Senior Security Engineer

TAIT

Lititz (Lancaster County)

On-site

USD 120,000 - 180,000

Full time

7 days ago
Be an early applicant
Application generator

An application made for this job — a tailored resume and cover letter that speak straight to the posting.

Get past ATS filters

Job summary

TAIT is seeking a hands‑on Senior Security Engineer to mature and scale our Global Technology Services security program. This role blends strategy with execution, partnering with IT, operations, and business stakeholders to strengthen TAIT’s resilience across corporate IT, cloud, endpoints, and manufacturing-adjacent environments.

The ideal candidate will have 12+ years in information security, strong hands-on security control experience, and the ability to translate risk into practical security

Qualifications

  • 12+ years in information security or related roles.
  • Hands-on experience building and operating security controls in enterprise environments.
  • Practical knowledge of IAM: MFA, SSO, conditional access, privileged access.
  • Experience with endpoint protection, patching, and hardening.
  • Knowledge of network security: firewalls, VPNs, segmentation, monitoring.
  • Experience supporting incident response and investigations.
  • Ability to communicate risk to technical and non-technical audiences.

Responsibilities

  • Design, implement, and improve security controls across identity, endpoints, networks, cloud, SaaS, and data platforms.
  • Translate security strategy into practical roadmaps, standards, and implementations.
  • Hardening systems with IT and operations teams to reduce attack surface.
  • Evaluate tooling and improve coverage, config, monitoring, and integration.
  • Support secure architecture decisions for new systems and initiatives.
  • Strengthen identity security and least-privilege access across systems.
  • Improve vulnerability management, remediation tracking, and SLA reporting.
  • Improve logging, alerting, and detection capabilities.
  • Assist with incident response planning, tabletop exercises, and reviews.
  • Communicate security risks and recommendations to stakeholders.

Skills

Information security
Security engineering
IAM & MFA
Endpoint security
Vulnerability management
Network security
Incident response
Cross-functional collaboration
Secure architecture

Tools

Firewall technologies
VPNs & remote access

Job description

TAIT partners with artists, brands, IP holders and place makers to bring culture-defining, never-before-seen experiences to life. With a legacy of innovation spanning over 45 years, TAIT has grown from pioneering in rock ‘n’ roll concert staging to setting the global standard for extraordinary live events and experiences through cutting-edge technology, precision engineering, and creative design. TAIT’s 20 global offices have developed iconic productions and experiences in over 30 countries, all seven continents, and even outer space for renowned performers, theme parks, exhibits, and venues across the globe, including partnerships with Taylor Swift, Cirque Du Soleil, Royal Opera House, Nike, NASA, Bloomberg, Google, Beyoncé, and The Olympics
TAIT is looking for a hands‑on Senior Security Engineer (SSE) to help mature and scale our developing Information Security program within TAIT’s Global Technology Services ("GTS") team.
This role is ideal for someone who can operate across both strategy and execution—designing practical security controls, partnering closely with IT and operational teams, improving technical defenses, and reducing risk across corporate IT, cloud and SaaS platforms, endpoints, networks, identity systems, and manufacturing‑adjacent environments.
The successful candidate will be a senior individual contributor who can build, improve, and operationalize security controls—not simply identify gaps. This person will work closely with the VP, Cybersecurity, Security Analysts, IT Infrastructure teams, and business stakeholders to strengthen TAIT’s resilience against both known and emerging threats in a complex, global environment.

