Security Engineer

Posted Yesterday
Be an Early Applicant
9 Locations
Hybrid
Mid level
Consulting • Financial Services
The Role
Build, validate, tune, and operate security detections across SIEM, XDR, cloud, identity, endpoint, network, email, and application platforms. Investigate incidents, perform root-cause analysis, improve controls, validate telemetry, automate response workflows, maintain detection lifecycle processes, and support hybrid and multi-cloud security environments. The role includes on-call participation, documentation, threat hunting, attack simulation, purple teaming, and collaboration with security, infrastructure, cloud, networking, and application teams.
Summary Generated by Built In

#LI-CR2 #LI-Hybrid

Responsibilities

The Security Detection Engineer is a senior, hands-on technical role responsible for building, tuning, validating, and operating security detections across CBIZ environments. Detection engineering is the core of the role: translating threat intelligence, adversary behavior, incident findings, and business risk into dependable analytics that identify suspicious activity with useful context. The engineer also investigates incidents, improves supporting controls, and uses automation to increase speed, consistency, and coverage. This is not a passive monitoring or ticket-routing role; the engineer owns detection problems from use-case design and telemetry validation through deployment, triage support, measurement, and continuous improvement.

 

 

Essential Functions and Primary Duties
 

Detection Engineering and Threat Analytics

  • Design, test, deploy, document, and maintain detection content across SIEM, XDR, NDR, identity, email, endpoint, network, cloud, and application security platforms.

  • Turn threat intelligence, adversary tactics and techniques, incident findings, and business risk into prioritized detection use cases; develop behavioral, correlation, threshold, anomaly, and indicator-based analytics.

  • Map detection coverage to recognized adversary behaviors and maintain clear traceability among threats, telemetry, analytics, response actions, and control owners.

  • Validate detections through structured testing, historical-log review, attack simulation, purple-team exercises, and post-incident analysis; tune for meaningful signal while reducing false positives and duplicates.

  • Own the detection lifecycle, including intake, prioritization, peer review, testing, release, version control, performance review, exception handling, and retirement.

  • Monitor detection health, data freshness, rule execution, alert quality, and coverage gaps; drive corrective action when controls or telemetry degrade.

Telemetry, Logging, and Detection Architecture

  • Partner with cloud, identity, endpoint, network, infrastructure, and application teams to onboard, normalize, and retain security-relevant telemetry.

  • Assess log quality and availability, including timestamps, identity context, event fidelity, field mapping, parsing, retention, and ingestion health required for reliable investigations and detections.

  • Document data dependencies and recovery procedures for critical detections, and contribute to detection architecture, data-source strategy, and use-case roadmaps across hybrid and multi-cloud environments

Security Operations, Incident Response, and Engineering

  • Investigate and respond to alerts and incidents across SIEM, XDR, NDR, identity, email, endpoint, network, and cloud platforms; lead work from triage and scoping through containment, eradication, recovery, validation, and lessons learned.

  • Perform root-cause analysis, reconstruct activity across data sources, preserve relevant evidence, validate remediation, and convert incidents, near misses, and control failures into improved detections, playbooks, and preventive controls.

  • Configure, harden, maintain, and troubleshoot security controls across Microsoft Azure, Azure Virtual Desktop, AWS, and Microsoft 365 security and compliance platforms, including identity protection, Conditional Access, email defense, endpoint security, DLP, cloud workload protection, and tenant baselines.

  • Support certificate-based authentication, encryption, and PKI dependencies; coordinate remediation and control changes with technology owners and confirm intended security outcomes.

  • Participate in an on-call rotation and after-hours response as needed.

Automation, Documentation, and Collaboration

  • Use PowerShell, Python, Bash, APIs, SOAR workflows, and other automation methods to enrich alerts, test controls, improve data quality, orchestrate response, and reduce repetitive work.

  • Build reusable queries, scripts, integrations, dashboards, investigation guidance, runbooks, playbooks, SOPs, and knowledge articles that improve operational consistency.

  • Evaluate AI-enabled security capabilities responsibly to improve detection development and investigation efficiency while retaining appropriate human review and control.

  • Partner with Security Operations, GRC, IT, Cloud, Networking, Systems, Endpoint, application owners, threat intelligence, vulnerability management, and red/purple teams; provide technical guidance and peer review when appropriate.

 

 

Preferred Qualifications
 

  • 3-5 years of experience in information security, security operations, detection engineering, incident response, threat hunting, or security engineering.

  • Proven hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform.

  • Strong ability to analyze authentication, endpoint, network, email, cloud, and application telemetry and translate findings into durable detection logic.

  • Hands-on experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation.

  • Working knowledge of adversary behavior, common attack techniques, detection lifecycle practices, and methods for validating detection coverage.

  • Experience securing Azure and/or AWS environments and operating Microsoft 365 security capabilities; experience supporting or securing Azure Virtual Desktop is required.

  • Working knowledge of PKI, certificate-based authentication, encryption, enterprise logging architectures, networking, identity and access, endpoint security, and malware fundamentals.

  • Strong PowerShell skills and experience with Linux command-line administration, logs, and services; ability to work independently, exercise sound judgment, and drive complex work to completion.

  • Advanced skill with SIEM query languages, detection-as-code, source control, testing frameworks, SOAR, APIs, and automated response.

  • Experience with threat hunting, attack simulation, purple teaming, adversary emulation, breach-and-attack simulation, or measuring detection coverage and quality.

  • Experience with AI-assisted security analytics and responsible use of AI in detection and response workflows.

