What You'll Do
- You will own small-to-medium engineering projects end-to-end, configure and operate control sets without direct oversight, and partner closely with Senior and Principal engineers on the larger initiatives that cross multiple domains.
- You’re the engineer who can pick up a control implementation, deliver it, document it, and hand it off cleanly to operations.
- You’ll start to grow real depth in a domain you care about — identity, endpoint, vulnerability, cloud security, or logging — and you’ll be a working partner to Associate engineers on day-to-day execution.
Key Responsibilities
- Project ownership: Take small-to-medium engineering projects end-to-end — scoping, design partnership with a Senior, build, test, deploy, document, and hand off to operations. Deliver them on time without surprises.
- Control implementation and operation: Configure and operate security controls across identity, network, cloud, endpoint, logging/monitoring, encryption/key management, and vulnerability management. Execute against approved patterns and standards.
- Domain depth: Develop deepening expertise in at least one control domain (e.g., endpoint, identity, vulnerability management, cloud security, IAM, monitoring). Become a real go-to on that domain for the team.
- Vulnerability and patch operations: Run vulnerability and patch workflows — scan, prioritize, remediate, validate. Track remediation against SLA and close the loop.
- Change support: Participate in change reviews, assess security impact for in-scope systems, implement approved changes, and validate post-change posture.
- Evidence and documentation: Produce clean operational documentation — runbooks, change records, evidence artifacts — that holds up under audit and peer review.
- Detection and response support: Partner with the SOC and Detection Engineering on logging coverage, telemetry quality, and the engineering pieces of response (access tooling, isolation capabilities, evidence capture).
- Associate mentorship: Pair with Associate engineers on day-to-day execution. Review their tickets, walk them through the toolset, and grow them toward independence.
- Automation and tooling: Contribute scripts and automation to reduce manual toil (validation checks, evidence collection, repeatable deployments) under the guidance of Senior+ engineers.
What Success Looks Like
By 90 days: You’ve owned at least one small-to-medium project end-to-end — a vulnerability project, a hardening change, a logging coverage gap, or a tool configuration — and the result is documented, evidenced, and handed off cleanly.
By 6–12 months: You’re the go-to on at least one domain, you’re trusted to execute approved patterns without close oversight, Associate engineers are routinely paired with you, and you’re a working partner on at least one cross-team initiative led by a Senior or Principal engineer.
Required Qualifications
- 3+ years in security engineering, cloud engineering, or security operations with hands-on responsibility for implementing controls.
- Strong fundamentals in at least one of: identity and access management, network segmentation, vulnerability management, cloud security, endpoint security, centralized logging.
- Experience with at least one major cloud platform (Azure, AWS, GCP) in an engineering capacity.
- Comfortable executing vulnerability and patch workflows (scan, prioritize, remediate, validate).
- Ability to write clear operational documentation — runbooks, evidence artifacts, change records.
- Strong collaboration skills across Security, IT, and delivery teams.
- Comfortable mentoring Associate Engineers on day-to-day work
Preferred Qualifications
- Regulated-environment exposure (CMMC, NIST 800-171, FedRAMP-aligned, SOC 2, ISO 27001).
- Scripting / automation experience (Python, PowerShell, Bash); infrastructure-as-code familiarity a plus.
- Security certifications (Security+, SSCP, GSEC, AZ-500, AWS Security Specialty, or cloud/security engineering equivalents).
- Familiarity with incident-response procedures and evidence handling.
- Bachelor’s degree in Computer Science, Information Systems, Cybersecurity, or related field — or equivalent applicable years of experience
Skills Required
- 3+ years in security engineering, cloud engineering, or security operations with hands-on responsibility for implementing controls.
- Strong fundamentals in at least one of: identity and access management, network segmentation, vulnerability management, cloud security, endpoint security, centralized logging.
- Experience with at least one major cloud platform (Azure, AWS, GCP) in an engineering capacity.
- Comfortable executing vulnerability and patch workflows (scan, prioritize, remediate, validate).
- Ability to write clear operational documentation -- runbooks, evidence artifacts, change records.
- Strong collaboration skills across Security, IT, and delivery teams.
- Comfortable mentoring Associate Engineers on day-to-day work.
- Position limited to U.S. persons as defined in 22 C.F.R. § 120.62 (U.S. citizens, lawful permanent residents, certain protected individuals).
- Regulated-environment exposure (CMMC, NIST 800-171, FedRAMP-aligned, SOC 2, ISO 27001).
- Scripting / automation experience (Python, PowerShell, Bash); infrastructure-as-code familiarity.
- Security certifications (Security+, SSCP, GSEC, AZ-500, AWS Security Specialty, or equivalents).
- Familiarity with incident-response procedures and evidence handling.
- Bachelor's degree in Computer Science, Information Systems, Cybersecurity, or related field, or equivalent experience.
Aprio Compensation & Benefits Highlights
The following summarizes recurring compensation and benefits themes identified from responses generated by popular LLMs to common candidate questions about Aprio and has not been reviewed or approved by Aprio.
-
Fair & Transparent Compensation — Pay is generally positioned as competitive and fairly paid across many roles, with clearer benchmarking helped by public job-posted ranges and compensation aggregators.
-
Healthcare Strength — Health, dental, and vision coverage is positioned as comprehensive and available from day one for full-time hires, which is stronger than the more typical waiting-period approach.
-
Retirement Support — Retirement offerings include a 401(k) with profit sharing and access to FSA/Dependent Care accounts, which can improve total rewards when firm performance supports contributions.
Aprio Insights
What We Do
Aprio is a premier CPA and business advisory firm that advises clients and associates on how to achieve what’s next. Aprio’s associates work as integrated teams across advisory, assurance, tax, outsourcing, staffing and private client services, bringing the best thinking and personal commitment to each client. Across practices, Aprio brings together proven expertise, deep understanding and strategic foresight for industries including Manufacturing and Distribution; Non-Profit and Education; Professional Services; Real Estate and Construction; Retail, Franchise and Hospitality; and Technology and Blockchain. Headquartered in Atlanta, Georgia, Aprio has grown to over 1,000+ team members. To serve clients wherever life or business may take them, Aprio’s teams speak more than 30 languages and work with clients in over 50 countries.








