Senior Cybersecurity Engineer
Rockville, MDAll locationsRockville, MDAtlanta, GAHackensack, NJWashington, D.C.Austin, TXBoston, MACharlotte, NCDallas, TXDenver, CONew York, NYPhiladelphia, PAChicago, IL Remote
$100,000–$125,000 a yearJobFig found this opening at its original source and checks that it remains available.
About the role
Aprio’s Cybersecurity Engineering team builds and operates the controls that make the firm defensible: identity, network segmentation, cloud security baselines, endpoint, monitoring, encryption, and vulnerability management. The Senior Cybersecurity Engineer is the senior individual contributor on that team — the engineer who takes a control domain from “documented” to “running cleanly in production,” sets the standard for how it’s done, and pulls the Mid and Associate engineers up with them. This is a hands-on engineering role that also leads cross-team initiatives. This position supports U.S. Government engagements that may involve Controlled Unclassified Information (CUI) and requires access to export‑controlled technical data. In accordance with CUI and U.S. export control regulations, this position is limited to ‘U.S. persons’ (including U.S. citizens, lawful permanent residents, and certain protected individuals) as defined in 22 C.F.R. § 120.62. These requirements are only tied to this specific job posting. We are an equal opportunity employer and all Aprio employment decisions are made in accordance with applicable laws. You will own the operational health of one or two engineering domains, lead cross-team initiatives that touch multiple control areas, and design the patterns the rest of the team executes against.
What you'll bring
- 5+ years in security engineering, with hands-on responsibility for implementing controls across identity, network, cloud, endpoint, and/or monitoring.
- Strong fundamentals in IAM, network segmentation, encryption / key management, and centralized logging / monitoring.
- Experience with at least one major cloud platform (Azure, AWS, GCP) in a security-engineering capacity.
- Ability to produce clear architecture documentation, runbooks, and decision records that hold up under audit and peer review.
- Excellent written and verbal communication
- able to explain tradeoffs across Security, IT, and delivery audiences in plain language.
- Comfortable mentoring less senior engineers and owning quality-of-output for one or more domains.
- Regulated-environment experience (CMMC, NIST 800-171, NIST 800-53, FedRAMP-aligned, SOC 2, ISO 27001, HIPAA, PCI).
- Infrastructure-as-code experience (Terraform, Bicep, Pulumi) and policy-as-code (Sentinel, OPA).
- Security tooling integration experience (SIEM, EDR, vulnerability scanning, IAM, secrets management).
- Industry certifications (one or more): CISSP, CCSP, GIAC (e.g., GCED, GPEN, GCWN), AZ-500, AWS Security Specialty.
- Experience supporting a SOC’s detection/response engineering needs.