> Markdown version of [/jobs/ext/2659954-enterprise-security-engineer](https://www.wearedevelopers.com/jobs/ext/2659954-enterprise-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Enterprise Security Engineer - **Company:** The Apex - **Location:** Los Angeles, CA, United States - **Experience:** Experienced - **Salary:** $100,000.0 - $135,000.0 - **Contract:** Permanent contract - **Skills:** Kubernetes Security, Active Directory, Amazon Web Services, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Computer Programming, Computer Engineering, Domain Name System Security Extensions, Multi-Factor Authentication, Identity and Access Management, Intrusion Detection Systems, Information Systems Security Architecture Professional, Python (Programming Language), Network Security, Network Segmentation, OAuth, Open Web Application Security, Windows PowerShell, Systems Development Life Cycle, Remote Access Technology, Azure Active Directory, Zero Trust Network Access, Sherwood Applied Business Security Architecture, Security Assertion Markup Language (SAML), Secure Coding, Security Information and Event Management, Single Sign-On, Software Engineering, TCP/IP, Software Vulnerability Management, EndPointSecurity, Apex Code, Scripting, Google Cloud, Cloud Platform System, Software Security, Mitre Att&ck, Multi-Cloud, Cyber Threat Analysis, Firewalls (Computer Science), Cloudformation, Information Technology, Cybercrime, CIS Benchmarks, Restful APIs, Terraform, Splunk, Devsecops, Security Orchestration, Automation & Response, Static Application Security Testing, Vulnerability Analysis, Dynamic Application Security Testing - **Published:** August 24, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=e3758be9f0b9d876 ## About the Role The ideal candidate combines deep technical expertise with strong business acumen to develop security solutions that align with organizational objectives, regulatory requirements, and industry best practices., Bachelor's degree in Cybersecurity, Computer Science, Information Technology, Information Systems, Computer Engineering, or a related technical field. Preferred Master's degree in Cybersecurity, Information Security, Computer Science, or related discipline. Professional Certifications (Preferred) One or more of the following: * CISSP (Certified Information Systems Security Professional) * CISM (Certified Information Security Manager) * CCSP (Certified Cloud Security Professional) * SABSA Security Architecture Certification * AWS Certified Security - Specialty * Microsoft Azure Security Engineer Associate * GIAC Security Certifications (GIAC, GSEC, GDSA, etc.), * 7-10+ years of experience in cybersecurity, information security, network security, cloud security, or related IT disciplines. * 3-5+ years of experience designing security architectures or leading cybersecurity engineering initiatives. * Experience implementing enterprise security controls and security frameworks. * Experience securing cloud platforms such as AWS, Azure, or Google Cloud Platform., * Enterprise Security Architecture * Zero Trust Architecture * Secure-by-Design Principles * Threat Modeling * Security Control Design * Security Roadmap Development Network & Infrastructure Security * Firewalls * IDS/IPS * VPN Technologies * Network Segmentation * DNS Security * TCP/IP Protocols * Secure Network Design Cloud Security * AWS Security Services * Microsoft Azure Security Services * Google Cloud Security * Container Security * Kubernetes Security * Infrastructure as Code (Terraform, CloudFormation) Identity & Access Management * Active Directory * Entra ID (Azure AD) * Single Sign-On (SSO) * Multi-Factor Authentication (MFA) * OAuth * SAML * Privileged Access Management (PAM) Security Operations * SIEM Platforms (Elastic,Splunk) * Endpoint Detection & Response (EDR/XDR) * Vulnerability Management * Security Monitoring * Threat Intelligence * Incident Response Application Security * Secure SDLC * DevSecOps * Application Security Testing (SAST/DAST) * API Security * OWASP Top 10 * Secure Coding Practices Programming & Automation * Python * PowerShell * Bash/Shell Scripting * REST APIs * Security Automation Required Soft Skills * Strategic thinking and problem-solving * Strong analytical and risk assessment capabilities * Excellent written and verbal communication skills * Ability to communicate complex technical concepts to non-technical audiences * Leadership and mentoring skills * Project and stakeholder management * Cross-functional collaboration * Decision-making under pressure * Strong documentation and presentation skills, * Experience with large-scale enterprise environments. * Experience in regulated industries (financial services, healthcare, government, aerospace, defense, etc.). * Experience with cloud-native security and DevSecOps practices. * Knowledge of MITRE ATT&CK framework and threat intelligence methodologies. * Experience supporting security audits and compliance assessments. * Experience designing resilient and highly available security architectures. ## Description The Enterprise Security Engineer is responsible for designing, implementing, and maintaining secure enterprise architectures, systems, applications, networks, and cloud environments. This role provides technical leadership in cybersecurity strategy, risk management, security engineering, and compliance initiatives while ensuring Apex's information assets are protected against evolving cyber threats., Security Architecture & Design * Design and maintain enterprise-wide cybersecurity architecture aligned with business and technology strategies. * Develop secure architectures for cloud, on-premises, hybrid, and multi-cloud environments. * Create and maintain security standards, reference architectures, and technical design documents. * Perform threat modeling and security architecture reviews for new systems, applications, and infrastructure. * Evaluate emerging technologies and recommend security controls and solutions. Security Engineering & Implementation * Design, implement, and optimize security controls across networks, systems, endpoints, applications, and cloud platforms. * Lead deployment and integration of security technologies including SIEM, IDS/IPS, DLP, EDR/XDR, IAM, and vulnerability management platforms. * Develop and automate security processes using scripting and infrastructure-as-code methodologies. * Collaborate with infrastructure, application development, and cloud engineering teams to embed security into technology solutions. Risk Management & Compliance * Conduct security risk assessments, vulnerability assessments, and security audits. * Identify security gaps and develop remediation strategies. * Ensure compliance with applicable regulatory and industry frameworks, including: + NIST 800-53 + NIST 800-171/172 + ISO 27001 + CIS Controls + SOC 2 * Support governance, risk, and compliance (GRC) initiatives. Incident Response & Security Operations * Provide architectural guidance during cybersecurity incidents and investigations. * Support incident response, threat hunting, and forensic analysis activities. * Review security events and identify opportunities to strengthen defensive capabilities. * Assist in developing cyber resilience and business continuity strategies. Leadership & Collaboration * Serve as a cybersecurity subject matter expert for technical and business stakeholders. * Mentor junior cybersecurity engineers, analysts, and administrators. * Present security recommendations, risk assessments, and strategic initiatives to leadership. * Partner with IT, engineering, operations, legal, and compliance teams to support enterprise security objectives. ## Related Videos - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Keeping applications secure by evolving OAuth 2.0 and OpenID Connect](https://www.wearedevelopers.com/videos/100152-keeping-applications-secure-by-evolving-oauth-2-0-and-openid-connect) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Why Upskilling And Reskilling is Important For Developers](https://www.wearedevelopers.com/magazine/428-why-upskilling-and-reskilling-is-important-for-developers) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Is Software Engineering Over-Saturated?](https://www.wearedevelopers.com/magazine/418-is-software-engineering-over-saturated)