Job Closed

This listing is no longer active.

Zayo Group logo
Zayo Group

Zayo provides mission-critical bandwidth to the world’s most impactful companies, fueling the innovations that are transforming our society. Zayo’s 141,000-mile network in North America and Europe includes extensive metro connectivity to thousands of buildings and data centers. Zayo’s communications infrastructure solutions include dark fiber, private data networks, wavelengths, Ethernet, and dedicated Internet access. Zayo serves wireless and wireline carriers, media, tech, content, finance, healthcare and other large enterprises.

Senior Cybersecurity Engineer

Security EngineerSecurity EngineerFull TimeRemoteSeniorTeam 1,001-5,000

Location

United States

Posted

32 days ago

Salary

$95.1K - $146.3K / year

Seniority

Senior

Job Description

Senior Cybersecurity Engineer

Zayo Group

Role Description Our Senior Cybersecurity Engineer is responsible for protecting Zayo computer networks from cybersecurity attacks and unauthorized access, with a primary focus on the security, design, and operational integrity of Active Directory (AD) and hybrid identity environments. This role leads efforts to assess, harden, and modernize AD infrastructure, ensuring resilience against identity-based threats. The engineer partners with Cybersecurity, Infrastructure, and Cloud teams to implement secure identity architectures, enforce least privilege, and align with regulatory and security best practices. This role may require rotating 24x7 on-call support. - Design, implement, and secure Active Directory (AD) and Azure Entra ID environments, including hybrid identity configurations. - Lead Active Directory security assessments across enterprise AD forests, identifying misconfigurations, attack paths, and control gaps. - This role is focused on enterprise identity security, privileged access governance, and hybrid identity protection — not traditional Windows systems administration. - Partner with internal and external stakeholders to develop and maintain a prioritized remediation roadmap, aligned to: - Zayo risk posture - Regulatory requirements - Internal policies and security standards - Drive execution of remediation efforts to reduce AD-related risk and improve overall security posture. - Lead AD security hardening initiatives, including: - Tiered administration model (Tier 0/1/2) - Privileged access restrictions - Secure Group Policy design - Monitor and defend against identity-based attacks such as: - Pass-the-Hash / Pass-the-Ticket - Kerberoasting - Credential dumping - Implement and manage Privileged Access Management (PAM) and Privileged Identity Management (PIM) solutions. - Manage and secure Group Policy Objects (GPOs) to enforce enterprise security standards. - Oversee identity lifecycle processes within AD, including provisioning, deprovisioning, and access reviews. - Integrate AD with enterprise IAM platforms (e.g., SailPoint, CyberArk) and cloud identity providers. - Implement and maintain Multi-Factor Authentication (MFA) and Conditional Access policies. - Monitor AD logs and security events using SIEM tools; investigate anomalies and support incident response. - Develop and maintain automation scripts (PowerShell) for AD management, reporting, and security enforcement. - Collaborate with Red Team / Blue Team exercises to validate AD security posture. - Document AD architecture, configurations, and security standards. - Stay current with emerging threats, vulnerabilities, and best practices in AD and identity security. Qualifications - Bachelor’s degree in computer science, cybersecurity, or a related field (or equivalent experience). - Minimum of five (5) years of experience managing and securing Active Directory environments. - Demonstrated experience leading AD security assessments and remediation programs in complex enterprise environments. - Strong expertise in: - AD architecture (domains, forests, trusts) - Group Policy management - DNS, LDAP, Kerberos authentication - Hands-on experience with Azure Entra ID and hybrid identity architectures. - Experience with PowerShell scripting for automation and administration. - Strong understanding of identity-based attack techniques and mitigation strategies. - Experience with SIEM tools (e.g., Splunk, Sentinel) for monitoring and incident response. - Knowledge of security frameworks and compliance standards (NIST, ISO 27001, CIS Benchmarks). - Strong analytical, troubleshooting, and problem-solving skills. - Excellent communication and collaboration abilities. Preferred Qualifications - Experience implementing Tier 0/Tier 1/Tier 2 AD security models. - Familiarity with tools such as: - BloodHound - PingCastle - Microsoft Defender for Identity - Experience with Zero Trust architecture and identity-centric security models. - Exposure to IAM platforms (e.g., SailPoint) for identity governance integration. - Relevant certifications (e.g., Microsoft Certified: Identity and Access Administrator, CISSP, CISM). Tech Stack - Active Directory (AD DS) - Azure Entra ID - Group Policy (GPO) - PowerShell - SIEM (Sumologic) - Microsoft Defender for Identity - PAM / PIM solutions (CyberArk) Benefits - Excellent Health, Dental & Vision Insurance - Retirement 401(k) Savings Plan - Generous paid time off policy including paid parental leave

Related Categories

Related Job Pages

More Security Engineer Jobs

Full TimeRemoteTeam 51-200H1B Sponsor

• Formulating and executing service delivery strategies aligned with quality standards. • Working with clients to understand requirements and planning technical activities. • Leading project’s technical team within the scope of the engagement. • Documenting and presenting product security risks in both technical and business language. • Conducting technical QA and presenting deliverables to technical and business audiences. • Building and developing relationships with cross-client teams and partners. • Ensuring client satisfaction and business growth by communicating lessons learned.

Greece
Glean logo

Cloud Security Engineer

Glean

Search across all your company's apps to find exactly what you need and discover the things you should know.

Full TimeRemoteTeam 11-50H1B Sponsor

• Collaborate with cross-functional teams to design and architect secure cloud infrastructure solutions on AWS and Azure • Identify potential security vulnerabilities and gaps in existing infrastructure and propose remediation plans • Implement cloud-native security technologies and best practices to address identified gaps • Analyze security logs and metrics to proactively detect and respond to security incidents • Develop and deploy security controls, such as identity and access management (IAM), network security policies, and encryption mechanisms • Leverage software engineering skills to create security-specific features, particularly in the areas of authentication, authorization, and rate limiting • Create documentation and train and guide team members and other stakeholders on security best practices

United States
$153K - $238K / year
Job Closed
Glean logo

Software Engineer, Platform Security

Glean

Search across all your company's apps to find exactly what you need and discover the things you should know.

Full TimeRemoteTeam 11-50H1B Sponsor

• Design, develop, and maintain secure software for core platform functionalities • Collaborate with cross-functional teams (engineering, product) to integrate security best practices throughout the development lifecycle • Stay up-to-date on the latest security threats, vulnerabilities, and mitigation strategies • Conduct security code reviews and identify potential security risks in existing codebases • Develop and implement automated security testing procedures • Respond to security incidents and participate in incident response procedures • Continuously improve the platform's security posture by identifying and implementing security enhancements • Document security processes, procedures, and best practices

United States
$153K - $238K / year
Job Closed
Zscaler logo

Security Architect

Zscaler

Zscaler helps leading organizations in 180+ countries securely transform their networks and applications for a mobile and cloud-first world. Founded in 2008, th

Full TimeRemoteTeam 8,697Since 2007

• Build secure agent runtimes, libraries, and reference implementations while implementing core agent patterns like planner/executor, tool routing, and RAG boundaries • Build and secure MCP servers, clients, tool registries, and connector patterns with robust authentication, authorization, and audit logging • Enforce secure-by-default controls including schema validation, tool allowlists, redaction, and policy checks • Threat model and test agent workflows for prompt injection and data exfiltration to build repeatable security evaluations

California
$182K - $260K / year