Cybersecurity Engineer

CBRE

Richardson (TX)

On-site

USD 90,000 - 140,000

Full time

5 days ago
Be an early applicant
Application generator

Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.

Get past ATS filters

Job summary

CBRE seeks a Cybersecurity Engineer in Richardson, TX to deploy and tune security controls across endpoint, identity, network and cloud domains. You will build detections, investigate incidents, and automate routine tasks in a large, global environment.

You will work with SIEM and data pipelines, maintain runbooks, and collaborate with cross‑functional teams on hardening and threat intel. A strong security foundation and clear written comms are essential.

Qualifications

  • 3+ years in information security or IT infrastructure.
  • Hands-on security engineering or SOC experience (1+ year).
  • Experience with at least two of: EDR, email gateways, next‑gen firewalls, web proxies, WAFs, or cloud logging.
  • Familiarity with Microsoft Entra ID (Azure AD) and attack patterns.
  • Experience with SIEM or security data pipeline platforms.
  • Proficiency in SQL and Python for log analysis.

Responsibilities

  • Deploy, configure and maintain security controls across EDR, email security, proxies, firewalls, identity and cloud platforms.
  • Onboard new log sources and troubleshoot ingestion/parsing issues.
  • Support detection-coverage assessments against MITRE ATT&CK by documenting log source coverage and gaps.
  • Build and tune detections in SIEM and data pipelines per senior guidance.
  • Investigate suspicious activity and document findings for incidents.
  • Run IOC searches across networks, identity, cloud and email logs when needed.
  • Write and maintain scripts/integrations to automate security tasks.
  • Collaborate with network/identity/cloud teams to implement hardening changes.
  • Track vulnerability and threat intel for the CBRE stack and translate to patches/detections.
  • Maintain runbooks and investigation notes.
  • Participate in on-call rotation for tooling and pipelines.

Skills

Security engineering
SOC experience
SQL
Python
Troubleshooting
Written communication

Tools

CrowdStrike Falcon
Microsoft Defender
Azure Monitor
AWS CloudTrail
VPC Flow Logs
Palo Alto Networks

Job description

About The Role

CBRE runs one of the largest and most varied technology estates in commercial real estate: corporate networks across more than 100 countries, cloud platforms on AWS, Azure and Google Cloud, client-facing applications, and building systems in the properties we manage. Protecting that estate takes a team of engineers who understand how the pieces fit together and where attackers look for gaps.

As a Cybersecurity Engineer, you deploy, operate and tune the security controls and detection pipelines that defend that estate. You work across identity, endpoint, network, cloud and email security under the guidance of senior engineers and architects. You make sure security telemetry reaches the security operations center (SOC) in usable form, you investigate what the tools surface, and you fix problems at the source. This is a hands‑on role for someone who has solid security fundamentals and wants to build depth across multiple technologies in a large, global environment.

What You Will Do
  • Deploy, configure and maintain security controls across endpoint detection and response (EDR), email security, web proxy, firewall, identity and cloud platforms.
  • Monitor log-source health for the security data pipeline. Onboard new sources, troubleshoot ingestion and parsing failures, and elevate schema issues that need architectural changes.
  • Support detection-coverage assessments against the MITRE ATT&CK framework by gathering evidence of what each log source captures and documenting gaps.
  • Build and tune detections in the security information and event management (SIEM) and data pipeline platforms, working from requirements set by senior engineers.
  • Conduct technical investigations into suspicious activity: unusual sign-ins, credential attacks, malware delivery, and suspicious network traffic. Document findings clearly and elevate confirmed incidents.
  • Run indicator-of-compromise searches across network, identity, cloud and email logs when threat intelligence or an incident calls for it.
  • Write and maintain scripts and integrations that automate repetitive security tasks.
  • Work with network, identity, cloud and infrastructure teams to implement hardening changes and validate that fixes hold.
  • Track vulnerability and threat intelligence relevant to the CBRE technology stack and help translate it into patch and detection priorities.
  • Maintain technical documentation: runbooks, configuration records and investigation notes.
  • Participate in an on-call rotation for security tooling and pipeline issues. [Confirm on-call expectations with hiring manager.]
What you bring
  • Three or more years in information security, IT infrastructure or a related technical role, with at least one year of hands‑on security engineering or SOC experience.
  • Working experience with at least two of: EDR platforms (for example, CrowdStrike Falcon or Microsoft Defender), email security gateways, next-generation firewalls (for example, Palo Alto Networks), web proxies, web application firewalls, or cloud-native logging (AWS CloudTrail, VPC Flow Logs, Azure Monitor).
  • Familiarity with Microsoft Entra ID (Azure AD) and common identity-based attack patterns such as password spraying and impossible‑travel sign‑ins.
  • Exposure to a SIEM or security data pipeline platform, including reading and searching logs and understanding how parsing and normalization work.
  • Basic familiarity with the MITRE ATT&CK framework and how techniques map to log sources.
  • Proficiency in SQL and at least one scripting language (Python preferred) for log analysis and basic automation.
  • Sound troubleshooting instincts and the ability to work through an investigation methodically from indicator to conclusion.
  • Clear written communication. You can explain a technical finding to a colleague who was not in the room.
Preferred
  • Experience with security data pipeline platforms (for example, Databahn, Cribl) or SOAR and automation tooling (for example, Torq).
  • Cloud security exposure on AWS, Azure or Google Cloud.
  • One or more of: Security+, CySA+, GCIH, GSEC, or an entry‑level vendor certification (CrowdStrike, Palo Alto Networks PCNSA, Microsoft SC-200 or SC-900).
  • Experience working in a multi‑entity or multi‑tenant environment.
How We Work

