> Markdown version of [/jobs/ext/3021834-sr-security-engineer-nyc-ny-hybrid-onsite](https://www.wearedevelopers.com/jobs/ext/3021834-sr-security-engineer-nyc-ny-hybrid-onsite). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Sr. Security Engineer, NYC NY - Hybrid Onsite - **Company:** Stellent IT LLC - **Location:** New York, NY, United States (Remote available) - **Experience:** Expert - **Salary:** $161,800.0 - $184,600.0 - **Contract:** Temporary to permanent - **Skills:** Microsoft Windows, Active Directory, Artificial Intelligence, Microsoft Azure, Cloud Computing, Cloud Computing Security, Cyber Security, Computer Networks, Dynamic Host Configuration Protocol, Domain Name System (DNS), Multi-Factor Authentication, Event Logging, Identity and Access Management, Intrusion Detection and Prevention, Intrusion Detection Systems, Virtual Private Networks (VPN), Network Security, Routing, Network Segmentation, Azure Active Directory, Runbook, Security Information and Event Management, Software Engineering, TCP/IP, Software Vulnerability Management, Cloud Platform System, Office365, Mitre Att&ck, Cyber Threat Analysis, Firewalls (Computer Science), Microsoft Fabric, AI Platforms, Information Technology, Cybercrime, Virtual Agents, CIS Benchmarks, Firewall Services Module, SentinelOne Expertise, Vulnerability Analysis - **Published:** September 21, 2026 - **Apply:** https://www.careerjet.com/jobad/us49b4beb181ef0a2dca02e50550ef9a63 ## About the Role * Bachelor's degree in Cybersecurity, Information Technology, Computer Science, or related field; equivalent experience may be considered. * 7+ years of cybersecurity experience, including security engineering, architecture, or advanced security operations responsibilities. * Experience leading security projects from planning and design through implementation and operational support. * Experience designing, implementing, and supporting enterprise security technologies and controls across cloud, network, endpoint, identity, vulnerability management, and monitoring domains. * Strong knowledge of security tools and platforms, including SIEM, EDR/EPS, IDS/IPS, vulnerability scanners, endpoint protection, email security, and network security solutions. * Experience securing cloud environments, preferably Microsoft Azure and Microsoft 365/O365, and working with cloud security architectures. * Strong understanding of networking concepts and protocols, including TCP/IP, DNS, DHCP, routing, switching, firewalls, VPN, WAFs, segmentation, and IDS/IPS/HIDS technologies. * Strong experience with Windows, Active Directory, Azure AD, Group Policy, event logs, and security hardening. * Understanding common attack patterns, threat progression, MITRE ATT&CK , NIST, CIS, and threat intelligence frameworks. * Experience supporting security programs within regulated industries such as financial services, banking, insurance, healthcare, or legal services. * Strong analytical, problem-solving, critical-thinking, troubleshooting, organizational, and prioritization skills. * Excellent written, verbal, and interpersonal communication skills, with the ability to communicate effectively with technical and non-technical stakeholders, including executive leadership. * Demonstrated ability to work independently and collaboratively, take ownership of issues, build relationships with technology teams, and influence security outcomes across the organization., * Experience with Microsoft Azure security services, Microsoft Entra ID, Microsoft Purview, DLP, and information protection technologies. * Experience with network firewalls, network segmentation, vulnerability management platforms such as Tenable, and endpoint security platforms such as SentinelOne or Microsoft Defender. * Experience with cloud security platforms or CNAPP technologies. * Experience supporting ISO 27001, NIST, or financial services compliance programs. * Industry certifications such as CISSP, CCSP, CISM, or equivalent certifications. ## Description Our client is seeking an experienced Senior Security Engineer to join its Information Security team within a fast-paced financial services environment. Reporting to the Cybersecurity Manager, this role will help design, implement, administer, and continuously improve enterprise security controls that protect the organization's systems, applications, networks, data, and information assets. The Senior Security Engineer will serve as a technical leader across identity and access management, cloud security, endpoint security, vulnerability management, network security, data protection, security monitoring, and incident response. This role partners with Infrastructure, Cloud, Networking, Application