Cybersecurity Sr Engineer

CBRE Group
Richardson, TX, United States
3 days ago
Apply on www.techcareers.com
Prepare application

Role details

Contract type
Permanent contract
Employment type
Full-time (> 32 hours)
Experience level
Expert
Working hours
Regular working hours

Tech stack

Artificial Intelligence Amazon Web Services Amazon Cloudfront Amazon Elastic Compute Cloud Amazon S3 Microsoft Azure Bash Shell Microsoft Online Services Cyber Security Databases Continuous Integration Relational Databases
+43 more
Software Debugging Software Design Patterns Linux DevOps Domain Name System (DNS) Github Identity and Access Management Python (Programming Language) Key Management Lightweight Directory Access Protocols (LDAP) PostgreSQL Microsoft SQL Server MySQL Object-Oriented Software Development Open Web Application Security Logstash Ansible Prometheus Ruby Software Engineering Systems Integration Datadog Data Logging DevOps Tools - Open-source Saltstack Large Language Models Multi-Agent Systems Software Security Backend Gitlab Git Concourse Kubernetes Infrastructure Automation Frameworks Route53 Api Design Api Gateway Terraform Software Version Control Devsecops AWS EKS Jenkins Golang

Job description

The mission of the individual in this role is to leverage their strong understanding of enterprise-level knowledge and/or expert knowledge to mitigate cyber security risk with a focus on agentic workflow engineering. They will actively work with the CBRE business, Digital & Technology and other partner organizations (Compliance, Risk Mgmt., Audit, & Legal) to seamlessly integrate security processes, tools, and people into the business culture providing a holistic security ecosystem, driving continuous improvements and seamless protection and monitoring capabilities globally. Leads and executes on complex initiatives that drive problem resolution, designing and operating the secure agentic AI workflows, automation, and platform services that underpin the Global Cyber Security Office DevSecOps ecosystem. As a senior member on the team, this individual will help shape the direction of a progressive product team with a mindset toward being agile and solving problems iteratively.

Experience in all skills listed is not necessary to be qualified for the position. If you have relevant similar experience, we still want to talk to you.

What you’ll do

  • Design, build, and operate agentic AI workflows and automation that orchestrate LLMs, tools, and enterprise systems to reduce manual toil across the Global Cyber Security Office, applying secure-by-design patterns and human approval gates for high-impact actions.
  • Develop and maintain Model Context Protocol (MCP) servers, tools, and agent integrations, enforcing least-privilege tool permission scoping, input and output validation, and guardrails against prompt injection, unsafe tool use, and data exfiltration.
  • Integrate agentic workflows with approved LLM and model services through the enterprise API gateway, implementing identity-aware access control, output filtering, and policy enforcement for responsible AI use.
  • Establish evaluation, testing, and runtime observability for agent behavior, including tracing, logging, and metrics that make agent decisions auditable and support incident response for AI security events.
  • Ensure operational integrity of Global Cyber Security Office DevSecOps application hosting and infrastructure, including hosting security tools and scanning agents, the internal security pipeline, and third-party vendor applications.
  • Administer and troubleshoot AWS EKS Kubernetes clusters, managing manifest and Helm chart lifecycle, global multi-region cluster failover, and disaster recovery plans.
  • Triage, debug, and perform root cause analysis across commonly used cloud provider services such as IAM, Compute, Storage, DNS, Certificate, and Secrets Management.
  • Build and maintain automation and governance around organizational secrets management, enforcing least-privilege access, rotation, and lifecycle controls for the machine and human identities used by agents and services.
  • Develop bespoke automation and integrations for backend systems using languages such as Python, Bash, Ruby, and/or Go, favoring modular, testable, configuration-driven, and idempotent designs.
  • Automate the collection of metrics from DevSecOps tools and implement AppSec log ingestion at scale using tools such as Logstash, Datadog, and Prometheus.
  • Track, compare, and report SLOs and SLIs against defined SLAs to ensure the reliability and availability of critical internal customer services, including the agentic platform.
  • Partner with platform, application, and security teams to operationalize secure agentic patterns, drive resolution of security findings, and mentor engineers on safe agent design and DevSecOps practices.
  • Contribute to policy, standards, and governance for agentic AI and automation, aligning controls with frameworks such as NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS.
  • Develop reporting exhibiting operational excellence and product performance metrics.
  • On-call rotation for ensuring uptime, and functionality of critical internal customer services.
  • Have well founded opinions and be willing to express your disagreement when something doesn’t pass the ‘smell test’ for you.
  • Other duties as assigned.
  • Mentors and coaches team members to further develop competencies. Leads by example and models behaviors that are consistent with the company’s values.

