Lead Engineer, Infrastructure Security

Randstad Digital Americas

Newport Beach (CA)

On-site

USD 133,000 - 185,000

Full time

2 days ago
Be an early applicant

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical
Prescription
Dental
Vision
AD&D
Life insurance offerings
Short-term disability
401K plan

Job summary

Randstad Digital Americas is seeking a Lead Security Infrastructure Engineer to join our team in Newport Beach, California. This permanent role offers a salary between $133,000 and $185,000 per year and a standard 8am–5pm schedule, requiring a Bachelor’s degree.

You will own end-to-end remediation across Azure, hybrid/on‑prem, network and endpoints, partner with GCS, translate findings into sprint-ready work, mentor engineers, and drive security maturity and compliance with NIST 800-53, CIS

Qualifications

  • 8+ years in infrastructure security engineering.
  • Bachelor's degree in CS, engineering, or related field.
  • Certs: CISSP, CISM, CISA or GIAC/SANS.
  • Experience with NIST 800-53, CIS Benchmarks, PCI-DSS, SOC 2.
  • Hands-on Azure security with Defender for Cloud and Entra ID.

Responsibilities

  • Serve as liaison to GCS and drive remediation alignment.
  • Translate security findings into Agile-ready Jira work.
  • Lead hands-on remediation across Azure, hybrid, and endpoints.
  • Mentor Infrastructure engineers on secure configuration.
  • Ensure changes comply with change controls and SLAs.
  • Drive security maturity metrics and audit readiness.

Skills

Azure
Jira
Security leadership
Cloud Security
Automation / IaC
Vulnerability management
Incident response

Education

Bachelor's degree in CS, engineering, or related

Tools

Defender for Cloud
Entra ID
Microsoft Security Baselines
Azure environments
Network security
Configuration management

Job description

Job Summary

Our client is looking for a Lead Security Infrastructure Engineer to join their team.

location: Newport Beach, California
job type: Permanent
salary: $133,000 - 185,000 per year
work hours: 8am to 5pm
education: Bachelors

Responsibilities
  • Serve as the dedicated, named liaison to GCS - including Security Engineering & Operations, IAM, Software & Product Security, Data Governance, and Digital Fraud teams - consuming security findings, audit results, and risk-prioritized remediation requirements defined by GCS.
  • Maintain a continuous, standing engagement cadence with GCS leadership to ensure Infrastructure's Cloud Engineering (Core/On-Prem and Cloud) and Networking teams are aligned to current GCS priorities, SLAs, and control objectives.
  • Translate GCS inputs into Agile‑ready Jira work (stories, tasks, acceptance criteria) aligned to Infrastructure sprint planning.
  • Execute hands‑on remediation for high‑risk or complex findings across Azure, hybrid/on‑prem, network, and endpoint environments.
  • Provide direct production change execution for security remediations, following change controls and minimizing business impact.
  • Guide and mentor Infrastructure engineers on secure configuration, remediation techniques, and security best practices.
  • Lead remediation efforts across Platform Engineering, Network & Edge, and Client Services.
  • Security Partnership & Translation: Ability to translate GCS findings and priorities - spanning Security Engineering & Operations, IAM, Software & Product Security, Data Governance, and Digital Fraud - into Infrastructure execution.
  • Agile Enablement: Strong experience converting non‑Agile security inputs into sprint‑ready work items.
  • Hands‑On Remediation: Expert‑level ability to remediate security issues across Azure, hybrid, network, and endpoint platforms.
  • Risk Alignment: Executes remediation strictly aligned to GCS's risk framework and SLAs.
  • Technical Leadership: Guides teams on secure practices and serves as escalation point for complex remediation.
  • Automation Mindset: Uses scripting, IaC, and configuration management to scale remediation and reduce manual effort.
  • Production Discipline: Comfortable making high‑impact production changes safely and responsibly.
  • Vendor & Contractor Oversight: Directs external remediation resources with clear standards and quality control.
  • Communication: Clear, trusted communicator with Infrastructure leadership and GCS.
  • Accountability: Owns outcomes-backlog reduction, compliance metrics, and security maturity improvement.
  • Vulnerability Management & Patch Lifecycle: Owns the end-to‑end finding-to-close process for infrastructure; tracks remediation SLAs, drives KPI improvement, and maintains an aging backlog with clear accountability.
  • Cloud Security Posture: Hands‑on proficiency securing Azure environments using Defender for Cloud, Entra ID conditional access, and Microsoft security baselines; able to assess and remediate cloud misconfigurations independently.
  • Compliance Frameworks: Working knowledge of NIST 800-53, CIS Benchmarks, PCI‑DSS, and SOC 2; able to map infrastructure controls to framework requirements and produce audit‑ready evidence.
Qualifications
  • Must Have Skills - looking for 8+ years ideally
  • Bachelor's - in CS, engineering, or related
  • Certs - CISSP, CISM, CISA, or GIAC / SANS (e.g. GCED, GPEN, GCIH) relevant to infrastructure security
  • Working knowledge of NIST 800-53, CIS Benchmarks, PCI‑DSS, and SOC 2; able to map infrastructure controls to framework requirements and produce audit‑ready evidence.
  • Hands‑on proficiency securing Azure environments using Defender for Cloud, Entra ID conditional access, and Microsoft security baselines; able to assess and remediate cloud misconfigurations independently.
  • Ability to translate GCS findings and priorities - spanning Security Engineering & Operations, IAM, Software & Product Security, Data Governance, and Digital Fraud - into Infrastructure execution.
  • Expert‑level ability to remediate security issues across Azure, hybrid, network, and endpoint platforms.
Skills

