Security Engineer

ClarkDietrich Building Systems

Olde West Chester (OH)

Hybrid

USD 110,000 - 150,000

Full time

48 hours ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Benefits offered by this job

Full benefits package
401(k) with company match
Tuition reimbursement
Professional certification support

Job summary

ClarkDietrich Building Systems is hiring a Security Engineer in West Chester, OH, with a hybrid schedule. You will design, implement, and operate security controls across identity, endpoints, networks, cloud, and AI-enabled systems to reduce cyber risk while enabling technology use.

You will partner with infrastructure, application, data, privacy, and business teams to build resilient services, detect threats, and translate findings into practical actions.

Qualifications

  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field; or equivalent relevant experience.
  • Five or more years of progressive IT or cybersecurity experience with hands-on security engineering, architecture, operations, or incident response.
  • Demonstrated experience securing cloud platforms, identity, endpoints, networks, applications/APIs, SaaS, data, or AI-enabled systems.

Responsibilities

  • Design secure platforms and implement preventive, detective, and recovery controls across hybrid infrastructure, SaaS, cloud, endpoints, networks, and business apps.
  • Strengthen identity through MFA, Conditional Access, least privilege, and lifecycle governance.
  • Secure cloud-native workloads; assess configurations, APIs, containers, serverless, and CI/CD pipelines.
  • Identify vulnerabilities, misconfigurations, and risk; drive verified remediation with asset owners.
  • Embed security by design via architecture reviews and threat modeling for new systems and changes.
  • Govern AI security by managing sanctioned AI services, data flows, access, and lifecycle.

Skills

Identity and access management
Cloud security
Threat modeling
Automation (PowerShell/Python)
Incident response
Security architecture
SIEM/EDR tooling

Education

Bachelor's degree in cybersecurity, computer science, information systems, engineering, or related field

Tools

SIEM
EDR
Cloud security tooling
Posture management
Infrastructure as code

Job description

Description

Are you interested in working for a company that fosters growth opportunities, community involvement and a team oriented atmosphere? ClarkDietrich fosters a work-life balance and offers competitive compensation and benefits. Join a team that is STRONGER THAN STEEL, by applying to become a Security Engineer at our West Chester, OH location.

Position Summary

The Security Engineer designs, implements, and operates security controls across identity, endpoints, networks, cloud services, applications, data, and AI-enabled systems. This hands-on role reduces cyber risk while enabling the responsible use of modern technology. The engineer partners with infrastructure, application, data, legal, privacy, and business teams to build resilient services, detect and respond to threats, and translate technical findings into practical action.

Key Responsibilities
Security architecture and engineering
  • Engineer secure platforms. Design and improve preventive, detective, and recovery controls across hybrid infrastructure, SaaS, cloud platforms, endpoints, networks, and business applications.
  • Strengthen identity. Implement MFA, Conditional Access, least privilege, privileged-access management, lifecycle governance, service-identity controls, and periodic access reviews.
  • Secure cloud-native workloads. Assess cloud configurations, APIs, containers, serverless services, infrastructure as code, CI/CD pipelines, secrets, and software supply-chain dependencies.
  • Manage exposure. Identify and prioritize vulnerabilities, attack paths, misconfigurations, unsupported assets, and internet-facing risk; partner with owners through verified remediation.
  • Embed security by design. Perform architecture reviews and threat modeling for new systems, integrations, vendors, and major changes; define proportionate control requirements before production.
AI and emerging-technology security
  • Govern enterprise AI use. Maintain visibility into approved and unapproved AI services, models, agents, copilots, plugins, data connections, and business use cases; help teams choose secure, sanctioned paths.
  • Secure AI systems end to end. Review data flows, model and API access, retrieval pipelines, vector stores, prompts, tools, memory, outputs, and human-approval points across the AI lifecycle.
  • Threat-model AI-specific abuse. Evaluate prompt injection, sensitive-data disclosure, insecure output handling, model or data poisoning, excessive agency, identity abuse, supply-chain compromise, denial of service, and unsafe tool execution.
  • Implement AI guardrails. Apply strong authentication, scoped authorization, data classification and DLP, secrets management, content filtering, tool isolation, rate limits, audit logging, monitoring, and human-in-the-loop controls.
  • Validate before and after launch. Coordinate security testing, adversarial evaluation, red teaming, misuse-case testing, and ongoing monitoring for AI applications and material model, prompt, tool, or data changes.
  • Enable safe adoption. Translate AI policy into usable engineering standards and employee guidance; investigate shadow-AI and risky data-handling patterns without defaulting to indiscriminate blocking.
  • Use AI responsibly in security operations. Apply automation and AI-assisted analysis to accelerate triage, investigation, detection development, and reporting while preserving evidence, access controls, validation, and accountable human decisions.
Detection, incident response, and resilience
  • Improve detection. Engineer useful telemetry and detections across identity, endpoint, network, cloud, email, applications, data, and AI services; tune alerting to improve signal quality.
  • Respond to incidents. Lead or support triage, containment, eradication, recovery, evidence preservation, communications, and post-incident improvement, including identity and token compromise.
  • Automate repeatable work. Build scripts, queries, playbooks, and integrations that improve investigation speed, control consistency, and operational visibility.
  • Protect recovery paths. Validate hardening, patching, backup security, recovery procedures, and disaster-recovery assumptions through exercises and technical testing.
  • Share actionable intelligence. Produce decision-ready metrics and concise reporting on exposure, incidents, control health, AI risk, remediation performance, and residual risk.
Governance and collaboration
  • Maintain security standards, diagrams, procedures, playbooks, risk decisions, and operational records that are clear enough for another engineer to use.
  • Support audits and controls related to Japanese Sarbanes-Oxley (J-SOX), change management, privacy, third-party risk, and applicable company requirements.
  • Evaluate security and AI vendors, permission requests, data usage, architectural fit, contractual security commitments, and operational ownership.
  • Communicate risk in business terms, collaborate across technical and nontechnical teams, and provide targeted security guidance and awareness.
  • Participate in security projects, an on-call rotation, and related responsibilities as business and threat conditions evolve.
Requirements
REQUIRED QUALIFICATIONS
  • Bachelor's degree in cybersecurity, computer science, information systems, engineering, or a related field, or equivalent relevant experience.
  • Five or more years of progressive IT or cybersecurity experience, including substantial hands‑on responsibility for security engineering, architecture, operations, or incident response.
  • Demonstrated experience securing at least three of the following domains: cloud platforms, enterprise identity, endpoints, networks, applications/APIs, SaaS, data platforms, or AI-enabled systems.
  • Strong knowledge of identity and access management, modern authentication, network and web protocols, operating-system security, logging, vulnerability management, and secure configuration practices.
  • Experience with SIEM, endpoint detection and response, cloud-security or posture-management tooling, and investigation using structured queries and multiple telemetry sources.
  • Ability to automate tasks and analyze data using PowerShell, Python, APIs, infrastructure as code, or comparable tools.
  • Working knowledge of AI and generative-AI architecture, including model APIs, retrieval-augmented generation, agents and tool use, enterprise copilots, and common AI security failure modes.
  • Experience applying threat modeling, security testing, risk assessment, and secure-development practices to new technology or business applications.
  • Clear written and verbal communication, sound judgment, and the ability to coordinate effectively during ambiguous or high-pressure events.
Preferred Qualifications
  • Experience with Microsoft 365, Microsoft Entra, Microsoft Defender, SharePoint, Azure, AWS, or comparable enterprise platforms.
  • Hands‑on experience assessing or operating generative-AI applications, enterprise copilots, AI agents, model gateways, or AI security‑posture and monitoring capabilities.
  • Experience in a manufacturing, industrial, distributed‑site, OT/IoT, or regulated environment.
  • Familiarity with NIST Cybersecurity Framework, NIST AI Risk Management Framework, CIS Controls, ISO 27001, secure software-development practices, and recognized AI/LLM security guidance.
  • Relevant certification such as CISSP, CCSP, GIAC, Security+, a cloud‑security certification, or equivalent demonstrated capability.
What Success Looks Like
  • Critical identity, cloud, endpoint, network, application, data, and AI risks have clear owners, realistic priorities, and verified remediation.
  • New AI use cases reach production through a repeatable security‑review process with documented data boundaries, permissions, abuse cases, guardrails, logging, and accountable approval.
  • Detection and incident‑response workflows produce faster, more reliable decisions with less avoidable alert noise and stronger evidence preservation.
  • Security controls are measurable, documented, supportable, and resilient to personnel, platform, and threat changes.
  • Leaders receive concise reporting that connects engineering activity to business resilience, compliance, responsible AI adoption, and residual risk.
WORK ENVIRONMENT