We value engineers who are direct about what is broken and specific about how to fix it. You will get real access, real ownership of defined workstreams, and senior engineers who expect you to ask questions and challenge assumptions. We invest in people who want to grow; this role is a clear path to senior engineering.

CBRE's RISE values, Respect, Integrity, Service and Excellence, define how we treat each other and our clients. They apply to how we run security, too: we protect people first, we tell the truth about risk, and we hold ourselves to the standard we ask of others.

Why CBRE

CBRE is the world's largest commercial real estate services and investment firm, with more than 140,000 employees serving clients in more than 100 countries. Few security teams see the range of technology, geography and threat activity you will see here, which makes it a strong place to build a career.

Equal opportunity

CBRE is an equal opportunity employer. We do not discriminate on the basis of race, color, religion, sex, sexual orientation, gender identity, national origin, age, disability, veteran status or any other characteristic protected by law. [Confirm final EEO statement with HR for the posting jurisdiction.]

Our Values in Hiring

At CBRE, we are committed to fostering a culture where everyone feels they belong. We value diverse perspectives and experiences, and we welcome all applications.

Disclaimers

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Applicant AI Use Disclosure

We value human interaction to understand each candidate's unique experience, skills and aspirations. We do not use artificial intelligence (AI) tools to make hiring decisions, and we ask that candidates disclose any use of AI in the application and interview process.

About CBRE Group, Inc.

CBRE Group, Inc. (NYSE:CBRE), a Fortune 500 and S&P 500 company headquartered in Dallas, is the world's largest commercial real estate services and investment firm (based on 2024 revenue). The company has more than 140,000 employees (including Turner & Townsend employees) serving clients in more than 100 countries. CBRE serves clients through four business segments: Advisory (leasing, sales, debt origination, mortgage serving, valuations); Building Operations & Experience (facilities management, property management, flex space & experience); Project Management (program management, project management, cost consulting); Real Estate Investments (investment management, development). Please visit our website at www.cbre.com.

Equal Employment Opportunity: CBRE is an equal opportunity employer that values diversity. We have a long-standing commitment to providing equal employment opportunity to all qualified applicants regardless of race, color, religion, national origin, sex, sexual orientation, gender identity, pregnancy, age, citizenship, marital status, disability, veteran status, political belief, or any other basis protected by applicable law.

Candidate Accommodations: CBRE values the differences of all current and prospective employees and recognizes how every employee contributes to our company's success. CBRE provides reasonable accommodations in job application procedures for individuals with disabilities. If you require assistance due to a disability in the application or recruitment process, please submit a request via email at recruitingaccommodations@cbre.com or via telephone at +1 866 225 3099 (U.S.) and +1 866 388 4346 (Canada).

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cybersecurity Engineer
Cybersecurity Engineer

CBRE • Dallas (TX)

On-site
USD 120,000 - 160,000
Cybersecurity Sr Engineer
Cybersecurity Sr Engineer

CBRE • Richardson (TX)

On-site
USD 120,000 - 190,000
Cybersecurity Engineer
Cybersecurity Engineer

CBRE Group, Inc. • Richardson (TX)

On-site
USD 100,000 - 150,000
Cybersecurity Sr Engineer
Cybersecurity Sr Engineer

CBRE Group, Inc. • Richardson (TX)

On-site
USD 140,000 - 180,000
Security Officer
Security Officer

Cbre • Dallas (TX)

On-site
USD 38,000 - 48,000
VP, Head of BOE Data Engineering
VP, Head of BOE Data Engineering

CBRE • Richardson (TX)

On-site
USD 170,000 - 210,000
Cybersecurity Engineer
Cybersecurity Engineer

Cybersecurity Jobs • Richardson (TX)

On-site
USD 100,000 - 130,000
EHS Technician
EHS Technician

CBRE • Eagle Mountain (UT)

On-site
USD 95,000 - 125,000
HSE Consultant - Data Center, Safety Specialist
HSE Consultant - Data Center, Safety Specialist

CBRE • Phoenix (AZ)

On-site
USD 90,000 - 120,000
Mobile Engineer
Mobile Engineer

CBRE • Pittsburgh

On-site
USD 60,000 - 85,000