineer specializing in Microsoft Security Stack and Automation to join our client's dynamic cybersecurity team.\nTitle: Lead Cybersecurity Engineer\nJobDiva #: 26-00397\nCompany: MEP Construction Industry Client\nSalary: $150000 - $180000+/Year based on skills and experience\nPosition Type: Direct Placement (Full Time role)\nLocation: United States\n100% Remote Job\nDepartment: Information Technology — Cybersecurity\nReports To: Director, Infrastructure (in partnership with the vCISO)\nDirect Reports: None; Technical lead for security engineering work across IT and the operating companies\nPosition Summary\nClient is scaling its technology estate faster than its security controls were built to carry — ERP consolidation in flight, a new Microsoft Fabric data platform, enterprise AI assistants rolling out, and a growing set of field-service and OT systems across multiple operating companies. Security today is delivered through a mix of Microsoft-native tooling, a managed detection provider, and vCISO oversight. What does not exist yet is a deep, hands-on engineering bench that owns the controls end to end.\nThe Lead Cybersecurity Engineer is the senior technical practitioner in that function. The role designs, builds, and operates Client's preventive and detective controls — identity, endpoint, email, cloud, network, and data protection — hardens the environments the business is standing up, leads incident response on the technical side, and turns audit and insurance requirements into implemented configuration rather than documented intent.\nThis is a builder's role in an environment with real acquisition velocity: new operating companies arrive with their own tenants, their own tooling, and their own gaps. Success is measured in controls that are deployed, monitored, and evidenced — not in policy documents or dashboards nobody acts on.\nRequired Qualifications\nBachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.\n7 or more years in information security with at least three in a hands-on security engineering role owning production controls.\nDeep, current expertise with the Microsoft security stack — Entra ID, Defender XDR, Sentinel, and Purview — including configuration, tuning, and troubleshooting at enterprise scale.\nDemonstrated incident response experience as a technical lead, from detection through containment, eradication, and post-incident review.\nStrong foundation in identity and access engineering, including conditional access design, privileged access management, and least-privilege enforcement.\nPractical experience running a vulnerability management program with measured remediation against defined service levels.\nWorking knowledge of a recognized control framework such as NIST CSF or CIS Controls, and experience producing audit-grade evidence.\nScripting and automation capability — PowerShell, Python, or equivalent — applied to security operations and configuration at scale.\nAbility to explain technical risk and remediation trade-offs clearly to IT leadership, business stakeholders, and non-technical executives.\nPreferred Qualifications\nIndustry certification such as CISSP, GCIH, GCIA, GPEN, OSCP, or Microsoft security certifications.\nExperience securing multi-tenant or multi-operating-company environments and integrating acquisitions onto a common security standard.\nExperience in construction, specialty contracting, manufacturing, distribution, or field services, including OT or ICS exposure.\nExperience securing enterprise AI deployments — assistant governance, data exposure controls, and model or prompt risk.\nCloud security depth in Azure, including posture management, workload protection, and infrastructure-as-code review.\nExperience managing a managed detection and response or SOC provider relationship to measurable outcomes.\nFamiliarity with cyber insurance underwriting requirements and customer security questionnaire processes.\nKey Responsibilities\nSecurity Architecture & Engineering\nDesign and implement the technical security architecture across identity, endpoint, email, network, cloud, and data — translating the security strategy set with the vCISO into deployed, tested configuration.\nServe as security engineering's design authority on major programs: ERP consolidation, the Microsoft Fabric data platform, enterprise AI assistant deployment, CRM selection, and integration platform work.\nBuild and maintain hardening standards and secure baselines for Windows, Linux, mobile, and cloud workloads, and enforce them through configuration management rather than manual review.\nDefine and operate the secure-by-default patterns other IT teams build against — reference designs for network segmentation, secrets management, logging, and third-party connectivity.\nLead the security engineering workstream for acquisition integrations: assess the acquired estate, prioritize remediation, and bring tenants and endpoints onto Client standards.\nThreat Detection & Response\nOwn the technical relationship with the managed detection and response provider — tuning detections, closing coverage gaps, validating alert quality, and holding the provider to response commitments.\nEngineer detection content and log pipelines in Microsoft Sentinel and Defender XDR, including data source onboarding, analytics rules, and automated response playbooks.\nAct as technical incident commander during security incidents: containment, forensics, eradication, recovery, and the written post-incident review with tracked corrective actions.\nRun purple-team and tabletop exercises against realistic scenarios — ransomware, business email compromise, vendor compromise, and OT disruption — and convert findings into engineering work.\nMaintain and continuously improve the incident response runbooks, escalation paths, and evidence-handling procedures used across the operating companies.\nIdentity & Access\nEngineer and operate the identity security stack — Entra ID conditional access, MFA and phishing-resistant authentication, privileged identity management, and lifecycle joiner-mover-leaver automation.