Senior Security Engineer

KPA

Lafayette (CO)

On-site

USD 110,000 - 130,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Job summary

KPA is seeking a Senior Security Engineer to own security platforms, cloud security, identity, and automation. The role requires a hands-on engineer who can lead complex projects and collaborate with IT Operations and DevOps to improve KPA's security posture.

The successful candidate will manage vulnerability, endpoint, and identity security; lead incident response; and drive compliance with SOC 2 and NIST CSF, while securing Azure, AWS, and M365 environments.

Qualifications

  • 5+ years in security engineering or related senior role.
  • Experience with Azure, AWS, Microsoft 365 and identity security.
  • Familiarity with CI/CD, Kubernetes, container security, and DevSecOps.
  • Scripting/automation in PowerShell or Python; REST APIs.
  • Experience with SOC 2 and NIST CSF or equivalent.
  • Certifications such as CISSP, CCSP, AWS Security are preferred.
  • Bachelor’s degree in Computer Science, IT or Cybersecurity or equivalent experience.

Responsibilities

  • Own enterprise security platforms and related technologies (CrowdStrike, Rapid7, Cisco, KnowBe4).
  • Lead vulnerability management, endpoint security, identity security, and privileged access.
  • Own security incident response, investigations, containment and post-incident reviews.
  • Maintain SOC 2 controls, security audits, and compliance initiatives.
  • Manage cloud/network security and secure cloud connectivity across Azure, AWS, M365.
  • Strengthen identity governance across Entra ID, AWS Identity Center, Auth0, SSO, PIM.
  • Integrate security into CI/CD pipelines and IaC, containers, Kubernetes, and cloud workloads.
  • Improve cloud security posture management, logging, detection, and remediation.
  • Manage email security (Microsoft 365, SendGrid, SES) and phishing protection.
  • Build security automation using PowerShell, Python, Graph, REST, and AI-assisted tooling.
  • Oversee vendor risk management and third-party security assessments.
  • Develop and enforce security policies, standards and procedures.
  • Support AI security and governance initiatives and security architecture reviews.

Skills

Security engineering
Cloud security
Identity security
Vulnerability management
CI/CD security
Scripting (PowerShell, Python)
DevSecOps
SOC 2/NIST CSF
Zero trust
Communication & leadership

Education

Bachelor's degree in Computer Science / Cybersecurity

Tools

CrowdStrike
Rapid7 InsightIDR
Rapid7 InsightVM
Rapid7 InsightAppSec
Cisco Umbrella
Cisco Duo
KnowBe4
Cisco Meraki
Microsoft Entra ID
AWS Identity Center
Auth0
Snyk

Job description

Position Description

KPA is seeking a Senior Security Engineer to serve as the senior technical counterpart to the Director of Security & Technology. This role owns KPA's security platforms, cloud security, identity, automation, and technical security initiatives. The ideal candidate is a hands‑on security engineer with strong cloud and infrastructure experience who can independently lead complex security projects, partner effectively with IT Operations and DevOps, and continuously improve KPA's security posture.

KPA is seeking a Senior Security Engineer to serve as the senior technical counterpart to the Director of Security & Technology. This role owns KPA's security platforms, cloud security, identity, automation, and technical security initiatives. The ideal candidate is a hands‑on security engineer with strong cloud and infrastructure experience who can independently lead complex security projects, partner effectively with IT Operations and DevOps, and continuously improve KPA's security posture.