Development, business stakeholders, auditors, and security service providers to strengthen Our client's security posture, support regulatory and audit requirements, and advance strategic security initiatives. The ideal candidate brings strong technical judgment, communication skills, ownership, and a customer-service mindset, with experience applying security frameworks and controls aligned with ISO 27001, NIST CSF, NIST RMF, CIS Controls, SOC requirements, and financial services regulatory expectations. Core Responsibilities: * Design, implement, maintain, and continuously improve enterprise security controls across cloud, network, endpoint, identity, data protection, and monitoring domains. * Lead security engineering initiatives, including architecture reviews, secure design recommendations, technical implementation, and operational support of security technologies. * Manage and enhance identity security controls, including Microsoft Entra ID, Conditional Access, multi-factor authentication, privileged access management, role-based access controls, and identity governance. * Manage and optimize security tools and platforms, including endpoint protection, SIEM, DLP, vulnerability management, email security, network security, and cloud security solutions. * Lead vulnerability management activities, including assessments, remediation planning, risk prioritization, reporting, and coordination with technology teams. * Support incident response, threat hunting, root cause analysis, forensics, detection engineering, automation workflows, and incident response playbooks. * Develop and maintain security procedures and standards, technical baselines, procedures, guidance, and other governance materials. * Perform technical risk assessments and recommend risk mitigation strategies for systems, applications, vendors, infrastructure, cloud environments, and business processes. * Support regulatory, audit, and compliance initiatives, including ISO 27001, NIST Cybersecurity Framework, SOC examinations, and other applicable security standards. * Review and approve security-related changes to enterprise systems, including firewall rules, cloud configurations, privileged access requests, and infrastructure modifications. * Partner with IT and business teams to integrate security requirements into enterprise initiatives and operational processes while balancing security, operational, and business objectives. * Evaluate emerging cybersecurity threats, technologies, and industry best practices; recommend improvements to strengthen security maturity and operational effectiveness. Work Arrangements & Availability: * Our client offers a hybrid work program, with remote work opportunities based on role and department needs. Employees are expected to work in the office at least three days per week, with schedules determined by management based on business and operational requirements. * Candidates must be able to provide onsite support during business-critical incidents, technology outages, audits, and operational events, including occasional early morning coverage beginning as early as 7:00 AM or after-hours support when required., AI Engineer 4 (AI Foundations, VLM Customization) At Capital One, we are creating responsible and reliable AI systems, changing banking for good. For years, Capital One has been an… + 6 hours ago, AI Engineer 4 (Gen AI Platform Services: Agentic AI, Agent Guardrails, Agent Evaluation, Agent Memory) At Capital One, we are creating responsible and reliable AI systems, changing… + 6 hours ago ## Related Videos - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Creating a routing app with Google Maps API from scratch](https://www.wearedevelopers.com/videos/831-creating-a-routing-app-with-google-maps-api-from-scratch) - [An Applied Introduction to eBPF with Go](https://www.wearedevelopers.com/videos/1075-an-applied-introduction-to-ebpf-with-go) - [Technical Documentation - How Can I Write Them Better and Why Should I Care?](https://www.wearedevelopers.com/videos/681-technical-documentation-how-can-i-write-them-better-and-why-should-i-care) - [A Technical Introduction to Bitcoin's 2nd Layer- The Lightning Network](https://www.wearedevelopers.com/videos/15-a-technical-introduction-to-bitcoin-s-2nd-layer-the-lightning-network) - [Turning Container security up to 11 with Capabilities](https://www.wearedevelopers.com/videos/718-turning-container-security-up-to-11-with-capabilities) ## Related Articles - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing) - [Fully Remote Software Engineer Jobs](https://www.wearedevelopers.com/magazine/447-fully-remote-software-engineer-jobs) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed)