Principal Service Engineer - Security Focused
Active
Job description
Working from industry-standard cybersecurity frameworks, you will lead multi-team programs spanning secure configuration and policy enforcement, identity and privileged access, vulnerability and configuration compliance, threat detection, and automated response. You will extend NDE's security programs into the cloud space using the industry-standard cybersecurity frameworks- governance and secure configuration standards, exposure and vulnerability management, identity and privileged access, configuration compliance, and threat detection and response - defining the controls, adoption plan, and success measures for each. You will lead AI-driven security operations across cloud, network, and infrastructure environments and define security standards for agentic systems that monitor, troubleshoot, configure, and remediate this estate, embedding AI-first security principles into their architecture, engineering, deployment, governance, and incident response, including least-privilege access for agents that operate network and infrastructure. You will respond to incidents and highly complex issues as a senior technical lead in the on-call (DRI) rotation - driving triage, root-cause analysis, containment, and enforcement actions - and then implement the automations and controls that prevent recurrence. You will build coalitions of support across Cloud Network Engineering, security, identity, and application teams to deliver difficult cross-organization projects, resolve team misalignments, and influence security policy, standards, and architectural review. You will ensure adherence to and implementation of security, privacy, and compliance standards - including threat modeling, proactive security reviews, penetration testing, SOX compliance, and audits - while developing thought leadership and mentoring other engineers. Embody our culture and values. Bachelor's Degree in Computer Science, Information Technology, Mechanical Engineering, Electrical Engineering, Aerospace Engineering, Data Science, Cybersecurity, or related field AND 6+ years technical experience in software engineering, network engineering, service engineering, systems engineering, or industrial controls OR equivalent experience. 5+ years technical experience working with large-scale cloud or distributed systems, including leading security architecture or security programs across multiple teams. Deep experience securing Azure network infrastructure - Network Security Groups, Application Security Groups, Azure Firewall and Firewall Manager, Web Application Firewall, DDoS Protection, NAT Gateway and SNAT behavior, Private Link and private endpoints, and hub-and-spoke topologies. Experience with enterprise hybrid connectivity and its security implications - ExpressRoute circuits, private peering and gateways, BGP and AS-path routing behavior, VNet peering, network zoning and trust boundaries, and DNS design including Anycast and Private DNS zones. Experience delivering security automation and infrastructure as code - ARM templates, Bicep or Terraform, PowerShell or Python, REST APIs, Azure DevOps pipelines, and policy-as-code. Experience applying a security framework such as the NIST Cybersecurity Framework 2.0 or Zero Trust to build and mature enterprise security programs, including threat modeling, security reviews, and audit and SOX readiness. Experience in SOC, SecOps, or InfoSec environments, including incident response, threat hunting, and vulnerability management across cloud and hybrid environments. Relevant industry certifications such as AZ-500, SC-100, CISSP, CCSP, CCNP or CCIE Security, OSCP, or SANS GIAC (GCIA, GCIH, GPCS).