> Markdown version of [/jobs/ext/1240995-senior-security-engineer](https://www.wearedevelopers.com/jobs/ext/1240995-senior-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Engineer - **Company:** Creative Realities, Inc. - **Location:** Louisville, KY, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Amazon Web Services, Computing Platforms, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Identity and Access Management, IT Management, Intrusion Detection and Prevention, Systems Development Life Cycle, Cloud Services, Security Information and Event Management, Software Engineering, Systems Integration, Software Vulnerability Management, Enterprise Software Applications, Information Technology, CIS Benchmarks, Security Orchestration, Automation & Response - **Published:** July 11, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=7f4798739e97af4b ## About the Role * Bachelor's degree in Cybersecurity, Computer Science, Information Technology, or a related field. * 5+ years of progressive experience in cybersecurity, cloud security, or security engineering. * Experience maintaining mature security programs supporting SOC 2 Type II, ISO 27001, NIST CSF, or CIS Controls. * Strong experience securing AWS and Azure cloud environments. * Experience with SIEM, EDR/XDR, IAM, vulnerability management, endpoint security, WAF, encryption, and cloud security technologies. * Experience supporting customer audits, security questionnaires, and third-party risk assessments. * Excellent written and verbal communication skills with both technical and business stakeholders. Required / Preferred Certifications Required: * CISSP, CISM, or equivalent security certification. Preferred: * AWS Certified Security - Specialty * Microsoft Certified: Azure Security Engineer Associate (AZ-500) * Certified Cloud Security Professional (CCSP) * GIAC security certifications Key Competencies / Behaviors * Professional demeanor with unquestionable integrity * Technical leadership and mentoring * Excellent problem-solving and analytical thinking * Ability to communicate security risks to executive leadership * Strong project management and collaboration skills * Self-motivated with a continuous learning mindset ## Description The Senior Security Engineer (SSE) is responsible for designing, implementing, and continuously improving the security posture of Creative Realities' cloud infrastructure, enterprise systems, and software platforms. This hands-on technical leadership role partners with Cloud Operations, IT, Engineering, Product, and Client Services to ensure the confidentiality, integrity, and availability of company and customer environments., The SSE is responsible for maintaining and continuously improving CRI's SOC 2 Type II security program, strengthening cloud security across AWS and Azure, integrating security into the Secure Software Development Lifecycle (Secure SDLC), and leading security operations, incident response, vulnerability management, identity and access management, and security automation initiatives. The SSE will work independently with direction from the VP of Cloud Operations and Security while serving as a trusted security advisor to internal teams and customers., * Maintain and continuously improve CRI's security program while supporting ongoing SOC 2 Type II compliance and applicable security frameworks. * Design, implement, and enforce security controls across AWS, Azure, and enterprise IT environments. * Lead vulnerability management, remediation tracking, and risk prioritization. * Manage Identity and Access Management (IAM), including SSO, MFA, privileged access, and least-privilege controls. * Develop, maintain, and lead incident response plans, security investigations, post-incident reviews, and forensic activities. * Partner with Engineering and Product teams to integrate security throughout the Secure Software Development Lifecycle (Secure SDLC). * Lead security architecture reviews for new cloud services, applications, and infrastructure. * Manage and improve SIEM, EDR/XDR, cloud security monitoring, and threat detection capabilities. * Develop security automation to improve operational efficiency, monitoring, and compliance validation. * Support customer security reviews, RFP responses, security questionnaires, and client assessments. * Conduct internal security reviews and support external audits. * Develop and deliver security awareness training and mentor technical staff on security best practices. * Evaluate emerging threats and recommend improvements to CRI's overall security posture. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [A practical guide to writing secure Dockerfiles](https://www.wearedevelopers.com/videos/109-a-practical-guide-to-writing-secure-dockerfiles) - [Thinking Differently - How to Make Money from Cyber Attacks & Cheats](https://www.wearedevelopers.com/videos/745-thinking-differently-how-to-make-money-from-cyber-attacks-cheats) - [Your Manager Doesn’t Come with a User Manual (But You Can Totally Write One)](https://www.wearedevelopers.com/videos/1495-your-manager-doesn-t-come-with-a-user-manual-but-you-can-totally-write-one) - [What makes Cybersecurity different for critical infrastructure?](https://www.wearedevelopers.com/videos/571-what-makes-cybersecurity-different-for-critical-infrastructure) - [OPA for the cloud natives](https://www.wearedevelopers.com/videos/713-opa-for-the-cloud-natives) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [The 12 Best Jobs for Software Engineers](https://www.wearedevelopers.com/magazine/401-the-12-best-jobs-for-software-engineers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Best Paying Jobs in Technology](https://www.wearedevelopers.com/magazine/256-best-paying-jobs-in-technology)