Cerity Partners Tax, Accounting & Advisory Services is a highly sophisticated CPA and advisory practice serving high-net-worth individuals, multi-generational families, real estate investors, entrepreneurs, family offices, and closely held businesses. Our clients expect a high-touch experience and proactive advice. We emphasize planning and strategy—not simply preparing tax returns after the fact. We have been highly successful in attracting and retaining exceptional professionals because of the sophistication of our work, our flexible work environment and our firm culture. We maintain a two-level review process designed to ensure exceptional technical quality and client service. We also make a significant investment in training and professional development. All staff members are assigned a mentor ("buddy") and participate in regular monthly check-ins with principals and partners to support ongoing development, communication and career growth.
Cybersecurity Engineer
Location
United States
Posted
9 days ago
Salary
$115K - $130K / year
Seniority
Mid Level
Job Description
Cybersecurity Engineer
Cerity Partners
Role Description We are seeking a Cybersecurity Engineer with 3-5 years of hands-on experience to join our growing cybersecurity team. In this role, you will be responsible for the day-to-day engineering, administration, and optimization of our security tools and infrastructure. You will work closely with the Cybersecurity Manager and the broader IT team to implement, monitor, and improve the security controls that protect our Microsoft Azure / M365 cloud environment, endpoints, and data. This is a hands-on technical role with meaningful exposure to compliance frameworks, incident response, and vendor management - making it an excellent opportunity for someone who wants to grow their career across the full breadth of cybersecurity in a regulated financial services environment. Qualifications - 5 - 7 years of hands-on experience in cybersecurity engineering, security operations, or a closely related technical security role. - Strong working knowledge of Microsoft Azure and M365 security capabilities, including Entra ID (Azure AD), Conditional Access, Defender suite, and Purview. - Experience deploying, managing, and tuning EDR platforms (e.g., SentinelOne, CrowdStrike, Microsoft Defender for Endpoint). - Experience with SIEM platforms - log ingestion, correlation rule development, alert tuning, and dashboard creation (e.g., FortiSIEM, Sentinel, Splunk, or comparable). - Demonstrated experience managing enterprise patching programs across Windows endpoints and servers, with familiarity in patch management tooling (e.g., WSUS, Intune, SCCM/MECM, or third-party solutions). - Hands-on experience with vulnerability scanning platforms (e.g., Tenable, Qualys, Rapid7) including scan configuration, result analysis, and remediation workflow management. - Ability to assess and prioritize vulnerabilities using contextual risk factors beyond raw CVSS scores, including asset exposure, exploit availability, and business impact. - Solid understanding of identity and access management concepts including MFA, SSO, RBAC, and privileged access management. - Familiarity with endpoint management tools such as Microsoft Intune and application control technologies like AppLocker. - Experience with vulnerability management tools and processes (e.g., Tenable, Qualys, Rapid7). - Working knowledge of common security frameworks and standards (NIST CSF, CIS Controls, MITRE ATT&CK). - Competency in scripting for automation and reporting (PowerShell preferred; Python a plus). - Strong analytical and problem-solving skills with the ability to investigate complex security events across multiple data sources. - Excellent written and verbal communication skills - able to clearly explain technical security topics to both technical and non-technical audiences. - Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field - or equivalent practical experience. Requirements - Participate in incident detection, investigation, containment, and remediation activities. - Perform log analysis and forensic investigation across endpoint, network, identity, and cloud environments. - Document incidents thoroughly, including root cause analysis, timeline reconstruction, and lessons learned. - Coordinate with the managed SOC provider on alert escalation, tuning requests, and incident handoff procedures. - Contribute to the development and testing of incident response playbooks and procedures. - Support the ongoing maintenance of SOC 2 Type 2 compliance, including evidence collection, control testing, and audit coordination through our compliance automation platform (Drata). - Assist with the development, review, and enforcement of cybersecurity policies, standards, and procedures. - Contribute to vendor security assessments and due diligence reviews as part of our vendor risk management program. - Support Business Continuity Plan (BCP) documentation, tabletop exercises, and testing activities. - Help prepare materials and reporting for the Cyber Risk Steering Committee (CRSC) and other governance bodies. - Support the development and delivery of security awareness training and phishing simulation campaigns. - Serve as a knowledgeable security resource for IT colleagues and the broader organization, translating technical concepts into clear, actionable guidance. - Collaborate with cross-functional teams including IT infrastructure, compliance, and risk management to integrate security into business processes. Benefits - Health, dental, and vision insurance – day 1! - 401(k) savings and investment plan options with 4% match - Flexible PTO policy - Parental Leave - Financial assistance for advanced education and professional designations - Opportunity to give back time to local communities - Commuter benefits Company Description Cerity Partners is committed to providing an environment where all individuals can be their authentic selves. We are an Equal Opportunity Employer who respects each individual and supports the diverse cultures, perspectives, and experiences of our colleagues. We are dedicated to building an inclusive and diverse workforce and will not discriminate based on race, religion, national origin, sex, sexual orientation, age, veteran status, disability status, or any other applicable characteristics protected by law. Cerity Partners is committed to working with and providing accommodations to applicants with disabilities or special needs. For those needing accommodations, please reach out to careers@ceritypartners.com. Applicants must be authorized to work for any employer in the U.S.
