Job Closed
This listing is no longer active.
Dayforce is a global HCM platform offering a comprehensive array of services encompassing payroll, HR, benefits, workforce management, talent, and analytics. With the mission of "m
Principal Cybersecurity Engineer
Location
United States
Posted
64 days ago
Salary
$111K - $198K / year
Seniority
Lead
Job Description
Principal Cybersecurity Engineer
Dayforce
Dayforce is a global human capital management (HCM) company headquartered in Toronto, Ontario, and Minneapolis, Minnesota, with operations across North America, Europe, Middle East, Africa (EMEA), and the Asia Pacific Japan (APJ) region. Our award-winning Cloud HCM platform offers a unified solution database and continuous calculation engine, driving efficiency, productivity and compliance for the global workforce. Our brand promise - Makes Work Life Better™ - Reflects our commitment to employees, customers, partners and communities globally. About the opportunity We are seeking a Security Engineer Prin with strong expertise in Identity and Access Management (IAM) to support and secure a FedRAMP ATO–authorized environment. The ideal candidate has hands-on experience designing, implementing, and operating Privileged Access Management (PAM) and Identity Governance & Administration (IGA) solutions while ensuring compliance with NIST 800-53 Moderate controls. This role requires deep technical skills in Delinea PAM, One Identity IGA, Microsoft Entra ID, Azure Automation and automation using PowerShell, calling API’s and modern scripting languages to support secure, scalable, and compliant cloud environments. What you'll get to do Identity & Access Management - Design, implement, and maintain Delinea PAM solutions for privileged account discovery, credential vaulting, session management, and just-in-time access. - Implement and support One Identity IGA for identity lifecycle management, access requests, approvals, certifications, and role-based access control. - Design, develop, and maintain API integrations between IAM platforms (Delinea PAM, One Identity IGA, Microsoft Entra ID) and non-identity systems, including ServiceNow, SIEM/SOAR platforms, and other enterprise applications. - Manage and secure identities in Microsoft Entra ID (Azure AD), including: - Conditional Access policies - MFA and passwordless authentication - Privileged Identity Management (PIM) - External and workforce identities Security Engineering & Automation - Develop and maintain PowerShell automation for IAM, PAM, and compliance workflows. - Create scripts and tools using Python, Bash, or other modern languages to integrate security platforms and automate controls. - Integrate IAM solutions with cloud platforms, SaaS applications, and on-prem systems. - Support secure API integrations and identity federation (SAML, OAuth 2.0, OIDC). - Automate identity lifecycle, access requests, approvals, provisioning, and deprovisioning workflows using REST APIs, webhooks, and scripted integrations. FedRAMP & Compliance - Implement and operate security controls aligned with NIST 800-53 Moderate. - Support FedRAMP ATO audits, assessments, and continuous monitoring activities. - Produce and maintain technical documentation, SOPs, and evidence artifacts. - Participate in vulnerability remediation, access reviews, and incident response related to identity security. - Ability to obtain and maintain Public Trust clearance Skills and experience we value - 5+ years engineering experience with IAM capabilities / technologies such as IGA, PAM, and IAM - Familiarity with Proofpoint email security platforms, including identity-based threat protection and user risk signals. - Experience implementing and managing FIDO2 / hardware security keys (e.g.,YubiKeys) for phishing-resistant authentication. - Expert knowledge and hands-on technical experience with MS Entra,Onprem Delinea PAM, IAM, and One Identity IGA solutions - Expert knowledge and hands-on technical experience with automation calling API’s - Expert knowledge of SSO, MFA, RBAC, MS Entra PIM - Highly proficient in automation scripting languages such as PowerShell - Superior communication skills (written and verbal) with an ability to articulate complex topics in a business understandable manner at all levels in an enterprise - Ability to prioritize workload and consistently meet deadlines in a fast-paced environment - Certifications such as CISSP, Cloud Security (CCSP, CCSK, AZ-305, AZ-500) are highly desirable - Bachelor’s degree is a plus What’s in it for you Dayforce is fueled by the diversity of our talented employees. We are an equal opportunity employer and consider and embrace ALL individuals and what makes them unique. We believe our employees should be happy and healthy, with peace of mind and a sense of fulfillment. We encourage individuals to apply based on their passions. Dayforce encourages personal