Cybersecurity Sr Engineer

CBRE Group, Inc.

Richardson (TX)

On-site

USD 180,000 - 240,000

Full time

8 days ago

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

CBRE Group, Inc. is seeking a senior security professional to design, build, and operate agentic AI workflows and automation across the Global Cyber Security Office.

This role focuses on integrating security into enterprise workflows, implementing least-privilege access, and maintaining observability for AI-driven security actions. You will collaborate with Compliance, Risk, Audit, Legal, and platform teams to shape a progressive DevSecOps culture, mentoring engineers and contributing to

Qualifications

  • Bachelor's degree in a related field plus a minimum of 3 years related work experience; or equivalent combination.
  • Advanced experience designing and operating automation or agentic AI workflows, including agent frameworks or orchestration and integration with LLM or model services.
  • Working knowledge of the Model Context Protocol (MCP) specification and security implications of agentic AI tool-use patterns.
  • Intermediate experience administering Kubernetes and managing manifests with Helm.
  • Intermediate experience with AWS services IAM, KMS, EC2, EKS, S3, Route53, CloudFront, ACM, Secrets Manager.
  • Intermediate experience with other cloud providers (GCP, Alibaba, Azure).
  • Intermediate experience with Terraform.
  • Linux systems administrator skills.
  • DevOps/CICD pipelines experience (GitHub Actions, GitLab, Jenkins, Concourse).
  • Configuration management tools (Chef, Ansible, SaltStack).
  • Advanced scripting in Python, Bash, Ruby, Go.
  • RDBMS and vector storage familiarity (Postgres, MySQL, MS SQL, vector stores).
  • Git/GitHub source control understanding.
  • Infrastructure as Code familiarity.
  • Experience with Microsoft ecosystem, AD/LDAP.
  • API development and backend integration experience.
  • Microservice design/development experience.
  • Familiarity with AI security frameworks (NIST AI RMF, OWASP LLM Top 10, MITRE ATLAS).
  • Understanding of prompt injection, unsafe tool use, and data exfiltration risks.

Responsibilities

  • Design, build, and operate agentic AI workflows and automation that orchestrate LLMs, tools, and enterprise systems to reduce manual toil.
  • Develop and maintain MCP servers, tools, and agent integrations with least-privilege tool permission scoping and input/output validation.
  • Integrate agentic workflows with approved LLM/model services through the enterprise API gateway with access control and policy enforcement.
  • Establish evaluation, testing, and runtime observability for agent behavior and incident response for AI security events.
  • Ensure operational integrity of Global Cyber Security Office DevSecOps hosting, tools, pipelines, and third-party apps.
  • Administer and troubleshoot AWS EKS Kubernetes clusters, multi-region failover, and disaster recovery plans.
  • Triage, debug, and perform root cause analysis across cloud services (IAM, Compute, Storage, DNS, Certificates, Secrets).
  • Manage secrets lifecycle with least-privilege access and rotation for machine and human identities.
  • Develop automation and integrations for backend systems using Python, Bash, Ruby, Go with modular, testable designs.
  • Automate metric collection from DevSecOps tools and ingest AppSec logs using Logstash, Datadog, Prometheus.
  • Track and report SLOs/SLIs against SLAs for internal customer services and the agentic platform.
  • Collaborate with platform, app, and security teams to operationalize secure agentic patterns and mentor engineers.
  • Contribute to policy and governance for agentic AI aligning with NIST/OWASP/MITRE frameworks.
  • Develop reporting on operational excellence and product performance metrics.
  • On-call rotation to ensure uptime and function of internal services.
  • Mentor team members and model desired behaviors aligned with CBRE values.
  • Other duties as assigned.

Skills

Automation workflows
Agentic AI
Kubernetes
AWS
DevSecOps
Python
Go
Terraform
Security governance

Education

Bachelor's degree in related field

Tools

Helm
Terraform
GitHub Actions

Job description

About the role

The mission of the individual in this role is to leverage their strong understanding of enterprise-level knowledge and/or expert knowledge to mitigate cyber security risk with a focus on agentic workflow engineering. They will actively work with the CBRE business, Digital & Technology and other partner organizations (Compliance, Risk Mgmt., Audit, & Legal) to seamlessly integrate security processes, tools, and people into the business culture providing a holistic security ecosystem, driving continuous improvements and seamless protection and monitoring capabilities globally. Leads and executes on complex initiatives that drive problem resolution, designing and operating the secure agentic AI workflows, automation, and platform services that underpin the Global Cyber Security Office DevSecOps ecosystem. As a senior member on the team, this individual will help shape the direction of a progressive product team with a mindset toward being agile and solving problems iteratively.