Related Guides
Related Categories
Related Job Pages
More Security Engineer Jobs
Account Executive, Data Security – Majors
ZscalerWe make it easy to secure your cloud transformation. Get fast, secure, and direct access to apps without appliances.
• Serve as the primary specialist for customers, partners, and internal teams to drive revenue growth across the data security product portfolio • Partner with domain-expert solution engineers to capture customer requirements and craft compelling value propositions that close complex business deals • Own the regional quota and territory achievement by building and implementing account-based strategies to land and expand data security solutions • Collaborate synergistically with primary sales teams and leadership to ensure a unified and effective Zscaler presence in the market • Engage stakeholders across the organization, selling effectively to both C-suite executives and technical practitioners
• Monitor and triage security alerts from SIEM, EDR, and other tools; escalate and respond as needed. • Investigate security incidents, determine root cause, document findings, and develop IOCs to prevent recurrence. • Support escalations from internal employees or customers with security-related concerns. • Assist with security reviews related to infrastructure and system changes. • Build, enhance, and maintain internal security tooling and scripting repositories. • Contribute to the development of detection content, alert tuning, and automation pipelines. • Drive annual security team goals and cross-functional initiatives. • Author and maintain clear, actionable documentation and knowledge bases. • Mentor junior team members and share expertise across the organization. • Participate in a rotating on-call schedule for security operations support.
• Design and implement security solutions to enable customers to securely deploy and govern Claude Enterprise • Assess existing security, identity, data, cloud and SaaS architectures and advise on best-in-class solutions for securing enterprise AI tooling across customers in a wide range of industries • Conduct comprehensive evaluations of AI tools (e.g. Claude, Claude Enterprise), platform configurations, data access patterns, connector usage, security controls, processes and personnel to deliver informed recommendations leveraging your expertise in security engineering and AI governance • Design and implement security controls for enterprise AI platforms, including SSO, SCIM, RBAC, MFA, conditional access, admin roles, user lifecycle management, retention policies, audit logging, workspace controls, DLP, and acceptable-use enforcement • Assess and govern AI platform features such as file uploads, custom assistants, projects, GPTs, connectors, browsing, code execution, data analysis, plugins, agents, API access, and external sharing • Review and secure AI integrations with enterprise repositories and collaboration platforms, including Google Drive, SharePoint, OneDrive, Slack, Teams, GitHub, GitLab, Jira, Confluence, Salesforce, Snowflake, Databricks, and BI platforms • Manage and lead end-to-end AI Security Implementation efforts as part of a project team; including activities such as identity integration, access control design, data protection controls, AI platform configurations, connector governance, monitoring / logging and incident response workflows
Developer Intern, Data Security
1PasswordProductive businesses use 1Password to secure employees at scale.
• Be partially responsible for the underlying cryptography across our products. • Help build cryptographic libraries and implement the latest algorithms directly into our client applications with security, performance and usability in mind. • Develop proof-of-concepts and implement new industry specifications into code. • Conduct code and design reviews to ensure good cryptographic hygiene and standards across our codebase.




