> Markdown version of [/jobs/ext/2707817-security-engineer](https://www.wearedevelopers.com/jobs/ext/2707817-security-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Security Engineer - **Company:** Cleary Gottlieb Steen & Hamilton LLP - **Location:** New York, NY, United States - **Experience:** Expert - **Salary:** $160,000.0 - $185,000.0 - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Artificial Intelligence, Amazon Web Services, Microsoft Azure, Software as a Service, Cloud Computing Security, Cloud Engineering, Cyber Security, Information Systems, Computer Networks, Information Leak Prevention, Data Loss, Network Address Translation, Infrastructure as a Service (IaaS), Identity and Access Management, Log Analysis, Microsoft Software, Routing, Platform as a Service (PAAS), Role-Based Access Control, Security Information and Event Management, Software Engineering, Data Logging, Cloud Platform System, Office365, Firewalls (Computer Science), Build Management, Palo Alto Networks, Splunk, Devsecops, Cisco - **Published:** September 4, 2026 - **Apply:** https://careers-clearygottlieb.icims.com/jobs/1809/senior-security-engineer/job?mode=apply&apply=yes&in_iframe=1&hashed=-336061782 ## About the Role * Bachelor's degree in Information Systems, Information Security, Risk Management, or a related field * At least five years experience in Information Security or similar type role * Awareness of basic tenets of secure software development * Solid understanding of networking concepts, such as routing, firewalls, NAT translation, proxies, and other next gen SASE solutions. * Familiarity with Data Loss concepts and strategies * Deep level security information and event management (SIEM) log analysis * Ability to fulfill responsibilities in a timely manner and with exactitude * Extreme thoroughness and the ability to be directed on important initiatives, but to work independently to ensure the optimal outcome, reporting back to senior management on important milestones or issues that arise. * Several Information Security certifications are considered a significant plus (Microsoft, CISSP, CISM, Palo Alto, Splunk, Cisco are a few that would be considered standout achievements). ## Description AI and Agentic Security: * Lead the Firm's strategy, design, and implementation of scalable AI security and agentic security controls. * Work closely with the Firm's IT and AI acceleration teams to onboard newly developed AI use cases in a security manner, including end to end DevSecOps and CSPM tooling. Cloud Security: * Design, implement, and maintain a secure and resilient cloud architecture, encompassing Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS) solutions. This includes Azure, AWS, Office365, and all manner of SaaS applications. * Design and build continuous audit and alerting capabilities in our cloud environments using native toolsets. Identity and Access Management: * Develop and implement robust identity and access management strategies for cloud environments, ensuring proper authentication and authorization controls. * Monitor and manage user access permissions, following the principle of least privilege. Data Protection: * Use leading edge Microsoft 365 Security and Purview technologies to establish and enforce data protection policies to safeguard sensitive information. * Monitor for data leakage to and from the cloud and on prem. Incident Response: * Lead incident response efforts for security incidents, coordinating with internal and external stakeholders. * Implement logging and monitoring solutions to detect and respond to security events in real-time. Security Infrastructure Management: * Design, implement, and manage security infrastructure to safeguard the firm's networks, systems, and applications. * Conduct regular security assessments and vulnerability scans to identify and address potential risks. * Incident Response and Investigation * Lead incident response efforts and conduct thorough investigations in the event of security incidents or breaches. * Collaborate with legal and IT teams to ensure proper documentation and reporting of security incidents. Collaboration and Communication * Work with key stakeholders and internal IT contacts to conduct risk assessments against new technologies being considered for use. Formally document these risk assessments such that they can be easily understood by stakeholders. * Collaborate with IT, legal, and compliance teams to align security initiatives with overall business objectives. * Communicate security risks and recommendations to both technical and non-technical stakeholders. ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [How Cisco embraced a DevOps culture within its network engineering team](https://www.wearedevelopers.com/videos/99-how-cisco-embraced-a-devops-culture-within-its-network-engineering-team) - [Our journey with Spring Boot in a microservice architecture](https://www.wearedevelopers.com/videos/511-our-journey-with-spring-boot-in-a-microservice-architecture) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [You can’t hack what you can’t see](https://www.wearedevelopers.com/videos/41-you-can-t-hack-what-you-can-t-see) - [Computer Vision from the Edge to the Cloud done easy](https://www.wearedevelopers.com/videos/263-computer-vision-from-the-edge-to-the-cloud-done-easy) ## Related Articles - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Software Engineer Career: Things You Should Know](https://www.wearedevelopers.com/magazine/143-software-engineer-career-things-you-should-know) - [What is Software Engineering?](https://www.wearedevelopers.com/magazine/289-what-is-software-engineering)