Requirements

  • Bachelor’s degree (BA/BS) in a related field of work plus a minimum of 3 years related work experience; or equivalent combination of education and experience (equivalent work experience = 2 years of related experience for every year of higher level education).
  • Advanced experience designing and operating automation or agentic AI workflows, including agent frameworks or orchestration and integration with LLM or model services
  • Working knowledge of the Model Context Protocol (MCP) specification, including its primitive types and the security implications of agentic AI tool-use patterns
  • Intermediate experience administering Kubernetes and managing manifests with Helm
  • Intermediate experience solutioning with AWS services such as IAM, KMS, EC2, EKS, S3, Route53, CloudFront, ACM, Secrets Manager
  • Intermediate experience solutioning and working with one or more other cloud providers aside from AWS such as GCP, Alibaba, Azure
  • Intermediate experience writing, and running Terraform
  • Intermediate Linux systems administrator experience or equivalent skills
  • Intermediate experience or equivalent skills with DevOps or CICD pipelines (GitHub Actions, GitLab, Jenkins, Concourse, etc.)
  • Intermediate experience with configuration management tools such as Chef, Ansible, or SaltStack, with a strong preference for Chef
  • Advanced experience automating multiple systems using functional and object-oriented languages such as Python, Bash, Ruby, and Go
  • Intermediate experience with RDBMS databases such as Postgres, MySQL, and MS SQL Server, and with vector storage solutions
  • Intermediate understanding of source control management and practices using Git, and GitHub
  • Intermediate understanding of Infrastructure as Code
  • Experience with the Microsoft ecosystem
  • Directory services like AD, and LDAP
  • Understanding and experience with backend software application development, including API development, and integrating with third party sources
  • Understanding of system integration design patterns at scale with experience in microservice design or development
  • Familiarity with AI security frameworks and guidance such as NIST AI RMF, OWASP LLM Top 10, and MITRE ATLAS
  • Understanding of prompt injection, unsafe tool use, and data exfiltration risks in agentic systems, and the defense-in-depth controls used to mitigate them
  • Strong written and verbal communication skills with the ability to explain complex cybersecurity and agentic AI concepts clearly across technical and business stakeholders. Able to document standards, author technical reports, and collaborate effectively across engineering, operations, and compliance teams.
  • Strong analytical and decision-making skills with experience solving complex cybersecurity problems. Able to evaluate competing technical solutions, apply risk-based reasoning, and deliver strategies that improve enterprise security posture and operational resilience., Applicants must be currently authorized to work in the United States without the need for visa sponsorship now or in the future.

About the company

When you join CBRE, you become part of the global leader in commercial real estate services and investment that helps businesses and people thrive. We are dynamic problem solvers and forward-thinking professionals who create significant impact. Our collaborative culture is built on our shared values - respect, integrity, service and excellence - and we value the diverse perspectives, backgrounds and skillsets of our people. At CBRE, you have the opportunity to chart your own course and realize your potential. We welcome all applicants., CBRE Group, Inc. (NYSE:CBRE), a Fortune 500 and S&P 500 company headquartered in Dallas, is the world’s largest commercial real estate services and investment firm (based on 2024 revenue). The company has more than 140,000 employees (including Turner & Townsend employees) serving clients in more than 100 countries. CBRE serves clients through four business segments: Advisory (leasing, sales, debt origination, mortgage serving, valuations); Building Operations & Experience (facilities management, property management, flex space & experience); Project Management (program management, project management, cost consulting); Real Estate Investments (investment management, development). Please visit our website at www.cbre.com., CBRE, Inc. is an Equal Opportunity and Affirmative Action Employer (Women/Minorities/Persons with Disabilities/US Veterans)

Apply for this position

This job is hosted externally. Click below to view the full posting and apply.

Apply on www.techcareers.com
Prepare application

Good distractions

Talks and stories from around this role — technically off-topic, practically not.

1:45 min

Transitioning from software development to security roles

Stefania Chaplin · World Congress 2022

6:21 min

Investigating push inefficiencies with upstream Git experts

Jonathan Creamer · Coffee With Developers

50 sec

Why developer happiness matters in web frameworks

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

2:18 min

Scaling MySQL databases for massive user growth

Johannes Nicolai Johannes Nicolai +1 · LIVE

4:01 min

Finding personal fulfillment in the cybersecurity industry

LIVE

56 sec

Favorite git commands and the importance of patch commits

Eileen Uchitelle Eileen Uchitelle +1 · Coffee With Developers

Videos

See all

Related articles

See all