Get a reply from this employer — a resume and cover letter tailored to exactly what they’re hiring for.
Lennar is seeking a Staff Security Engineer to own and drive security capabilities across cloud, network, data, and endpoint domains. You will lead engineering direction, guardrails, and hands-on cloud security for IaaS, PaaS, and SaaS environments in a senior technical ownership role.
You will mentor engineers, collaborate with architecture and development teams, and guide cross-domain security controls while aligning with legal and risk requirements.
Summary of Position: The Staff Security Engineer is the senior technical owner of the security capabilities the Enterprise Security Office runs: network security, data security, endpoint security, edge and web application protection, application security, security operations and SIEM, and vulnerability and posture management. The role sets engineering direction across all of these domains and keeps hands‑on ownership of cloud security for IaaS, PaaS, and SaaS environments.
Summary of Position: The Staff Security Engineer is the senior technical owner of the security capabilities the Enterprise Security Office runs: network security, data security, endpoint security, edge and web application protection, application security, security operations and SIEM, and vulnerability and posture management. The role sets engineering direction across all of these domains and keeps hands‑on ownership of cloud security for IaaS, PaaS, and SaaS environments.
This is an individual contributor role with technical leadership responsibility and no direct reports. The Staff Security Engineer works with security engineers, architects, infrastructure teams, and application development teams so that controls in every domain are designed, deployed, and configured correctly, and mentors senior and junior engineers on the team.
Own the cloud security strategy and its implementation across public cloud (IaaS, PaaS) and SaaS platforms, and lead the design, implementation, and management of:
Guide the design and operation of next-generation firewalls, remote access VPN, and cloud-native firewall controls covering traffic entering and leaving the network.
Guide the controls that prevent data loss through browsers, email, and removable media, including enterprise browser isolation, email security, and data classification and labeling.
Guide endpoint detection and response, application control, and server protection across laptops, desktops, and servers.
Guide web application firewall coverage and rule tuning for public-facing applications, including false-positive reduction with application owners.
Guide static and dynamic testing, dependency and secret scanning, and pipeline controls for cloud-native development and delivery platforms (DevOps, CI/CD), with remediation workflows run alongside development teams before and after code ships.
Contribute detection logic, log source onboarding, and automated response playbooks, support triage of complex or cross-domain alerts, and make sure cloud telemetry reaches the SIEM in a usable form.
Guide vulnerability scanning and posture assessment across endpoints, servers, and cloud, and drive prioritized remediation with infrastructure and application owners.
Contribute to the Cybersecurity Program and to the Security Engineering and Architecture roadmaps.
Meet legal, compliance, and regulatory requirements that apply to security controls in any domain, including cloud.
Provide input to Lennar's Risk Management, Compliance, and Incident Response teams for every domain the team owns.
Lead vendor and product evaluations, including requirements definition, proof of concept, risk assessment, procurement support, and selection recommendations.
Evaluate new and emerging services and technologies and recommend where they fit the existing control set.
Drive remediation