Responsibilities
  • Own KPA's enterprise security platforms, including CrowdStrike, Rapid7 (InsightIDR, InsightVM, InsightAppSec, MDR), Cisco Umbrella, Cisco Duo, KnowBe4, and related technologies.
  • Lead vulnerability management and remediation, endpoint security, identity security, privileged access, penetration testing, and security hardening initiatives.
  • Lead security incident response, investigations, containment, remediation, and post‑incident reviews.
  • Own the ongoing operation of SOC 2 controls, security audit requirements, and technical compliance initiatives.
  • Own Cisco Meraki security, VPN infrastructure, network security controls, and secure cloud connectivity.
  • Secure Azure, AWS, Microsoft 365, Entra ID, AWS Identity Center, Auth0, and cloud‑native workloads using modern security best practices.
  • Administer and improve identity governance across Microsoft Entra ID, Cisco Duo, AWS Identity Center, Auth0, SSO, SCIM, Conditional Access, PIM, privileged accounts, service accounts, and authentication architecture.
  • Partner with DevOps to integrate security into CI/CD pipelines, Infrastructure as Code, containers, Kubernetes, and cloud workloads, including SAST, DAST, Snyk, and other application security technologies.
  • Own and continually improve KPA's cloud security posture management, workload protection, identity controls, logging, alerting, detection engineering, and remediation processes.
  • Own email security across Microsoft 365, SendGrid, Amazon SES, SPF, DKIM, DMARC, and phishing protection.
  • Build security automation using PowerShell, Python, Microsoft Graph, REST APIs, and AI‑assisted development.
  • Lead security assessments for new vendors, SaaS platforms, cloud services, and third‑party integrations; administer third party vendor management (TPVM) and support ongoing vendor risk management.
  • Administer and improve KPA's security awareness program, security policies, standards, and technical procedures.
  • Support AI security and governance initiatives, including ChatGPT Enterprise, Claude, MCP, and emerging AI technologies.
  • Support security architecture reviews for new cloud services, platforms, integrations, and technical initiatives.
  • Proactively identify security gaps, technical debt, and opportunities to improve KPA's security posture through automation, AI, and modern engineering practices.
Qualifications
  • 5+ years of experience in security engineering, cloud security, infrastructure security, or a related senior technical role.
  • Strong knowledge of identity security, endpoint security, vulnerability management, network security, incident response, and zero trust principles.
  • Experience securing Azure, AWS, Microsoft 365, Entra ID, Windows, and Linux.
  • Familiarity with CI/CD pipelines, Kubernetes, container security, application security scanning, and DevSecOps practices.
  • Scripting and automation experience using PowerShell, Python, REST APIs, or similar technologies.
  • Experience supporting SOC 2 & NIST CSF or comparable security and compliance frameworks.
  • Relevant certifications such as CompTIA Security+, CISSP, CCSP, AWS Certified Security, or equivalent certifications are preferred.
  • Excellent communication, documentation, project leadership, and problem‑solving skills.
  • Bachelor's degree in Computer Science, Information Technology or Cybersecurity or equivalent experience.
Success Criteria
  • Work ethic that aligns with KPA's core values:
    • Trust: earning trust through integrity, expertise, and acting in the client's best interest.
    • Innovation: continuously seeking out ways to better serve clients.
    • Excellence: holding ourselves to high standards in everything we do.
    • Results: moving with purpose to deliver meaningful outcomes.
  • Owns and continually improves KPA's enterprise security platforms and technical security controls.
  • Improves KPA's security posture across endpoints, identity, networking, cloud, and DevOps environments.
  • Delivers complex security initiatives with strong planning, communication, documentation, testing, and post‑implementation validation.
  • Reduces manual security work through automation and modern engineering practices.
  • Serves as the senior escalation point for complex security incidents and technical security issues.
  • Partners effectively with IT Operations and DevOps to embed security into operational and development workflows.
Physical Requirements

Physical demands described here are representative of those that must be met by an employee to successfully perform the essential functions of this job. Reasonable accommodations may be made to enable individuals with disabilities to perform the essential functions.

  • Working at a computer typing and view a screen - Constantly
  • Stationary sitting or standing - Constantly
  • Visual Recognition - Constantly
  • Hearing/Listening - Occasionally
  • Communicating verbally and/or in writing - Occasionally
  • Travel - Seldom
Compensation
  • Annual base salary range between $110-130k commensurate with experience.
  • Bonus potential of 10% annually
Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Information Security Engineer
Senior Information Security Engineer

Linuxconfig • Lafayette (CO), Northern (KY)

Hybrid
USD 110,000 - 150,000
Senior Security Engineer
Senior Security Engineer

Linuxconfig • Lafayette (CO)

On-site
USD 110,000 - 130,000
Senior Security Engineer
Senior Security Engineer

Kpaonline • Lafayette (CO)

On-site
USD 110,000 - 130,000
Annual bonus (10%)
Senior Cloud & Security Engineer
Senior Cloud & Security Engineer

Kpaonline • Lafayette (CO)

On-site
USD 110,000 - 125,000
Help Desk Technician
Help Desk Technician

Kpaonline • Lafayette (CO)

On-site
USD 45,460 - 49,593
Medical insurance
Dental insurance
Vision insurance
+2
Senior Security Engineer: Cloud, Identity & Automation
Senior Security Engineer: Cloud, Identity & Automation

Linuxconfig • Lafayette (CO), Northern (KY)

Hybrid
USD 110,000 - 150,000
Help Desk Technician
Help Desk Technician

KPA • Lafayette (CO)

On-site
USD 69,000 - 75,000
Medical Benefits
401k with company match
Paid time off
DevOps Engineer
DevOps Engineer

Jobfu • Westminster (CO)

On-site
USD 140,000 - 155,000
Annual bonus 10%
Competitive salary
Senior Software Engineer
Senior Software Engineer

CloudDevs • United States

Remote
USD 140,000 - 150,000
Medical Benefits
401k with Company match
Paid Time Off
Information Security Admin
Information Security Admin

Kforce Inc • Scottsdale (AZ)

On-site
USD 90,000 - 120,000
Medical benefits
Dental/Vision insurance
401(k) matching