\nDrive least-privilege across cloud and on-premises: privileged access workstations, just-in-time elevation, service account governance, and periodic access recertification.\nSecure machine and workload identity for integrations, APIs, and automation, including secrets management and credential rotation.\nPartner with the applications team so role design in ERP, CRM, and field-service platforms is enforceable and segregation-of-duties conflicts are caught before go-live.\nVulnerability & Risk Management\nOwn the vulnerability management program end to end — discovery, prioritization by exploitability and business exposure, remediation tracking, and reporting against defined SLAs.\nRun internal and third-party penetration testing and red-team engagements, and drive findings to closure with the accountable technical owners.\nMaintain an accurate asset inventory across endpoints, servers, cloud resources, SaaS, and field devices as the foundation for coverage measurement.\nAssess and monitor third-party and supply chain risk for critical vendors, and set the security requirements built into vendor selection and contracts.\nQuantify and report residual risk to IT leadership and the vCISO in terms of business impact rather than raw finding counts.\nCompliance, OT & Partnership\nTranslate cyber insurance, customer, and contractual security requirements into implemented controls with evidence that survives audit.\nSupport attestation and assessment work against recognized frameworks — NIST CSF, CIS Controls, and customer-driven questionnaires — as the technical subject matter expert.\nExtend appropriate controls into OT and field-service environments — building systems, shop floor, fleet telematics, and connected field devices — with segmentation and monitoring suited to availability-sensitive systems.\nPartner with the AI function on securing assistant and model use: data exposure controls in Microsoft Purview, prompt and output handling, and guardrails against shadow AI.\nDeliver security awareness and phishing simulation content that changes behavior, and coach IT and operating company staff on secure practice.\nTechnical Environment\nThe Lead Cybersecurity Engineer operates and hardens the following stack:\nLayer\nPlatform / Tooling\nIdentity\nMicrosoft Entra ID — conditional access, MFA, PIM, identity protection\nEndpoint & email\nMicrosoft Defender for Endpoint and Defender for Office 365; managed EDR coverage\nDetection & response\nMicrosoft Sentinel; Defender XDR; 24x7 managed detection and response partner\nCloud & infrastructure\nMicrosoft Azure; Microsoft 365; hybrid Windows and Linux estate\nData & AI governance\nMicrosoft Purview — DLP, sensitivity labeling, model and prompt governance\nData platform\nMicrosoft Fabric (F64 today, F128 planned), OneLake, Azure data lake and warehouse\nVulnerability management\nEnterprise vulnerability scanning, attack surface management, penetration testing partners\nNetwork\nFirewall, secure edge and remote access, segmentation across OpCo sites\nBusiness systems\nIFS Cloud, Vista/Viewpoint, Sage Intacct, ComputerEase; Boomi integration platform\nField service & OT\nBuildOps and OpCo field-service systems; fleet telematics and connected field devices\nFirst-Year Success Measures\nSecure baselines defined and enforced for endpoints, servers, and cloud workloads, with measured configuration compliance rather than sampled review.\nConditional access and phishing-resistant MFA fully deployed across the enterprise, with privileged access under just-in-time control.\nDetection coverage mapped to a recognized threat framework, with priority log sources onboarded to Sentinel and alert quality measurably improved.\nVulnerability remediation operating to defined SLAs, with critical and high findings trending down quarter over quarter.\nIncident response plan tested through at least two exercises, with corrective actions tracked to closure.\nSecurity engineering requirements embedded as a standard gate in ERP, data platform, and AI program delivery.\nAcquisition security integration playbook published and applied to at least one operating company onboarding.\nCyber insurance and customer security requirements satisfied with evidence produced from operating systems rather than assembled by hand.\nKey Competencies\nHands-on engineer first — builds and operates controls rather than delegating them to documents.\nRisk-based prioritizer; distinguishes what is exploitable and material from what is merely reportable.\nCalm and decisive under incident pressure, with disciplined communication to leadership.\nEnables the business securely instead of defaulting to no; finds the controlled path to yes.\nAutomates repeat work and measures control effectiveness continuously.\nCollaborative across IT pillars — infrastructure, applications, data, integration, and AI.\nIntellectually current on the threat landscape without chasing tooling for its own sake.\nThis role offers an engaging environment where your expertise will directly impact the organization’s ability to defend against evolving cyber threats while advancing your career in cybersecurity engineering.\nPay: $150,000.00 - $180,000.00 per year\nBenefits:\nDental insurance\nHealth insurance\nVision insurance\nEducation:\nBachelor's (Preferred)\nExperience:\nInformation security: 7 years (Required)\nSecurity engineering: 3 years (Required)\nAzure: 3 years (Required)\nBuild automation: 3 years (Required)\nPowerShell: 1 year (Preferred)\nPython: 1 year (Preferred)\nIdentity & access management: 3 years (Required)\nThreat detection & response: 3 years (Required)\nVulnerability management: 2 years (Required)\nRisk management: 2 years (Required)\nData lake: 2 years (Required)\nWork Location: Remote","datePosted":"2026-08-09T15:05:07.930Z","dateModified":"2026-08-09T15:05:07.930Z","hiringOrganization":{"@type":"Organization","name":"Centralpointpartners","sameAs":"https://jobsearcher.com"},"jobLocation":{"@type":"Place","address":{"@type":"PostalAddress","addressLocality":"Remote","addressRegion":"OR","addressCountry":"US"}},"identifier":{"@type":"PropertyValue","name":"JobSearcher","value":"7de4cd5074f359f2678c7050"},"url":"https://jobsearcher.com/jobs/7de4cd5074f359f2678c7050"}}