Cybersecurity Engineer

Hillpointe

Winter Park (FL)

On-site

USD 110,000 - 170,000

Full time

3 days ago
Be an early applicant
Application generator

Don’t send a generic resume — generate a resume and cover letter tailored to this exact role.

Get past ATS filters

Job summary

Hillpointe is seeking a Cybersecurity Engineer to manage day-to-day security operations in a fully cloud-based environment. This role drives the approved security agenda, oversees MDR, and leads vulnerability remediation with system owners while coordinating with MSPs and vendors.

The successful candidate will own detection and response across cloud identity, endpoints, and infrastructure, act as incident commander for security events, and guide incident response planning, metrics, and reporting

Qualifications

  • 4+ years of hands-on cybersecurity operations, cloud environment
  • Experience with security monitoring and SIEM platforms, from detection to disposition
  • Practical experience with endpoint detection and response and cloud-native security tooling
  • Knowledge of cloud identity security: conditional access, MFA, privileged access management
  • Experience running a vulnerability management program and driving remediation
  • Participation in audits/compliance programs such as SOC 2, ISO 27001, or NIST CSF
  • Ability to lead incidents calmly under pressure with clear documentation
  • Strong written communication for policies, runbooks, findings, and summaries
  • Judgment in escalation and independent handling of security issues

Responsibilities

  • Own detection and response across cloud identity, endpoint, email, and cloud infrastructure; triage, containment, eradication, recovery
  • Serve as primary incident responder and incident commander for security events with cross-team coordination
  • Maintain the incident response plan with tabletop exercises and post-incident reviews
  • Develop and tune detection rules, alert logic, and automated response playbooks
  • Build and maintain runbooks for recurring incident types

Skills

Security monitoring & SIEM
Incident response leadership
Cloud identity security
Vulnerability management
Audits & compliance (SOC 2, ISO 27001)
Security governance & runbooks
Written communication

Tools

SIEM platforms
EDR tools
CI/CD security tooling
IAM / PAM concepts

Job description

WHY HILLPOINTE?

Hillpointe is a fully integrated real estate development and investment management firm focused on developing market-rate workforce housing across the Sun Belt. Ranked at the top of NMHC's list of Builders and Developers, our team ensures best-in-class execution.

Built on its long and proven track record of real estate development, the firm's investment approach is centered around its in-house general contracting expertise, enabling direct control of cost and delivery timeframe. For each project, Hillpointe directly controls land acquisition, land development, construction, procurement of building materials, asset management, and capital markets. This is more than just a job - it's a career-defining opportunity! At Hillpointe, you'll be part of a dynamic, innovative team that has tangible impacts on day-to-day operations and contributes directly to overall success.

Cybersecurity Engineer

The Cybersecurity Engineer owns the day-to-day security operations of the organization's fully cloud-based technology environment. This is the company's dedicated security role, and it operates with a high degree of independence: the incumbent drafts and sets the approved operational security agenda, oversees external MDR, drives vulnerability and access remediation with system owners, and carries the organization through external audit. Because the scope is broad by design, the role is structured to scale through leverage — directing managed security service providers and specialist vendors for around-the-clock monitoring and surge capacity, while retaining ownership of strategy, configuration, escalation, and outcomes in-house.

The successful candidate is equally comfortable investigating an alert at the console and explaining residual risk to business leadership. This is a high-visibility role with a direct line to decisions about how the organization protects its data, its residents' information, and its capital.