Key Responsibilities
Security Engineering
  • Design, implement, and improve security controls across identity, endpoint, network, cloud, SaaS, email, vulnerability management, and logging & data platforms.
  • Translate security strategy into practical technical roadmaps, standards, and implementation.
  • Partner with IT infrastructure and operations teams to harden systems, reduce attack surface, improve security posture, and shift security design to become a core component of infrastructure design.
  • Evaluate current security tooling and recommend improvements to coverage, configuration, monitoring, and integration.
  • Support secure architecture decisions for new systems, applications, infrastructure changes, and business initiatives.
Identity, Access, and Privilege Management
  • Strengthen identity security, including MFA, conditional access, SSO, privileged access, service accounts, and account lifecycle controls.
  • Help reduce excessive capabilities and improve least-privilege access across critical systems.
  • Partner with IT to improve privileged account management, administrative access, and remote access practices.
Endpoint, Vulnerability, and Threat Reduction
  • Improve endpoint security coverage, hardening, detection, and response capabilities.
  • Own or support vulnerability management processes, including scanning, prioritization, remediation tracking, and SLA reporting.
  • Work with IT teams to reduce exposure from unpatched systems, edge devices, VPNs, remote access platforms, and high-risk vulnerabilities.
  • Support ransomware resilience efforts, including backup validation, recovery planning, segmentation, and incident readiness.
Detection, Logging, and Incident Readiness
  • Improve logging, alerting, and visibility across critical systems and data.
  • Work with internal analysts and external providers to improve detection quality and response processes.
  • Support incident response planning, tabletop exercises, and technical response procedures.
  • Assist with post-incident reviews and drive security improvements based on lessons learned.
Governance Support and Risk Reduction
  • Support development of technical security standards, baselines, and procedures.
  • Provide technical input for security risk assessments, vendor reviews, audits, cyber insurance requests, and business security questions.
  • Help prioritize security work based on business risk, operational impact, and practical feasibility.
  • Communicate security risks and recommendations clearly to both technical and non-technical audiences.
Required Qualifications
  • 12+ years of experience in information security, security engineering, infrastructure security, or related technical roles.
  • Strong hands‑on experience implementing and operating security controls in enterprise environments.
  • Practical knowledge of identity and access management, including MFA, SSO, conditional access, privileged access, and directory services.
  • Experience with endpoint security platforms, vulnerability management, patching processes, and security hardening.
  • Working knowledge of network security concepts, including firewalls, VPNs, segmentation, secure remote access, and network monitoring.
  • Experience supporting incident response, security investigations, or security operations.
  • Ability to work effectively with infrastructure, helpdesk, operations, engineering, and business teams.
  • Strong communication skills, including the ability to explain technical risk in business terms.
  • Ability to operate independently in a small security team and prioritize work based on risk.

TAIT is an equal opportunity employer fully committed to diversity and inclusion in the workplace. All qualified applicants will receive consideration for employment without regard to race, color, religion, sex, sexual orientation, gender identity, national origin, disability, or status as a protected veteran or any other protected characteristic as outlined by international, national, state, or local laws.

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer: Resilient Cloud Security
Senior Security Engineer: Resilient Cloud Security

TAIT • Lititz

On-site
USD 120,000 - 180,000
Production Technician
Production Technician

TAIT • Lititz

On-site
USD 42,000 - 64,000
Medical, dental & vision insurance
HSA with employer contributions
Flexible Spending Accounts
+2
Production Technician-2nd Shift
Production Technician-2nd Shift

TAIT • Lititz

On-site
USD 48,000 - 60,000
Health insurance
401(k) plan with company match
Paid time off
+1
Quality Control Specialist
Quality Control Specialist

TAIT • Cumberland Heights (TN)

On-site
USD 50,000 - 70,000
Medical, dental, vision insurance
HSA with employer contributions
401(k) with company match
+2
Business Technology Partner - Global Procurement & Supply Chain
Business Technology Partner - Global Procurement & Supply Chain

TAIT • Lititz

On-site
USD 120,000 - 180,000
Medical insurance
Health Savings Account (HSA)
Flexible Spending Accounts (Medical)
+9
Quality Control Specialist
Quality Control Specialist

TAIT • Nashville (TN)

On-site
USD 42,000 - 64,000
Medical, dental, vision
HSA with employer contributions
401(k) with match
+1
Project Manager - Themed Entertainment
Project Manager - Themed Entertainment

TAIT • Orlando (FL)

On-site
USD 100,000 - 150,000
Medical, dental, and vision insurance
HSA with employer contributions
Flexible Spending Accounts (Medical &
Project Manager - Touring N.A.
Project Manager - Touring N.A.

TAIT • Lititz

On-site
USD 90,000 - 130,000
Medical insurance
Dental insurance
Vision insurance
+10
Project Manager
Project Manager

TAIT • Cumberland Heights (TN)

On-site
USD 90,000 - 130,000
Client Support Manager – Cruise market
Client Support Manager – Cruise market

TAIT • Lititz

On-site
USD 65,000 - 95,000
Medical, dental, and vision insurance
401(k) with company match
Paid vacation and 12 holidays
+1