Cybersecurity Engineer
Job Description
CBRE is seeking a Cybersecurity Engineer to support and secure global, enterprise-scale directory services in a hybrid environment. In this role, you will engineer and maintain Active Directory and Entra ID, with a focus on authentication, automation, monitoring, vulnerability investigation, and advanced L3 troubleshooting.
This position is based in Richardson, TX and operates in a hybrid work setup. The minimum experience requirement is 3+ years, and a Bachelor’s Degree is preferred.
What You’ll Do
- Architect, implement, and maintain secure directory systems, including on-premises and cloud AD and Entra ID environments.
- Act as a subject matter expert for authentication and directory-facilitated authorization.
- Investigate and resolve security vulnerabilities tied to directory system components.
- Lead and contribute to global projects that enable and support directory services.
- Develop and maintain automated solutions to monitor and manage directory service components at scale.
- Provide L3 support for critical directory service components, including troubleshooting complex authentication and directory issues.
- Collaborate with a globally distributed team with members located in different regions.
- Manage and guide permissions, group policies, and access controls for AD and Entra ID.
- Coordinate with IT and security teams to support compliance and security best practices.
- Document processes, configurations, and incident responses.
- Model behaviors consistent with CBRE RISE values and influence outcomes across multi-discipline teams.
- Communicate difficult and complex ideas in a way that enables influence and alignment.
Requirements
- Bachelor’s Degree preferred with 5-8 years of relevant experience, including 3+ years supporting enterprise or government-level directory services (AD, Entra ID/Azure AD).
- In-depth understanding of AD and Entra ID architecture, permissions, and security best practices.
- Expertise with Active Directory, Entra ID, Azure, AWS, GCP, DNS, Entra Conditional Access, Entra Connect, and Federation.
- Strong scripting and automation capability using PowerShell, Python, or similar tools.
- Expertise in authentication protocols including Kerberos, SAML, OAuth, and related technologies.
- Experience with monitoring tools and SIEM platforms.
- Excellent troubleshooting, communication, and documentation skills.
- Relevant certifications are preferred, including Microsoft Certified and CISSP (or similar).
- Innovative mindset to develop approaches beyond existing solutions, using standard and innovative methods with broad business impact.
- Expert organizational skills and an advanced, inquisitive problem-solving approach.
Technologies
- Active Directory, Entra ID, Azure AD
- Entra Conditional Access, Entra Connect, Federation
- Azure, AWS, GCP, DNS
- PowerShell, Python
- Kerberos, SAML, OAuth
- SIEM
Certifications (Preferred)
- Microsoft Certified
- CISSP