Senior Security Engineer/Architect

Brownstein Hyatt Farber Schreck

Denver (CO)

On-site

USD 170,000 - 200,000

Full time

14 days+

Get more replies from employers

Send a job-specific resume in minutes.

Benefits offered by this job

Medical, Dental, Vision
401k+ match
Profit sharing
Vacation/Sick/Personal time off

Job summary

Brownstein Hyatt Farber Schreck is seeking a Senior Security Engineer / Architect in Denver. This high-visibility position involves leading security initiatives, mentoring team members, and acting as the principal architect for a robust security environment. The ideal candidate will have substantial experience in security engineering and will directly collaborate with leadership on defensive strategies.

We're offering a competitive salary ranging from $170,000 to $200,000 annually, along with a comprehensive benefits package.

Qualifications

  • 10+ years of progressive experience in information security.
  • Proven track record in leading security architecture initiatives.
  • Deep mastery of Microsoft enterprise security stack.

Responsibilities

  • Provide architectural oversight across the firm’s security stack.
  • Own the detection engineering lifecycle in the enterprise SIEM.
  • Lead the firm’s proactive threat hunting program.
  • Serve as the lead technical responder during significant security incidents.
  • Lead identity security strategy and drive secure configurations.

Skills

Information Security
Security Architecture
Detection Engineering
Incident Response
Microsoft Security Suite
Threat Analysis
PowerShell
Python

Education

Relevant Certifications (CISSP, GCIH, etc.)

Tools

Microsoft Entra ID
Microsoft Azure
Microsoft Sentinel
Microsoft Defender
SIEM Platforms

Job description

Overview

After opening its doors in Denver in 1968, Brownstein Hyatt Farber Schreck has since expanded around the country, with 14 offices, 700+ employees and 300+ attorneys and policy professionals nationwide. And with over 55 years in the industry, we’re committed to creating strong relationships with not only our clients, but with each other and our communities. Are you looking for camaraderie, collaboration and a challenge? Are you looking for an environment committed to creating strong relationships and a building a collaborative culture? If so, we want you at Brownstein.

At Brownstein, clients get access to the top legal minds in the industry, powerful policy knowledge, and best-in-class business acumen to solve businesses’ toughest challenges. Brownstein is a law and lobbying firm that has been making moves for more than 50 years to stay at the vanguard of its industry. You’ll find this firm at the heart of many of the most important cases, the most significant deals, and the country’s most pivotal legislation. Brownstein—we’re all in. For more information, visit us at bhfs.com.

We have an immediate need for a Senior Security Engineer / Architect to join our Denver office. This is a high-visibility, high-trust position for a seasoned practitioner ready to operate as the firm’s go-to technical expert across detection engineering, incident response, and security architecture. Working in close partnership with the CISO, you will shape the firm’s technical roadmap, lead the engineering execution behind the security strategy, and influence how the firm uses its security investments. You will be the lead technical voice during incidents, mentor the rest of the team, and support the CISO in representing the firm’s security capabilities to clients, regulators, auditors, and outside counsel.

If you are energized by the prospect of serving as the principal architect and lead technical defender for an organization where confidentiality is non-negotiable, and you want a role where your judgment carries weight at the leadership table alongside the CISO, we would like to meet you.

