> Markdown version of [/jobs/ext/93588-senior-security-controls-engineer](https://www.wearedevelopers.com/jobs/ext/93588-senior-security-controls-engineer). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Senior Security Controls Engineer - **Company:** American Credit Acceptance - **Location:** Meridian, ID, United States - **Experience:** Expert - **Contract:** Permanent contract - **Skills:** Microsoft Windows, Amazon Web Services, Proxy Servers, Systems Engineering, Microsoft Azure, Cloud Computing Security, Configuration Management, Continuous Integration, Linux, Document Management Systems, Identity and Access Management, Information Technology Operations, Networking Hardware, Python (Programming Language), System Center Configuration Manager, Networking Basics, Routing, PCI Data Security Standards, Windows PowerShell, Cloud Services, Ansible, Security Information and Event Management, Software Vulnerability Management, Data Logging, Scripting, Firewalls (Computer Science), Microsoft InTune, Azure Security Center, Falcon Platform, Puppet, Terraform, SentinelOne Expertise, Qualys, Vulnerability Analysis - **Published:** May 27, 2026 - **Apply:** https://www.indeed.com/viewjob?jk=f1b3c8ab3e41149b ## About the Role Do you have experience in Windows?, * 7+ years in security engineering, systems engineering, or infrastructure engineering with a strong focus on security controls and hardening. * Hands-on expertise with Windows and Linux hardening, identity controls, and endpoint security control configuration. * Experience implementing benchmark-based configuration standards (e.g., CIS) and managing exceptions/risk acceptances. * Strong understanding of networking fundamentals (segmentation, firewalls, proxies, routing) and how to apply compensating controls. * Cloud security controls experience in Azure and/or AWS (IAM, network controls, logging, security services). * Proficiency in scripting/automation (PowerShell and/or Python); familiarity with infrastructure as code (e.g., Terraform) preferred. * Ability to translate risk into technical control requirements and document controls for audit and compliance purposes. * Excellent written and verbal communication; ability to work across infrastructure, application, and governance teams., * Experience with configuration management and compliance platforms (e.g., Intune, Group Policy, SCCM/MECM, Ansible, Chef, Puppet). * Experience with vulnerability scanning and exposure management tools (e.g., Tenable, Qualys, Rapid7) and mitigation engineering workflows. * Experience tuning EDR policies and implementing detection/response guardrails (e.g., Microsoft Defender for Endpoint, SentinelOne, CrowdStrike). * Experience with SIEM/SOAR integration for control telemetry and automated response. * Security certifications (one or more): CISSP, GIAC (GSEC/GCED/GCIA), CCSP, AZ-500, AWS Security Specialty, or equivalent. * Prior work in regulated industries (financial services, healthcare) with control evidence expectations (SOC 2, PCI DSS, GLBA)., This role requires the ability to work effectively with production systems and coordinate maintenance windows, change control, and emergency response activities when required. ## Description The Senior Security Controls Engineer designs, implements, and continuously improves technical security controls that reduce risk across on-premises, cloud, and endpoint environments. This role specializes in hardening, benchmark compliance, configuration risk reduction, compensating controls for non-patchable vulnerabilities, and control automation at scale. The engineer partners with IT operations, platform teams, and risk/compliance to ensure controls are effective, measurable, and audit-ready., * Engineer and maintain preventive and detective controls across endpoints, servers, network, identity, and cloud services (Azure/AWS). * Lead configuration hardening initiatives using industry benchmarks (e.g., CIS) and establish secure configuration baselines for common platforms (Windows, Linux, network devices, cloud services). * Design compensating controls for vulnerabilities that cannot be remediated through patching (e.g., configuration changes, isolation, access controls, WAF rules, EDR policy tuning, segmentation). Own the technical control lifecycle: control requirements design implementation testing/validation monitoring * continuous improvement. * Develop and maintain control-as-code and automation (PowerShell/Python/Terraform/CI-CD) to deploy and enforce configurations consistently. * Implement configuration compliance monitoring, drift detection, and remediation workflows; integrate with ticketing/ITSM for exception handling. * Partner with Vulnerability Management to translate findings into durable mitigations (hardening, compensating controls, secure defaults) and reduce recurring exposure. * Collaborate with SOC/IR to improve detections and containment policies aligned to threats and incidents; tune controls based on lessons learned. * Produce audit-ready evidence: control narratives, diagrams, test results, screenshots/exports, and KPI dashboards. * Maintain standards, procedures, and runbooks for control engineering; mentor junior engineers and provide technical leadership to cross-functional teams. Typical Deliverables * Secure configuration baselines and reference architectures for key platforms. * Benchmark compliance reporting (coverage, drift, exceptions) with remediation plans. * Compensating control designs and validation artifacts for non-patchable risk. * Automation modules/scripts (policy-as-code) to deploy or enforce controls at scale. * Control test plans, operational metrics, and audit evidence packages., * Control engineering mindset: designs controls that are measurable, testable, and durable. * Risk-based prioritization: focuses effort where likelihood and impact are highest. * Systems thinking: understands dependencies and minimizes operational disruption. * Automation-first: reduces manual work by codifying and scaling controls. * Stakeholder partnership: collaborates with IT and product teams to drive adoption., * Reduction in recurring high/critical findings attributable to configuration or control gaps. * Benchmark compliance coverage (%) and drift rate over time across in-scope assets. * Mean time to mitigate (MTTM) for non-patchable vulnerabilities using compensating controls. * Control effectiveness test pass rate and audit evidence readiness (time to produce evidence). * Automation impact: number of controls deployed/enforced via code and reduction in manual effort. ## Related Videos - [Docker network without Docker](https://www.wearedevelopers.com/videos/1418-docker-network-without-docker) - [Automate everything via NodeJS and Puppeteer](https://www.wearedevelopers.com/videos/322-automate-everything-via-nodejs-and-puppeteer) - [Security Pitfalls for Software Engineers](https://www.wearedevelopers.com/videos/726-security-pitfalls-for-software-engineers) - [Docker exec without Docker](https://www.wearedevelopers.com/videos/1094-docker-exec-without-docker) - [Checkmate: 5 Real Incidents That Can End a Software Company](https://www.wearedevelopers.com/videos/100126-checkmate-5-real-incidents-that-can-end-a-software-company) - [The Memory Leak That Ate Our Cluster: A Postmortem](https://www.wearedevelopers.com/videos/2057-the-memory-leak-that-ate-our-cluster-a-postmortem) ## Related Articles - [Events like RSAC Get You CISOs. Developers Decide What Actually Gets Deployed.](https://www.wearedevelopers.com/magazine/693-events-like-rsac-get-you-cisos-developers-decide-what-actually-gets-deployed) - [Understanding and Mitigating Common Web Vulnerabilities](https://www.wearedevelopers.com/magazine/565-understanding-and-mitigating-common-web-vulnerabilities) - [What Are The Top Skills Required For Azure Developers?](https://www.wearedevelopers.com/magazine/77-what-are-the-top-skills-required-for-azure-developers) - [9 Ways to Make Money Hacking](https://www.wearedevelopers.com/magazine/333-9-ways-to-make-money-hacking) - [Walking Into The Era of Supply Chain Risks](https://www.wearedevelopers.com/magazine/106-walking-into-the-era-of-supply-chain-risks) - [Dev Digest 134 - Where pixels sing?](https://www.wearedevelopers.com/magazine/477-dev-digest-134-where-pixels-sing)