  • Relevant certifications such as Security+, GIAC, Microsoft security certifications, ISC2 CC or CISSP, or comparable credentials.

  • Experience in a large enterprise SOC, hybrid or multi-cloud environment, or large-scale security transformation.

 

Qualifications

Minimum Qualifications Required

  • College Degree or equivalent required
  • 1 year related experience
  • Proficient use of applicable technology
  • Ability to follow technical instructions and guidelines
  • Ability to document daily activities and system functions
  • Able to work in team environment
  • Demonstrated ability to communicate verbally and in writing throughout all levels of organization both internally and externally
  • Ability to travel as required by business and on-call availability
  • Able to lift up to 50 lbs



 

About Us

CBIZ, Inc. (NYSE: CBZ) is a leading professional services advisor to middle-market businesses nationwide. With industry knowledge and expertise in accounting, tax, advisory, benefits, insurance, and technology, CBIZ delivers actionable insights to help clients anticipate what is next and discover new ways to accelerate growth. CBIZ has more than 9,500 team members across 23 major markets coast to coast.

CBIZ strives to be our team members' employer of choice by creating an environment where team members are appreciated, recognized for their contributions, and provided with opportunities to grow, both personally and professionally, throughout their careers.

Together, CBIZ and CBIZ CPAs are ranked as one of the top providers of accounting services in the United States. CBIZ CPAs is an independent CPA firm that provides audit, review and attest services, while CBIZ provides business consulting, tax and financial services. In certain jurisdictions, CBIZ CPAs operates under its previous name, Mayer Hoffman McCann P.C.

Skills Required

  • College degree or equivalent
  • At least 1 year of related experience
  • Proficient use of applicable technology
  • Ability to follow technical instructions and guidelines
  • Ability to document daily activities and system functions
  • Ability to work in a team environment
  • Strong verbal and written communication skills across organizational levels
  • Ability to travel as required by business needs
  • Ability to participate in on-call availability
  • Ability to lift up to 50 pounds
  • 3–5 years of experience in information security, security operations, detection engineering, incident response, threat hunting, or security engineering
  • Hands-on experience creating and tuning detections in an enterprise SIEM, XDR, or comparable security analytics platform
  • Ability to analyze authentication, endpoint, network, email, cloud, and application telemetry
  • Experience with security investigations, incident response, log analysis, root-cause analysis, and remediation validation
  • Knowledge of adversary behavior, attack techniques, detection lifecycle practices, and detection coverage validation
  • Experience securing Azure or AWS environments and operating Microsoft 365 security capabilities
  • Experience supporting or securing Azure Virtual Desktop
  • Knowledge of PKI, certificate-based authentication, encryption, enterprise logging, networking, identity and access, endpoint security, and malware fundamentals
  • Strong PowerShell skills and Linux command-line administration experience
  • Advanced skill with SIEM query languages, detection-as-code, source control, testing frameworks, SOAR, APIs, and automated response
  • Experience with threat hunting, attack simulation, purple teaming, adversary emulation, breach-and-attack simulation, or detection coverage measurement
  • Experience with AI-assisted security analytics and responsible AI use in detection and response
  • Relevant certifications such as Security+, GIAC, Microsoft security certifications, ISC2 CC, or CISSP
  • Experience in a large enterprise SOC, hybrid or multi-cloud environment, or large-scale security transformation
Am I A Good Fit?
beta
Get Personalized Job Insights.
Our AI-powered fit analysis compares your resume with a job listing so you know if your skills & experience align.

The Company
HQ: Cleveland, OH
3,512 Employees

What We Do

Named one of the "Best & Brightest Places to Work for"​ in the Nation, CBIZ, Inc. (NYSE: CBZ) provides professional business services that help clients better manage their finances and employees. CBIZ provides its clients with financial services including accounting, tax, financial advisory, government health care consulting, risk advisory, real estate consulting, and valuation services. Employee services include employee benefits consulting, property and casualty insurance, retirement plan consulting, payroll, life insurance, HR consulting, and executive recruitment. As one of the nation’s largest brokers of employee benefits and property and casualty insurance, and one of the largest accounting and valuation companies in the United States, the Company’s services are provided through more than 100 Company offices in 33 states. CBIZ is associated with Mayer Hoffman McCann P.C. (MHM)*, a national, independent CPA firm. Through this association, we offer audit and attest services.

Similar Jobs

Worth Logo Worth

Security Engineer

Artificial Intelligence • Fintech • Software • Financial Services
In-Office or Remote
4 Locations
70 Employees

SailPoint Logo SailPoint

Security Engineer

Artificial Intelligence • Cloud • Sales • Security • Software • Cybersecurity • Data Privacy
Remote or Hybrid
United States
2461 Employees
145K-245K Annually

Nasuni Logo Nasuni

Security Engineer

Artificial Intelligence • Big Data • Cloud • Security • Software • Cybersecurity • Infrastructure as a Service (IaaS)
Easy Apply
Remote or Hybrid
United States
550 Employees

CrowdStrike Logo CrowdStrike

Security Engineer

Cloud • Computer Vision • Information Technology • Sales • Security • Cybersecurity
Remote or Hybrid
USA
11000 Employees
120K-180K Annually

Similar Companies Hiring

Granted Thumbnail
Artificial Intelligence • Healthtech • Insurance • Mobile • Financial Services
New York, New York
23 Employees
Hanover Park Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
42 Employees
Onshore Thumbnail
Artificial Intelligence • Fintech • Software • Financial Services
New York, New York
60 Employees

Sign up now Access later

Create Free Account

Please log in or sign up to report this job.

Create Free Account