Key Responsibilities:
  • Own detection and response across cloud identity, endpoint, email, and cloud infrastructure, including triage, containment, eradication, and recovery
  • Serve as primary incident responder and incident commander for security events, coordinating internal stakeholders, managed service providers, and outside counsel or forensics as required
  • Maintain and exercise the incident response plan, including tabletop exercises and post-incident reviews that produce tracked corrective actions
  • Develop and tune detection rules, alert logic, and automated response playbooks to reduce mean time to detect and mean time to respond
  • Build and maintain runbooks for recurring incident types so that response is repeatable and not dependent on a single individual
Security Monitoring, SIEM & Reporting
  • Administer the security information and event management (SIEM) platform, including data source onboarding, log ingestion health, normalization, and retention configuration
  • Manage ingestion cost and data tiering to keep monitoring coverage aligned with budget
  • Build and maintain dashboards, analytics rules, and workbooks that provide operational visibility into the security posture of the cloud environment
  • Produce recurring security reporting for IT leadership and executive stakeholders, translating technical findings into business risk and clear recommendations
  • Define and track security metrics — detection coverage, alert volume and disposition, patch and remediation timeliness, phishing susceptibility, and audit readiness
Vulnerability & Configuration Management
  • Run the vulnerability management lifecycle across endpoints, servers, cloud workloads, and third-party platforms: discovery, assessment, risk-based prioritization, remediation tracking, and verification
  • Partner with system and application owners to drive remediation to closure, escalating where service-level targets are at risk
  • Assess and harden security configuration baselines against recognized benchmarks, and monitor for configuration drift
  • Coordinate external penetration testing and vulnerability assessments, and manage the resulting findings through to resolution
  • Maintain the risk register and formal exception process for accepted risks, with documented compensating controls and review dates
Identity & Privileged Access Governance
  • Administer privileged identity and privileged access management, including just-in-time elevation, approval workflows, activation justification, and time-bound role assignment
  • Conduct recurring privileged access reviews and audits, validating that standing administrative access is eliminated or justified and that every elevation is attributable
  • Own access review and recertification cycles across the cloud tenant and integrated business platforms, coordinating with business owners as reviewers
  • Review and strengthen conditional access, multifactor authentication, and device compliance policies, including break-glass account controls and their periodic testing
  • Monitor for identity-based threats — token theft, consent phishing, risky sign-ins, legacy authentication, and over-permissioned service principals and application registrations
  • Provide security oversight of the organization's cloud productivity tenant and cloud infrastructure platform, including tenant-level security configuration and posture management
  • Embed security into development and automation pipelines: secrets management, dependency and container scanning, infrastructure-as-code review, and pipeline identity and permission hygiene
  • Review and advise on cloud architecture changes, network segmentation, and secure-by-default configuration before deployment rather than after
  • Administer cloud-delivered secure access and secure web gateway capabilities for private application access, internet egress filtering, and conditional network controls
  • Govern third-party application consent, API permissions, and integration security across the cloud tenant
Data Protection, Compliance & eDiscovery
  • Serve as the primary owner for the annual SOC 2 audit: control mapping, evidence collection, gap remediation, auditor liaison, and management of the readiness timeline
  • Maintain the security control framework and supporting policy set, keeping documentation current and demonstrably operating
  • Administer the data governance and compliance platform, including data loss prevention policies, sensitivity labeling, retention, and insider risk controls
  • Conduct eDiscovery searches, legal holds, exports, and collection activities in support of legal, human resources, and compliance requests, maintaining defensible chain of custody
  • Support security questionnaires, investor and lender due-diligence requests, and cyber insurance renewals with accurate control attestations
  • Track applicable regulatory and contractual obligations relating to personal information and advise the business on required controls
Security Awareness & Human Risk
  • Own the security awareness program end to end: content selection, campaign calendar, assignment, completion tracking, and effectiveness measurement
  • Design and administer simulated phishing campaigns, including scenario selection, difficulty progression, targeting, and results analysis
  • Deliver targeted follow-up training and coaching for repeat-susceptible users, favoring constructive reinforcement over punitive measures
  • Provide role-specific training for higher-risk functions such as finance, accounting, and executive support, with emphasis on payment fraud and business email compromise
  • Contribute security content to new-hire onboarding in partnership with Human Resources and Training
  • Manage outsourced security functions and managed security service providers, including scope definition, service-level expectations, escalation paths, and performance review
  • Validate provider work rather than accepting it at face value: review alert dispositions, challenge false-negative and false-positive patterns, and audit coverage gaps
  • Evaluate, pilot, and recommend security tooling, with attention to consolidation and total cost of ownership rather than point-solution accumulation
  • Own security vendor relationships, contract renewals, and license true-ups in coordination with IT leadership
  • Conduct third-party and vendor security risk assessments for new platforms prior to adoption
Qualifications:
Required:
  • 4+ years of hands-on experience in cybersecurity operations, security engineering, or a security-focused systems administration role, in a predominantly cloud environment
  • Demonstrated experience with security monitoring and SIEM platforms, including detection tuning and investigation of real alerts through to disposition
  • Practical experience with endpoint detection and response and cloud-native security tooling across identity, endpoint, email, and cloud workloads
  • Working knowledge of cloud identity security, including conditional access, multifactor authentication, and privileged access management concepts
  • Experience running a vulnerability management program, including prioritization and driving remediation through other teams
  • Direct participation in a recognized audit or compliance program such as SOC 2, ISO 27001, or NIST Cybersecurity Framework, including evidence collection
  • Ability to lead an incident calmly under pressure and to document what happened clearly afterward
  • Strong written communication: policies, runbooks, findings, and executive-level summaries
  • Sound judgment about what to elevate and what to handle independently, with the discretion the role requires
Preferred:
  • Experience administering a cloud data governance and compliance platform, including data loss prevention and eDiscovery
  • Experience integrating security controls into CI/CD pipelines and infrastructure-as-code workflows
  • Experience managing or holding a managed security service provider accountable to service levels
  • Scripting or automation capability for reporting, evidence collection, and repetitive response tasks
  • Experience administering a security awareness and simulated phishing platform
  • Familiarity with secure access service edge or zero-trust network access technologies
  • Exposure to real estate, construction, property management, or another multi-site operating environment
  • Relevant certifications such as CISSP, CISM, GIAC, CCSP, or vendor-specific cloud security certifications; certification is valued but does not substitute for demonstrated hands‑on capability
  • This is a fully cloud-based environment. Incumbents primarily work in an office setting with occasional travel between office locations required. The role requires availability outside standard business hours for security incidents, and as the primary on-call escalation. Occasional extended hours may be needed to support audit deadlines, remediation windows, or critical incidents.