Essential Duties and Responsibilities
  • Security Architecture and Strategy
    • Provide architectural oversight across the firm’s security stack, ensuring that identity, endpoint, network, data, and cloud controls are designed and implemented coherently and in line with best practices.
    • Own the design, deployment, and continuous improvement of security controls and capabilities across Microsoft Entra ID, Conditional Access, Microsoft, Azure, and the broader Microsoft Defender suite (Endpoint, Identity, Cloud, Cloud Apps), driving appropriate utilization of the broader Microsoft security suite so that the firm consistently realizes the full value of its licensed protections and stays at the leading edge of Microsoft’s evolving security platform.
    • Serve as the CISO’s primary technical advisor on security design, investment, and risk decisions; partner on business case development and contribute to executive presentation of major initiatives.
    • Lead the technical evaluation of security technologies, including proof-of-concept design and vendor assessment, and develop recommendations that inform the CISO’s decisions on the firm’s security stack.
    • Partner with infrastructure, identity, and application teams to embed security into every project lifecycle, leading design reviews, threat modeling, and risk-based recommendations.
  • Detection and Response Engineering
    • Own the detection engineering lifecycle in the firm’s enterprise SIEM platform: develop, tune, and retire analytics rules; build and refine workbooks; and curate connectors and data sources to ensure high-fidelity visibility across the environment.
    • Design and thoughtfully implement User and Entity Behavior Analytics (UEBA) capabilities, baselining normal activity for users, service accounts, and entities, and tuning anomaly detections to surface meaningful risk while minimizing analyst fatigue.
    • Set the strategy for SIEM log onboarding, parsers, filters, and ingestion pipelines; balance signal fidelity against cost, and align telemetry with detection priorities.
    • Build and curate advanced KQL libraries, hunting notebooks, and automations (Logic Apps, playbooks, SOAR-style workflows) that elevate the entire team’s capability and accelerate triage, enrichment, and response.
    • Continuously benchmark detection coverage against current adversary tradecraft, with particular emphasis on threats targeting law firms and professional services organizations.
  • Threat Hunting and Threat Intelligence
    • Lead the firm’s proactive, hypothesis-driven threat hunting program: define methodology, set cadence, and own outcomes across endpoints, identity, email, cloud workloads, and SaaS, leveraging Sentinel, Defender XDR Advanced Hunting, and other tools.
    • Serve as the firm’s authority on adversary behavior relevant to legal services, translating industry, sector, and geopolitical threat intelligence into actionable detections, hunts, and architectural improvements.
    • Mature the firm’s threat hunting program over time, ensuring documented hypotheses, tracked coverage gaps, and a durable feedback loop into detection engineering and architecture.
  • Incident Response and Resolution
    • Serve as the lead technical responder during significant security incidents, directing investigation, containment, eradication, and recovery activities under the CISO’s overall incident leadership and in close partnership with IT leadership, outside counsel, and external IR partners as appropriate.
    • Lead deep-dive forensic analysis across Microsoft 365, Entra ID, Azure, endpoints, email, and network telemetry; reconstruct attacker activity; and produce clear, defensible findings suitable for executive, legal, and client audiences.
    • Author and maintain the firm’s incident response playbooks; co-lead executive tabletop exercises and after-action reviews with the CISO; and ensure lessons learned become durable engineering and architectural improvements.
  • Identity, Access, and Data Protection
    • Lead the technical execution of the firm’s identity security strategy, guiding architectural decisions across Entra ID, including Conditional Access, Privileged Identity Management, Identity Protection, and risk-based authentication, all aligned to a Zero Trust strategy.
    • Partner on the design and operation of data protection controls such as Microsoft Purview information protection, DLP, insider risk management, and eDiscovery considerations appropriate for a law firm environment.
    • Drive secure configuration baselines for Microsoft 365 and Azure workloads, including CIS, Microsoft Secure Score, and firm-specific hardening standards.
  • Program Leadership and Mentorship
    • Serve as the senior technical voice within the security team; mentor analysts and engineers, raise the bar on detection, hunting, and response, and contribute to hiring decisions for the function.
    • Support the CISO in client security reviews, third-party audits, and regulatory inquiries; act as the firm’s primary technical voice during high-stakes external engagements.
    • Help shape the firm’s security culture through clear, credible, and confident communication with non-technical audiences.
Required and Preferred Qualifications
  • Ten or more years of progressive experience in information security, including substantial time as a senior individual contributor in security engineering, detection engineering, or threat analysis roles.
  • Relevant certifications are valued and, in some cases, may substitute for portions of the experience requirements. Strong candidates will typically hold one or more of the following: CISSP, GCIH, GCDA, GCFA, OSCP, and/or related Microsoft certifications such as SC-100/200/300 and AZ-500.
  • A documented track record of leading security architecture and detection engineering initiatives end-to-end with measurable improvements to an organization’s security posture.
  • Deep, hands-on mastery of the Microsoft enterprise security stack, including Entra ID, Conditional Access, Microsoft 365, Azure, Microsoft Sentinel, and the Microsoft Defender suite.
  • Demonstrated experience setting detection engineering strategy in a modern SIEM, including authoring and tuning high-fidelity analytics rules, implementing and tuning UEBA, and managing log sources and ingestion economics at scale; advanced proficiency with KQL is required.
  • Proven experience serving as the lead technical responder or incident commander on significant security incidents, including investigations spanning cloud identity, email, endpoints, and SaaS.
  • Fluency with adversary tradecraft and frameworks including MITRE ATT&CK, the cyber kill chain, and Zero Trust architectural principles.
  • Recognized strength across core security architecture domains: identity, endpoint, network, email, data protection, and cloud security.
  • Scripting and automation depth in PowerShell and at least one general-purpose language (Python preferred) for detection, enrichment, response, and analytics workflows.
  • Sound judgment, discretion, and the ability to handle highly confidential client and firm information with care.
  • Exceptional written and verbal communication skills.

Compensation and Benefits: Brownstein Hyatt Farber Schreck offers a benefit package that includes medical, dental, vision, 401k+ match, profit sharing, and vacation/sick/personal time off. We are offering salary for this role, commensurate with experience ranging from $170,000 - $200,000 annually, and eligible for a discretionary bonus.

To Apply: Please submit a cover letter and resume

Get your free, confidential resume review.
or drag and drop your file here.
Similar jobs

Similar jobs worth comparing

Senior Security Engineer (Remote, NY, DC)
Senior Security Engineer (Remote, NY, DC)

MAP SSG • United States

Hybrid
USD 145,000 - 180,000
Hybrid work flexibility
Lead Engineer: Information Security
Lead Engineer: Information Security

Mayer Brown • Los Angeles (CA)

On-site
USD 135,000 - 180,000
Medical/dental/vision insurance
401(k) plan
Paid time off
Senior Security Architect & Detection Lead (MS Stack)
Senior Security Architect & Detection Lead (MS Stack)

Brownstein Hyatt Farber Schreck • Denver (CO)

On-site
USD 170,000 - 200,000
Medical, Dental, Vision
401k+ match
Profit sharing
+1
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Miami (FL)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Houston (TX)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Company-funded 401k contributions
Zero-cost employer-covered health insurance
+2
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Los Angeles (CA)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • Chicago (IL)

On-site
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+3
Senior Enterprise Systems Engineer
Senior Enterprise Systems Engineer

GT Restructuring • Town of Florida (NY)

Hybrid
USD 120,000 - 160,000
Security Architect
Security Architect

FBT Gibbons • Louisville (KY)

Hybrid
USD 100,000 - 130,000
Health care coverage
401(k) retirement plan with employer matching
Paid time off
Senior Security Client Solution Architect (Remote)
Senior Security Client Solution Architect (Remote)

Myriad360 • California (MO)

Remote
USD 250,000 - 275,000
Unlimited Paid Time Off (PTO)
Incentive compensation plans
Company-funded 401k contributions
+2