The Senior Cyber Security Engineer protects the company's systems and information by designing, building, and supporting complex security solutions while driving the organization's compliance posture against applicable industry frameworks and client requirements. This role tackles ambiguous, high-impact security problems that lack predefined solutions and provides pragmatic, risk-based guidance for new technology initiatives with minimal oversight from the manager. Drawing on deep expertise across security tools, techniques, and processes, the Senior CSE monitors and responds to security alerts, manages incidents, and identifies and remediates vulnerabilities across the environment. The Senior CSE partners with technical teams and business stakeholders to focus on the highest priority risks while enabling the business to deliver client solutions securely.
This position focuses on safeguarding valuable information through the establishment, enforcement, and managing of security standards. This role involves solving complex cyber security problems without predefined solutions that can significantly affect the company. The position also includes security guidance for new technology implementations with very limited oversight from the manager. This role uses cyber security expertise for alert evaluation, incident management, and vulnerability management.
Responsibilities
- Monitor and respond to security alerts and tickets with professional acuity and precision.
- Work with BC employees to provide support on complex issues, address security questions, and address concerns/threats.
- Develop, implement, and enforce security standards and guidelines for the company.
- Participate in the incident management process, working closely with other team members to respond and resolve security events and incidents.
- Perform regular vulnerability and security assessments and recommend security solutions to mitigate potential risks.
- Provide necessary security requirements and guidance for the company during new technology evaluations and implementations.
- Coordinate and manage legal discovery and holds, as well as contract reviews and client security questionnaires.
- Identify opportunities to improve processes and tasks via automation or efficiency.
- Perform complex scripting and script debugging for automating security tasks.
- Anticipate security challenges and implement preventative measures.
- Ensure compliance with all relevant regulations and standards.
- Make critical decisions balancing risks and opportunities to impact positively the company's overall security.
- Flexibility to adapt and execute various additional assignments based on evolving need
Additional Focus Areas
Security Engineering & Architecture
- Design, build, and automate security solutions and tooling to detect, prevent, and manage threats across the environment.
- Shape the security architecture of cloud and infrastructure environments.
- Guide new technology initiatives with a security-first lens, providing pragmatic, risk-based recommendations that enable the business rather than block it.
- Build and tune SIEM ingests, use cases, and alerting to sharpen detection capabilities.
Detection, Response & Access
- Investigate and respond to alerts, incidents, and vulnerabilities, turning insight into action using established tools and playbooks.
- Champion zero-trust and least-privilege access through regular access reviews.
Compliance & Risk
- Drive compliance and control maturity against applicable industry frameworks and contractual security requirements (e.g., SOC2, CMMC), including control implementation, audit preparation, and remediation tracking.
- Assess risk across supplier and third-party relationships, and support Legal with eDiscovery and preservation requests as needed.
Collaboration & Mentorship
- Partner closely with technical and business teams to deliver secure, high-quality capabilities, prioritizing the risks that matter most.
- Keep a pulse on emerging threats and technologies and help shape how the team responds to them.
- Provide mentorship, guidance, and knowledge-sharing to help less experienced team members develop their skills and grow within their roles.
Skills and Competencies
- Strong comprehension and demonstratable skills in information and data security principles and practices.
- Data-driven decision-making ability, with strong analytical and problem-solving skills.
- Excellent communication skills to effectively provide relevant technical guidance to a broad set of stakeholders and mentor employees.
- Proven skills in application security, software development security, authentication security, SEIM, automation, incident management, vulnerability management, compliance, and security solution implementation.
- Strong Microsoft/Azure security skills, including automation.
Experience
- Typically, a minimum of 8 years of relevant cyber security experience.
- Experience with incident and vulnerability management and security guidance.
Preferred Experience
- Relevant governance/compliance certifications (e.g., CISSP, CISA, CRISC, CGRC) preferred.
- 6+ years of direct cyber security experience, including hands-on compliance or audit-support work.
- Working knowledge across many of the following domains, with deeper hands-on expertise in at least three or four: identity & access management; communications & network; asset; operations; software development; application; SIEM and detection engineering; automation/scripting; incident and vulnerability management; and assessment/compliance/audit support.
- Working knowledge of AI-specific security considerations (e.g., securing AI/ML systems and evaluating AI-assisted tools for security use), and comfort using AI tools to improve security operations.
Education
- A relevant degree in computer science, cybersecurity, information systems, or related field or equivalent experience is required.
- Relevant certifications (CISSP, Security+, etc).
