EngineerJobs.io
← Back to all jobs

Job Description

ClarkDietrich is seeking a Security Engineer to design, implement, and operate security controls across identity, endpoints, networks, cloud services, applications, data, and AI-enabled systems. This role works closely with infrastructure and business teams to improve threat detection and response, reduce cyber risk, and convert security findings into actions that teams can execute.

This is an onsite position in West Chester, OH, supporting a security program that spans hybrid environments and responsible AI use. The role includes security engineering and operational responsibilities, including participation in an on-call rotation.

Key Responsibilities

  • Design and improve preventive, detective, and recovery controls across hybrid infrastructure, SaaS, cloud platforms, endpoints, networks, and business applications.
  • Implement MFA, Conditional Access, least privilege, privileged-access management, lifecycle governance, service-identity controls, and periodic access reviews.
  • Assess cloud configurations and security exposure across APIs, containers, serverless services, infrastructure as code, CI/CD pipelines, secrets, and software supply-chain dependencies.
  • Identify and prioritize vulnerabilities, attack paths, misconfigurations, unsupported assets, and internet-facing risk, partnering with system owners through verified remediation.
  • Lead architecture reviews and threat modeling for new systems, integrations, vendors, and major changes, defining proportionate control requirements before production.
  • Maintain visibility into approved and unapproved AI services, models, agents, copilots, plugins, data connections, and business use cases to support secure, sanctioned adoption paths.
  • Review AI lifecycle data flows, including model and API access, retrieval pipelines, vector stores, prompts, tools, memory, outputs, and human-approval points.
  • Evaluate AI and application risks such as prompt injection, sensitive-data disclosure, insecure output handling, model or data poisoning, excessive agency, identity abuse, supply-chain compromise, denial of service, and unsafe tool execution.
  • Apply authentication and scoped authorization, data classification and DLP, secrets management, content filtering, tool isolation, rate limits, audit logging, monitoring, and human-in-the-loop controls.
  • Coordinate security testing including adversarial evaluation, red teaming, misuse-case testing, and ongoing monitoring for AI applications and for material model, prompt, tool, or data changes.
  • Translate AI policy into usable engineering standards and employee guidance, including investigating shadow-AI and risky data-handling patterns without indiscriminate blocking.
  • Use automation and AI-assisted analysis to speed triage, investigation, detection development, and reporting while preserving evidence, access controls, validation, and accountable human decisions.
  • Engineer telemetry and detections across identity, endpoint, network, cloud, email, applications, data, and AI services; tune alerting to improve signal quality.
  • Lead or support triage, containment, eradication, recovery, evidence preservation, communications, and post-incident improvement, including identity and token compromise.
  • Build scripts, queries, playbooks, and integrations to improve investigation speed, control consistency, and operational visibility.
  • Validate hardening, patching, backup security, recovery procedures, and disaster-recovery assumptions through exercises and technical testing.
  • Produce decision-ready metrics and concise reporting on exposure, incidents, control health, AI risk, remediation performance, and residual risk.
  • Maintain security standards, diagrams, procedures, playbooks, risk decisions, and operational records that another engineer can use.
  • Support audits and controls related to Japanese Sarbanes-Oxley (J-SOX), change management, privacy, third-party risk, and applicable company requirements.
  • Evaluate security and AI vendors including permission requests, data usage, architectural fit, contractual security commitments, and operational ownership.
  • Communicate risk in business terms, collaborate across technical and nontechnical teams, and provide targeted security guidance and awareness.
  • Participate in security projects, on-call rotation responsibilities, and related duties as business and threat conditions evolve.

Requirements

  • Bachelor’s degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
  • Five or more years of progressive IT or cybersecurity experience with substantial hands-on security engineering, architecture, operations, or incident response responsibility.
  • Demonstrated experience securing at least three of the following domains: cloud platforms, enterprise identity, endpoints, networks, applications/APIs, SaaS, data platforms, or AI-enabled systems.
  • Strong knowledge of identity and access management, modern authentication, network and web protocols, operating-system security, logging, vulnerability management, and secure configuration practices.
  • Experience with SIEM, endpoint detection and response, cloud-security or posture-management tooling, and investigation using structured queries and multiple telemetry sources.
  • Ability to automate tasks and analyze data using PowerShell, Python, APIs, infrastructure as code, or comparable tools.
  • Working knowledge of AI and generative-AI architecture, including model APIs, retrieval-augmented generation, agents and tool use, enterprise copilots, and common AI security failure modes.
  • Experience applying threat modeling, security testing, risk assessment, and secure-development practices to new technology or business applications.
  • Clear written and verbal communication, sound judgment, and ability to coordinate effectively during ambiguous or high-pressure events.

Technologies

  • MFA, Conditional Access, privileged-access management, service-identity controls
  • CI/CD pipelines, infrastructure as code, PowerShell, Python, APIs
  • SIEM, endpoint detection and response
  • Retrieval-augmented generation, vector stores, DLP, audit logging
  • Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint
  • Azure, AWS
  • NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, ISO 27001
  • CISSP, CCSP, GIAC, Security+

Benefits

  • Full benefits package (Medical, Dental, Vision, Flexible Spending Accounts and Life Insurance)
  • 401(k) with company match
  • Annual Incentive
  • Paid Time Off
  • Tuition Reimbursement
  • Professional Certification Reimbursement Program
  • Community Service Day

Preferred Qualifications

  • Experience with Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint, Azure, AWS, or comparable enterprise platforms.
  • Hands-on experience assessing or operating generative-AI applications, enterprise copilots, AI agents, model gateways, or AI security-posture and monitoring capabilities.
  • Experience in a manufacturing, industrial, distributed-site, OT/IoT, or regulated environment.
  • Familiarity with NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, ISO 27001, secure software-development practices, and recognized AI/LLM security guidance.
  • Relevant certification such as CISSP, CCSP, GIAC, Security+, a cloud-security certification, or equivalent demonstrated capability.

What Success Looks Like

  • Critical identity, cloud, endpoint, network, application, data, and AI risks have clear owners, realistic priorities, and verified remediation.
  • New AI use cases reach production through a repeatable security-review process with documented data boundaries, permissions, abuse cases, guardrails, logging, and accountable approval.
  • Detection and incident-response workflows support faster, more reliable decisions with less avoidable alert noise and stronger evidence preservation.
  • Security controls are measurable, documented, supportable, and resilient to personnel, platform, and threat changes.
  • Leaders receive concise reporting connecting engineering activity to business resilience, compliance, responsible AI adoption, and residual risk.

Work Environment

  • Regular work in an office environment may be required; a hybrid schedule may be available upon approval.
  • The role may join an on-call rotation and may require occasional travel or work in data-center, manufacturing, or network environments.
  • Reasonable accommodation may be provided to enable qualified individuals to perform the essential functions.

Salary: USD 94,100 - 168,200 per year.

Similar Jobs