This position may require regular work in an office environment, with a hybrid schedule available upon approval. The role may also join an on‑call rotation and require occasional travel or work in data‑center, manufacturing, or network environments. Reasonable accommodation may be provided to enable qualified individuals to perform the essential functions.

Clarkdietrich Benefits Include
  • Full benefits package (Medical, Dental, Vision, Flexible Spending Accounts and Life Insurance)
  • 401(k) with company match
  • Annual Incentive
  • Paid Time Off
  • Tuition Reimbursement
  • Professional Certification Reimbursement Program
  • Community Service Day
Get your free, confidential resume review.

or drag and drop your file here.

Similar jobs

Similar jobs worth comparing

Security Engineer
Security Engineer

Socket.dev • Olde West Chester (OH)

Hybrid
USD 110,000 - 150,000
Full benefits package (medical, dental
401(k) with company match
Annual incentive
+2
Security Engineer: AI & Cloud Defense Architect
Security Engineer: AI & Cloud Defense Architect

Socket.dev • Olde West Chester (OH)

Hybrid
USD 110,000 - 150,000
Full benefits package (medical, dental
401(k) with company match
Annual incentive
+2
Security & IT Manager
Security & IT Manager

Clark • New York (NY)

On-site
USD 120,000 - 160,000
Healthcare
Unlimited PTO
Equity
+3
Security Engineer
Security Engineer

xbowcareers • United States

Remote
USD 140,000 - 210,000
Competitive salary
Equity or incentive plan
401k plan
Security Engineer: AI, Cloud & Resilient Defense Architect
Security Engineer: AI, Cloud & Resilient Defense Architect

ClarkDietrich Building Systems • Olde West Chester (OH)

Hybrid
USD 110,000 - 150,000
Full benefits package
401(k) with company match
Tuition reimbursement
+1
Cybersecurity Engineer
Cybersecurity Engineer

OneImaging • Bellevue (WA)

On-site
USD 100,000 - 130,000
Health Care Plan
Retirement Plan
Paid Time Off
+2
Senior Cybersecurity Analyst
Senior Cybersecurity Analyst

ISO New England Inc. • Holyoke (MA)

On-site
USD 135,000 - 168,000
Performance bonus
Enhanced 401(k) and financial planning
Tuition reimbursement
+6
Remote Senior Cybersecurity Engineer - Build & Own Controls
Remote Senior Cybersecurity Engineer - Build & Own Controls

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000
Security Engineer
Security Engineer

Insight Global • Naperville (IL)

On-site
USD 100,000 - 130,000
Sr. CyberSecurity Engineer
Sr. CyberSecurity Engineer

Think Consulting • Columbus (OH)

On-site
USD 140,000 - 190,000