Learn more about our work:
Climate Change and Resilience - Brown and Caldwell
Data Center Water - Brown and Caldwell
Emerging Contaminants and PFAS - Brown and Caldwell
Digital Solutions - Brown and Caldwell
News - Brown and Caldwell
Projects - Brown and Caldwell
Industrial Water - Brown and Caldwell
Salary Range: The anticipated starting pay range for this position is based on the employee’s primary work location and may be more or less depending upon skills, experience, and education. These ranges may be modified in the future.
Location A: $129,000 - $177,000
Location B: $142,000 - $194,000
Location C: $155,000 - $212,000
You can view which BC location applies to you here. If you have any questions, please speak with your Recruiter.
Benefits and Other Compensation: We provide a comprehensive benefits package that promotes employee health, performance, and success which includes medical, dental, vision, short and long-term disability, life insurance, an employee assistance program, paid time off and parental leave, paid holidays, 401(k) retirement savings plan with employer match, performance-based bonus eligibility, employee referral bonuses, tuition reimbursement, pet insurance and long-term care insurance. Click here to see our full list of benefits.
About Brown and Caldwell
Headquartered in Walnut Creek, California, Brown and Caldwell is a full-service environmental engineering and construction services firm with 50 offices and over 2,100 professionals across North America and the Pacific. For more than 75 years, we have created leading-edge environmental solutions for municipalities, private industry, and government agencies. We strive to be the company of choice—to our clients, who benefit from our passion for delivering exceptional quality, and to our employees, present and future, who share our commitment to client service, collaboration, and innovation. Join us, and you will find a home where you can do your best work, reach new levels of expertise, and enjoy exceptional development opportunities. For more information, visit www.brownandcaldwell.com
This position is subject to a pre-employment background check and a pre-employment drug test.
Notice to Third Party Agencies: Brown and Caldwell does not accept unsolicited resumes from recruiters or employment agencies. In the event a recruiter or agency submits a resume or candidate without a previously signed agreement and approved engagement request with Brown and Caldwell, Brown and Caldwell reserves the right to pursue and hire those candidate(s) without any financial obligation to the recruiter or agency.
Brown and Caldwell is proud to be an EEO/AAP Employer. Brown and Caldwell encourages protected veterans, individuals with disabilities, and applicants from all backgrounds to apply. Brown and Caldwell ensures nondiscrimination in all programs and activities in accordance with Title VI of the Civil Rights Act.
Equal Opportunity Employer/Protected Veterans/Individuals with Disabilities
This employer is required to notify all applicants of their rights pursuant to federal employment laws. For further information, please review the Know Your Rights notice from the Department of Labor.
Skills Required
- Typically a minimum of 8 years of relevant cybersecurity experience
- Experience with incident management and vulnerability management
- Experience providing cybersecurity guidance
- Relevant degree in computer science, cybersecurity, information systems, or a related field, or equivalent experience
- Strong information and data security knowledge and skills
- Experience in application security, software development security, authentication security, SIEM, automation, incident management, vulnerability management, compliance, and security solution implementation
- Strong Microsoft and Azure security skills, including automation
- Relevant cybersecurity certifications such as CISSP or Security+
- Relevant governance and compliance certifications such as CISSP, CISA, CRISC, or CGRC
- At least 6 years of direct cybersecurity experience, including hands-on compliance or audit-support work
- Hands-on expertise across at least three or four cybersecurity domains, including identity and access management, network security, asset security, security operations, software development, application security, SIEM and detection engineering, automation and scripting, incident and vulnerability management, or assessment and compliance
- Working knowledge of AI-specific security considerations and AI tools for security operations
What We Do
Headquartered in Walnut Creek, Calif., Brown and Caldwell is an employee-owned firm with 2,100+ professionals serving clients locally and globally from 52 locations. We are the largest engineering and construction firm solely focused on the U.S. water and environmental sectors. Our creative designs and progressive solutions have helped municipal, federal and private organizations overcome their most complex environmental challenges. We offer a comprehensive range of engineering, scientific, consulting and construction services and all the essential ingredients® for a successful project and a standout experience. We are passionate about delivering exceptional service, collaborating with clients, adding value through innovation and building relationships that last. This passion dates back to Ken Brown and Dave Caldwell, who, since founding the company in 1947, stood out for their ability to solve engineering challenges, apply technology to emerging environmental problems, and serve their community. Service, great technical solutions, innovation. These are the qualities our founders carried forward as the world changed and the company grew into what it is today. Now, more than 75 years later, these qualities are just as important – essential, really – to Brown and Caldwell and to our clients.








