Lead Cybersecurity Engineer - Microsoft Security Stack/Automation
Job Summary
We are seeking a highly skilled Lead Cybersecurity Engineer specializing in Microsoft Security Stack and Automation to join our client's dynamic cybersecurity team.
Title: Lead Cybersecurity Engineer
JobDiva #: 26-00397
Company: MEP Construction Industry Client
Salary: $150000 - $180000+/Year based on skills and experience
Position Type: Direct Placement (Full Time role)
Location: United States
100% Remote Job
Department: Information Technology — Cybersecurity
Reports To: Director, Infrastructure (in partnership with the vCISO)
Direct Reports: None; Technical lead for security engineering work across IT and the operating companies
Position Summary
Client is scaling its technology estate faster than its security controls were built to carry — ERP consolidation in flight, a new Microsoft Fabric data platform, enterprise AI assistants rolling out, and a growing set of field-service and OT systems across multiple operating companies. Security today is delivered through a mix of Microsoft-native tooling, a managed detection provider, and vCISO oversight. What does not exist yet is a deep, hands-on engineering bench that owns the controls end to end.
The Lead Cybersecurity Engineer is the senior technical practitioner in that function. The role designs, builds, and operates Client's preventive and detective controls — identity, endpoint, email, cloud, network, and data protection — hardens the environments the business is standing up, leads incident response on the technical side, and turns audit and insurance requirements into implemented configuration rather than documented intent.
This is a builder's role in an environment with real acquisition velocity: new operating companies arrive with their own tenants, their own tooling, and their own gaps. Success is measured in controls that are deployed, monitored, and evidenced — not in policy documents or dashboards nobody acts on.
Required Qualifications
Bachelor's degree in computer science, information systems, cybersecurity, or equivalent practical experience.
7 or more years in information security with at least three in a hands-on security engineering role owning production controls.
Deep, current expertise with the Microsoft security stack — Entra ID, Defender XDR, Sentinel, and Purview — including configuration, tuning, and troubleshooting at enterprise scale.
Demonstrated incident response experience as a technical lead, from detection through containment, eradication, and post-incident review.
Strong foundation in identity and access engineering, including conditional access design, privileged access management, and least-privilege enforcement.
Practical experience running a vulnerability management program with measured remediation against defined service levels.
Working knowledge of a recognized control framework such as NIST CSF or CIS Controls, and experience producing audit-grade evidence.
Scripting and automation capability — PowerShell, Python, or equivalent — applied to security operations and configuration at scale.
Ability to explain technical risk and remediation trade-offs clearly to IT leadership, business stakeholders, and non-technical executives.
Preferred Qualifications
Industry certification such as CISSP, GCIH, GCIA, GPEN, OSCP, or Microsoft security certifications.
Experience securing multi-tenant or multi-operating-company environments and integrating acquisitions onto a common security standard.
Experience in construction, specialty contracting, manufacturing, distribution, or field services, including OT or ICS exposure.
Experience securing enterprise AI deployments — assistant governance, data exposure controls, and model or prompt risk.
Cloud security depth in Azure, including posture management, workload protection, and infrastructure-as-code review.
Experience managing a managed detection and response or SOC provider relationship to measurable outcomes.
Familiarity with cyber insurance underwriting requirements and customer security questionnaire processes.
Key Responsibilities
Security Architecture & Engineering
Design and implement the technical security architecture across identity, endpoint, email, network, cloud, and data — translating the security strategy set with the vCISO into deployed, tested configuration.
Serve as security engineering's design authority on major programs: ERP consolidation, the Microsoft Fabric data platform, enterprise AI assistant deployment, CRM selection, and integration platform work.
Build and maintain hardening standards and secure baselines for Windows, Linux, mobile, and cloud workloads, and enforce them through configuration management rather than manual review.
Define and operate the secure-by-default patterns other IT teams build against — reference designs for network segmentation, secrets management, logging, and third-party connectivity.
Lead the security engineering workstream for acquisition integrations: assess the acquired estate, prioritize remediation, and bring tenants and endpoints onto Client standards.
Threat Detection & Response
Own the technical relationship with the managed detection and response provider — tuning detections, closing coverage gaps, validating alert quality, and holding the provider to response commitments.
Engineer detection content and log pipelines in Microsoft Sentinel and Defender XDR, including data source onboarding, analytics rules, and automated response playbooks.
Act as technical incident commander during security incidents: containment, forensics, eradication, recovery, and the written post-incident review with tracked corrective actions.
Run purple-team and tabletop exercises against realistic scenarios — ransomware, business email compromise, vendor compromise, and OT disruption — and convert findings into engineering work.
Maintain and continuously improve the incident response runbooks, escalation paths, and evidence-handling procedures used across the operating companies.
Identity & Access
Engineer and operate the identity security stack — Entra ID conditional access, MFA and phishing-resistant authentication, privileged identity management, and lifecycle joiner-mover-leaver automation.