Agile,CIS Benchmarks,Cloud,Cloud Security Posture,Cloud Engineering,configuration management,control objectives,Cybersecurity Services,Data Governance,IAM,Computer Science,Jira,Azure,Azure environments,Microsoft security,PCI‑DSS,sprint planning,Product Security,Vulnerability Management,Communication,communicator,dedicated,leadership,technical liaison,Accountability,business impact,acceptance criteria,conditional access,audit,Automation,Partnership,CISM,CISA,CISSP,change controls,Client Services,executable,remediation techniques,GCIH,secure configuration,Infrastructure Security,Infrastructure,KPI,mentors,mentor,NIST 800-53,Platform Engineering,quality control,compliance metrics,risk,security,Security Engineering,security best practices,technical leadership

Equal Opportunity Employer

Equal Opportunity Employer: Race, Color, Religion, Sex, Sexual Orientation, Gender Identity, National Origin, Age, Genetic Information, Disability, Protected Veteran Status, or any other legally protected group status.

At Randstad Digital, we welcome people of all abilities and want to ensure that our hiring and interview process meets the needs of all applicants. If you require a reasonable accommodation to make your application or interview experience a great one, please contact HRsupport@randstadusa.com.

Pay offered to a successful candidate will be based on several factors including the candidate's education, work experience, work location, specific job duties, certifications, etc. In addition, Randstad Digital offers a comprehensive benefits package, including:

  • medical
  • prescription
  • dental
  • vision
  • AD&D
  • life insurance offerings
  • short-term disability
  • 401K plan

(all benefits are based on eligibility).

This posting is open for thirty (30) days.

Qualified applicants in San Francisco with criminal histories will be considered for employment in accordance with the San Francisco Fair Chance Ordinance.

Qualified applicants with arrest or conviction records will be considered for employment in accordance with the Los Angeles County Fair Chance Ordinance for Employers and the California Fair Chance Act.

We will consider for employment all qualified Applicants, including those with criminal histories, in a manner consistent with the requirements of applicable state and local laws, including the City of Los Angeles' Fair Chance Initiative for Hiring Ordinance.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Sr. Cloud Security Engineer
Sr. Cloud Security Engineer

LHH • San Francisco (CA)

Hybrid
USD 180,000 - 250,000
Medical, dental, and vision insurance
401(k) plan with match
19 days of PTO + 11 paid holidays
+1
Azure Security Consultant
Azure Security Consultant

Randstad Digital Americas • Conyers (GA)

Remote
Comprehensive benefits package
401(k) plan (based on eligibility)
Medical, dental, and vision insurance
Senior Cyber Security Engineer
Senior Cyber Security Engineer

Cloud Software Group • San Ramon (CA)

On-site
USD 160,000 - 241,000
Global Cybersecurity Engineer
Global Cybersecurity Engineer

Ledgent Technology • Manassas (VA)

Hybrid
USD 140,000 - 145,000
Medical insurance
Dental insurance
Vision insurance
+5
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing • San Francisco (CA)

Hybrid
USD 120,000 - 180,000
Sr. Systems Engineer
Sr. Systems Engineer

Jobs via Dice • Trenton (NJ)

Remote
USD 110,000 - 120,000
Medical benefits
401K plan
Comprehensive health insurance
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing • Salt Lake City (UT)

Hybrid
USD 100,000 - 140,000
Hybrid work model
Senior Cloud Platform Engineer (contract)
Senior Cloud Platform Engineer (contract)

Capgemini • Charlotte (NC)

On-site
Medical benefits
Dental benefits
Vision benefits
+1
IT & Security Engineer
IT & Security Engineer

Ultimate Staffing Services • San Francisco (CA)

On-site
USD 130,000 - 180,000
Information Security Engineer
Information Security Engineer

Randstad Digital • Charlotte (NC)

On-site
USD 67,000 - 74,000
Medical insurance
Vision insurance
401K plan