and professional growth. We offer excellent time away from work programs, comprehensive wellness initiatives and recognition through competitive pay and benefits. With a commitment to community impact, including volunteer days and our charity, Dayforce Cares we provide opportunities for you to thrive both in your career and personal life. Our focus is not just on your job but on supporting you to be the best version of yourself. About the Salary Ranges Please note that the salary range mentioned in this job description should serve simply as a guide. The final compensation offered may vary based on a variety of factors, including bonuses and/or incentives, or a candidate’s experience, skills, budget and location. Our company is committed to providing a fair, equitable, and competitive package that reflects the value an individual brings to the organization. Fraudulent Recruiting Beware of fraudulent recruiting. Legitimate Dayforce contacts will use an @dayforce.com email address. We do not request money, checks, equipment orders, or sensitive personal data during the recruitment process. If you have been asked for any of the above, or believe you have been contacted by someone posing as a Dayforce employee, please refer to our fraudulent recruiting statement found here: https://www.dayforce.com/be-aware-of-recruiting-fraud Dayforce actively monitors all job applications to ensure authenticity. Submissions determined to be fraudulent or misleading will be declined from the recruitment process #LI-Remote
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
• Provide experienced leadership to guide the development of the front-end of the NATO DIANA OS application through a successful NATO Office of Security (NOS) accreditation process • Lead the successful security approval for each DIANA OS release • Develop and maintain a continuously updated Accreditation Pack aligned with NATO requirements • Produce a complete set of security artefacts ready for NOS/NCIA review • Provide input into the accreditation process being managed by other DIANA OS vendors • Promote a security-by-design foundation for future migration to Luxembourg Cyber Defence Cloud (LCDC) and uplift to NATO RESTRICTED
Information Systems Security Officer I
Bellese TechnologiesImproving the healthcare journey through civic innovation.
• (1) SIA Maintenance (Primary Focus): You will proactively identify system changes in HQR and QMARS and document them in a Security Impact Analysis (SIA) to ensure the ATO remains valid. • CFACTS Governance: You will serve as the "Source of Truth" for the system's security posture in CFACTS, managing control implementation statements and evidence. • Audit Defense & Evidence Gathering: You will lead the "Audit Season" efforts, gathering screenshots, logs, and process documentation to prove to CMS auditors that controls are "Effective." • Risk Advising: You will attend sprint ceremonies for HQR (50%) and QMARS (50%) to advise developers on CMS security standards before they build, preventing "security rework" later. • POA&M Life-cycle: You will track security weaknesses from discovery to remediation, ensuring the program meets CMS's strict 30/60/90-day patching windows. • Policy Stewardship: You will ensure all program documentation (Contingency Plans, Incident Response Plans) is reviewed and signed off annually per FISMA requirements.
Manager, Information Security
Neovia LogisticsA leading contract logistics provider, we solve mission-critical supply chain needs for customers around the world.
• Responsible for leading and maturing the company’s global information security polices, governance framework across warehouse and corporate environments. • Ensures that Neovia maintains a structured, risk-based, and scalable security posture aligned with business objectives, customer expectations, regulatory obligations and the ever-evolving threat landscape. • Maintains awareness of new threats and creates vehicles for quickly addressing day zero risks. • Supports global locations, ensuring that information security policies, standards and control objectives are consistently defined, governed and aligned with operational reality. • Drives the development and maintenance of the Information Security Management System (ISMS), supports certificate initiatives (ISO 27001 etc), oversees enterprise security risk management, and ensures structured audit readiness across regions by partnering with Neovia’s internal GRC and legal teams. • Responsible for the security strategy, working with Engineering and leadership to recommend software and solutions to solve complex problems and make Neovia safer. • Helps evaluate security capabilities, identify maturity gaps, and provide structured recommendations to IT and executive leadership to ensure ongoing improvement of Neovia’s security posture. • Owns end-user testing and education.