Experience in all skills listed is not necessary to be qualified for the position. If you have relevant similar experience, we still want to talk to you.

What you'll do
  • Design, build, and operate agentic AI workflows and automation that orchestrate LLMs, tools, and enterprise systems to reduce manual toil across the Global Cyber Security Office, applying secure-by-design patterns and human approval gates for high-impact actions.
  • Develop and maintain Model Context Protocol (MCP) servers, tools, and agent integrations, enforcing least-privilege tool permission scoping, input and output validation, and guardrails against prompt injection, unsafe tool use, and data exfiltration.
  • Integrate agentic workflows with approved LLM and model services through the enterprise API gateway, implementing identity-aware access control, output filtering, and policy enforcement for responsible AI use.
  • Establish evaluation, testing, and runtime observability for agent behavior, including tracing, logging, and metrics that make agent decisions auditable and support incident response for AI security events.
  • Ensure operational integrity of Global Cyber Security Office DevSecOps application hosting and infrastructure, including hosting security tools and scanning agents, the internal security pipeline, and third-party vendor applications.
  • Administer and troubleshoot AWS EKS Kubernetes clusters, managing manifest and Helm chart lifecycle, global multi-region cluster failover, and disaster recovery plans.
  • Triage, debug, and perform root cause analysis across commonly used cloud provider services such as IAM, Compute, Storage, DNS, Certificate, and Secrets Management.
  • Build and maintain automation and governance around organizational secrets management, enforcing least-privilege access, rotation, and lifecycle controls for the machine and human identities used by agents and services.
  • Develop bespoke automation and integrations for backend systems using languages such as Python, Bash, Ruby, and/or Go, favoring modular, testable, configuration-driven, and idempotent designs.
  • Automate the collection of metrics from DevSecOps tools and implement AppSec log ingestion at scale using tools such as Logstash, Datadog, and Prometheus.
  • Track, compare, and report SLOs and SLIs against defined SLAs to ensure the reliability and availability of critical internal customer services, including the agentic platform.
  • Partner with platform, application, and security teams to operationalize secure agentic patterns, drive resolution of security findings, and mentor engineers on safe agent design and DevSecOps practices.
  • Contribute to policy, standards, and governance for agentic AI and automation, aligning controls with frameworks such as NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS.
  • Develop reporting exhibiting operational excellence and product performance metrics.
  • On-call rotation for ensuring uptime, and functionality of critical internal customer services.
  • Have well founded opinions and be willing to express your disagreement when something doesn't pass the 'smell test' for you.
  • Other duties as assigned.
  • Mentors and coaches team members to further develop competencies. Leads by example and models behaviors that are consistent with the company's values.
What you'll need
  • Bachelor's degree (BA/BS) in a related field of work plus a minimum of 3 years related work experience; or equivalent combination of education and experience (equivalent work experience = 2 years of related experience for every year of higher level education).
  • Advanced experience designing and operating automation or agentic AI workflows, including agent frameworks or orchestration and integration with LLM or model services
  • Working knowledge of the Model Context Protocol (MCP) specification, including its primitive types and the security implications of agentic AI tool-use patterns
  • Intermediate experience administering Kubernetes and managing manifests with Helm
  • Intermediate experience solutioning with AWS services such as IAM, KMS, EC2, EKS, S3, Route53, CloudFront, ACM, Secrets Manager
  • Intermediate experience solutioning and working with one or more other cloud providers aside from AWS such as GCP, Alibaba, Azure
  • Intermediate experience writing, and running Terraform
  • Intermediate Linux systems administrator experience or equivalent skills
  • Intermediate experience or equivalent skills with DevOps or CICD pipelines (GitHub Actions, GitLab, Jenkins, Concourse, etc.)
  • Intermediate experience with configuration management tools such as Chef, Ansible, or SaltStack, with a strong preference for Chef
  • Advanced experience automating multiple systems using functional and object-oriented languages such as Python, Bash, Ruby, and Go
  • Intermediate experience with RDBMS databases such as Postgres, MySQL, and MS SQL Server, and with vector storage solutions
  • Intermediate understanding of source control management and practices using Git, and GitHub
  • Intermediate understanding of Infrastructure as Code
  • Experience with the Microsoft ecosystem
  • Directory services like AD, and LDAP
  • Understanding and experience with backend software application development, including API development, and integrating with third party sources
  • Understanding of system integration design patterns at scale with experience in microservice design or development
  • Familiarity with AI security frameworks and guidance such as NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
  • Understanding of prompt injection, unsafe tool use, and data exfiltration risks in agentic systems, and the defense-in-depth controls used to mitigate them
  • Strong written and verbal communication skills with the ability to explain complex cybersecurity and agentic AI concepts clearly across technical and business stakeholders. Able to document standards, author technical reports, and collaborate effectively across engineering, operations, and compliance teams.
  • Strong analytical and decision-making skills with experience solving complex cybersecurity problems. Able to evaluate competing technical solutions, apply risk-based reasoning, and deliver strategies that improve enterprise security posture and operational resilience.
Why CBRE

