Senior Security Engineer

Kforce Inc.
Scarsdale, NY, United States
13 days ago

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Experience required
5 years minimum
Working hours
Regular working hours
Job source

Tech stack

Artificial Intelligence Amazon Web Services Microsoft Azure Content Delivery Networks Cloud Computing Code Review Cyber Security Query Languages Identity and Access Management Virtual Private Networks (VPN) Information Systems Security Architecture Professional Python (Programming Language)
+16 more
Network Security Network Architecture Network Segmentation Open Web Application Security Windows PowerShell Zero Trust Network Access Security Information and Event Management Google Cloud Software Security HybridCloud Firewalls (Computer Science) Information Technology Firewall Services Module Service Stack Static Application Security Testing Dynamic Application Security Testing

Job description

Kforce has a client in Scarsdale, NY that is seeking a highly technical Security Engineer with expertise across cloud, identity, network, application, and enterprise security. The ideal candidate can secure and troubleshoot complex environments, review code, manage XDR/SIEM detections, lead incident response, automate security workflows, and translate technical controls into audit-ready compliance evidence. This position is on-site 3-days a week near Scarsdale, NY. Responsibilities:

  • Control Ownership: Design, deploy, and manage hands-on security controls across cloud, application, and network environments
  • Infrastructure Hardening: Hardened enterprise cloud environments, identity systems, network security groups, firewalls, and remote distributed edge systems
  • Security Operations: Monitor and tune the daily security stack (XDR, SIEM, and SOC workflows) by building custom detections and triaging alerts
  • Incident Response: Lead incident response end-to-end, including triage, containment, eradication, and root cause analysis
  • Network Segmentation: Maintain network architecture, including segmentation, firewall rules, VPNs, and Zero Trust access frameworks
  • AppSec & Code Review: Evaluate application code and system designs for security gaps, partnering with engineering on remediation
  • SecOps Automation: Automate repetitive security operations tasks through scripting to accelerate detection and response
  • Identity Management: Administer IAM systems, manage access reviews, audit privileged accounts, and enforce MFA/SSO
  • Compliance Maintenance: Maintain control evidence for regulatory frameworks, support auditor requests, and track remediation findings
  • Vendor Management: Direct external security service providers, retaining accountability for final delivery and outcomes
  • Policy & Training: Maintain internal security policies, support user awareness programs, and answer vendor security questionnaires

Requirements

  • Bachelor’s degree in Computer Science, IT, or a related field, or equivalent practical experience
  • Relevant industry certifications (e.g., AWS/Azure/GCP security, CISSP, GCIH, CySA+, or equivalent)
  • 7+ years of experience in information security with a focus on hands-on engineering, preferably in a regulated sector
  • 5+ years of experience securing hybrid cloud environments
  • Deep engineering experience managing security controls across diverse modern technology stacks
  • Expertise with enterprise cloud security architectures and centralized identity providers
  • Understanding of firewall rules, network segmentation, VPNs, and Zero Trust Network Access
  • Application security depth, including standard code reviews, OWASP top threats, and SAST/DAST tooling
  • Experience building and tuning detections in XDR, SIEM, and SOC environments
  • Proven incident response experience from initial triage through to root cause documentation
  • Ability (e.g., Python, PowerShell, or specialized query languages) to automate daily operations
  • Working compliance background with frameworks like SOC 2, NIST, or equivalent data privacy standards
  • Experience securing endpoint devices, including data encryption at-rest and in-transit across distributed physical assets
  • Familiarity with AI security, including securing corporate AI usage and evaluating AI-driven tools

Nice-to-Have:

  • SecOps automation leveraging advanced analytics or automation orchestration platforms
  • Experience with cloud firewalls and content delivery network (CDN) security
  • Experience securing specialized distributed hardware, endpoint kiosks, or public-facing remote equipment
  • Vendor risk management experience, including third-party risk tracking and due diligence
  • Familiarity with GRC systems or automated compliance tracking platforms
  • Exposure to agentic AI tooling or emerging AI governance programs
  • Experience working within a regulated, data-sensitive industry

Benefits & conditions

The pay range is the lowest to highest compensation we reasonably in good faith believe we would pay at posting for this role. We may ultimately pay more or less than this range. Employee pay is based on factors like relevant education, qualifications, certifications, experience, skills, seniority, location, performance, union contract and business needs. This range may be modified in the future.

We offer comprehensive benefits including medical/dental/vision insurance, HSA, FSA, 401(k), and life, disability & ADD insurance to eligible employees. Salaried personnel receive paid time off. Hourly employees are not eligible for paid time off unless required by law. Hourly employees on a Service Contract Act project are eligible for paid sick leave.

Note: Pay is not considered compensation until it is earned, vested and determinable. The amount and availability of any compensation remains in Kforce’s sole discretion unless and until paid and may be modified in its discretion consistent with the law.

About the company

By clicking ā€œApply Todayā€ you agree to receive calls, AI-generated calls, text messages or emails from Kforce and its affiliates, and service providers. Note that if you choose to communicate with Kforce via text messaging the frequency may vary, and message and data rates may apply. Carriers are not liable for delayed or undelivered messages. You will always have the right to cease communicating via text by using key words such as STOP.

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.kforce.com

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

6:10 min

Unlocking free learning credits via Google Cloud Innovators

Asrar Asrar Ā· WWC 2024

3:39 min

Addressing code review surrender and process exploitation

Laura Tacho Laura Tacho Ā· WWC Europe 2026

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

4:42 min

Container hosting options available on Google Cloud Platform

Federico Fregosi Ā· WWC 2022

56 sec

The hidden costs of delayed peer code reviews

Tim Gilboy Tim Gilboy

3:22 min

Transitioning from software engineering to security roles

Anna Oliveira Ā· Coffee With Developers

Videos

See all

Related articles

See all