Note:Selecting “no” will not eliminate you from consideration for this role.
Message frequency may vary. Message and data rates may apply.

Hillpointe uses AI-assisted technology to help our team review applications. This technology compares your resume and application questions to the skills and experience our hiring team has identified as important for this role. The tool does not reject candidates or make hiring decisions; all hiring decisions are made by our team. You may opt out of AI-assisted review, and opting out will not affect your candidacy.

Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Cyber Security Analyst
Cyber Security Analyst

Holland & Hart LLP • Denver (CO)

On-site
USD 90,000 - 120,000
Manager, Security Engineering, Cloud & AppSec
Manager, Security Engineering, Cloud & AppSec

Horizon3 AI • United States

On-site
USD 149,850 - 185,000
Health, vision & dental insurance
Flexible vacation policy
Generous parental leave
+2
Senior Cloud Security Engineer
Senior Cloud Security Engineer

JMJ PHILLIP • Turkey (TX)

On-site
USD 150,000 - 200,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc. • Dallas (TX)

On-site
USD 90,000 - 130,000
Cybersecurity Engineer
Cybersecurity Engineer

Golden Nugget Las Vegas • Houston (TX)

On-site
USD 90,000 - 130,000
Multiple benefit plans
Paid Time Off
401K
+5
Security Engineer II
Security Engineer II

Healthcare Outcomes Performance Co. (HOPCo) • Phoenix (AZ)

On-site
USD 120,000 - 170,000
Information Security Engineer (IS Engr I) - REMOTE
Information Security Engineer (IS Engr I) - REMOTE

Net Health • Pittsburgh

Remote
USD 66,000 - 82,000
Sr. Security Engineer
Sr. Security Engineer

HKS, Inc • Dallas (TX)

On-site
USD 120,000 - 160,000
Senior IT Systems Engineer
Senior IT Systems Engineer

NightDragon Acquisition Corp. • United States

Remote
USD 142,000 - 162,000
Inclusive team
Growth opportunities
Innovative culture
+2
Senior IT Systems Engineer
Senior IT Systems Engineer

horizon3ai • United States

Remote
USD 142,000 - 162,000
Inclusive Team
Growth Opportunities
Hybrid & Remote Work
+3