When you join CBRE, you become part of the global leader in commercial real estate services and investment that helps businesses and people thrive. We are dynamic problem solvers and forward-thinking professionals who create significant impact. Our collaborative culture is built on our shared values — respect, integrity, service and excellence — and we value the diverse perspectives, backgrounds and skillsets of our people. At CBRE, you have the opportunity to chart your own course and realize your potential. We welcome all applicants.

Our Values in Hiring

At CBRE, we are committed to fostering a culture where everyone feels they belong. We value diverse perspectives and experiences, and we welcome all applications.

Disclaimers

Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

Applicant AI Use Disclosure

We value human interaction to understand each candidate's unique experience, skills and aspirations. We do not use artificial intelligence (AI) tools to make hiring decisions, and we ask that candidates disclose any use of AI in the application and interview process.

About CBRE Group, Inc.

CBRE Group, Inc. (NYSE:CBRE), a Fortune 500 and S&P 500 company headquartered in Dallas, is the world’s largest commercial real estate services and investment firm (based on 2024 revenue). The company has more than 140,000 employees (including Turner & Townsend employees) serving clients in more than 100 countries. CBRE serves clients through four business segments: Advisory (leasing, sales, debt origination, mortgage serving, valuations); Building Operations & Experience (facilities management, property management, flex space & experience); Project Management (program management, project management, cost consulting); Real Estate Investments (investment management, development). Please visit our website at www.cbre.com.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Cybersecurity Sr Engineer
Cybersecurity Sr Engineer

CBRE • Richardson (TX)

On-site
USD 140,000 - 190,000
VP, Head of BOE Data Engineering
VP, Head of BOE Data Engineering

CBRE • Richardson (TX)

On-site
USD 170,000 - 210,000
Principal AI Engineer
Principal AI Engineer

CBRE • Richardson (TX)

On-site
USD 180,000 - 240,000
Manager, AI Visibility & Content Discoverability
Manager, AI Visibility & Content Discoverability

CBRE • New York (NY)

On-site
USD 100,000 - 115,000
401K
Dental insurance
Health insurance
+2
Associate Director, Business Process Transformation - Dallas
Associate Director, Business Process Transformation - Dallas

CBRE Group, Inc. • Dallas (TX)

Hybrid
USD 140,000 - 158,000
Manager, AI Visibility & Content Discoverability
Manager, AI Visibility & Content Discoverability

CBRE • Baltimore (MD)

On-site
USD 100,000 - 115,000
401(k) plan
Dental insurance
Health insurance
+2
Associate Director, Business Process Transformation - Dallas
Associate Director, Business Process Transformation - Dallas

CBRE • Dallas (TX)

Hybrid
USD 140,000 - 158,000
Performance bonus
Data Center Manager (Electrical/Mechanical Background Required
Data Center Manager (Electrical/Mechanical Background Required

CBRE • Allen (TX)

On-site
USD 90,000 - 130,000
Senior Principal AI/ML Engineer
Senior Principal AI/ML Engineer

CBRE • Atlanta (GA)

On-site
USD 235,000 - 255,000
Strategic Governance Engagement Director
Strategic Governance Engagement Director

CBRE • United States

On-site
USD 150,000 - 210,000