Who We Are Founded in 2012 by 3 expert hackers with no investment capital, Trail of Bits is the premier place for security experts to boldly advance security and address technology’s newest and most challenging risks. It has helped secure some of the world's most targeted organizations and devices. Our combination of novel research with practical solutions reduces the security risks that our clients face from emerging technologies. Our work helps drive the security industry and the public understanding of the technology underlying our world. Cybersecurity preparedness is a moving target. Companies like ours are the tip of the spear in the fight against attackers. Our research-based and custom-engineering approach ensures that our client’s capabilities are at the forefront of what’s available. For companies and technologies that live and die by their security, a proactive, tailored approach is required to keep one step ahead of attackers. Democratizing security information is essential. As part of our business, we provide ongoing informational support through blogs, whitepapers, newsletters, meetups, and open-source tools. The more the community understands security, the more they’ll understand why a company like ours is so unique and valuable. Role Trail of Bits seeks a Senior Security Engineer specializing in Application Security for Agentic AI systems, within our growing Software Assurance team. You will conduct comprehensive security assessments of large language model systems, examining software across the AI supply chain and application stack — such as LLM web applications, agentic coding tools, training data and inference pipelines, and guardrail mechanisms. Additionally, this role will be responsible for development, and operationalization of prompt injection techniques, for use in end-to-end application security reviews. You will identify and analyze novel attack vectors and vulnerabilities specific to AI and agentic environments, focusing on real-world failure modes, system integration issues, and unauthorized access vectors. This role allows you to apply application security experience and adversarial thinking to the latest agentic systems and buisness integrations. In addition to performing technical assessments, you will contribute to threat modeling, adoption risk frameworks for generative AI tooling, and delivering specialized training to clients on Agentic AI security concepts, including prompt injection, ML-specific attacks, and data pipeline threats. What You'll Achieve - Agentic AI Security Assessments: Conduct comprehensive application security assessments of agentic AI pipelines, tools, and frameworks for leading companies and labs. Examine vulnerabilities in model architectures, guardrails, and deployment infrastructure while developing mitigation strategies. - Prompt Injection Research & Development: Develop and share novel prompt injection techniques targeting agentic workflows, including indirect injection via tool outputs, multi-turn manipulation, and cross-agent exploitation. Produce actionable attack libraries and defensive countermeasures for client engagements. - Application Security Assessment: Conduct security assessments of client code bases using a combination of static analysis, dynamic testing, and manual code review, identifying vulnerabilities and developing mitigation strategies, with a focus on findings at the intersection of application security and Agentic AI security. - Threat Modeling: Conduct threat modeling and risk assessments to proactively identify potential risks for clients and develop mitigation strategies for future prevention, with particular attention to prompt injection attack surfaces in agentic orchestration layers. - Client Engagement: Work with leading industry teams to review system code and architecture, and help assure their products through system analysis and modeling. - AI Policy & Compliance Initiatives: Develop and contribute to AI regulatory frameworks, establishing assurance methods and auditing processes for mission-critical AI applications while ensuring alignment with emerging industry standards and safety requirements. What You'll Bring - AI Security Expertise: Demonstrated interest and experience in agentic AI security, with demonstrated ability to identify and mitigate AI-specific vulnerabilities across complex systems, including hands-on experience with prompt injection attacks and defenses. - Technical AI Knowledge: Deep understanding of AI/ML architectures, frameworks (PyTorch, Jax, LangChain, RAG systems, etc.), and MLOps practices, combined with robust security engineering expertise. - Application Security Skills: Track record of conducting technical security assessments of software, including software and system hardening, security policy analysis, and implementing effective security measures. - Prompt Injection Proficiency: Practical experience designing and executing prompt injection workflows against production LLM systems, agentic pipelines, and tool-use environments, including familiarity with emerging taxonomies and mitigation approaches. - Programming Proficiency: Strong knowledge of multiple programming languages such as Rust, Golang, Kotlin, Swift, Objective-C, JavaScript/TypeScript, Python, Ruby, C and/or C++ for both security analysis and tool development. - Hacker Mindset: A creative and adversarial mindset, with a passion for discovering novel attack vectors and understanding how systems work across many layers of abstraction. - Communication Skills: Ability to effectively communicate complex security concepts to diverse stakeholders and deliver clear, actionable recommendations. The base salary for this full-time position ranges from $100,000 to $200,000 excluding benefits and potential bonuses. Various factors influence our salary ranges, including the specific role, level of seniority, geographic location, and the nature of the employment contract. An individual's specific work location, unique skills, experience, and relevant educational background will determine the final offer within this range. The presented salary range encompasses the starting salaries for all U.S. locations. For a precise salary estimate tailored to your preferred location, please discuss it with your recruiter during the hiring process. Trail of Bits, Inc. participates in E-Verify, the US federal electronic employment eligibility verification program. Learn more. Only applications completed via our Careers page will be considered for further review. When you apply, you'll be added to our newsletter so you can stay updated on company news and opportunities. You can opt out anytime.