Drive least-privilege across cloud and on-premises: privileged access workstations, just-in-time elevation, service account governance, and periodic access recertification.
Secure machine and workload identity for integrations, APIs, and automation, including secrets management and credential rotation.
Partner with the applications team so role design in ERP, CRM, and field-service platforms is enforceable and segregation-of-duties conflicts are caught before go-live.
Vulnerability & Risk Management
Own the vulnerability management program end to end — discovery, prioritization by exploitability and business exposure, remediation tracking, and reporting against defined SLAs.
Run internal and third-party penetration testing and red-team engagements, and drive findings to closure with the accountable technical owners.
Maintain an accurate asset inventory across endpoints, servers, cloud resources, SaaS, and field devices as the foundation for coverage measurement.
Assess and monitor third-party and supply chain risk for critical vendors, and set the security requirements built into vendor selection and contracts.
Quantify and report residual risk to IT leadership and the vCISO in terms of business impact rather than raw finding counts.
Compliance, OT & Partnership
Translate cyber insurance, customer, and contractual security requirements into implemented controls with evidence that survives audit.
Support attestation and assessment work against recognized frameworks — NIST CSF, CIS Controls, and customer-driven questionnaires — as the technical subject matter expert.
Extend appropriate controls into OT and field-service environments — building systems, shop floor, fleet telematics, and connected field devices — with segmentation and monitoring suited to availability-sensitive systems.
Partner with the AI function on securing assistant and model use: data exposure controls in Microsoft Purview, prompt and output handling, and guardrails against shadow AI.
Deliver security awareness and phishing simulation content that changes behavior, and coach IT and operating company staff on secure practice.
Technical Environment
The Lead Cybersecurity Engineer operates and hardens the following stack:
Layer
Platform / Tooling
Identity
Microsoft Entra ID — conditional access, MFA, PIM, identity protection
Endpoint & email
Microsoft Defender for Endpoint and Defender for Office 365; managed EDR coverage
Detection & response
Microsoft Sentinel; Defender XDR; 24x7 managed detection and response partner
Cloud & infrastructure
Microsoft Azure; Microsoft 365; hybrid Windows and Linux estate
Data & AI governance
Microsoft Purview — DLP, sensitivity labeling, model and prompt governance
Data platform
Microsoft Fabric (F64 today, F128 planned), OneLake, Azure data lake and warehouse
Vulnerability management
Enterprise vulnerability scanning, attack surface management, penetration testing partners
Network
Firewall, secure edge and remote access, segmentation across OpCo sites
Business systems
IFS Cloud, Vista/Viewpoint, Sage Intacct, ComputerEase; Boomi integration platform
Field service & OT
BuildOps and OpCo field-service systems; fleet telematics and connected field devices
First-Year Success Measures
Secure baselines defined and enforced for endpoints, servers, and cloud workloads, with measured configuration compliance rather than sampled review.
Conditional access and phishing-resistant MFA fully deployed across the enterprise, with privileged access under just-in-time control.
Detection coverage mapped to a recognized threat framework, with priority log sources onboarded to Sentinel and alert quality measurably improved.
Vulnerability remediation operating to defined SLAs, with critical and high findings trending down quarter over quarter.
Incident response plan tested through at least two exercises, with corrective actions tracked to closure.
Security engineering requirements embedded as a standard gate in ERP, data platform, and AI program delivery.
Acquisition security integration playbook published and applied to at least one operating company onboarding.
Cyber insurance and customer security requirements satisfied with evidence produced from operating systems rather than assembled by hand.
Key Competencies
Hands-on engineer first — builds and operates controls rather than delegating them to documents.
Risk-based prioritizer; distinguishes what is exploitable and material from what is merely reportable.
Calm and decisive under incident pressure, with disciplined communication to leadership.
Enables the business securely instead of defaulting to no; finds the controlled path to yes.
Automates repeat work and measures control effectiveness continuously.
Collaborative across IT pillars — infrastructure, applications, data, integration, and AI.
Intellectually current on the threat landscape without chasing tooling for its own sake.
This role offers an engaging environment where your expertise will directly impact the organization’s ability to defend against evolving cyber threats while advancing your career in cybersecurity engineering.
Pay: $150,000.00 - $180,000.00 per year
Benefits:
Dental insurance
Health insurance
Vision insurance
Education:
Bachelor's (Preferred)
Experience:
Information security: 7 years (Required)
Security engineering: 3 years (Required)
Azure: 3 years (Required)
Build automation: 3 years (Required)
PowerShell: 1 year (Preferred)
Python: 1 year (Preferred)
Identity & access management: 3 years (Required)
Threat detection & response: 3 years (Required)
Vulnerability management: 2 years (Required)
Risk management: 2 years (Required)
Data lake: 2 years (Required)
Work Location: Remote