Cybersecurity Sr Engineer
Job Description
CBRE is seeking a Cybersecurity Sr Engineer to help mitigate enterprise cyber security risk by embedding security processes, tools, and people into business practices. This role also supports and maintains secure GenAI and LLM solutions while contributing to global AI security governance, threat modeling, incident response, and reporting.
Location
Richardson, TX (onsite)
Experience and Education
- Minimum experience: 3 years
- Education: Bachelor’s degree (BA/BS) in a related field of work
- Equivalent experience: 2 years of related experience for every year of higher level education
Key Responsibilities
- Support and maintain secure solutions for GenAI, LLMs, agents, and MLOps platforms
- Develop and implement guardrails, access controls, and prompt protection
- Lead AI-focused threat modeling and work to reduce model/system attack surface
- Align AI security controls with NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, and MITRE ATLAS
- Collaborate with red teams and support adversarial testing
- Guide incident response playbooks for AI security events
- Integrate security capabilities with secrets managers and cloud-native security platforms
- Deploy security tooling and observability for AI behavior
- Mentor teams and serve as a subject matter expert (SME) on AI risks and controls
- Contribute to policy and governance for responsible AI use
- Develop reporting that demonstrates operational excellence and product performance metrics
- Participate in an on-call rotation to ensure uptime and functionality of critical internal customer services
- Maintain well founded opinions and be willing to express disagreement when approaches do not meet internal evaluation standards
- Mentor and coach team members to develop competencies; model behaviors consistent with the company’s values
- Other duties as assigned
Required Skills and Qualifications
- Advanced experience administering security-based tools related to CSPM/CNAPP, CIEM, and vulnerability scanners (OSA, SAST, DAST)
- Intermediate experience with cloud services including OpenSearch, Azure OpenAI, and AWS Bedrock
- Intermediate experience solutioning and working with cloud providers in addition to AWS such as GCP, Alibaba, or Azure
- Intermediate experience writing and running Terraform
- Intermediate Linux systems administrator experience (or equivalent skills)
- Intermediate experience with DevOps or CI/CD pipelines (e.g., GitHub Actions, GitLab, Jenkins)
- Intermediate experience automating multiple systems using functional and object-oriented programming languages
- Intermediate experience with RDBMS and Vector storage solutions
- Intermediate understanding of source control management and practices using Git and GitHub
- Advanced experience onboarding and integrating with third-party PaaS & SaaS
- Experience with the Microsoft ecosystem
- Directory services experience including AD and LDAP
- Understanding of backend application development, including API development, and integration with third-party sources
- Understanding of system integration design patterns at scale, including experience in microservice design or development
- Strong written and verbal communication skills, including the ability to explain complex cybersecurity concepts across technical and business stakeholders, document standards, author technical reports, and collaborate across engineering, operations, and compliance teams
- Strong analytical and decision-making skills with experience solving complex cybersecurity problems, evaluating competing solutions, applying risk-based reasoning, and delivering strategies that improve enterprise security posture and operational resilience
Technologies
- GenAI, LLMs, agents, MLOps
- Guardrails, prompt protection
- NIST AI RMF, ISO/IEC 42001, OWASP LLM Top 10, MITRE ATLAS
- CSPM/CNAPP, CIEM, OSA, SAST, DAST
- OpenSearch, Azure OpenAI, AWS Bedrock, GCP, Alibaba, Azure
- Terraform, Linux, DevOps
- CI/CD pipelines, GitHub Actions, GitLab, Jenkins
- Functional and object-oriented programming languages
- RDBMS, Vector storage solutions
- Git, GitHub
- PaaS, SaaS
- Microsoft ecosystem, AD, LDAP
- API development, microservice design
Applicant AI Use Disclosure
- CBRE does not use artificial intelligence (AI) tools to make hiring decisions.
- Candidates are asked to disclose any use of AI in the application and interview process.
Work Authorization
Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.
Candidate Accommodations
CBRE provides reasonable accommodations in job application procedures for individuals with disabilities. If you require assistance due to a disability in the application or recruitment process, please submit a request via email at [email protected] or via telephone at +1 866 225 3099 (U.S.) and +1 866 388 4346 (Canada).